Log information management method and device, electronic equipment and storage medium

By judging the permissions of the target user and the encryption status of the log information in the log management system, decrypting the irreversible encrypted log information, solving the problems of convenience and security of log information acquisition in traditional systems, and achieving safe and reliable log information management.

CN120217437APending Publication Date: 2025-06-27BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510326225.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Traditional log management systems manage access rights to log information through whitelists, resulting in system users outside the whitelist being unable to obtain log information, reducing the convenience of use and posing a security risk of critical data leakage.

Method used

By responding to the target user's log query request, the matching log information set is obtained, and permissions are obtained based on the user category and business category. If the user does not have permissions, determine whether the key data of the log information is reversible encrypted information, and when it is determined that it is reversible encrypted, it is decrypted and irreversible encrypted to be displayed to the user.

Benefits of technology

Desensitization of log data is realized, ensuring the security of key data, and improving the convenience of log information, so that each user can obtain basic log information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217437A_ABST
    Figure CN120217437A_ABST
Patent Text Reader

Abstract

The invention discloses a log information management method and device, electronic equipment and a storage medium, and relates to the field of data acquisition, the method comprises the following steps: obtaining a log information set matched with a log query request in response to the obtained log query request of a target user; according to the user category of the target user and the service category of the current log information, when it is determined that the target user does not have the acquisition permission of the current log information and the key data of the current log information are reversible encryption information, decrypting the key data of the current log information, and performing irreversible encryption processing on a decryption result, and displaying the irreversible encryption result to the target user. According to the technical scheme, desensitization processing of the log data is achieved, the data safety of key data in the log information is ensured, each user in the log system has the permission to obtain the basic log information, and the use convenience of the log information is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encryption, and in particular to a method, device, electronic device, and storage medium for log information management. Background Art

[0002] Since log information contains a large amount of key data such as user behaviors, system operations, network accesses, etc., the security protection of log information has become an important issue for log management systems.

[0003] In traditional technical solutions, log management systems usually manage the access rights of log information through a whitelist, that is, users with the qualification to obtain log information are configured in the whitelist, and only users in the whitelist can obtain the log information in the system, while users outside the whitelist cannot obtain any log information, so as to ensure the data security of log information.

[0004] However, such a management method makes other system users outside the whitelist unable to obtain even basic log information, greatly reducing the usability of log information. If a system user is temporarily added to the whitelist for using log information, there is also a security risk of key data leakage during that period. Summary of the Invention

[0005] The present invention provides a method, device, electronic device, and storage medium for log information management to solve the problem that there are security risks in the key data of log information.

[0006] According to one aspect of the present invention, a method for log information management is provided, including:

[0007] In response to obtaining a log query request of a target user, obtaining a set of log information that matches the log query request; wherein, the set of log information includes at least one log information;

[0008] According to the user category of the target user and the service category of the at least one log information, determining whether the target user has the access right to each log information;

[0009] If it is determined that the target user does not have the access right to the current log information, determining whether the key data of the current log information is reversibly encrypted information;

[0010] If it is determined to be reversibly encrypted information, decrypting the key data of the current log information and performing irreversible encryption processing on the decryption result to display the irreversible encryption result to the target user.

[0011] After determining whether the key data of the current log information is reversibly encrypted information, it further includes: if it is determined that it is not reversibly encrypted information, performing irreversible encryption processing on the key data of the current log information to display the irreversible encryption result to the target user.

[0012] After determining whether the target user has the access right to each log information, it further includes: if it is determined that the target user has the access right to the current log information, determining whether the key data of the current log information is unencrypted information; if it is determined to be unencrypted information, displaying the current log information to the target user; if it is determined that it is not unencrypted information, performing decryption processing on the key data of the current log information and displaying the decryption result to the target user.

[0013] The irreversible encryption processing of the decryption result includes: determining the risk level of the target user according to the historical behavior record of the target user; obtaining a matching target encryption level according to the risk level of the target user; wherein different encryption levels correspond to at least one of different encryption methods, encryption ranges, and encryption degrees; performing irreversible encryption processing on the decryption result according to the target encryption level.

[0014] The determining the risk level of the target user according to the historical behavior record of the target user includes: obtaining a matching category association degree according to the user category of the target user and the service category of the current log information; determining the risk level of the target user according to the historical behavior record of the target user and the category association degree.

[0015] After displaying the irreversible encryption result to the target user, it further includes: in response to obtaining a download instruction for the log information set, performing encryption processing on the log information set to generate an encrypted log file; in response to obtaining a storage instruction, determining whether the storage location of the storage instruction is compliant; if it is determined that the storage location of the storage instruction is compliant, performing decryption processing on the encrypted log file to send the decrypted log file to the target user; if it is determined that the storage location is non-compliant, sending the encrypted log file to the target user.

[0016] According to another aspect of the present invention, there is provided a log information management device, including:

[0017] A log information acquisition module, configured to acquire a log information set matching the log query request in response to obtaining a log query request of a target user; wherein the log information set includes at least one log information;

[0018] An access permission determination module, configured to determine whether the target user has the access permission for each log information according to the user category of the target user and the service category of the at least one log information;

[0019] An encrypted information determination module, configured to determine whether the key data of the current log information is reversibly encrypted information if it is determined that the target user does not have the access permission for the current log information;

[0020] A decryption processing execution module, configured to perform decryption processing on the key data of the current log information and perform irreversible encryption processing on the decryption result if it is determined to be reversibly encrypted information, so as to display the irreversible encryption result to the target user.

[0021] According to another aspect of the present invention, there is provided an electronic device, where the electronic device includes:

[0022] At least one processor; and

[0023] A memory communicatively connected to the at least one processor; wherein,

[0024] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the log information management method according to any embodiment of the present invention.

[0025] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the log information management method according to any embodiment of the present invention when executed.

[0026] According to another aspect of the present invention, there is provided a computer program product including a computer program that implements the log information management method according to any embodiment of the present invention when executed by a processor.

[0027] The technical solution of the embodiment of the present invention, in response to obtaining a log query request of a target user, obtains a set of log information matching the log query request; according to the user category of the target user and the service category of the current log information, when it is determined that the target user does not have the access permission for the current log information, determines whether the key data of the current log information is reversibly encrypted information, and when it is determined to be reversibly encrypted information, performs decryption processing on the key data of the current log information and performs irreversible encryption processing on the decryption result, so as to display the irreversible encryption result to the target user. Thereby, not only the desensitization processing of log data is realized, ensuring the data security of the key data in the log information, but also each user in the log system has the access permission for the basic log information, greatly improving the convenience of using the log information.

[0028] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0030] Figure 1 is a flowchart of a log information management method provided according to Embodiment 1 of the present invention;

[0031] Figure 2 is a flowchart of another log information management method provided according to Embodiment 2 of the present invention;

[0032] Figure 3 is a flowchart of yet another log information management method provided according to Embodiment 3 of the present invention;

[0033] Figure 4 is a schematic structural diagram of a log information management device provided according to Embodiment 4 of the present invention;

[0034] Figure 5 is a schematic structural diagram of an electronic device for implementing the log information management method of the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0036] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0037] Embodiment 1

[0038] Figure 1 FIG. is a flowchart of a log information management method provided in Embodiment 1 of the present invention. This embodiment is applicable to the case of desensitizing key data of log information. This method can be executed by the log information management device in any embodiment of the present invention. The log information management device can be implemented in the form of hardware and / or software, and can be configured in an electronic device such as a server, as Figure 1 shown, the method includes:

[0039] S101. In response to obtaining a log query request of a target user, obtain a set of log information that matches the log query request; wherein, the set of log information includes at least one piece of log information.

[0040] The administrator can allocate the log acquisition permissions of each user in the server. For example, users with log acquisition permissions are assigned to the permission whitelist; when a log query request of a target user is obtained, all log information that matches the log query request is obtained to form a set of log information; then, it is judged whether the target user is in the permission whitelist. If the target user is in the permission whitelist, it is considered that the target user has the acquisition permission for all log information in the system, that is, at this time, the target user has the acquisition right for each piece of log information in the set of log information.

[0041] S102. According to the user category of the target user and the service category of the at least one piece of log information, judge whether the target user has the acquisition permission for each piece of log information.

[0042] The server can also classify the log information in the system by business. For example, according to the keywords, category identifiers, or source identifiers in the log information, different log information is assigned to different business categories to indicate that the log information belongs to a specific business category; at the same time, the administrator can also classify the users in the system according to the department or job responsibilities, and users in different user categories have the right to obtain log information in one or more business categories; for example, when the user category is an operation and maintenance user, it has the right to obtain operation and maintenance logs in the system but does not have the right to obtain transaction logs.

[0043] When the log information set includes multiple log information, for each log information, it is necessary to compare the business category of the current log information with the user category of the target user to determine whether the target user has the right to obtain the current log information; obviously, if the user category of the target user matches the business category of the current log information, the target user has the right to obtain the current log information; if the user category of the target user does not match the business category of the current log information, the target user does not have the right to obtain the current log information.

[0044] S103. If it is determined that the target user does not have the right to obtain the current log information, determine whether the key data of the current log information is reversibly encrypted information.

[0045] Each log information in the system may exist in two forms. One is in non-encrypted form, that is, there is no encryption information in the log information, and all data contents in the log information are saved in the system in an open data form, and all parameter information can be directly obtained through this log information; the other is in encrypted form, that is, one or more key data in the log information exist in encrypted form, and all parameter information cannot be directly obtained through this log information; among them, the key data includes keywords reflecting data information such as user behavior, system operations, network access, and user information.

[0046] In particular, to ensure the content integrity of the log information, the log information existing in the encrypted state in the system is obviously encrypted by a reversible encryption method; among them, reversible encryption means that the encrypted data can be restored to the original data through the decryption process. For example, the encryption operations are performed by symmetric encryption methods and asymmetric encryption methods; irreversible encryption means that the encrypted data cannot be restored to the original data through the decryption process. For example, the encryption operations are performed by hash functions and salted hashes.

[0047] S104. If it is determined that the key data of the current log information is reversibly encrypted information, decrypt the key data of the current log information and perform irreversible encryption processing on the decryption result to display the irreversible encryption result to the target user.

[0048] If the current log information exists in the form of reversible encrypted information, since the target user does not have the permission to obtain the log information, if the log information is displayed in the form of the current reversible encrypted information, there is a risk that the log information will be decrypted and restored. Therefore, it is necessary to perform irreversible encryption processing on the current log information. At this time, first, for the current reversible encrypted information, it is decrypted through a matching decryption method, and then the decryption result is subjected to irreversible encryption processing to display the irreversible encryption result to the target user to ensure the information security of the log information.

[0049] In particular, compared with directly performing irreversible encryption processing on the reversible encrypted information, the technical solution of the embodiment of the present invention first decrypts the reversible encrypted information to restore the log information to the original data form, and then performs irreversible encryption processing on the original data. This is because for reversible encrypted information, its encryption result may have a different number of data bits from the original data, and it is impossible to directly know the accurate number of data bits of the encryption result. If the reversible encryption result has more data bits than the original data, then when performing irreversible encryption processing on the reversible encrypted information, if the number of data bits of the original data is still used as the encryption object, some encryption results will not be used as the encryption object, resulting in incomplete encryption and still having a security risk of information leakage.

[0050] If the reversible encryption result has fewer data bits than the original data, other information will be misused as the encryption object, resulting in incomplete display of other information and affecting the usability of the log information. Therefore, in the embodiment of the present invention, the reversible encrypted information is first decrypted to ensure that the original data form with complete data bits is obtained, and then the original data is subjected to irreversible encryption processing, which not only ensures the complete encryption of the original data but also avoids redundant encryption of the displayable part of the log information.

[0051] Optionally, in the embodiment of the present invention, after determining whether the key data of the current log information is reversible encrypted information, it further includes: if it is determined that it is not reversible encrypted information, performing irreversible encryption processing on the key data of the current log information to display the irreversible encryption result to the target user. If the current log information does not exist in the form of reversible encrypted information but in the form of non-encrypted information, since the target user does not have the permission to obtain the log information, it is necessary to encrypt the log information. Among them, the encryption method can be randomly selected from a variety of reversible encryption methods, or it can be encrypted through a reversible encryption method matching the current business category according to the business category to which the current log information belongs, so as to ensure the display security of the log information.

[0052] Optionally, in the embodiments of the present invention, after determining whether the target user has the access right to each log information, the following steps are further included: If it is determined that the target user has the access right to the current log information, determine whether the key data of the current log information is unencrypted information; if it is determined to be unencrypted information, display the current log information to the target user; if it is determined that it is not unencrypted information, decrypt the key data of the current log information and display the decryption result to the target user.

[0053] Specifically, if it is determined that the target user has the access right to the current log information, it is also necessary to determine whether the key data of the current log information is unencrypted information. If it is determined to be unencrypted information, the current log information can be directly displayed to the target user; if it is determined that it is not unencrypted information, that is, encrypted information, then the key data of the current log information needs to be decrypted and the decryption result is displayed to the target user, so as to intuitively display all the data content of the log information to the user and improve the display effect of the log information.

[0054] Optionally, in the embodiments of the present invention, the irreversible encryption process for the decryption result includes: determining the risk level of the target user according to the historical behavior record of the target user; obtaining the matching target encryption level according to the risk level of the target user; where different encryption levels correspond to at least one of different encryption methods, encryption ranges, and encryption degrees; performing irreversible encryption on the decryption result according to the target encryption level.

[0055] Specifically, the historical behavior record reflects all the operation behaviors of the user in the log system, including the types, quantities, and frequencies of the log information obtained, or reflects all the operation behaviors of the user under the current business category, including the quantities and frequencies of the log information obtained under the current business category; according to the historical behavior record of the user, the behavior risks existing for the user or the behavior risks existing for the user under the current business category can be obtained; for example, for an operation and maintenance personnel, they usually only focus on operation and maintenance logs. If they frequently obtain transaction logs that are not related to their own responsibilities, then the behavior of this user obviously has a certain security risk. Therefore, through a risk prediction model or a risk mapping table, based on the historical behavior record of the user, the matching risk level can be obtained.

[0056] Under different risk levels, the encryption method, encryption scope, and encryption degree of the log information that the user does not have access to are different; among them, the encryption method refers to which specific encryption method is used for encryption. For example, the hash function or salted hash in the above technical solution; the encryption scope refers to which parameter items in a log information are encrypted. The number and type of parameter items to be encrypted are different for different encryption scopes. For example, the first-level encryption scope requires encrypting each parameter item in the log information, and the second-level encryption scope only requires encrypting the specified parameter items in the log information; the encryption degree refers to the number of encryption digits of the current parameter item to be encrypted. For example, for a mobile phone number, only the middle four digits can be encrypted, while the first three digits and the last three digits remain the original data unchanged, or all eleven digits can be encrypted so that all eleven digits are presented in the form of asterisks ("*").

[0057] For example, if the target user is an operation and maintenance personnel and their behavior of obtaining transaction logs is not frequent, and this behavior of obtaining transaction logs is an accidental behavior, it is speculated that the purpose of their obtaining transaction logs may be for normal operation and maintenance detection. Then, for the encryption of this log information, only general encryption operations are required, such as only encrypting the middle four digits of the mobile phone number, or only encrypting one or a few specified parameter items; but if their behavior of obtaining transaction logs is relatively frequent and this behavior of obtaining transaction logs is not an accidental behavior, and it is speculated that there may be other purposes for their obtaining transaction logs and there is a certain security risk, then for the encryption of this log information, a larger range of encryption is required, such as encrypting all digits of the mobile phone number, or encrypting a larger number of parameter items or all parameter items.

[0058] Accordingly, for a user who does not have access to the current log information, based on their historical behavior records in the log system or in the business category to which the current log information belongs, the specific encryption method, encryption scope, and encryption degree are determined, greatly improving the security of the log system, ensuring the information security of the log system, and avoiding the leakage of key data in the log information.

[0059] Optionally, in the embodiment of the present invention, the determining the risk level of the target user according to the historical behavior record of the target user includes: obtaining the matching category association degree according to the user category of the target user and the business category of the current log information; and determining the risk level of the target user according to the historical behavior record of the target user and the category association degree.

[0060] Specifically, the category correlation degree refers to the correlation degree between the user category of the target user and the business category of the current log information. As described in the above technical solution, if the user category of the target user and the business category of the current log information match, the target user has the access right to the log information. When the user category of the target user and the business category of the current log information do not match, the category correlation degree reflects the rationality of the target user's attempt to obtain the current log information.

[0061] If the user category of the target user does not match the business category of the current log information, but there is a certain business interaction with the current business category, or there is a certain business similarity, then the target user may attempt to obtain the log information under the current business category for data analysis or data testing. At this time, the behavior of the target user to obtain the log information of the current business category is reasonable, and the corresponding user risk level is relatively low. If the user category of the target user has no business interaction with the current business category and does not have business similarity, the behavior of the target user to obtain the log information of the current business category is unreasonable, and the corresponding user risk level is relatively high.

[0062] The category correlation degrees between each user category and different business categories are pre-configured. According to the user category of the target user and the business category of the current log information, the matching category correlation degree can be directly obtained. Then, after obtaining the risk level of the target user through the historical behavior record, the category correlation degree can be used as the calculation weight of the risk level, and the risk level after numerical correction can be obtained based on the category correlation degree, so as to perform irreversible encryption processing according to the risk level after numerical correction, further improving the security of the log system, ensuring the information security of the log system, and avoiding the leakage of key data in the log information.

[0063] In the technical solution of the embodiment of the present invention, in response to obtaining the log query request of the target user, a log information set matching the log query request is obtained. According to the user category of the target user and the business category of the current log information, when it is determined that the target user does not have the access right to the current log information, it is judged whether the key data of the current log information is reversible encrypted information, and when it is determined that it is reversible encrypted information, the key data of the current log information is decrypted, and the decryption result is irreversibly encrypted, so as to display the irreversible encryption result to the target user. This not only realizes the desensitization processing of log data, ensures the data security of the key data in the log information, but also enables each user in the log system to have the access right to the basic log information, greatly improving the convenience of using the log information.

[0064] Embodiment 2

[0065] Figure 2The flowchart of a log information management method provided in the second embodiment of the present invention. The relationship between this embodiment and the above embodiment is that the downloaded file of the log information set is encrypted again. As Figure 2 shown, the method includes:

[0066] S201. In response to obtaining a log query request of a target user, obtain a log information set that matches the log query request; wherein, the log information set includes at least one log information.

[0067] S202. According to the user category of the target user and the service category of the at least one log information, determine whether the target user has the access right to each log information.

[0068] S203. If it is determined that the target user does not have the access right to the current log information, determine whether the key data of the current log information is reversibly encrypted information.

[0069] S204. If it is determined to be reversibly encrypted information, decrypt the key data of the current log information, and perform irreversible encryption processing on the decryption result to display the irreversible encryption result to the target user.

[0070] S205. In response to obtaining a download instruction for the log information set, perform encryption processing on the log information set to generate an encrypted log file.

[0071] After presenting the log information set to the target user, if a download instruction issued by the target user is obtained, a log file is generated according to the log information set, and the log file is encrypted to generate an encrypted log file; wherein, the encrypted log file encrypts the original content of the file, that is, all the log information contained in the file, through a reversible encryption method to maximize the confidentiality and security of the file.

[0072] S206. In response to obtaining a storage instruction, determine whether the storage location of the storage instruction is compliant.

[0073] To ensure the security of log information, the log information in the log system is usually only allowed to be saved in a specified electronic device or storage address. When obtaining a storage instruction issued by the user again, accordingly, the device identifier for issuing the storage instruction, for example, the MAC (Media Access Control) address, or the address identifier, for example, the IP address (Internet Protocol Address), can be used to determine whether the storage location of the current storage instruction is compliant.

[0074] S207. If it is determined that the storage location of the storage instruction is compliant, decrypt the encrypted log file to send the decrypted log file to the target user.

[0075] If the device identifier that issues the storage instruction is in the valid device set, and / or the address identifier that issues the storage instruction is in the valid address set, it indicates that the storage location of the storage instruction is compliant. At this time, it is necessary to decrypt the encrypted log file to send the decrypted log file to the target user. In particular, after obtaining the download instruction, the log file is saved in the form of an encrypted log file, aiming to ensure that the generated file to be downloaded is also in an encrypted state, preventing the log file from being obtained by other means while the file itself is still in an encrypted state.

[0076] S208. If it is determined that the storage location is non-compliant, send the encrypted log file to the target user.

[0077] If the device identifier that issues the storage instruction is not in the valid device set, or the address identifier that issues the storage instruction is not in the valid address set, it indicates that the storage location of the storage instruction is non-compliant. The log file that is already in an encrypted state is directly sent to the target user to ensure the information security of the log file.

[0078] The technical solution of the embodiment of the present invention encrypts the log information set in response to obtaining the download instruction of the log information set to generate an encrypted log file; in response to obtaining the storage instruction, determines whether the storage location of the storage instruction is compliant; if it is determined that the storage location of the storage instruction is compliant, decrypts the encrypted log file to send the decrypted log file to the target user; if it is determined that the storage location is non-compliant, sends the encrypted log file to the target user. Thus, through the encryption process of the log file to be downloaded, the confidentiality and security of the log information are further improved.

[0079] Embodiment III

[0080] Figure 3 It is a flowchart of a log information management method provided by Embodiment III of the present invention. The relationship between this embodiment and the above embodiments is that the access permission of the target user and the data type of the key data of the log information are sequentially judged. As Figure 3 shown, the method includes:

[0081] S301. In response to obtaining the log query request of the target user, obtain the log information set that matches the log query request; wherein, the log information set includes at least one log information.

[0082] S302. Determine whether the target user has the access right to each log information according to the user category of the target user and the service category of the at least one log information; if not, execute S303; if so, execute S306.

[0083] S303. Determine whether the key data of the current log information is reversibly encrypted information; if so, execute S304; if not, execute S305.

[0084] S304. Decrypt the key data of the current log information, and perform irreversible encryption on the decryption result to display the irreversible encryption result to the target user.

[0085] S305. Perform irreversible encryption on the key data of the current log information to display the irreversible encryption result to the target user.

[0086] S306. Determine whether the key data of the current log information is non-encrypted information; if so, execute S307; if not, execute S308.

[0087] S307. Display the current log information to the target user.

[0088] S308. Decrypt the key data of the current log information and display the decryption result to the target user.

[0089] The technical solution of the embodiment of the present invention, in response to obtaining a log query request of a target user, obtains a set of log information matching the log query request; according to the user category of the target user and the service category of the current log information, when it is determined that the target user does not have the access right to the current log information, determines whether the key data of the current log information is reversibly encrypted information, and when it is determined that it is reversibly encrypted information, decrypts the key data of the current log information and performs irreversible encryption on the decryption result to display the irreversible encryption result to the target user. Thus, not only the desensitization processing of log data is realized, ensuring the data security of the key data in the log information, but also each user in the log system has the access right to the basic log information, greatly improving the convenience of using log information.

[0090] Embodiment 4

[0091] Figure 4 FIG. 4 is a structural block diagram of a log information management device provided in Embodiment 4 of the present invention, which specifically includes:

[0092] A log information acquisition module 401, configured to obtain a set of log information matching the log query request in response to obtaining a log query request of a target user; wherein, the set of log information includes at least one log information;

[0093] An access permission determination module 402, configured to determine whether the target user has the access permission for each piece of log information according to the user category of the target user and the service category of the at least one piece of log information;

[0094] An encrypted information determination module 403, configured to determine whether the key data of the current log information is reversibly encrypted information if it is determined that the target user does not have the access permission for the current log information;

[0095] A decryption processing execution module 404, configured to perform decryption processing on the key data of the current log information and perform irreversible encryption processing on the decryption result if it is determined to be reversibly encrypted information, so as to display the irreversible encryption result to the target user.

[0096] The technical solution of the embodiment of the present invention, in response to obtaining a log query request of a target user, obtains a set of log information matching the log query request; according to the user category of the target user and the service category of the current log information, when it is determined that the target user does not have the access permission for the current log information, determines whether the key data of the current log information is reversibly encrypted information, and when it is determined to be reversibly encrypted information, performs decryption processing on the key data of the current log information and performs irreversible encryption processing on the decryption result, so as to display the irreversible encryption result to the target user. Thereby, not only the desensitization processing of log data is realized, ensuring the data security of the key data in the log information, but also each user in the log system has the access permission for the basic log information, greatly improving the convenience of using the log information.

[0097] Optionally, the log information management device is further configured to perform irreversible encryption processing on the key data of the current log information if it is determined that it is not reversibly encrypted information, so as to display the irreversible encryption result to the target user.

[0098] Optionally, the log information management device is further configured to determine whether the key data of the current log information is non-encrypted information if it is determined that the target user has the access permission for the current log information; if it is determined to be non-encrypted information, display the current log information to the target user; if it is determined that it is not non-encrypted information, perform decryption processing on the key data of the current log information and display the decryption result to the target user.

[0099] Optionally, the log information management device is further configured to determine the risk level of the target user according to the historical behavior record of the target user; obtain a matching target encryption level according to the risk level of the target user; where different encryption levels correspond to at least one of different encryption methods, encryption ranges, and encryption degrees; perform irreversible encryption processing on the decryption result according to the target encryption level.

[0100] Optionally, the log information management device is further configured to obtain a matching category association degree according to the user category of the target user and the service category of the current log information; and determine the risk level of the target user according to the historical behavior record of the target user and the category association degree.

[0101] Optionally, the log information management device is further configured to, in response to obtaining a download instruction for the log information set, perform encryption processing on the log information set to generate an encrypted log file; in response to obtaining a storage instruction, determine whether the storage location of the storage instruction is compliant; if it is determined that the storage location of the storage instruction is compliant, perform decryption processing on the encrypted log file to send the decrypted log file to the target user; if it is determined that the storage location is non-compliant, send the encrypted log file to the target user.

[0102] The above device can execute the log information management method provided in any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method. Technical details not described in detail in this embodiment can be found in the log information management method provided in any embodiment of the present invention.

[0103] Embodiment Five

[0104] Figure 5 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, electronic devices, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0105] As Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0106] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0107] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the log information management method.

[0108] In some embodiments, the log information management method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit. In some embodiments, part or all of the computer program can be loaded and / or installed onto a heterogeneous hardware accelerator via the ROM and / or the communication unit. When the computer program is loaded into the RAM and executed by the processor, one or more steps of the log information management method described above can be executed. Alternatively, in other embodiments, the processor can be configured to execute the log information management method in any other appropriate way (e.g., by means of firmware).

[0109] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.

[0110] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or electronic device.

[0111] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0112] To provide interaction with a user, the systems and techniques described herein can be implemented on a heterogeneous hardware accelerator that has: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the heterogeneous hardware accelerator. Other kinds of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0113] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data electronic device), or a computing system that includes middleware components (e.g., an application electronic device), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0114] The computing system can include a client and an electronic device. The client and the electronic device are generally far from each other and typically interact through a communication network. The relationship between the client and the electronic device is created by computer programs that run on respective computers and have a client-server relationship with each other. The electronic device can be a cloud electronic device, also known as a cloud computing electronic device or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0115] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0116] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A log information management method, characterized in that: include: In response to obtaining a log query request of a target user, obtaining a log information set matching the log query request; wherein the log information set includes at least one log information; Determining whether the target user has permission to obtain each log information according to the user category of the target user and the business category of the at least one log information; If it is determined that the target user does not have the authority to obtain the current log information, determining whether the key data of the current log information is reversibly encrypted information; If it is determined to be reversibly encrypted information, the key data of the current log information is decrypted, and the decrypted result is irreversibly encrypted to display the irreversible encryption result to the target user.

2. The method according to claim 1, characterized in that After determining whether the key data of the current log information is reversibly encrypted information, it also includes: If it is determined that the information is not reversibly encrypted, irreversible encryption is performed on the key data of the current log information to display the irreversible encryption result to the target user.

3. The method according to claim 1, characterized in that After determining whether the target user has the authority to obtain each log information, the method further includes: If it is determined that the target user has the permission to obtain the current log information, determining whether the key data of the current log information is unencrypted information; If it is determined to be non-encrypted information, the current log information is displayed to the target user; If it is determined that it is not unencrypted information, the key data of the current log information is decrypted and the decryption result is displayed to the target user.

4. The method according to claim 1, characterized in that: The irreversible encryption processing of the decryption result includes: Determine the risk level of the target user based on the historical behavior record of the target user; According to the risk level of the target user, a matching target encryption level is obtained; wherein different encryption levels correspond to at least one of different encryption methods, encryption ranges, and encryption degrees; According to the target encryption level, irreversible encryption processing is performed on the decryption result.

5. The method according to claim 4, characterized in that Determining the risk level of the target user according to the historical behavior record of the target user includes: According to the user category of the target user and the business category of the current log information, obtaining a matching category association degree; The risk level of the target user is determined according to the historical behavior record of the target user and the category association degree.

6. The method according to claim 1, characterized in that After the irreversible encryption result is displayed to the target user, the method further includes: In response to obtaining a download instruction for the log information set, encrypting the log information set to generate an encrypted log file; In response to obtaining the storage instruction, determining whether the storage location of the storage instruction is compliant; If it is determined that the storage location of the storage instruction is compliant, decrypting the encrypted log file to send the decrypted log file to the target user; If it is determined that the storage location is not compliant, the encrypted log file is sent to the target user.

7. A log information management device, characterized in that: include: A log information acquisition module, configured to acquire a log information set matching the log query request in response to acquiring a log query request of a target user; wherein the log information set includes at least one log information; An acquisition authority judgment module, used to judge whether the target user has the acquisition authority of each log information according to the user category of the target user and the business category of the at least one log information; An encryption information judgment module, used to judge whether the key data of the current log information is reversibly encrypted information if it is determined that the target user does not have the access authority to the current log information; The decryption processing execution module is used to decrypt the key data of the current log information if it is determined to be reversibly encrypted information, and to irreversibly encrypt the decryption result so as to display the irreversible encryption result to the target user.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the log information management method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the log information management method according to any one of claims 1 to 6 when executed.

10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the log information management method according to any one of claims 1 to 6 is implemented.