Data desensitization method and system

Through real-time big data processing technology and calculus modeling, the noise injection intensity in the desensitization algorithm is dynamically adjusted, solving the problem of low data desensitization efficiency in the enterprise risk control field, and real-time privacy protection and data utility improvements are achieved.

CN120337258APending Publication Date: 2025-07-18XIAMEN MEIYA YIAN INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510427567.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing technology has low data desensitization efficiency in the field of enterprise risk control, which cannot meet real-time requirements, resulting in data "visible and unavailable, and cannot meet the real-time query requirements of enterprise risk control business systems.

Method used

Using real-time big data processing technology, combined with calculus modeling and dynamic calibration methods, by constructing data desensitization programs, dynamically adjusting the noise injection intensity in the desensitization algorithm, real-time sensitivity evaluation and noise injection are achieved, and privacy protection intensity and data availability are balanced.

Benefits of technology

In the enterprise risk control data scenario, real-time privacy protection is achieved, improving data utility by 41%, while reducing privacy leakage risk by 63%, meeting the real-time needs of enterprise risk control business systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337258A_ABST
    Figure CN120337258A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a data desensitization method and system, and the method comprises the steps: obtaining real-time plaintext data needed by an enterprise risk control business system in response to a risk data request sent by the enterprise risk control business system; performing sensitivity evaluation on the real-time plaintext data to obtain a real-time sensitivity change of the real-time plaintext data; dynamically injecting noise matched with the real-time sensitivity change into the real-time plaintext data to obtain adjusted data; based on the sensitivity of the adjusted data, adjusting the desensitization intensity of the adjusted data to obtain candidate data; and performing attenuation degree adjustment on the sensitive information of the candidate data to obtain and output desensitized data to the enterprise risk control business system. According to the method, the privacy disclosure risk can be reduced while the data utility is improved, so that the real-time requirement of an enterprise risk control business system is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly to a data desensitization method and system in the technical field of data processing. Background Art

[0002] In the field of enterprise risk control, the current situation of data desensitization is relatively single. Most data is desensitized according to specific rules, resulting in data being "visible but unavailable", and the efficiency of data desensitization is relatively low. The desensitization of hundreds of megabytes of data is in the minute level, which cannot meet the real-time requirements of the enterprise risk control business system. Summary of the Invention

[0003] The purpose of the present invention is to provide a data desensitization method and system, and the specific technical solutions adopted are as follows:

[0004] In the first aspect, an embodiment of the present invention provides a data desensitization method, which includes:

[0005] Responding to a risk data request sent by an enterprise risk control business system, and obtaining real-time plaintext data required by the enterprise risk control business system;

[0006] Performing a sensitivity assessment on the real-time plaintext data to obtain a real-time sensitivity change of the real-time plaintext data;

[0007] Dynamically injecting noise matching the real-time sensitivity change into the real-time plaintext data to obtain adjusted data;

[0008] Based on the sensitivity of the adjusted data, adjusting the desensitization intensity of the adjusted data to obtain candidate data;

[0009] Adjusting the attenuation degree of sensitive information of the candidate data, and obtaining and outputting desensitized data to the enterprise risk control business system.

[0010] In the second aspect, a data desensitization system is provided, and the system includes:

[0011] An acquisition module, configured to respond to a risk data request sent by an enterprise risk control business system, and obtain real-time plaintext data required by the enterprise risk control business system;

[0012] An evaluation module, configured to perform a sensitivity assessment on the real-time plaintext data to obtain a real-time sensitivity change of the real-time plaintext data;

[0013] An injection module, configured to dynamically inject noise matching the real-time sensitivity change into the real-time plaintext data to obtain adjusted data;

[0014] An adjustment module, configured to adjust the desensitization intensity of the adjusted data based on the sensitivity of the adjusted data to obtain candidate data;

[0015] An output module, configured to adjust the attenuation degree of the sensitive information of the candidate data to obtain and output the desensitized data to the enterprise risk control business system.

[0016] In a third aspect, a computer program product is provided, which includes: computer program code, when the computer program code runs on a computer, enabling the computer to execute the method in the first aspect or any one of the possible implementation manners described in the first aspect.

[0017] In a fourth aspect, a computer-readable storage medium is provided, which stores computer program code, when the computer program code runs on a computer, enabling the computer to execute the method in the first aspect or any one of the possible implementation manners described in the first aspect.

[0018] The present invention has the following beneficial effects: For a risk data request sent by an enterprise risk control business system, obtain the real-time plaintext data required by the enterprise risk control business system; and perform a sensitivity assessment on the real-time plaintext data to obtain the real-time sensitivity change of the real-time plaintext data. In this way, by performing a real-time sensitivity assessment on the real-time plaintext data, the real-time sensitivity change of the real-time plaintext data can be analyzed in a timely and accurate manner. Then, based on the real-time sensitivity change, inject noise that meets the privacy budget into the real-time plaintext data to obtain adjusted data. In this way, according to the real-time sensitivity change, the noise injection intensity in the desensitization algorithm is automatically adjusted, so as to balance the privacy protection intensity and data availability. Finally, based on the sensitivity of the adjusted data, adjust the desensitization intensity of the adjusted data to obtain candidate data; and adjust the attenuation degree of the sensitive information of the candidate data to obtain and output the desensitized data to the enterprise risk control business system. In this way, in the enterprise risk control data scenario, through the integration of dynamic desensitization and encryption algorithms, real-time privacy protection based on mathematical analysis is realized. While improving data utility, the risk of privacy leakage can also be reduced to meet the real-time requirements of the enterprise risk control business system. Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1It is a schematic diagram of the implementation process of a data desensitization method provided by an embodiment of the present invention;

[0021] Figure 2 It is another schematic diagram of the implementation process of a data desensitization method provided by an embodiment of the present invention;

[0022] Figure 3 It is yet another schematic diagram of the implementation process of a data desensitization method provided by an embodiment of the present invention;

[0023] Figure 4 It is a schematic diagram of the composition structure of a data desensitization system provided by an embodiment of the present invention;

[0024] Figure 5 It is a schematic diagram of the structure of a computer device provided by an embodiment of the present invention. Detailed implementation manners

[0025] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following, in combination with the accompanying drawings and preferred embodiments, details a data desensitization method proposed according to the present invention, its specific implementation manners, structures, features and effects as follows. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0026] Among them, in the description of the embodiments of the present invention, unless otherwise specified, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present invention, "multiple" means two or more than two.

[0027] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or indicating relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.

[0029] In some embodiments, the application of data desensitization technology is very extensive. With the continuous deepening of enterprise risk control business and the frequent occurrence of data leakage incidents, data desensitization technology has become an important means to protect enterprise privacy and secrets. With the continuous increase in data volume and the surging demand for real-time data desensitization, technologies such as single technology, single algorithm model, and single programming language can no longer meet the current real-time requirements. In particular, there are serious deficiencies in data desensitization efficiency and privacy computing efficiency. The entire enterprise risk control industry (audit, supervision, compliance, etc.) urgently needs a data desensitization method that makes data "usable but invisible".

[0030] In the field of enterprise risk control, the current situation of data desensitization is relatively single. Most data is desensitized according to specific rules, resulting in data being "visible but unusable" and having low efficiency in data desensitization. The desensitization of hundreds of megabytes of data takes minutes, which cannot meet the real-time requirements of enterprise risk control business systems (for example: the query request returns the paged result within 300 milliseconds).

[0031] Based on this, the big data real-time processing technology introduced in the embodiments of the present invention uses methods such as calculus modeling and dynamic calibration to give full play to the maximum processing advantage of the server and build the optimal data desensitization program to ensure the real-time processing of data desensitization. At the same time, a data desensitization result with periodic data desensitization indicators is constructed for verification, and the data desensitization result is repeatedly verified in different periods to ensure the access security and real-time response ability of enterprise risk control data to the greatest extent.

[0032] Next, the specific solution of a data desensitization method provided by the present invention will be specifically described with reference to the accompanying drawings. Please refer to Figure 1 , which shows a schematic diagram of the implementation framework of a data desensitization method provided by an embodiment of the present invention. The enterprise risk control system 11 includes: audit, supervision, legal affairs, supervision, education, ···;

[0033] First, the enterprise risk control business system 11 initiates a risk data request. After passing the unified permission authentication, it sends a real-time data query request to the enterprise risk digital platform 12 (that is Figure 1The compliance request shown). After receiving the risk request, the enterprise risk digital platform 12 performs a query, extracts the data required by the risk control business system (raw plaintext data), and submits it to the data real-time desensitization engine 13. After receiving the data, the data real-time desensitization engine 13 first initializes the sensitivity gradient field: constructs a dynamic desensitization policy, determines the recognition rules for sensitive fields in the real-time plaintext data, and the initial sensitivity evaluation benchmark. The process of automatically adjusting the noise injection intensity in the desensitization algorithm according to the real-time sensitivity change of the data received by the data real-time desensitization engine is mainly to balance the privacy protection intensity and data availability. "Constructing the calculus calculation pipeline" combines the mathematical operations related to calculus (such as integration) with the dynamic data stream processing flow (Flink) to form a hierarchical and continuous calculation link. It includes: differential calculation, noise integration, frequency domain filtering, statistical correction, etc. (i.e., differential privacy injection, feature-preserving integration, statistical constraint correction, and frequency domain desensitization operator). Before data desensitization, "reversibility control" can be configured through a specific mathematical mechanism to allow authorized users to restore the original desensitized data when meeting the preset conditions, while ensuring that unauthorized users cannot reverse-derive sensitive information. After the real-time desensitization engine finishes processing, the data is pushed to the "enterprise risk control business system" after authentication. In Figure 1 it, the sensitivity gradient field is used to evaluate the dynamic sensitivity of different fields in the real-time plaintext data in real time; the desensitization kernel function is used to dynamically adjust the data deformation intensity during real-time data desensitization while retaining key business features; "differential privacy injection" is introduced to dynamically inject noise that meets the privacy budget through integral operations to balance data availability and privacy security; the "feature-preserving integrator" is used to maintain key statistical features (such as mean, variance, etc.) through mathematical constraints during data desensitization while dynamically adjusting the desensitization intensity according to sensitivity; the "frequency domain desensitization operator" is constructed to process the data by converting it from the time domain to the frequency domain, and desensitization is achieved by dynamically adjusting the attenuation degree of sensitive information of different frequency components; "reversibility control" is introduced to enable authorized users to restore the original desensitized data when meeting the preset conditions, while ensuring that unauthorized users cannot reverse-derive sensitive information.

[0034] The embodiment of the present application provides a data desensitization method. Please refer to Figure 2 which shows a schematic implementation flow diagram of a data desensitization method provided by an embodiment of the present invention. The method includes:

[0035] 201, in response to a risk data request sent by the enterprise risk control business system, obtain the real-time plaintext data required by the enterprise risk control business system.

[0036] Here, the enterprise risk control business system initiates a risk data request. After passing the permission verification, it initiates a real-time data query request to the enterprise risk digital platform. After receiving the real-time query request, the enterprise risk data platform extracts the data required by the risk control business system (the original plaintext data, i.e., the real-time plaintext data) and submits it to the real-time data desensitization engine.

[0037] In some possible implementation manners, "reversibility control" is configured before data desensitization, allowing authorized users to restore the original desensitized data when meeting preset conditions, while ensuring that unauthorized users cannot reverse-derive sensitive information. This can be achieved through the following steps: First, obtain the identity information of the user terminal. For example, this identity information is used to represent whether the user terminal has been authorized. After that, when the identity information of the user terminal meets the preset key control parameters, authorize the user terminal to be able to reversely restore the real-time plaintext data corresponding to the desensitized data. For example, by setting reversibility control, allowing authorized users to restore the original desensitized data when meeting preset conditions, while ensuring that unauthorized users cannot reverse-derive sensitive information. In this way, the reversibility of data encryption is combined with the irreversibility of traditional desensitization to achieve a balance between security and practicality through mathematical constraints.

[0038] Ensure conditional reversibility by constructing the Jacobian matrix: When det(J)≠0, the authorized user can restore the real-time plaintext data by solving the partial differential equations.

[0039] 202, perform a sensitivity assessment on the real-time plaintext data to obtain the real-time sensitivity change of the real-time plaintext data.

[0040] Here, the real-time data desensitization engine initializes the sensitivity gradient field of the real-time plaintext data. By constructing a dynamic desensitization strategy, determining the recognition rules for sensitive fields in the real-time plaintext data, and the initial sensitivity assessment benchmark, sensitivity assessment is realized to obtain the real-time sensitivity change of the real-time plaintext data.

[0041] In some possible implementation manners, the above step 202 can be achieved through Figure 3 the steps shown as follows:

[0042] 301, perform a sensitivity assessment on the real-time plaintext data to determine the sensitive fields and the initial sensitivity.

[0043] Here, by calculating the gradient field of the real-time plaintext data, the initialization of the sensitivity gradient field is realized, and a dynamic sensitivity assessment model is constructed to accurately identify the sensitive fields and the initial sensitivity of the real-time plaintext data.

[0044] In some possible implementation manners, the sensitive fields and the initial sensitivity of the real-time plaintext data can be identified through the following process:

[0045] First, determine the gradient field of the real-time plaintext data.

[0046] Here, the desensitization intensity is dynamically adjusted through a continuously differentiable sensitivity function, and the integral is combined to maintain the statistical characteristics of the data, achieving a mathematical balance between security and usability.

[0047] Define the sensitivity function in the real-time plaintext data: where x t is the input data vector at time t; φ(x t ) is a sensitivity classifier based on logistic regression, used to identify the sensitive categories of data fields (such as PII, PHI, etc.). For example, fields such as ID numbers and mobile phone numbers will be classified as highly sensitive data; ψ(x t ) is the gradient field of the data distribution, reflecting the change direction of the data in the feature space. For example, if the value of a certain field fluctuates violently in a short period of time (such as financial reimbursement risk data), its gradient value will increase significantly. λ is a Lagrange multiplier (for example, with a value range of 0.6 - 1.2), used to balance the weights of time sensitivity and space sensitivity.

[0048] Secondly, based on the gradient field and the sensitivity classifier, construct a dynamic sensitivity evaluation model for the real-time plaintext data.

[0049] Here, the sensitivity function constructs a dynamic sensitivity evaluation model through data type recognition technology, combined with the spatio-temporal characteristics of data flow. This dynamic sensitivity evaluation model includes: time dimension evaluation and space dimension evaluation.

[0050] Finally, based on the dynamic sensitivity evaluation model, perform sensitivity evaluation on the real-time plaintext data to obtain the sensitive fields and the initial sensitivity.

[0051] Here, the initial sensitivity is identified through the sensitivity classifier in the dynamic sensitivity model, and the sensitive fields are identified in real time through the gradient field.

[0052] In some possible implementation manners, through the sensitivity classifier in the dynamic sensitivity evaluation model, identify the change of the sensitivity of the real-time plaintext data over time to obtain the initial sensitivity; and through the gradient field in the dynamic sensitivity evaluation model, identify the sensitive fields of the real-time plaintext data.

[0053] For example, by capturing the change of sensitivity over time, such as detecting suddenly emerging high-risk fields in the real-time plaintext data (such as the bank cards for salary payment in the personnel system and the financial system), to achieve time dimension evaluation and obtain the initial sensitivity. By Analyze the distribution changes of data in the feature space, identify the aggregation areas of sensitive data (such as the clustering features of address fields), so as to achieve spatial dimension evaluation and obtain sensitive fields. In this way, through the dynamic sensitivity evaluation model, the spatial dimension evaluation and time dimension evaluation of real-time plaintext data can be carried out in real time and accurately, so as to obtain relatively accurate sensitive fields and initial sensitivities.

[0054] 302. Based on the sensitive fields and initial sensitivities, determine the real-time sensitivity change of the real-time plaintext data.

[0055] Here, according to the identification rules of sensitive fields and the initial sensitivity evaluation benchmark in the real-time plaintext data, compare the sensitive fields and the initial sensitivities, so as to identify the real-time sensitivity change of the real-time plaintext data, and submit the real-time sensitivity change to the data real-time desensitization engine. In this way, through the sensitivity evaluation of the real-time plaintext data, the sensitive fields and initial sensitivities in the real-time plaintext data can be accurately identified, so as to more accurately analyze the real-time sensitivity change of the real-time plaintext data.

[0056] In some possible implementation manners, the data real-time desensitization engine can initialize the sensitivity gradient field of the real-time plaintext data through the following process: train the φ(x t ) classifier with a CNN network, label sensitive fields such as PII and PHI in the dataset, and construct an initial gradient field The initialization of the sensitivity gradient field is the starting step for constructing a dynamic desensitization strategy. It determines the identification rules of sensitive fields and the initial sensitivity evaluation benchmark in the real-time plaintext data through mathematical modeling and machine learning techniques. The initialization of the sensitivity gradient field refers to establishing a dynamic evaluation starting point for data sensitivity through a data classification model and gradient field analysis.

[0057] The functions of performing the initialization of the sensitivity gradient field include: sensitive data identification and sensitivity quantization; among them:

[0058] Sensitive data identification includes: labeling sensitive fields such as personal identity information, supplier information, financial account amount information, and trade transaction information in the data.

[0059] Sensitivity quantization includes: providing an initial benchmark for subsequent dynamic adjustment of the desensitization intensity. For example, the sensitivity weights of different fields may be different.

[0060] 1) Train the classifier (ψ(x t ))

[0061] Input: data vector x t (such as field values, metadata, and context features in the database).

[0062] Model Selection: Adopt models such as Convolutional Neural Network (CNN) to train a binary or multi-class classifier to distinguish sensitive and non-sensitive data. For example, fields such as ID numbers and mobile phone numbers will be labeled as highly sensitive categories.

[0063] Training Data: It is necessary to label the dataset containing sensitive fields and define labels in combination with industry specifications (such as GDPR, financial data security standards).

[0064] 2) Construct the gradient field

[0065] Objective: Analyze the impact of data distribution characteristics on sensitivity. For example, the sensitivity of some fields may change with their occurrence frequency and associated fields in real-time plaintext data.

[0066] The data distribution gradient field ψ(x0) reflects the statistical correlation between fields (such as the correlation between zip code and address).

[0067] Calculation Method: Generate an initial gradient field through statistical analysis (such as probability density function) or graph neural network. For example, if the combination of field A and field B can uniquely identify a user, then the gradient values of both are relatively high.

[0068] 203. Dynamically inject noise matching the real-time sensitivity change into the real-time plaintext data to obtain the adjusted data.

[0069] Here, by calculating the gradient field of the real-time sensitivity change and injecting noise that meets the privacy budget in accordance with the change rate of the gradient field, the adjusted data is obtained. The noise matching the real-time sensitivity change is the noise that meets the privacy budget.

[0070] In some possible implementation manners, the above step 203 can be implemented through the following steps 231 to 233 (not shown in the figure):

[0071] 231. Obtain the gradient field corresponding to the real-time sensitivity change.

[0072] Here, the gradient field corresponding to the real-time sensitivity change can be obtained through the formula Calculated.

[0073] 232. Based on the gradient field corresponding to the real-time sensitivity change, determine the instantaneous change of data sensitivity.

[0074] Here, the instantaneous change of data sensitivity is obtained through the time derivative of the gradient field corresponding to the real-time sensitivity change. That is, through the time derivative of the sensitivity function, the de-sensitization intensity is adjusted according to the instantaneous change of sensitivity in the real-time plaintext data.

[0075] 233. Based on the instantaneous change of the data sensitivity, Laplace noise is superimposed on the real-time plaintext data in integral form to obtain the adjusted data.

[0076] Here, the larger the gradient field value S(t), the higher the current data sensitivity, and stronger noise needs to be injected (for example, increasing the variance σ of the Laplace noise). For example, the high-risk result field in the enterprise risk record may trigger a higher desensitization intensity. The dynamic calculation of the gradient field combined with the subsequent dual-channel integral constraint (maintaining the mean and variance) ensures that the desensitized data can still be used for statistical analysis.

[0077] In some possible implementation manners, by analyzing the sensitivity change rate, the noise injection intensity is adjusted in real time, and it can be achieved through the following process:

[0078] First, based on the instantaneous change of the data sensitivity, the sensitivity change rate is determined.

[0079] Here, the sensitivity change rate is obtained by taking the derivative of the instantaneous change of the data sensitivity.

[0080] Second, based on the sensitivity change rate, the noise injection intensity is determined.

[0081] For example, the noise injection intensity is proportional to the sensitivity change rate.

[0082] Finally, Laplace noise satisfying the noise injection intensity is superimposed on the real-time plaintext data in integral form to obtain the adjusted data.

[0083] For example, according to this noise injection intensity, Laplace noise is injected into the real-time plaintext data in integral form to obtain the adjusted data, so as to realize dynamic noise injection and adjust the noise intensity in real time.

[0084] In some possible implementation manners, the real-time privacy protection technology of "differential privacy injection" based on calculus theory and dynamic noise adjustment is used. By integral operation, noise satisfying the privacy budget is dynamically injected to balance data availability and privacy security. Second, key statistical features (such as mean, variance, etc.) are maintained through data constraints, and at the same time, the desensitization intensity is dynamically adjusted according to the sensitivity to make the data "usable but invisible". Finally, the data is processed by converting it from the time domain to the frequency domain through the "frequency domain desensitization operator", and desensitization is achieved by dynamically adjusting the attenuation degree of sensitive information of different frequency components. Among them, "differential privacy injection" is in the process of real-time data stream processing, according to the instantaneous change of the data sensitivity (measured by the derivative of the sensitivity function) Measure), Laplace noise is superimposed on the original data stream (that is, the real-time plaintext data) in integral form. The mathematical expression of the adjusted data: Where: D(t) is the original data stream (i.e., real-time plaintext data); ∈(τ) is a Laplace noise generator that satisfies: Δ is the predefined privacy budget; represents the instantaneous change rate of the sensitivity function (i.e., the sensitivity change rate), which determines the noise intensity. The noise injection intensity is proportional to the sensitivity change rate When the data sensitivity rises rapidly (such as detecting ID numbers, financial accounting amounts, etc.), the noise intensity is increased to enhance protection; when the sensitivity is low (such as ordinary text, descriptions, remarks, etc.), the noise is reduced to retain the data value, so as to achieve dynamic adjustment of the noise.

[0085] Through integral operation ensure that the cumulative noise does not exceed the preset global privacy budget Δ, which conforms to the mathematical definition of "differential privacy" to achieve the integral constraint of the privacy budget. The noise injection is completed synchronously with the data stream processing, and the delay is controlled within milliseconds (such as in scenarios like finance and trade where the delay growth rate meets the real-time business requirements.

[0086] In some possible implementation manners, the intensity of the injected noise can be dynamically determined through the following process: a process of automatically adjusting the noise injection intensity in the desensitization algorithm according to the real-time sensitivity change of the real-time plaintext data. Its core goal is to balance the privacy protection intensity and data availability.

[0087] 1) Calibration mechanism, including:

[0088] Calculate every Δt time (such as 50 - 100 milliseconds (ms)): Where represents the second derivative of the sensitivity function S(t), reflecting the acceleration change of the sensitivity; T is the sliding time window length (usually taking 3 - 5 sampling periods); Δσ is the standard deviation adjustment amount, which is used to control the intensity of Gaussian noise and automatically adjusts the noise injection intensity according to the second derivative change rate. This formula quantifies the degree of fluctuation of the data stream by integrating the absolute value of the acceleration of the sensitivity change. When the sensitivity changes rapidly (such as a sudden large amount of highly sensitive data), Δσ increases to enhance the noise; otherwise, the noise is reduced.

[0089] 2) Calibration objects, including: mainly adjusting the following two types of parameters: Noise standard deviation σ: Affects the data perturbation amplitude. The larger σ is, the stronger the privacy protection, but the higher the data distortion degree.

[0090] Lagrange multiplier λ: Controls the weight ratio between the sensitivity classifier φ(x t ) and the gradient field ψ(x t ), and is used to dynamically adjust the sensitivity determination criterion.

[0091] 3) Actual application scenarios, taking the financial risk data on weekdays as an example:

[0092] Normal query period: The sensitivity changes smoothly, Δσ≈0.05, and only a small amount of noise is injected.

[0093] Year-end audit / supervision peak: The second derivative of sensitivity surges, Δσ rises to 0.2, and enhanced field encryption is pushed in batches early in the morning. Risk during peak: The sensitivity remains at a high level but the change rate is low, and Δσ gradually drops to 0.158.

[0094] In some possible implementation methods, by constructing a calculus calculation pipeline, combining calculus-related mathematical operations (such as derivatives, integrals) with the dynamic data stream processing process to form a hierarchical and continuous calculation link, aiming to achieve complex operations such as dynamic evaluation of sensitivity, noise injection, and statistical feature preservation through mathematical modeling; among them, the data processing process of the data pipeline is: raw data stream → differential privacy injection → feature-preserving integration (noise integrator) → frequency-domain desensitization operator (frequency-domain filter) → statistical constraint correction → output desensitized stream. A big data real-time stream computing framework is used to achieve millisecond-level execution. The following process is used for illustration:

[0095] 1) Pipeline design principles, including:

[0096] Hierarchical embedding of calculus operations: Decompose differential calculation (sensitivity evaluation) and integral operations (noise accumulation) into independent processing layers, forming a processing sequence similar to a factory assembly line.

[0097] Sensitivity evaluation layer: Real-time calculation of the derivative of data sensitivity Dynamically judge the desensitization intensity.

[0098] Noise integrator: Through integral operation Accumulate Laplace noise to achieve dynamic allocation of privacy budget.

[0099] 2) Adaptation of the streaming processing engine, including: Using the phased processing ability of the stream processing framework to map mathematical operations to distributed tasks.

[0100] Windowed calculation: The data stream is sliced into micro-batches by time (such as 50 - 100ms windows), and differential and integral operations are completed within each window.

[0101] State management: Save intermediate calculation results (such as sensitivity gradient field, noise accumulation value) through the fault tolerance mechanism of the stream engine (such as Checkpoint) to ensure the continuity of the operation.

[0102] Core components of the pipeline, including: Sensitivity evaluation layer: Use CNN or logistic regression models to classify the data sensitivity level in real time, and calculate the sensitivity gradient field in combination with spatio-temporal features Output dynamic desensitization parameters (such as noise intensity σ).

[0103] Frequency domain filter: Convert the data stream to the frequency domain F(D)(ω) through Fourier transform, filter out high-frequency sensitive information using the hyperbolic tangent function (tanh), and then reconstruct the desensitized data through inverse transform.

[0104] 3) Statistical constraint correction layer, including: designing an integral constraint equation Ensure that statistics such as the mean and variance of the desensitized data are consistent with the original data.

[0105] 204. Based on the sensitivity of the adjusted data, adjust the desensitization intensity of the adjusted data to obtain candidate data.

[0106] In some possible implementation manners, the above step 204 may be implemented through the following steps 241 to 245 (not shown in the figure):

[0107] 241. Obtain the Gaussian kernel of the adjusted data.

[0108] Here, after obtaining the adjusted data, obtain the Gaussian kernel of the adjusted data to facilitate constructing a desensitization operator for the adjusted data through a variant of the Gaussian kernel.

[0109] 242. Based on the Gaussian kernel, construct a desensitization operator for the adjusted data.

[0110] Here, a variant of the Gaussian kernel is used to construct a desensitization operator: Where: f(x) is a data feature extraction function; σ is the dynamic standard deviation, which is calculated in real time for the integral interval [a, b] corresponding to the data life cycle. Calculate the data life cycle corresponding to the integral interval [a, b] in real time.

[0111] 243. Use the desensitization operator to dynamically adjust the deformation intensity of the adjusted data to obtain constrained data.

[0112] Here, the desensitization operator is used to dynamically adjust the data deformation intensity during real-time data desensitization while retaining key statistical features to obtain constrained data. The constraint of the adjusted data is achieved by introducing a feature-preserving integrator to obtain constrained data.

[0113] In some possible implementation manners, the feature-preserving integrator preserves key statistical features (such as mean, variance, etc.) through mathematical constraints during the data desensitization process, and at the same time dynamically adjusts the desensitization intensity according to the sensitivity. The feature-preserving integrator realizes statistical feature retention and dynamic security control during the dynamic desensitization process by constructing a dual-channel integral constraint.

[0114] Statistical Feature Preservation: Ensure that the desensitized data is consistent with the original data in terms of statistical distribution (such as mean, variance, etc.), and avoid data distortion that may affect subsequent analysis.

[0115] Dynamic Security Control: Dynamically adjust the variance according to the sensitivity function S(t), so that the desensitization intensity increases as the data sensitivity rises, reducing the risk of privacy leakage.

[0116] The core of the feature-preserving integrator consists of the following two differential equations: By solving this set of differential equations, while maintaining statistics such as the mean and variance, the variance increases moderately with sensitivity (α is the adjustment coefficient, recommended to be 0.05 - 0.2). Where:

[0117] The First Equation: The integral of the desensitized data stream with respect to the mean over time is equal to that of the original data stream D, ensuring that the overall mean of the desensitized data remains unchanged.

[0118] The Second Equation: The variance of the desensitized data increases by an increment that is positively correlated with the sensitivity S(t) on the basis of the original variance (σ is the adjustment coefficient), achieving a dynamic balance between security and data volatility.

[0119] 244. Calculate the derivative of the sensitivity of the constrained data in real time.

[0120] Here, the role of the desensitization operator includes: implementing Gaussian similarity measurement (i.e., the exponential part): by calculating the similarity between the data feature f(x) and the desensitized feature f(x ′ ), ensuring that the distribution of the desensitized data in the feature space is close to the original data. The dynamic standard deviation σ reflects the data volatility in real time: It is consistent with maintaining statistical characteristics in traditional data desensitization.

[0121] Sensitivity Dynamic Adjustment Term : Combine the time derivative of the sensitivity function S(t) to adjust the desensitization intensity according to the instantaneous change of sensitivity in the data stream. For example, when detecting highly sensitive fields (such as ID numbers, accounting voucher numbers, salary cards, etc.), automatically enhance the noise perturbation.

[0122] Lifecycle Integration (integration interval [a, b]): The integration range covers the entire lifecycle of the data (such as the collection, transmission, and storage stages), achieving the coherence of the desensitization strategy across stages, similar to the concept of adjusting the strategy according to different scenarios in dynamic desensitization.

[0123] 245. Based on the derivative of the sensitivity of the constrained data, adjust the desensitization intensity of the constrained data in real time to obtain the candidate data.

[0124] Here, through the Laplace transform or numerical integration method, it is ensured that the integral characteristics (such as the total amount and distribution form) of the data remain unchanged in the time domain / frequency domain. The term α·S(t) is introduced to enhance the desensitization noise corresponding to highly sensitive data, which is consistent with the idea of "adjusting the desensitization intensity as needed" in dynamic desensitization. Combining with the Apache Flink framework, the integral constraint equation is calculated in real time to achieve the synchronization of statistical features with millisecond-level delay. Through the second derivative evaluate the sensitivity change rate, automatically adjust the α coefficient (for example, it is recommended that α = 0.05 - 0.2 in scenarios such as finance and bid opening risk), so as to realize the real-time adjustment of the desensitization intensity of the constrained data and obtain the candidate data.

[0125] 205, adjust the attenuation degree of the sensitive information of the candidate data, and obtain and output the desensitized data to the enterprise risk control business system.

[0126] Here, the candidate data is transformed from the time domain to the frequency domain by using a frequency domain desensitization operator to obtain frequency components; and the attenuation degree of the sensitive information of the frequency components is dynamically adjusted, and the desensitized data is obtained and output to the enterprise risk control business system. For example, the data is transformed from the time domain to the frequency domain for processing, and desensitization is achieved by dynamically adjusting the attenuation degree of the sensitive information of different frequency components. Apply the Fourier transform to construct a frequency domain filter: where β is the frequency domain attenuation factor; the sensitivity gradient field parameter represents the sensitivity of different frequency components; the tanh function is a decay function with smooth transition to avoid data distortion caused by sudden changes in frequency bands; and the data is converted back to the time domain data through the inverse FFT. Here, the idea of data camouflage is applied and inherited, and the frequency domain dynamic adjustment is added; the functions are as follows:

[0127] Multi-granularity protection: Differential desensitization can be implemented for different frequency components. For example, high-frequency detail information (such as transaction timestamps) is completely blurred, and low-frequency trend information (such as monthly total consumption) retains the original distribution.

[0128] Real-time guarantee: Combining with the FFT algorithm (complexity O (nlogn) ), millisecond-level delay is achieved in a streaming computing framework (such as Flink) to meet the requirements of scenarios such as financial real-time risk control.

[0129] Reversibility control: By presetting the key to control the β parameter, authorized users can reversely restore the original data, taking into account both security and business audit requirements.

[0130] In some embodiments, after obtaining the desensitized data, the following process can be used for index verification:

[0131] 1) Privacy leakage degree: where is the Jacobian matrix of the desensitized data with respect to the original data, reflecting the sensitivity change of the desensitization operation; S(t) is the dynamic sensitivity function, evaluating the sensitivity degree of the data at the current moment; T is the time span of the data life cycle; ∈ max is a preset privacy protection threshold.

[0132] 2) Data utility loss: where μ D and respectively represent the means of the original data and the desensitized data; σ D and respectively represent the variances of the two.

[0133] 3) Real-time guarantee: The processing delay satisfies where κ is determined by the QoS level (it is recommended that κ ≤ 5ms / s in the enterprise risk control scenario).

[0134] In the embodiment of the present invention, through the integration of the dynamic desensitization idea and the encryption algorithm, real-time privacy protection based on mathematical analysis is achieved. In the enterprise risk control data scenario, during the data desensitization process, while the data utility is increased by 41%, the privacy leakage risk is reduced by 63% (test data when α = 0.1, β = 0.3, λ = 0.8). The computational complexity of the core differential operator is O(n log n), meeting the real-time processing requirements.

[0135] The embodiment of the present invention provides a data desensitization system. Please refer to Figure 4 , which shows the composition structure schematic diagram of a data desensitization system provided by an embodiment of the present invention. The system 400 includes:

[0136] An acquisition module 401, configured to obtain the real-time plaintext data required by the enterprise risk control business system in response to a risk data request sent by the enterprise risk control business system;

[0137] An evaluation module 402, configured to evaluate the sensitivity of the real-time plaintext data to obtain the real-time sensitivity change of the real-time plaintext data;

[0138] An injection module 403, configured to dynamically inject noise matching the real-time sensitivity change into the real-time plaintext data to obtain adjusted data;

[0139] An adjustment module 404, configured to adjust the desensitization intensity of the adjusted data based on the sensitivity of the adjusted data to obtain candidate data;

[0140] An output module 405, configured to adjust the attenuation degree of the sensitive information of the candidate data, and obtain and output the desensitized data to the enterprise risk control business system.

[0141] In some possible implementation manners, the evaluation module 402 is further configured to perform a sensitivity evaluation on the real-time plaintext data to determine sensitive fields and an initial sensitivity; and determine a real-time sensitivity change of the real-time plaintext data based on the sensitive fields and the initial sensitivity.

[0142] In some possible implementation manners, the evaluation module 402 is further configured to determine a gradient field of the real-time plaintext data;

[0143] build a construction dynamic sensitivity evaluation model of the real-time plaintext data based on the gradient field and a sensitivity classifier;

[0144] perform a sensitivity evaluation on the real-time plaintext data based on the dynamic sensitivity evaluation model to obtain the sensitive fields and the initial sensitivity.

[0145] In some possible implementation manners, the evaluation module 402 is further configured to identify a change in the sensitivity of the real-time plaintext data over time based on the sensitivity classifier in the dynamic sensitivity evaluation model to obtain the initial sensitivity; and identify the sensitive fields of the real-time plaintext data based on the gradient field in the dynamic sensitivity evaluation model.

[0146] In some possible implementation manners, the adjustment module 404 is further configured to obtain a Gaussian kernel of the adjusted data; build a desensitization operator for the adjusted data based on the Gaussian kernel; dynamically adjust the deformation intensity of the adjusted data by using the desensitization operator to obtain constrained data; calculate a derivative of the sensitivity of the constrained data in real time; and adjust the desensitization intensity of the constrained data in real time based on the derivative of the sensitivity of the constrained data to obtain the candidate data.

[0147] In some possible implementation manners, the output module 405 is further configured to convert the candidate data from the time domain to the frequency domain by using a frequency domain desensitization operator to obtain frequency components; dynamically adjust the attenuation degree of sensitive information of the frequency components, and obtain and output the desensitized data to the enterprise risk control service system.

[0148] In some possible implementation manners, the injection module 403 is further configured to obtain a gradient field corresponding to the real-time sensitivity change; determine an instantaneous change in data sensitivity based on the gradient field corresponding to the real-time sensitivity change; and superimpose Laplace noise on the real-time plaintext data in an integral form based on the instantaneous change in data sensitivity to obtain the adjusted data.

[0149] In some possible implementation manners, the injection module 403 is further configured to determine a sensitivity change rate based on an instantaneous change in the data sensitivity; determine a noise injection intensity based on the sensitivity change rate; and superimpose Laplace noise that meets the noise injection intensity on the real-time plaintext data in an integral form to obtain the adjusted data.

[0150] In some possible implementation manners, the obtaining module 401 is further configured to obtain identity information of the user terminal; and authorize the user terminal to reversely recover the real-time plaintext data corresponding to the desensitized data when the identity information of the user terminal meets a preset key control parameter.

[0151] Optionally, the transmission medium may be a wired link (such as, but not limited to, coaxial cable, optical fiber, and Digital Subscriber Line (DSL), etc.) or a wireless link (such as, but not limited to, Wireless Fidelity (WIFI), Bluetooth, and mobile device network, etc.). It should be noted that: for the system provided in the above embodiment, only the division of the above function modules is used for illustration. In actual application, the above functions may be assigned to different function modules according to needs, that is, the internal structure of the computer device is divided into different function modules to complete all or part of the functions described above. In addition, the method embodiments provided in the above embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiments and will not be elaborated here.

[0152] Figure 5 is a schematic structural diagram of a computer device provided by an embodiment of the present invention. Exemplarily, as Figure 5 shown, the computer device 500 includes: a memory 501, a processor 502, and a computer program 503 stored in the memory 501 and running on the processor 502. When the processor 502 executes the computer program 503, the computer device can execute any one of the data desensitization methods described above.

[0153] In addition, an embodiment of the present invention also protects a system, which may include a memory and a processor. Among them, executable program code is stored in the memory, and the processor is used to call and execute the executable program code to execute a data desensitization method provided by an embodiment of the present invention. In this embodiment, the system can be divided into functional modules according to the above method examples. For example, it can correspond to each functional module, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there may be other division methods in actual implementation. It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be repeated here.

[0154] It should be understood that the system provided in this embodiment is used to execute the above data desensitization method, so the same effect as the above implementation method can be achieved. In the case of adopting an integrated unit, the system may include a processing module and a storage module. Among them, when the system is applied to a device, the processing module can be used to control and manage the actions of the device. The storage module can be used to support the device to execute mutual program code, etc. Among them, the processing module can be a processor or a controller, which can implement or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure of the present invention. The processor can also be a combination that realizes computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processing (DSP) and a microprocessor, etc. The storage module can be a memory.

[0155] In addition, the system provided in the embodiment of the present invention can specifically be a chip, a component or a module. The chip may include a connected processor and a memory; among them, the memory is used to store instructions, and when the processor calls and executes the instructions, the chip can execute a data desensitization method provided by the above embodiment. This embodiment also provides a computer-readable storage medium, in which computer program code is stored. When the computer program code runs on a computer, the computer is enabled to execute the above related method steps to implement a data desensitization method provided by the above embodiment.

[0156] This embodiment also provides a computer program product. When the computer program product runs on a computer, it causes the computer to execute the above-related steps to implement a data desensitization method provided in the above embodiment. Among them, the system, computer-readable storage medium, computer program product, or chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here. Through the description of the above embodiments, those skilled in the art can understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the system is divided into different functional modules to complete all or part of the functions described above. In the embodiments provided by the present invention, it should be understood that the disclosed system and method can be implemented in other ways. For example, the system embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the system or unit can be in an electrical, mechanical, or other form.

[0157] It should be noted that the above sequence of the embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous. Each embodiment in this specification is described in a progressive manner, and the same or similar parts among the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. The above content is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention.

Claims

1. A data desensitization method, characterized in that, The data desensitization method includes: In response to a risk data request sent by an enterprise risk control business system, obtaining real-time plaintext data required by the enterprise risk control business system; Performing a sensitivity assessment on the real-time plaintext data to obtain the real-time sensitivity change of the real-time plaintext data; Dynamically injecting noise matching the real-time sensitivity change into the real-time plaintext data to obtain adjusted data; Adjusting the desensitization intensity of the adjusted data based on the sensitivity of the adjusted data to obtain candidate data; Adjusting the attenuation degree of sensitive information in the candidate data, and obtaining and outputting desensitized data to the enterprise risk control business system.

2. The data desensitization method according to claim 1, wherein The performing a sensitivity assessment on the real-time plaintext data to obtain the real-time sensitivity change of the real-time plaintext data includes: Performing a sensitivity assessment on the real-time plaintext data to determine sensitive fields and an initial sensitivity; Based on the sensitive fields and the initial sensitivity, determining the real-time sensitivity change of the real-time plaintext data.

3. A data desensitization method according to claim 2, characterized in that The performing a sensitivity assessment on the real-time plaintext data to determine sensitive fields and an initial sensitivity includes: Determining the gradient field of the real-time plaintext data; Based on the gradient field and a sensitivity classifier, constructing a dynamic sensitivity assessment model for the real-time plaintext data; Performing a sensitivity assessment on the real-time plaintext data based on the dynamic sensitivity assessment model to obtain the sensitive fields and the initial sensitivity.

4. A data desensitization method according to claim 3, characterized in that The performing a sensitivity assessment on the real-time plaintext data based on the dynamic sensitivity assessment model to obtain the sensitive fields and the initial sensitivity includes: Based on the sensitivity classifier in the dynamic sensitivity assessment model, identifying the change in the sensitivity of the real-time plaintext data over time to obtain the initial sensitivity; Based on the gradient field in the dynamic sensitivity assessment model, identifying the sensitive fields of the real-time plaintext data.

5. A data desensitization method according to claim 1, characterized in that, The adjusting the desensitization intensity of the adjusted data based on the sensitivity of the adjusted data to obtain candidate data includes: Obtaining the Gaussian kernel of the adjusted data; Based on the Gaussian kernel, constructing a desensitization operator for the adjusted data; Using the desensitization operator to dynamically adjust the deformation intensity of the adjusted data to obtain constrained data; Calculating the derivative of the sensitivity of the constrained data in real time; Based on the derivative of the sensitivity of the constrained data, adjusting the desensitization intensity of the constrained data in real time to obtain the candidate data.

6. A data desensitization method according to claim 1, characterized in that, The adjusting the attenuation degree of sensitive information in the candidate data, and obtaining and outputting desensitized data to the enterprise risk control business system includes: Using a frequency domain desensitization operator to transform the candidate data from the time domain to the frequency domain to obtain frequency components; Dynamically adjusting the attenuation degree of sensitive information in the frequency components, and obtaining and outputting the desensitized data to the enterprise risk control business system.

7. A data desensitization method according to claim 1, characterized in that The dynamically injecting noise matching the real-time sensitivity change into the real-time plaintext data to obtain adjusted data includes: Obtaining the gradient field corresponding to the real-time sensitivity change; Based on the gradient field corresponding to the real-time sensitivity change, determining the instantaneous change in data sensitivity; Based on the instantaneous change of the data sensitivity, Laplace noise is superimposed on the real-time plaintext data in integral form to obtain the adjusted data.

8. A data desensitization method according to claim 7, characterized in that, The step of based on the instantaneous change of the data sensitivity, superimposing Laplace noise on the real-time plaintext data in integral form to obtain the adjusted data includes: Based on the instantaneous change of the data sensitivity, determining the sensitivity change rate; Based on the sensitivity change rate, determining the noise injection intensity; Superimposing Laplace noise that meets the noise injection intensity on the real-time plaintext data in integral form to obtain the adjusted data.

9. A data desensitization method according to claim 1, characterized in that, The method further includes: Obtaining the identity information of the client; When the identity information of the client meets the preset key control parameters, authorizing the client to be able to reversely recover the real-time plaintext data corresponding to the desensitized data.

10. A data desensitization system, characterized in that, The system includes: An acquisition module, configured to acquire the real-time plaintext data required by the enterprise risk control business system in response to a risk data request sent by the enterprise risk control business system; An evaluation module, configured to evaluate the sensitivity of the real-time plaintext data to obtain the real-time sensitivity change of the real-time plaintext data; An injection module, configured to dynamically inject noise matching the real-time sensitivity change into the real-time plaintext data to obtain adjusted data; An adjustment module, configured to adjust the desensitization intensity of the adjusted data based on the sensitivity of the adjusted data to obtain candidate data; An output module, configured to adjust the attenuation degree of the sensitive information of the candidate data, and obtain and output the desensitized data to the enterprise risk control business system.

Citation Information

Cited By

  • Track privacy data protection and sharing method

    CN120724482A