Data processing method and device and electronic equipment
By identifying the request and response fields in the traffic data, and using preset key fields or neural network models to identify sensitive information, the problem of sensitive data leakage in digital products is solved, efficient and accurate protection of sensitive information is achieved, and security is improved.
Patent Information
- Application Number
- CN202410002663.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-07-04
AI Technical Summary
How to avoid sensitive data leakage in digital products, especially in restricted areas such as hospitals, to ensure that sensitive information does not flow out of the external network and is shared with other organizations.
By identifying request and response fields in traffic data, identify sensitive information using preset key field databases or neural network models, generate identification results, and manage them in embedded or monitoring mode to prevent sensitive information leakage.
It realizes efficient and accurate identification of sensitive information and timely prevention of leakage, improving the security of digital products, especially in monitoring mode, without affecting performance and security, and automatically terminates or discards sensitive information in embedded mode.
Smart Images

Figure CN120263744A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of information technology, and in particular, to a data processing method, apparatus, and electronic device. Background Art
[0002] As information technology becomes more and more popular, digital products are more and more widely used in all walks of life. The use of digital products can improve the work efficiency of all walks of life and reduce management costs. However, the application of digital products also faces various security problems, such as data destruction, data leakage, data tampering, etc.
[0003] For example, due to the restrictions of certain regional or hospital policies, patients' sensitive information can only be stored in the hospital intranet, and cannot be leaked to the extranet or shared with other organizations. Therefore, how to avoid sensitive data leakage to improve the security of digital products has become an urgent problem to be solved. Summary of the Invention
[0004] In view of at least one of the above problems, embodiments of the present application provide a data processing method, apparatus, and electronic device.
[0005] According to one aspect of the embodiments of the present application, a data processing method is provided, the method including:
[0006] Obtaining traffic data;
[0007] Identifying a request field or a response field in the traffic data;
[0008] Identifying whether the data related to the request or the response in the traffic data includes sensitive information, and generating an identification result.
[0009] According to one aspect of the embodiments of the present application, a data processing apparatus is provided, including:
[0010] An obtaining unit, which obtains traffic data;
[0011] A first identification unit, which identifies a request field or a response field in the traffic data;
[0012] A second identification unit, which identifies whether the data related to the request or the response in the traffic data includes sensitive information, and generates an identification result.
[0013] According to one aspect of the embodiments of the present application, a storage medium storing a computer-readable program is provided, characterized in that the computer-readable program causes a computer to execute the data processing method described in the foregoing aspect.
[0014] According to one aspect of the embodiments of the present application, an electronic device is provided, including the data processing apparatus described in the foregoing aspect.
[0015] With reference to the following description and the accompanying drawings, specific embodiments of the present application are disclosed in detail, indicating the ways in which the principles of the present application can be adopted. It should be understood that the embodiments of the present application are not limited thereby in scope. Within the scope of the terms of the appended claims, the embodiments of the present application include many variations, modifications, and equivalents.
[0016] Features described and / or illustrated for one embodiment can be used in the same or similar way in one or more other embodiments, combined with features in other embodiments, or substituted for features in other embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings included are used to provide a further understanding of the embodiments of the present application, which form a part of the specification, illustrate the embodiments of the present application, and together with the written description, explain the principles of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other embodiments based on these drawings without creative efforts. In the drawings:
[0018] Figure 1 is a schematic diagram of the data processing method of the embodiment of the present application;
[0019] Figure 2 is a schematic diagram of the implementation scenario of requests and responses of the embodiment of the present application;
[0020] Figure 3 is a schematic diagram of the implementation scenario of requests and responses of the embodiment of the present application;
[0021] Figure 4 is a schematic diagram of the monitoring mode data processing method of the embodiment of the present application;
[0022] Figure 5 is a schematic diagram of the embedded mode data processing method of the embodiment of the present application;
[0023] Figure 6 is a schematic diagram of the data processing device of the embodiment of the present application;
[0024] Figure 7 is a schematic diagram of an electronic device of the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] Referring to the accompanying drawings, the foregoing and other features of the embodiments of the present application will become apparent through the following description. In the description and drawings, specific embodiments of the present application are specifically disclosed, which show some embodiments in which the principles of the embodiments of the present application can be adopted. It should be understood that the present application is not limited to the described embodiments. On the contrary, the embodiments of the present application include all modifications, variations, and equivalents falling within the scope of the appended claims.
[0026] In the embodiments of the present application, terms such as "first" and "second" are used to distinguish different elements in terms of name, but do not represent the spatial arrangement or time sequence of these elements, and these elements should not be limited by these terms. The term "and / or" includes any one and all combinations of one or more of the associated listed terms. Terms such as "comprising", "including", "having", etc. mean the presence of the stated features, elements, components, or assemblies, but do not exclude the presence or addition of one or more other features, elements, components, or assemblies. In the embodiments of the present application, similar words such as "connected", "coupled", etc. do not limit to physical or mechanical connections, but may include electrical connections, whether directly or indirectly connected.
[0027] In the embodiments of the present application, the singular forms "a", "the", etc. include the plural forms and should be broadly understood as "a kind of" or "a class of" rather than being limited to the meaning of "one"; in addition, the term "the" should be understood to include both the singular form and the plural form unless the context clearly indicates otherwise. In addition, the term "according to" should be understood as "at least partially according to...", and the term "based on" should be understood as "at least partially based on...", unless the context clearly indicates otherwise.
[0028] Features described and / or illustrated for one embodiment can be used in the same or similar manner in one or more other embodiments, combined with the features in other embodiments, or replace the features in other embodiments. The term "comprising / including" as used herein means the presence of features, whole, steps, or components, but does not exclude the presence or addition of one or more other features, whole, steps, or components.
[0029] The embodiments of the present application relate to "microservices", which are designed to decouple the solution by decomposing functions into discrete services. A large single application and service can be split into several or even dozens of supporting microservices, which can scale individual components rather than the entire application stack to meet service level agreements. Microservices create applications around business domain components, and these applications can be developed, managed, and iterated independently. Using cloud architecture and platform-based deployment, management, and service functions in decentralized components makes product delivery simpler.
[0030] An embodiment of the present application proposes a data processing method.
[0031] Figure 1 It is a schematic diagram of the data processing method according to the embodiment of the present application. As Figure 1 shown, the method includes:
[0032] 101. Obtain traffic data;
[0033] 102. Identify the request field or response field in the traffic data;
[0034] 103. Identify whether the data related to the request or the response in the traffic data includes sensitive information, and generate an identification result.
[0035] In some embodiments, the traffic data may be the traffic data between the client (front-end) and the server (back-end), or may be the traffic data between the client (front-end) and the device (back-end, such as a medical device). Among them, the front-end and the back-end are connected through the public network. The traffic data may be a log file recording the data transmission between the front-end and the back-end. When data is transmitted between the front-end and the back-end, the data will pass through devices such as routers, gateways, and firewalls. These devices will monitor and record the data transmission situation and record it in the log file. The traffic data usually includes a timestamp, source address, destination address, protocol type, data size, data transmission status, etc. The protocol types applicable to the embodiments of the present application include but are not limited to the HTTP or HTTPS protocol.
[0036] In some embodiments, in 101, the traffic data from the front-end or the traffic data from the back-end may be obtained. Among them, the traffic data may be obtained from the aforementioned routers, gateways, or firewalls and other devices, or the existing scraping method may be used to obtain the traffic data. For example, the existing network data collection and analysis command statement "tcpdump" is used to capture the traffic data. The embodiments of the present application do not limit this. The traffic data may be plaintext data.
[0037] In some embodiments, the front end may send a request to the back end, and the back end may not send a response to the front end after receiving the request. For example, when the front end uploads data to the back end, it may only send a request and does not need to receive a response. Or, the front end may send a request to the back end, and the back end may send a response to the front end based on the request after receiving the request. For example, when the front end queries information from the back end, it may send a query request to the back end, and the back end returns the query result to the front end through the response. Or, the front end may not send a request to the back end, and the back end actively sends a response to the front end. For example, the back end periodically reports status information to the front end through the response. The embodiments of the present application are not limited thereto. Among them, the foregoing request and response are included in the traffic data. The request includes data related to the request, such as a request line, request headers, a request body, etc. The response includes data related to the response, such as a response line, response headers, a response body, etc. For example, the data related to the request or response (such as the request body or response body) may use the JSON format and carry data related to the service, but the embodiments of the present application are not limited thereto. The data related to the request or response (such as the request body or response body) may include parameters related to the request or response. Optionally, it may further include the values corresponding to the parameters.
[0038] Figure 2 is a schematic diagram of an implementation scenario in the embodiments of the present application, as Figure 2As shown, a client (such as a browser, application, etc.) can send a request to a server. After receiving the request, the server parses the request and performs business processing. After the business processing, the server needs to return the result of the business processing, i.e., the response, to the client. For example, if the front end hopes to query the information of patient XX, it can send a request to the back end. The request includes "select * from patient_name = XX", where the parameters include the query field "select" and the patient name field "patent_name", and the corresponding value of the parameter is XX. After receiving the request, the back end can search in the database, remote dictionary service redis, cache, and memory, and return a response to the front end. The response includes the query result. Optionally, the request can also include "select_location = redis", where the parameter includes the query location field "select_location", and the corresponding value of the parameter is redis. After receiving the request, the back end only searches in the remote dictionary service redis to check if the patient name XX exists. For example, if the front end hopes to query the information of all patients, it can send a request to the back end. The request includes "select * from all patient_name", where the parameters include the query field "select" and the patient name field "patent_name". After receiving the request, the back end can search in the database, remote dictionary service redis, cache, and memory, and return a response to the front end. The response includes all patients XX, YY, ZZ.... The above are only examples, and the embodiments of the present application are not limited thereto. For example, after receiving the request, the back end may not return a response, or the back end may actively send a response to the front end without receiving a request. Examples are not listed one by one here.
[0039] Figure 3 is a schematic diagram of an implementation scenario in an embodiment of the present application, as Figure 3As shown, a client (such as an application) can send a request to a device (medical device). After receiving the request, the device parses the request and performs business processing, but does not return a response. For example, if the front end wishes to control the device to start, it can send a request to the back end. The request includes command->start, where the parameter includes the command field command, and the corresponding value of the parameter is start. After receiving this request, the back end can start the device to run, but there is no need to send a response to the front end. For example, without receiving a request, the device can periodically and actively report the device operation status to the front end. The parameter includes the status field state, and the corresponding value of the parameter is the normal field normal. The above are only examples, and the embodiments of this application are not limited thereto. For example, the device can also report the device operation status to the front end in the response after receiving a request related to the operation status report from the front end. Examples are not given one by one here.
[0040] In some embodiments, the functions performed by 101-103 can be integrated into an independent computer with computing capabilities as microservices or components. The independent computer can be embedded in the link connecting the front end and the back end (such as routers, gateways, etc. set at the network edge), connected to the front end and the back end respectively, and traffic data will flow through the independent computer. Or, the functions performed by 101-103 can be directly integrated into the back end or the front end as microservices or components. The above situation is hereinafter referred to as the embedded mode. Or, the functions performed by 101-103 can be integrated into an independent computer with computing capabilities. The independent computer is connected to the back end or the front end, but is not embedded in the link connecting the front end and the back end. When the traffic data flows to the front end or the back end, it will not flow through the independent computer. The above situation is hereinafter referred to as the monitoring mode. The specific implementation manners in the embedded mode and the monitoring mode will be described separately later.
[0041] In some embodiments, in the embedded mode, the traffic data can be directly obtained, and the request field or response field can be directly identified in the traffic data, and it can be identified whether sensitive information is included. In the monitoring mode, the traffic data needs to be mirrored to generate a mirror copy of the traffic data. And, based on the mirror copy, the request field or response field in the traffic data is identified, and it is identified whether sensitive information is included in the data related to the request or the response in the traffic data. That is to say, it is necessary to identify the request field or response field in the mirror copy and identify whether sensitive information is included. Among them, mirroring the traffic data to generate a mirror copy of the traffic data includes: copying the traffic data to obtain a mirror copy that is exactly the same as the traffic data, and storing the mirror copy in a separate memory or in the memory inside the device that executes 101-103, so as to realize the backup of the traffic data.
[0042] The following describes how to identify request fields or response fields and determine whether sensitive information is included.
[0043] In some embodiments, in 102, request fields or response fields in the traffic data are identified. Specifically, the method of string matching is used to retrieve whether the "request" string or the "response" string is included in the traffic data (or mirror copy). When retrieved, the data related to the request or the response can be determined according to a predetermined request data structure or response data structure. Among them, the data related to the request or the response includes at least one of text data, voice data, picture data, and video data.
[0044] In some embodiments, sensitive information includes at least one of personal health information and personal identification information. For example, personal health information includes disease diagnosis information, hospitalization information, medical history information, fertility information, etc., and personal identification information includes name, document information, files, etc., which are not exemplified one by one here.
[0045] In some embodiments, a keyword field database or a lookup table (LUT) can be preset. The database or lookup table includes preset keyword fields related to requests and preset keyword fields related to responses. The preset keyword fields can include a preset parameter name field, a preset parameter value field, etc. For example, the preset keyword fields include fields related to sensitive information such as a name parameter field, an ID number parameter field, a contact information parameter field, a disease parameter field, a disease name parameter value field, etc., which are not exemplified one by one here.
[0046] In some embodiments, in 103, it can be determined whether there is data that matches a preset key field in the data related to the request or the response. Among them, when the data related to the request or the response includes text data, the character matching (exact matching or fuzzy matching) method can be used to determine whether there is data that matches the preset key field in the text data. When the data related to the request or the response includes picture data or video data, an optical character recognition (OCR) engine can be used to extract text information from the picture data or video data. For this OCR recognition, the OCR engines of Tesseract or Pytesseract can be used. First, an adaptive threshold is calculated to obtain a binary image, then text lines and words are searched, character contours are recognized, and finally words are generated according to the character contours, and the recognized text information is output. Specifically, relevant technologies can be referred to, and the embodiments of the present application are not limited thereto. When the data related to the request or the response includes audio data, a speech recognition algorithm can be used to convert the audio data into text information. The speech recognition algorithm includes, but is not limited to, Hidden Markov Model (HMM), Gaussian Mixture Model (GMM), Deep Neural Network (DNN), Recurrent Neural Network (RNN), Long Short-Term Memory Network (LSTM), etc. Specifically, relevant technologies can be referred to, and details are not elaborated here one by one. Then, the character matching (not limited to exact matching or fuzzy matching) method is used to determine whether there is data that matches the preset key field in the extracted or converted text information.
[0047] In some embodiments, when determining whether there is data that matches a preset key field in the data related to the request or the response (using the string matching (exact matching or fuzzy matching) method), if it is determined that the recognition result is that the data related to the request or the response includes sensitive information. Otherwise, it is determined that the recognition result is that the data related to the request or the response does not include sensitive information. For example, when there is a parameter that matches the preset key field in the data related to the request or the response, it is determined that the recognition result is that the data related to the request or the response includes sensitive information; or, when there is a parameter that matches the preset key field in the data related to the request or the response and the value corresponding to the parameter is non-empty, it is determined that the recognition result is that the data related to the request or the response includes sensitive information; or, when there is a parameter that matches the preset key field in the data related to the request or the response and the value corresponding to the parameter, it is determined that the recognition result is that the data related to the request or the response includes sensitive information. The embodiments of the present application are not limited thereto.
[0048] For example, the data related to the request includes "select * from patient_name = XX", and the preset keyword field includes "patient_name". That is to say, there is a parameter in the data related to the request that matches the preset keyword field, and the parameter corresponds to the value "XX" and is non-empty. Then it is determined that the recognition result is that the data related to the request or the response includes sensitive information.
[0049] For example, the data related to the request includes "select * all patient_name", and the preset keyword field includes "allpatient_name". That is to say, there is a parameter in the data related to the request that matches the preset keyword field. Then it is determined that the recognition result is that the data related to the request or the response includes sensitive information.
[0050] For example, the data related to the request includes "select * from patient_name = XX", and the preset keyword fields include "patient_name" and "XX". That is to say, there is a parameter in the data related to the request that matches the preset keyword field and the value corresponding to the parameter. Then it is determined that the recognition result is that the data related to the request or the response includes sensitive information.
[0051] In some embodiments, instead of using the method of matching with the preset keyword field string, it is also possible to retrieve whether there is a key parameter field or a key parameter value field in the data related to the request or the response to determine whether the data related to the request or the response includes sensitive information, so as to generate a recognition result. For example, when a key parameter field or a key parameter value field is retrieved, it is determined that the recognition result is that the data related to the request or the response includes sensitive information; otherwise, it is determined that the recognition result is that the data related to the request or the response does not include sensitive information. The embodiments of the present application are not limited thereto, and no further examples are given here.
[0052] In some embodiments, the storage location of the data field matched in the data related to the request or the response includes at least one of a database, a remote dictionary service Redis, a cache, a memory, and other storage units. The embodiments of the present application are not limited thereto.
[0053] In the above examples, a preset keyword field database or a lookup table (LUT) is taken as an example, but the present application is not limited thereto. For example, a neural network model for sensitive information recognition can also be pre-trained. The data related to the request or the response is used as the input of the neural network model, and the output result of the neural network model has two types. One is that it includes sensitive information, and the other is that it does not include sensitive information. No further details are given here.
[0054] The preset keyword field database or lookup table (LUT) in the above embodiments, or the pre-trained neural network model can be stored in the front end or the back end or the aforementioned independent computer, or in a memory connected to the front end or the back end or the aforementioned independent computer. The embodiments of the present application do not limit this.
[0055] In some embodiments, the method may further include: performing subsequent management according to the recognition result, which will be described in detail below.
[0056] In some embodiments, in the monitoring mode, since the recognition result is determined based on the mirror copy, the traffic data cannot be managed. When it is determined that the data related to the request or the response in the recognition result includes sensitive information, an alarm event can be created, and an alarm can be issued on at least one of the front end or the back end or the aforementioned independent computer. The ways of issuing the alarm include but are not limited to a sound alarm (such as a beeping sound or voice broadcast), or displaying a graphical alarm on the graphical user interface, etc. The content of the alarm includes the recognition result, and optionally, the type of sensitive information can also be included. The user can also choose to ignore the alarm or manually choose to disconnect the network connection between the front end and the back end to prevent the leakage of sensitive information. When it is determined that the data related to the request or the response in the recognition result does not include sensitive information, no processing is performed.
[0057] In some embodiments, in the embedding mode, the request or the response can be managed according to the recognition result, or the sensitive information can be managed. Among them, when the recognition result indicates that the data related to the request or the response includes sensitive information, the request or the response is terminated, that is, the request from the front end is no longer passed to the back end, or the response from the back end is no longer passed to the front end; or the request or the response after discarding the sensitive information is passed, that is, the sensitive information in the request or response is discarded and then passed to the back end or the front end. Optionally, the sensitive information can also be recorded; in addition, an alarm event can also be created, which will not be repeated here. When the recognition result indicates that the data related to the request or the response does not include sensitive information, the request or the response is passed, that is, the request from the front end is passed to the back end, or the request from the back end to the response is passed to the front end. Or, in the embedding mode, when the recognition result indicates that the data related to the request or the response includes sensitive information, an alarm event can be created to prompt the user to select whether to terminate the request or the response, or to select whether to discard the sensitive information. When the user selects to do so, the request or the response is terminated or the request or the response after discarding the sensitive information is passed. When the user selects not to do so, the request or the response can be passed; the content of the alarm includes the recognition result, and optionally, the sensitive information type can also be included. The user can judge whether to terminate the request or the response, or whether to discard the sensitive information according to the sensitive information type, which will not be elaborated here one by one.
[0058] Figure 4 is a schematic diagram of the data processing method according to an embodiment of the present application. For the monitoring mode, as Figure 4 shown, the method includes:
[0059] 401. Obtain traffic data;
[0060] 402. Mirror the traffic data to generate a mirror copy of the traffic data;
[0061] 403. Identify the request field or response field in the traffic data based on the mirror copy;
[0062] 404. Identify whether the data related to the request or the response in the traffic data includes sensitive information based on the mirror copy. When it includes, execute 405. When it does not include, end the operation;
[0063] 405. Create an alarm event.
[0064] Figure 5 is a schematic diagram of the data processing method according to an embodiment of the present application. For the embedding mode, as Figure 5 shown, the method includes:
[0065] 501. Obtain traffic data;
[0066] 502. Identify the request field or response field in the traffic data;
[0067] 503. Identify whether the data related to the request or the response in the traffic data includes sensitive information. If it does, execute 504; if not, execute 505;
[0068] 504. Terminate the request or the response, or transmit the request or the response after discarding the sensitive information;
[0069] 505. Transmit the request or the response.
[0070] Each of the above embodiments only exemplarily illustrates the embodiments of the present application, but the present application is not limited thereto, and appropriate modifications can also be made on the basis of the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.
[0071] The embodiments of the present application also provide a data processing device corresponding to the data processing method in the foregoing embodiments.
[0072] Figure 6 It is a schematic diagram of the data processing device according to the embodiments of the present application. As Figure 6 shown, the data processing device 600 includes:
[0073] An acquisition unit 601 that acquires traffic data;
[0074] A first identification unit 602 that identifies the request field or response field in the traffic data;
[0075] A second identification unit 603 that identifies whether the data related to the request or the response in the traffic data includes sensitive information and generates an identification result.
[0076] In some embodiments, optionally, the device may further include: a management unit 604 that manages the request or the response according to the identification result, or manages the sensitive information.
[0077] For the implementation manners of the acquisition unit 601, the first identification unit 602, the second identification unit 603, and the management unit 604, reference can be made to the foregoing embodiments, and details are not repeated here.
[0078] The acquisition unit 601, the first identification unit 602, the second identification unit 603, and the management unit 604 can be integrated into an independent computer with computing capabilities. This independent computer can be embedded in the link connecting the front end and the back end, connected to the front end and the back end respectively, and traffic data will flow through this independent computer. Or, it can be directly integrated into the back end or the front end. Or, it can be integrated into an independent computer with computing capabilities, which is connected to the back end or the front end but not embedded in the link connecting the front end and the back end, and the traffic data will not flow through this independent computer when flowing to the front end or the back end.
[0079] Each of the above embodiments only exemplarily illustrates the embodiments of the present application, but the present application is not limited thereto, and appropriate modifications can also be made on the basis of the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.
[0080] The embodiments of the present application also provide an electronic device. Figure 7 is a schematic diagram of the electronic device of the embodiments of the present application. As Figure 7 shown, the electronic device 700 may include: at least one interface (not shown in the figure), a processor (for example, a central processing unit (CPU)) 701, and a memory 702; the memory 702 is coupled to the processor 701.
[0081] In some embodiments, the functions of the data processing device 600 in the foregoing embodiments can be integrated into the processor 701. For example, the processor 701 can be configured to: acquire traffic data; identify a request field or a response field in the traffic data; identify whether the data related to the request or the response in the traffic data includes sensitive information, and generate an identification result.
[0082] Or, the data processing device 600 can be configured as a chip connected to the processor 701, and the corresponding functions can be realized under the control of the processor 701.
[0083] It should be noted that the electronic device 700 may also include Figure 7 components not shown in the figure, and reference can be made to the prior art.
[0084] In the embodiments of the present application, the processor 701 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor devices and / or logic devices.
[0085] In some embodiments, the memory 702 can store various data; in addition, it also stores a data processing program 703, traffic data, and a pre-set database or look-up table (LUT), or a pre-trained neural network model, and executes the program 703 under the control of the processor 701.
[0086] In some embodiments, the electronic device may be the aforementioned stand-alone computer, such as a personal computer, a server, a cloud computer, a workstation, a laptop computer, a mobile terminal, etc.; however, the embodiments of the present application are not limited thereto.
[0087] The embodiments of the present application also provide a computer-readable program, wherein when the program is executed in an electronic device, the program causes the electronic device to execute the data processing method of the embodiment.
[0088] The embodiments of the present application also provide a storage medium storing a computer-readable program, wherein the computer-readable program causes a computer to execute the data processing method of the embodiment.
[0089] The embodiments of the present application also provide a medical device (not shown). The medical devices described herein include, but are not limited to, computed tomography (CT) devices, magnetic resonance imaging (MRI) devices, C-arm imaging devices, positron emission tomography (PET) devices, single photon emission computed tomography (SPECT) devices, ultrasound devices, X-ray imaging devices, or any other suitable medical device.
[0090] For example, the medical device may include the aforementioned data processing device 600 or electronic device 700. Alternatively, the medical device may be connected to the aforementioned data processing device 600 or electronic device 700. The data processing method may also be independently or jointly implemented by the aforementioned medical device, a computer device connected to the medical device, or a computer device connected to the Internet cloud. The embodiments of the present application do not limit thereto.
[0091] One of the beneficial effects of the embodiments of the present application is that by identifying whether the data related to the request or the response in the traffic data includes sensitive information, thus, when sensitive information is identified, an alarm can be issued in a timely manner, or the request or response can be terminated, or the sensitive information in the request or response can be discarded, which can prevent the leakage of sensitive information in the request or response, protect the privacy of patients, and improve the security of digital products.
[0092] In addition, by presetting a keyword database or a LUT, thus, efficient and accurate identification of sensitive information can be achieved.
[0093] In addition, in the monitoring mode, it is possible to monitor whether there is a leakage of sensitive information without any performance and security impact on the original link.
[0094] In addition, in the embedding mode, when sensitive information is recognized, the request or response can be automatically terminated according to preset rules, or the sensitive information in the request or response can be discarded, preventing the leakage of sensitive information and further improving the security of digital products.
[0095] The above devices and methods of this application can be implemented by hardware or by a combination of hardware and software. This application relates to such a computer-readable program, which when executed by a logic component, can enable the logic component to implement the devices or constituent components described above, or enable the logic component to implement the various methods or steps described above. This application also relates to a storage medium for storing the above program, such as a hard disk, a magnetic disk, an optical disc, a DVD, a flash memory, etc.
[0096] The method / device described in combination with the embodiments of this application can be directly embodied as hardware, a software module executed by a processor, or a combination of the two. For example, one or more of the functional block diagrams shown in the figure and / or a combination of one or more of the functional block diagrams can correspond to each software module of the computer program flow, and can also correspond to each hardware module. These software modules can respectively correspond to the respective steps shown in the figure. These hardware modules can be implemented by solidifying these software modules using a field-programmable gate array (FPGA).
[0097] The software module can be located in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. A storage medium can be coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium; or the storage medium can be a component of the processor. The processor and the storage medium can be located in an ASIC. The software module can be stored in the memory of the mobile terminal or in a memory card that can be inserted into the mobile terminal. For example, if the device (such as a mobile terminal) uses a larger-capacity MEGA-SIM card or a large-capacity flash device, the software module can be stored in the MEGA-SIM card or the large-capacity flash device.
[0098] One or more of the functional blocks described in the accompanying drawings and / or one or more combinations of functional blocks can be implemented as a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, or any suitable combination thereof for performing the functions described in the present application. One or more of the functional blocks described in the accompanying drawings and / or one or more combinations of functional blocks can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in communication combination with a DSP, or any other such configuration.
[0099] The present application has been described above in connection with specific embodiments, but those skilled in the art should understand that these descriptions are exemplary and not a limitation on the scope of the present application. Those skilled in the art can make various variations and modifications to the present application based on the principles of the present application, and these variations and modifications are also within the scope of the present application.
Claims
1. A data processing method, characterized in that, The method includes: Obtaining traffic data; Identifying a request field or a response field in the traffic data; Identifying whether the data related to the request or the response in the traffic data includes sensitive information, and generating an identification result.
2. The method according to claim 1, characterized in that, The data related to the request or the response includes at least one of text data, voice data, picture data, and video data.
3. The method according to claim 1, characterized in that, The sensitive information includes at least one of personal health information and personal identification information.
4. The method according to claim 1, wherein Identifying whether the data related to the request or the response in the traffic data includes sensitive information and generating an identification result includes: Determining whether there is a parameter in the data related to the request or the response that matches a preset keyword field; When there is a parameter in the data related to the request or the response that matches a preset keyword field and the value corresponding to the parameter is not empty, determining that the identification result is that the data related to the request or the response includes sensitive information.
5. The method according to claim 1, characterized in that The method further includes: Mirroring the traffic data to generate a mirror copy of the traffic data; And, identifying a request field or a response field in the traffic data according to the mirror copy, and identifying whether the data related to the request or the response in the traffic data includes sensitive information.
6. The method according to claim 1, wherein The method further includes: Managing the request or the response according to the identification result, or managing the sensitive information.
7. The method according to claim 6, wherein Managing the request or the response according to the identification result includes: When the identification result is that the data related to the request or the response includes sensitive information, terminating the request or the response, or transmitting the request or the response after discarding the sensitive information; When the identification result is that the data related to the request or the response does not include sensitive information, transmitting the request or the response.
8. A data processing device, characterized in that, The device includes: An obtaining unit that obtains traffic data; A first identification unit that identifies a request field or a response field in the traffic data; A second identification unit that identifies whether the data related to the request or the response in the traffic data includes sensitive information and generates an identification result.
9. A storage medium storing a computer-readable program, characterized in that, The computer-readable program causes a computer to execute the data processing method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, The electronic device includes the data processing device according to claim 8.