Data processing method and device, electronic equipment and computer program product
By processing and replacing fields in business data between data centers in different regions, the problems of high deployment cost, high difficulty and high data leakage risks are solved, and safe and efficient cross-regional data processing is achieved.
Patent Information
- Application Number
- CN202510396494.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-08
AI Technical Summary
When deploying data centers in different regions, there are problems such as high deployment cost, high deployment difficulty and high data breach risk.
By obtaining the service data stored in the first data center, extracting preset fields, processing each field using data processing rules, obtaining the processed service field, replacing it with the fields in the original service data, returning it to the second data center, and filtering is performed using the data filtering device to ensure data security and efficiency.
It improves the security of cross-regional data processing, reduces deployment costs, improves data processing efficiency, and reduces the risk of data leakage.
Smart Images

Figure CN120277054A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of fintech, and in particular, to a method, apparatus, electronic device, and computer program product for processing data. Background Art
[0002] With the rapid development of the digitalization and globalization processes, data security has become the focus of attention for enterprises and individuals. With the rapid expansion of the business of financial institutions in other regions, they are facing more severe data security challenges. To ensure data security in other regions, the related technology is to perform local deployment of business data, that is, to migrate relatively sensitive business data including customer names, addresses, etc. to the location of financial institutions in other regions to achieve local storage and processing of data, and can also effectively prevent cross-border data flow and meet the local data security requirements.
[0003] However, the local data center can only retain internal management data, and all system modules involving customer information, such as employee systems, internal management, etc., as well as specific financial institution applications, need to be deployed and operated locally. When performing local deployment, not only high costs need to be invested, including computer room construction, hardware purchase, and network facility construction, but also a large amount of operation and maintenance costs need to be spent, such as employee training, daily operation and maintenance, etc., which significantly increases the financial pressure on the local area. Further, due to the significant differences in regulatory standards, technical environments, and customer requirements in different regions, business systems often need to be deeply customized to adapt to the local environment, which not only increases the complexity of development and testing, but also prolongs the project cycle, increases the error rate, and is difficult to form a synergy effect, reducing the efficiency and effectiveness of overall data management.
[0004] In view of the problems of high deployment costs, high deployment difficulties, and high data leakage risks in deploying data centers in different regions in the related art, no effective solution has been proposed yet. Summary of the Invention
[0005] The main purpose of this application is to provide a method, apparatus, electronic device, and computer program product for processing data to solve the problems of high deployment costs, high deployment difficulties, and high data leakage risks in deploying data centers in different regions in the related art.
[0006] To achieve the above object, according to one aspect of the present application, a method for processing data is provided. The method includes: obtaining a set of business data stored in a first data center, extracting preset fields from the set of business data to obtain M business fields, where the set of business data is used to indicate the business data of users handling financial business, and M is a positive integer; obtaining a data processing rule, and using the data processing rule to perform data processing on each business field to obtain M processed business fields, where the data processing rule includes multiple data processing strategies for processing business fields; replacing the fields in the set of business data based on each processed business field to obtain a set of processed business data, and returning the set of processed business data to a second data center, where the geographical location of the second data center is different from that of the first data center.
[0007] Further, extracting preset fields from a set of business data to obtain M business fields includes: obtaining a preset field list, where the preset field list includes field information of multiple preset fields, and the field information includes at least one of the following: preset field name, field type, and field level; performing field splitting on the set of business data to obtain N split fields, where N is greater than M and N is a positive integer; using the preset field list to screen the N split fields to obtain M business fields.
[0008] Further, using the preset field list to screen the N split fields to obtain M business fields includes: using the preset field list to screen the N split fields to obtain M initial business fields; extracting the field level of each initial business field from the preset field list to obtain M field levels, and associating the field level with each initial business field to obtain M business fields.
[0009] Further, using the data processing rule to perform data processing on each business field to obtain M processed business fields includes: grouping the M business fields according to the field level associated with each business field to obtain Y field groups, where each field group is associated with a field level, Y is less than or equal to M, and Y is a positive integer; extracting the data processing strategy corresponding to the field level of each field group from the data processing rule; using the Y data processing strategies to process each business field in each field group to obtain M processed business fields.
[0010] Further, after returning the set of processed business data to the second data center, the method further includes: determining a mapping relationship according to the M processed business fields, where the mapping relationship is used to indicate the association relationship between the M business fields and the M processed business fields; in the case of receiving a data restoration instruction sent by the second data center, restoring the set of processed business data according to the mapping relationship.
[0011] Further, the data processing rules include one of the following: when the preset field is a numeric field, hide the field at the preset position in the preset field; when the preset field is a text field, perform numeric conversion on the preset field; when the preset field is neither a numeric field nor a text field, perform truncation processing on the preset field.
[0012] Further, the first data center includes a data filtering device. Returning a set of processed service data to the second data center includes: controlling the data filtering device to filter a set of processed service data to obtain a set of filtered processed data; sending the set of filtered processed data to the second data center.
[0013] To achieve the above object, according to another aspect of the present application, there is provided a data processing device. The device includes: a first acquisition unit, configured to acquire a set of service data stored in the first data center, extract a preset field from the set of service data to obtain M service fields, where the set of service data is used to indicate the service data of users handling financial services, and M is a positive integer; a second acquisition unit, configured to acquire data processing rules, and use the data processing rules to perform data processing on each service field to obtain M processed service fields, where the data processing rules include multiple data processing strategies for processing service fields; a replacement unit, configured to replace the fields in the set of service data based on each processed service field to obtain a set of processed service data, and return the set of processed service data to the second data center, where the second data center is geographically different from the first data center.
[0014] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium. The computer-readable storage medium includes an executable program stored therein. When the executable program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above data processing methods.
[0015] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including one or more processors and a memory. The memory stores an executable program, and the processors are configured to run the program. When one or more programs are executed by one or more processors, one or more processors are caused to implement any one of the above data processing methods.
[0016] According to another aspect of the embodiments of the present invention, there is also provided a computer program product. The computer program product includes a computer program. When the computer program is executed by a processor, it implements any one of the above data processing methods.
[0017] In the embodiments of the present application, a data processing method is adopted. By obtaining a set of business data stored in a first data center, and extracting preset fields from the set of business data to obtain M business fields, where the set of business data is used to indicate the business data of users handling financial business, and M is a positive integer; obtaining a data processing rule, and using the data processing rule to perform data processing on each business field to obtain M processed business fields, where the data processing rule includes multiple data processing strategies for processing business fields; replacing the fields in the set of business data based on each processed business field to obtain a set of processed business data, and returning the set of processed business data to a second data center, where the second data center has a different geographical location from the first data center, thereby achieving the technical effects of improving the security of cross-regional data processing, increasing data processing efficiency, and reducing deployment costs, and further solving the problems of high deployment costs, high deployment difficulty, and high data leakage risk when deploying data centers in different regions. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings constituting a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0019] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a data processing method;
[0020] Figure 2 is a flowchart of a data processing method according to an embodiment of this application;
[0021] Figure 3 is a schematic diagram of an optional data processing system according to an embodiment of this application;
[0022] Figure 4 is a schematic diagram of a data processing device according to an embodiment of this application;
[0023] Figure 5 is a structure block diagram of an electronic device according to an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of this application.
[0025] It should be noted that in the description and claims of this application and the above-mentioned drawings, terms such as "first" and "second" are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0026] It should be noted that the relevant information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned user or institution through the interface, and after receiving the consent information feedback from the aforementioned user or institution, the relevant information can be obtained.
[0027] It should be noted that the information collected in this application is information and data authorized by the user or fully authorized by all parties, and the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, all comply with the relevant laws, regulations, and standards in the relevant regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse to use.
[0028] Embodiment 1
[0029] According to an embodiment of the present application, an embodiment of a method for data processing is also provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from that here.
[0030] The method embodiment provided by the first embodiment of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 It is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a data processing method, as Figure 1 shown. The computer terminal 10 (or mobile device) may include one or more ( Figure 1In the figure, the processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microcontroller unit (MCU) or a field-programmable gate array (FPGA)) is shown as 102a, 102b, ……, 102n, a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a keyboard, a cursor control device, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 The structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown in the figure, or have a different configuration from Figure 1 that shown in the figure.
[0031] It should be noted that the above one or more processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" in this article. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistor terminal path connected to an interface).
[0032] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data processing method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned data processing method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0033] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC) and a network interface, which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0034] The display may be, for example, a touch screen liquid crystal display (LCD), which may enable a user to interact with a user interface of the computer terminal 10 (or mobile device).
[0035] Under the above operating environment, this application provides Figure 2 The data processing method shown. Figure 2 is a flow chart of a method for processing data according to an embodiment of the present application, such as Figure 2 As shown, the method comprises the following steps:
[0036] Step S201, obtain a set of business data stored in the first data center, extract preset fields in the set of business data, and obtain M business fields, wherein the set of business data is used to indicate business data of a user handling financial business, and M is a positive integer.
[0037] Specifically, the first data center may be the data center of the financial institution in area A, the second data center may refer to the data center of the financial institution in area B, and area B is the main data center of the financial institution. Business data may refer to business data stored in the data center for handling financial business. In order to achieve secure transmission of data across regions, the real data is only stored in the local data center (that is, the first data center). The data stored in the data center in area B is processed data. First, a set of business data to be processed can be obtained. It should be noted that these business data can be included in multiple business systems of the financial institution, such as financial management systems, risk management systems, etc.
[0038] Furthermore, preset fields containing sensitive information are extracted from these business data, such as personal information (such as name, address), transaction records, account information and other sensitive information of users handling financial services. The extraction process can use data mining and pattern recognition technology to accurately filter out key preset fields from structured and unstructured data, thereby obtaining multiple business fields.
[0039] Step S202: Obtain data processing rules, and use the data processing rules to process each business field to obtain M processed business fields. The data processing rules include multiple data processing strategies for processing business fields.
[0040] Specifically, after obtaining multiple business fields, the business fields can be processed according to the obtained data processing rules, and then the corresponding processed business fields can be obtained, so as to ensure the security of data during cross-regional transmission.
[0041] It should be noted that the data processing rules can include specific strategies for processing various sensitive fields to adapt to different security levels and scenario requirements, and while protecting data security, ensure the smoothness of business processes and the user experience is not affected. For example, the processed data should still carry sufficient information so that the business system can correctly identify and process it. It can include masking strategies, replacement strategies, truncation strategies, etc.
[0042] Step S203: Replace the fields in a set of business data based on each processed business field to obtain a set of processed business data, and return the set of processed business data to the second data center, where the second data center has a different geographical location from the first data center.
[0043] Specifically, after processing multiple business fields, these processed business fields can be used to replace the corresponding sensitive business fields in the original business data to ensure that the sensitive information in the original data is effectively protected. For example, the phone number 10000000000 is processed into 100****0000, and the processed business field is used to replace the business field in the original set of business data, so as to obtain a set of processed business data, and then the data desensitization can be achieved while maintaining the integrity of the data structure and the basic requirements of business processing.
[0044] Furthermore, after obtaining the above-mentioned processed business data, these data can be securely transmitted to the second data center through the data exchange module. It should be noted that since the second data center represents the data center in Region B, when a set of processed business data reaches the second data center, the second data center can only access the processed information and cannot directly access any sensitive data, thus greatly reducing the risk of data leakage.
[0045] After the business process is completed, the second data center will need to return the processed data to the first data center for final data processing, storage, or business decision-making. After the data is returned to the first data center, the data restoration component associated with the first data center can identify the processed business fields and restore these fields to their original state according to the mapping relationship, restoring the integrity of the data and the availability of the original information. For example, 100****0000 is restored to 10000000000.
[0046] The data processing method provided by the embodiments of the present application obtains a set of business data stored in the first data center, extracts preset fields from the set of business data to obtain M business fields, where the set of business data is used to indicate the business data of users handling financial business, and M is a positive integer; obtains a data processing rule, and uses the data processing rule to process each business field to obtain M processed business fields, where the data processing rule includes multiple data processing strategies for processing business fields; replaces the fields in the set of business data based on each processed business field to obtain a set of processed business data, and returns the set of processed business data to the second data center, where the second data center is geographically different from the first data center, solving the problems of high deployment cost, high deployment difficulty, and high data leakage risk in the related art when deploying data centers in different regions. By obtaining business data, processing the preset fields in the business data, replacing the fields in the set of business data based on each processed business field, and finally returning the set of processed business data to the second data center, the technical effects of improving the security of cross-regional data processing, improving data processing efficiency, and reducing deployment costs are achieved.
[0047] Optionally, in the data processing method provided by the embodiments of the present application, extracting preset fields from a set of business data to obtain M business fields includes: obtaining a preset field list, where the preset field list includes field information of multiple preset fields, and the field information includes at least one of the following: preset field name, field type, and field level; performing field segmentation on the set of business data to obtain N segmented fields, where N is greater than M and N is a positive integer; and screening the N segmented fields using the preset field list to obtain M business fields.
[0048] Specifically, when extracting fields from the obtained set of business data, it is necessary to accurately locate and process the fields containing sensitive information while maintaining the integrity and availability of the business data. First, a preset field list including multiple preset fields to be processed and the corresponding field types and field levels can be obtained, where the field type can be text, number, date, etc., and the field level can be divided into three levels: high, medium, and low.
[0049] Furthermore, all the obtained field data are segmented, and the complex data structure is decomposed into multiple independent segmented fields. Then, a preset field list is used to screen the segmented fields, so as to identify the business fields that need special processing (i.e., data processing). At this time, the field information in the list can be compared with the fields of the business data, and the preset sensitive fields can be screened out according to the field name, type, and level. By using the preset field list for field screening in this embodiment, the accurate identification and processing of sensitive fields can be ensured, the unnecessary processing of non-sensitive data can be avoided, and the dual optimization of data security and business efficiency can be achieved.
[0050] Optionally, in the data processing method provided by the embodiment of the present application, screening the N segmented fields by using a preset field list to obtain M business fields includes: screening the N segmented fields by using a preset field list to obtain M initial business fields; extracting the field levels of each initial business field from the preset field list to obtain M field levels, and associating the field levels with each initial business field to obtain M business fields.
[0051] Specifically, since the preset field list contains detailed descriptions of all sensitive fields in the business data, including the field name, type, and level, when using the preset field list to screen the segmented fields, first, the field information in the list can be compared to identify the initial business fields that need special attention, ensuring that no sensitive field is missed, and at the same time avoiding unnecessary processing of non-sensitive fields, maintaining the accuracy and efficiency of data processing.
[0052] Once the initial business fields are screened out, it is also necessary to extract the field levels of each initial business field from the preset field list. Among them, the field levels can be divided into three levels: high, medium, and low, corresponding to different strictness data processing strategies. For example, the phone number is marked as a high-sensitive level and needs to be deeply desensitized; while the area code is marked as a low-sensitive level and only needs to be mildly processed or not processed.
[0053] Furthermore, after extracting the field levels of each initial business field, the corresponding field levels can be associated with each initial business field to form the final business fields. In this way, it provides guidance for subsequent data processing and also ensures the compliance and pertinence of data processing. Through the screening and level classification of the field list in this embodiment, different processing strategies can be adopted for fields with different sensitive levels, protecting sensitive information and retaining the business value of the data.
[0054] In order to perform refined processing on data of different sensitivities, optionally, in the data processing method provided in the embodiment of the present application, each business field is processed using data processing rules to obtain M processed business fields, including: grouping the M business fields according to the field level associated with each business field to obtain Y field groups, wherein each field group is associated with a field level, Y is less than or equal to M, and Y is a positive integer; extracting the data processing strategy of the field level corresponding to each field group from the data processing rules; and processing each business field in each field group using Y data processing strategies to obtain M processed business fields.
[0055] Specifically, when filtering out business fields from multiple segmented fields and processing the business fields, these fields can first be grouped according to the field levels defined in the preset field list to form multiple field groups. At this time, each field group is associated with a specific field level. In this way, the same processing strategy can be applied to fields of the same security level, thereby simplifying the data processing process and improving processing efficiency. For example, all fields with high sensitivity levels, such as ID numbers, telephone numbers, etc., are grouped together, while all fields with low sensitivity levels, such as area codes, account types, etc., are grouped together.
[0056] Further, after the field grouping is completed, the processing strategy corresponding to each field grouping can be extracted from the data processing rules to ensure that the data processing method matches the data security requirements. For example, fields with high sensitivity levels correspond to strict processing strategies, such as deep desensitization, encryption or shielding; while fields with low sensitivity levels only require light processing or no processing. Then, according to the extracted data processing strategy, the business fields in each field grouping are processed to obtain the processed business fields. For example, for a highly sensitive field group containing personal identity information, it can be processed by replacement or encryption, while for a low-sensitivity field group containing regional information, it is kept as it is or only format verification is performed. This embodiment can accurately protect data of different sensitivities by grouping business fields according to their security levels and applying different processing strategies in a targeted manner, avoiding over-protection or under-protection caused by one-size-fits-all data processing, significantly improving the efficiency of data processing, reducing the time and resource consumption of processing each field separately, while protecting data security, it also maintains the business functionality and integrity of the data as much as possible, and improves the user experience.
[0057] To ensure the secure transmission and compliant processing of data across regions, optionally, in the data processing method provided in the embodiments of the present application, after a set of processed service data is returned to the second data center, the method further includes: determining a mapping relationship according to M processed service fields, where the mapping relationship is used to indicate the association between the M service fields and the M processed service fields; and when receiving a data restoration instruction sent by the second data center, restoring the set of processed service data according to the mapping relationship.
[0058] Specifically, after the data is processed in the first data center and the processed service data is returned to the second data center, in order to obtain the original service data before the first data center needs to perform service management on the service data, these fields can be accurately restored to their original state according to the mapping relationship between the front and back fields. Among them, the mapping relationship is a two-way correspondence table that stores the association between the original service fields and their corresponding processed states, ensuring the accuracy of data processing and restoration.
[0059] First, a mapping record can be generated for each service field, recording its original value, processed value, and the processing strategy used, and then these relationships can be combined to obtain the mapping relationship. It should be noted that as the service data changes continuously, the mapping relationship needs to be updated regularly to maintain its consistency with the latest data state.
[0060] When the second data center completes the storage task of the processed service data, it can send a data restoration instruction to the first data center. At this time, after receiving the data restoration instruction, the first data center can restore a set of processed service data to its original state according to the pre-stored mapping relationship, that is, according to the information in the mapping table, restore the original value of the field. The corresponding data restoration operation can be performed reversely according to the processing strategy in the mapping table to restore the processed field to its original state. And after the data restoration is completed, the data integrity and accuracy are verified to ensure that no new errors or security risks are introduced during the data restoration process. Through the use of the mapping relationship to implement the data restoration operation in this embodiment, while meeting the business requirements, the potential risk of data leakage can be avoided, ensuring the business continuity of the data during cross-region processing and not affecting the efficiency of business decision-making and data management.
[0061] Optionally, in the data processing method provided in the embodiments of the present application, the data processing rules include one of the following: when the preset field is a numeric field, hiding the field at the preset position in the preset field; when the preset field is a text field, performing numeric conversion on the preset field; when the preset field is neither a numeric field nor a text field, performing truncation processing on the preset field.
[0062] Specifically, in order to protect sensitive information while maintaining the business value and processing efficiency of data, different data processing can be performed on different types of preset fields. Therefore, the data processing rules can include multiple data processing strategies. First, for numerical fields, especially those containing sensitive data, such as the user's contact phone number, etc., numerical hiding can be performed at a preset position, that is, by modifying some of the numbers in the field, using methods such as masking, replacement, or encryption, so that sensitive numerical information cannot be directly recognized during transmission. For example, the account balance is processed from 100000 to 1****00, or the transaction amount is encrypted, and the original information can only be restored when the decryption key is available. In the numerical hiding operation, it is necessary to ensure that the processed numerical value can maintain the correctness of its data type, and at the same time, through the recording of the mapping relationship, ensure that the data can be accurately restored.
[0063] Furthermore, for text fields, such as descriptive information of addresses, etc., more complex data processing can be performed to protect the private information therein, that is, a numerical conversion strategy is adopted to convert the text information into a numerical or code form that is not easily interpreted. For example, converting Zhang San to 123456, or encoding the address information, thereby achieving a certain degree of information confusion while maintaining the basic structure of the data. It should be noted that when performing numerical conversion, a secure and reversible conversion mechanism can be established to ensure that when the data is returned, the numerical value can be converted back to the original text information according to the mapping relationship, while avoiding introducing reversibility risks during the processing.
[0064] For preset fields that are neither numerical nor text, such as date and time, custom encoding, etc., at this time, a truncation processing strategy can be adopted, that is, removing unnecessary information from the field to reduce the exposure of sensitive information while maintaining the basic structure and type of the field. For example, truncating the complete date and time field from 12:34:56 on 2000-01-01 to 2000-01-01, or only retaining the first few key information for the custom encoding field; removing details such as street and house number to reduce the degree of information exposure. In this embodiment, data processing is achieved by using multiple data processing strategies. While protecting the data, it also maintains the business functionality and usability of the data, ensuring that the processed data can meet the requirements of the business system processing and does not affect the continuity and efficiency of the business process. Through the dynamic adjustment of the processing strategy, it is possible to flexibly respond to the processing requirements of different types of fields.
[0065] Optionally, in the data processing method provided in the embodiment of the present application, the first data center includes a data filtering device. Returning a set of processed business data to the second data center includes: controlling the data filtering device to perform filtering processing on a set of processed business data to obtain a set of filtered processed data; sending a set of filtered processed data to the second data center.
[0066] Specifically, to achieve secure data transmission, a data filtering device in the first data center can be used to filter a set of processed business data, reducing unnecessary data transmission and storage while maintaining the business value of the data. At this time, the data filtering device can further screen the processed business data to ensure that only data meeting specific conditions is transmitted to the second data center. For example, it can detect whether the processed data still meets the requirements of the business process, that is, the removed fields or information do not affect business decisions or operations; remove unnecessary data fields or information to reduce the size of data packets, thereby improving the speed and efficiency of data transmission and reducing transmission costs.
[0067] After the data filtering device completes the screening of the processed business data and obtains a set of filtered processed data, these data are sent to the second data center. In this embodiment, by using the data filtering device for data filtering processing, it is ensured that only securely processed data is transmitted, further reducing the potential security risks during data transmission. By reducing unnecessary data transmission, not only the cost of data transmission is reduced, but also the data storage and processing burden on the second data center is alleviated, improving the overall resource utilization rate.
[0068] The embodiment of the present application also provides a data processing system. Figure 3 It is a schematic diagram of an optional data processing system provided according to the embodiment of the present application. As Figure 3 shown, the system includes: a first data center and a second data center. Among them, the first data center can refer to the local data center of a financial institution in region A, and the second data center can refer to the data center of a financial institution in region B. The first data center is deployed in the same region as the technical base, hardware devices / computing resources, and virtual machines / cloud platforms. The second data center is deployed in the same region as the technical base, hardware devices / computing resources, and virtual machines / cloud platforms. The first data center includes application systems (including operating systems, middleware, and databases), data mining components, data tagging components, data processing components, data caching components, and data restoration components. The second data center includes application systems (including operating systems, middleware, and databases), employee systems, financial management systems, internal management systems, and risk management systems. The virtual machines / cloud platforms provide flexible computing resources and data processing environments. The hardware devices / computing resources include the necessary hardware devices and computing resources for the data center to support operations such as data filtering, processing, restoration, and storage.
[0069] After a user initiates a transaction request through a browser, client, ATM (Automatic Teller Machine), or POS (Point of Sale Terminal), etc., and generates a business data processing request upon transaction completion, the data mining component in the first data center obtains business data according to the request, classifies and counts it based on the characteristics of the fields, and then the data tagging component marks the sensitivity level of the business fields in the business data. That is, according to the recognition result of the data mining component, security level and sensitivity level labels are assigned to the sensitive fields, thus obtaining multiple business fields.
[0070] After the data processing component receives the processing request, it receives the business fields extracted by the data tagging component and processes them to obtain processed business fields, such as masking phone numbers, replacing names, truncating addresses, etc. Further, the data caching component generates a mapping relationship based on the processed business fields, and the data filtering device sends the business data including the processed business fields to the second data center.
[0071] After the second data center receives the filtered business data, it stores it in the database of the application system and returns a data restoration instruction to the first data center when business management is required. At this time, the data restoration component in the first data center restores the processed business data to its original state according to the mapping relationship in the data caching component and displays the restored business data on the browser, client, AIM machine, or POS machine. In this embodiment, by obtaining business data, processing the preset fields in the business data, replacing the fields in a set of business data based on each processed business field, and finally returning a set of processed business data to the second data center, cross-regional isolation of important data is achieved, and the technical effects of enhancing the security of cross-regional data processing, improving data processing efficiency, and reducing deployment costs are achieved.
[0072] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0073] Embodiment 2
[0074] The embodiment of the present application also provides a data processing device. It should be noted that the data processing device in the embodiment of the present application can be used to execute the data processing method provided in the embodiment of the present application. The following introduces the data processing device provided in the embodiment of the present application.
[0075] According to an embodiment of the present application, there is also provided an apparatus for implementing the above data processing method. Figure 4 It is a schematic diagram of a data processing apparatus provided according to an embodiment of the present application, as Figure 4 shown. The apparatus includes: a first acquisition unit 40, a second acquisition unit 41, and a replacement unit 42.
[0076] The first acquisition unit 40 is configured to acquire a set of service data stored in the first data center, extract preset fields from the set of service data to obtain M service fields, where the set of service data is used to indicate the service data of users handling financial services, and M is a positive integer.
[0077] The second acquisition unit 41 is configured to acquire a data processing rule, and use the data processing rule to perform data processing on each service field to obtain M processed service fields, where the data processing rule includes multiple data processing strategies for processing service fields.
[0078] The replacement unit 42 is configured to replace the fields in the set of service data based on each processed service field to obtain a set of processed service data, and return the set of processed service data to the second data center, where the second data center is geographically different from the first data center.
[0079] The data processing apparatus provided by the embodiment of the present application acquires a set of service data stored in the first data center through the first acquisition unit 40, extracts preset fields from the set of service data to obtain M service fields, where the set of service data is used to indicate the service data of users handling financial services, and M is a positive integer; the second acquisition unit 41 acquires a data processing rule, and uses the data processing rule to perform data processing on each service field to obtain M processed service fields, where the data processing rule includes multiple data processing strategies for processing service fields; the replacement unit 42 replaces the fields in the set of service data based on each processed service field to obtain a set of processed service data, and returns the set of processed service data to the second data center, where the second data center is geographically different from the first data center, solving the problems of high deployment cost, high deployment difficulty, and high data leakage risk in the related art when deploying data centers in different regions. By acquiring service data, processing the preset fields in the service data, and replacing the fields in the set of service data based on each processed service field, and finally returning the set of processed service data to the second data center, the technical effects of improving the security of cross-regional data processing, improving data processing efficiency, and reducing deployment costs are achieved.
[0080] Optionally, in the data processing device provided in the embodiments of the present application, the first acquisition unit 40 includes: an acquisition module, configured to acquire a preset field list, where the preset field list includes field information of a plurality of preset fields, and the field information includes at least one of the following: a preset field name, a field type, and a field level; a splitting module, configured to split a set of service data into N split fields, where N is greater than M and N is a positive integer; a first screening module, configured to screen the N split fields by using the preset field list to obtain M service fields.
[0081] Optionally, in the data processing device provided in the embodiments of the present application, the first acquisition unit 40 includes: a second screening module, configured to screen the N split fields by using the preset field list to obtain M initial service fields; a first extraction module, configured to extract the field level of each initial service field from the preset field list to obtain M field levels, and associate the field level with each initial service field to obtain M service fields.
[0082] Optionally, in the data processing device provided in the embodiments of the present application, the second acquisition unit 41 includes: a grouping module, configured to group the M service fields according to the field levels associated with each service field to obtain Y field groups, where each field group is associated with a field level, Y is less than or equal to M, and Y is a positive integer; a second extraction module, configured to extract the data processing policies corresponding to each field group from the data processing rules; a first processing module, configured to process each service field in each field group by using the Y data processing policies to obtain M processed service fields.
[0083] Optionally, in the data processing device provided in the embodiments of the present application, the device further includes: a determination unit, configured to determine a mapping relationship according to the M processed service fields after returning a set of processed service data to the second data center, where the mapping relationship is used to indicate the association relationship between the M service fields and the M processed service fields; a restoration unit, configured to restore a set of processed service data according to the mapping relationship when receiving a data restoration instruction sent by the second data center.
[0084] Optionally, in the data processing device provided in the embodiments of the present application, the data processing rules include one of the following: a hiding module, configured to hide the fields at the preset positions in the preset field when the preset field is a numeric field; a conversion module, configured to perform numeric conversion on the preset field when the preset field is a text field; a second processing module, configured to truncate the preset field when the preset field is neither a numeric field nor a text field.
[0085] Optionally, in the data processing device provided in the embodiments of the present application, the replacement unit 42 includes: a control module, configured to control a data filtering device to perform filtering processing on a set of processed service data to obtain a set of filtered processed data; a sending module, configured to send the set of filtered processed data to a second data center.
[0086] It should be noted here that the above-mentioned first acquisition unit 40, second acquisition unit 41, and replacement unit 42 correspond to steps S201 to S203 in Embodiment 1. The examples and application scenarios implemented by the above units and the corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1 above. It should be noted that the above modules or units may be hardware components or software components stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n). The above units may also be part of a device and may run in the computer terminal 10 provided in Embodiment 1.
[0087] Embodiment 3
[0088] An embodiment of the present application may provide a computer terminal, which may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal may also be replaced with a mobile terminal or other terminal devices such as an electronic device.
[0089] Optionally, in this embodiment, the above computer terminal may be located in at least one of multiple network devices in a computer network.
[0090] In this embodiment, the above computer terminal may execute program codes of the following steps in the data processing method: obtaining a set of service data stored in a first data center, extracting preset fields in the set of service data to obtain M service fields, where the set of service data is used to indicate service data of users handling financial services, and M is a positive integer; obtaining a data processing rule, and using the data processing rule to perform data processing on each service field to obtain M processed service fields, where the data processing rule includes multiple data processing strategies for processing service fields; replacing fields in the set of service data based on each processed service field to obtain a set of processed service data, and returning the set of processed service data to a second data center, where the second data center has a different geographical location from the first data center.
[0091] Optionally, the above computer terminal may execute the program code of the following steps in the data processing method: Extract preset fields from a set of service data to obtain M service fields, including: Obtain a preset field list, where the preset field list includes field information of multiple preset fields, and the field information includes at least one of the following: preset field name, field type, and field level; Perform field splitting on a set of service data to obtain N split fields, where N is greater than M and N is a positive integer; Use the preset field list to filter the N split fields to obtain M service fields.
[0092] Optionally, the above computer terminal may execute the program code of the following steps in the data processing method: Use the preset field list to filter the N split fields to obtain M service fields, including: Use the preset field list to filter the N split fields to obtain M initial service fields; Extract the field level of each initial service field from the preset field list to obtain M field levels, and associate the field level with each initial service field to obtain M service fields.
[0093] Optionally, the above computer terminal may execute the program code of the following steps in the data processing method: Use data processing rules to process each service field to obtain M processed service fields, including: Group the M service fields according to the field levels associated with each service field to obtain Y field groups, where each field group is associated with a field level, Y is less than or equal to M, and Y is a positive integer; Extract the data processing strategy for the field level corresponding to each field group from the data processing rules; Use the Y data processing strategies to process each service field in each field group to obtain M processed service fields.
[0094] Optionally, the above computer terminal may execute the program code of the following steps in the data processing method: After returning a set of processed service data to the second data center, the method further includes: Determine a mapping relationship according to the M processed service fields, where the mapping relationship is used to indicate the association relationship between the M service fields and the M processed service fields; In the case of receiving a data restoration instruction sent by the second data center, restore a set of processed service data according to the mapping relationship.
[0095] Optionally, the above data processing rules include one of the following: In the case where the preset field is a numerical field, hide the field at the preset position in the preset field; In the case where the preset field is a text field, perform numerical conversion on the preset field; In the case where the preset field is not a numerical field or a text field, perform truncation processing on the preset field.
[0096] Optionally, the above computer terminal may execute program code for the following steps in the data processing method: The first data center includes a data filtering device, and returning a set of processed service data to the second data center includes: controlling the data filtering device to perform filtering processing on a set of processed service data to obtain a set of filtered processed data; and sending the set of filtered processed data to the second data center.
[0097] Optionally, Figure 5 is a structural block diagram of an electronic device according to an embodiment of the present application. As Figure 5 shown, the electronic device may include: one or more ( Figure 5 only one is shown in the figure) processors 502, a memory 504, a storage controller, and a peripheral interface, wherein the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0098] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the data processing method and device in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above data processing method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely provided with respect to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise internal network, a local area network, a mobile communication network, and combinations thereof.
[0099] The processor may call the information and application programs stored in the memory through a transmission device to execute the above steps in the above data processing method.
[0100] An embodiment of the present application provides a solution for data processing. By obtaining a set of business data stored in a first data center, extracting preset fields from the set of business data to obtain M business fields, where the set of business data is used to indicate the business data of users handling financial business, and M is a positive integer; obtaining a data processing rule, and using the data processing rule to perform data processing on each business field to obtain M processed business fields, where the data processing rule includes multiple data processing strategies for processing business fields; replacing the fields in the set of business data based on each processed business field to obtain a set of processed business data, and returning the set of processed business data to a second data center, where the geographical location of the second data center is different from that of the first data center, thereby achieving the purpose of improving the security of cross-regional data processing, improving data processing efficiency, and reducing deployment costs, and further solving the problems of high deployment costs, high deployment difficulties, and high data leakage risks when deploying data centers in different regions.
[0101] Those of ordinary skill in the art can understand that Figure 5 the structure shown is only schematic, and the electronic device can also be a terminal device such as a smart phone, a tablet computer, a handheld computer, and a Mobile Internet Device (MID), a PAD, etc. Figure 5 It does not limit the structure of the above electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown in Figure 5 or have a different configuration from that shown in Figure 5 .
[0102] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disc, etc.
[0103] Embodiment 4
[0104] An embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the above storage medium can be used to store the program code executed by the data processing method provided in the first embodiment above.
[0105] Optionally, in this embodiment, the above storage medium may be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0106] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: obtaining a set of service data stored in the first data center, extracting preset fields from the set of service data to obtain M service fields, where the set of service data is used to indicate the service data of users handling financial services, and M is a positive integer; obtaining a data processing rule, and using the data processing rule to process each service field to obtain M processed service fields, where the data processing rule includes multiple data processing strategies for processing service fields; replacing the fields in the set of service data based on each processed service field to obtain a set of processed service data, and returning the set of processed service data to the second data center, where the second data center has a different geographical location from the first data center.
[0107] The present application also provides a computer program product, which is suitable for executing a program of the data processing method steps when executed on a data processing device.
[0108] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.
[0109] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0110] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces, and the indirect coupling or communication connection of units or modules may be in an electrical or other form.
[0111] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0112] In addition, the functional units in the various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0113] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0114] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A method for processing data, characterized in that, Applied to the first data center, including: Obtain a set of business data stored in the first data center, extract preset fields from the set of business data to obtain M business fields, where the set of business data is used to indicate the business data of users handling financial business, and M is a positive integer; Obtain data processing rules, and use the data processing rules to process each business field to obtain M processed business fields, where the data processing rules include multiple data processing strategies for processing business fields; Replace the fields in the set of business data based on each processed business field to obtain a set of processed business data, and return the set of processed business data to the second data center, where the second data center has a different geographical location from the first data center.
2. The method according to claim 1, wherein Extracting preset fields from the set of business data to obtain M business fields includes: Obtain a preset field list, where the preset field list includes field information of multiple preset fields, and the field information includes at least one of the following: preset field name, field type, and field level; Perform field splitting on the set of business data to obtain N split fields, where N is greater than M and N is a positive integer; Use the preset field list to filter the N split fields to obtain the M business fields.
3. The method according to claim 2, wherein Using the preset field list to filter the N split fields to obtain the M business fields includes: Use the preset field list to filter the N split fields to obtain M initial business fields; Extract the field level of each initial business field from the preset field list to obtain M field levels, and associate the field level with each initial business field to obtain the M business fields.
4. The method according to claim 1, characterized in that, Using the data processing rules to process each business field to obtain M processed business fields includes: Group the M business fields according to the field level associated with each business field to obtain Y field groups, where each field group is associated with a field level, Y is less than or equal to M, and Y is a positive integer; Extract the data processing strategy corresponding to the field level of each field group from the data processing rules; Use Y data processing strategies to process each business field in each field group to obtain the M processed business fields.
5. The method according to claim 1, wherein After returning the set of processed business data to the second data center, the method further includes: Determine a mapping relationship according to the M processed business fields, where the mapping relationship is used to indicate the association relationship between the M business fields and the M processed business fields; In the case of receiving a data restoration instruction sent by the second data center, restore the set of processed business data according to the mapping relationship.
6. The method according to claim 1, wherein The data processing rules include one of the following: In the case where the preset field is a numerical field, hide the field at the preset position in the preset field; In the case where the preset field is a text field, perform numerical conversion on the preset field. In the case that the preset field is not the numeric field or the text field, truncate the preset field.
7. The method according to claim 1, characterized in that, The first data center includes a data filtering device. Returning the set of processed service data to the second data center includes: Controlling the data filtering device to perform filtering processing on the set of processed service data to obtain a set of filtered processed data; Sending the set of filtered processed data to the second data center.
8. A data processing device, characterized in that, Includes: A first acquisition unit, configured to acquire a set of service data stored in the first data center, extract a preset field from the set of service data to obtain M service fields, where the set of service data is used to indicate service data of a user handling a financial service, and M is a positive integer; A second acquisition unit, configured to acquire a data processing rule, and use the data processing rule to perform data processing on each service field to obtain M processed service fields, where the data processing rule includes multiple data processing strategies for processing service fields; A replacement unit, configured to replace the fields in the set of service data based on each processed service field to obtain a set of processed service data, and return the set of processed service data to the second data center, where the second data center is geographically different from the first data center.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein when the executable program runs, it controls the device where the computer-readable storage medium is located to execute the data processing method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, Includes: A memory storing an executable program; A processor for running the program, wherein when the program runs, it executes the data processing method according to any one of claims 1 to 7.
11. A computer program product, comprising computer instructions, characterized in that, When the computer instruction is executed by the processor, it implements the steps of the data processing method according to any one of claims 1 to 7.