File desensitization method and device based on linux file system

By defining and managing desensitization rules at the Linux file system level, intercepting file read requests for real-time processing, solving the problem of insufficient flexibility in the existing technology, and achieving efficient, secure and flexible desensitization of sensitive data, suitable for a variety of file systems.

CN120337276APending Publication Date: 2025-07-18SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510338181.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing data desensitization solutions do not provide sufficient flexibility to adapt to different application scenarios and needs, especially in Linux file systems that cannot achieve fine-grained control of specific files or directories, and static data desensitization requires reprocessing of data to change the desensitization rules.

Method used

Define, configure and manage desensitization rules at the Linux file system level, intercept file read requests, perform real-time desensitization processing based on rule matching and user authentication, and record logs, supporting various desensitization modes such as masking, replacement, hashing, encryption, generalization, deformation and sampling.

Benefits of technology

It realizes flexible and fine-grained control of specified files or directories, and takes effect in real time. It does not require reprocessing of data. It is suitable for multiple file systems, protecting data from unauthorized access and reducing the risk of leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337276A_ABST
    Figure CN120337276A_ABST
Patent Text Reader

Abstract

The invention discloses a file desensitization method and device based on a linux file system, and relates to the technical field of data security, and the method comprises the following steps: defining, configuring and managing a desensitization rule; when a user initiates a file reading request, intercepting system calling in a Linux file system layer, matching the set file according to a predefined desensitization rule, and verifying whether desensitization operation needs to be executed or not by the user; carrying out desensitization processing on the file needing to be subjected to desensitization operation according to the matched desensitization mode; and returning the desensitized file to an upper caller, and recording a corresponding log. The method is applied to a linux file system, takes effect in a kernel module form, and can effectively protect the data from unauthorized access and leakage by performing real-time desensitization processing on the sensitive data, so that the risk of data leakage is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a file desensitization method and device based on the linux file system. Background Art

[0002] With the advent of the data era, data has become an important driving force for promoting business decision-making, innovation, and development. In this era, the collection, analysis, and utilization of massive amounts of data have brought unprecedented opportunities to enterprises, while also presenting major challenges in protecting personal privacy and data security. Data not only provides enterprises with in-depth business insights, helps them discover new business opportunities, but also promotes the provision of personalized experiences, enhancing customer satisfaction and loyalty. In addition, through the analysis of big data, enterprises can optimize operational efficiency, better assess risks, predict potential problems, and take preventive measures, thus gaining an advantageous position in the highly competitive market.

[0003] However, with the increase in data value, protecting data security and personal privacy has become particularly important. As a key technology, data desensitization ensures the security and compliance of data while protecting its value, and has become an essential part of the data era. By hiding or replacing sensitive information, data desensitization not only helps to comply with strict regulatory requirements, but also reduces the risk of data leakage, protects personal privacy, enhances customer trust, and promotes the effective utilization of data, laying a solid foundation for the sustainable development of enterprises.

[0004] The existing data desensitization methods mainly include static data desensitization and dynamic data desensitization. Static data desensitization refers to the desensitization of data stored in a database or file system to generate the desensitized data content; once the desensitization is completed, if the desensitization rules need to be changed, the data needs to be processed again. Dynamic data desensitization is performed instantaneously during data query and does not require physical modification of the data; however, it generally processes a specific file system, for example, a data desensitization method and system based on HDFS are introduced in CN107315972A.

[0005] However, the existing desensitization solutions may not provide sufficient flexibility to adapt to different application scenarios and requirements. For example, it is not possible to perform fine-grained control on specific files or directories. Static data desensitization requires pre-processing of data, and if the desensitization rules need to be changed, the data needs to be processed again. Some desensitization solutions may only be applicable to specific types of file systems and are not convenient for cross-system use. Summary of the Invention

[0006] In view of the requirements and deficiencies in the current technological development, the present invention provides a file desensitization method and device based on the linux file system to meet the need for efficient, secure, and flexible desensitization processing of sensitive data in the Linux environment.

[0007] In the first aspect, the present invention provides a file desensitization method based on the linux file system. The technical solution adopted to solve the above technical problems is as follows:

[0008] A file desensitization method based on the linux file system includes the following steps:

[0009] S1. Define, configure, and manage desensitization rules;

[0010] S2. When a user initiates a file reading request, intercept the system call at the Linux file system layer, and match the set files according to the predefined desensitization rules and verify whether the user needs to perform the desensitization operation;

[0011] S3. Desensitize the files that need to be desensitized according to the matched desensitization mode;

[0012] S4. Return the desensitized file to the upper-layer caller and record the corresponding log.

[0013] Optionally, when performing step S1, the defined desensitization rules include:

[0014] Define a unique rule identifier for each file or directory that needs to be desensitized;

[0015] Determine the files or directories that need to be desensitized;

[0016] Specify the sensitive fields or content that need to be desensitized;

[0017] Select a desensitization mode, including seven desensitization modes: masking, replacement, hashing, encryption, generalization, deformation, and sampling;

[0018] Specify the users or user groups to which the rule applies;

[0019] Configure the defined desensitization rules. The specific configuration process is as follows:

[0020] Initial loading: When the system starts for the first time or the file desensitization module is enabled for the first time, load the rule setting module into the linux file system kernel. At the same time, create and initialize the / proc / file_masking_list file, which serves as the key entry for receiving configuration information; set the permissions of the / proc / file_masking_list file to allow only the root user or users with specified permissions to read and write, ensuring the security and accuracy of the configuration information;

[0021] Receive configuration instructions: The administrator uses a command-line tool or a script written to write the defined desensitization rules to the / proc / file_masking_list file or update the existing desensitization rules; the content written in each line represents a complete desensitization rule, and its format follows the defined desensitization rules mentioned above;

[0022] Syntax and validity check: Automatically perform a syntax check on each written desensitization rule to ensure that the file or directory path meets the specified format requirements; for rules involving regular expression matching, check whether they conform to the regular expression specification;

[0023] Path conflict and priority management: When adding a new desensitization rule, automatically check whether it conflicts with the existing desensitization rules; and support setting rule priorities, enabling the administrator to clearly define which desensitization rule takes precedence in case of conflicts according to business requirements, ensuring the accuracy and consistency of desensitization rule execution;

[0024] Parse rules: Parse and convert the rules in text format read into an internal data structure for subsequent invocation and processing during the desensitization process;

[0025] Real-time update rules: The desensitization rules that have passed the syntax check, conflict check, and are parsed correctly will take effect immediately.

[0026] Optionally, the specific steps of step S2 include:

[0027] S2.1. When the user initiates a file reading request, the kernel module intercepts the system call at the Linux file system layer, extracts the relevant parameters of the reading request, and obtains the credentials of the user who initiated the request, and identifies the user identity and corresponding permissions through the user credentials;

[0028] S2.2. Call the original file reading function or mechanism of the Linux file system to obtain the requested file. If the request is successful, obtain the requested file; if the request fails, return the corresponding error code and error message to the client;

[0029] S2.3. Check whether the file path matches the path pattern in the configured desensitization rules. If it matches, perform subsequent desensitization processing; if it does not match, directly release the file;

[0030] S2.4. According to the matching desensitization rules, perform user verification to verify whether the user or user group information of the current request invoker is within the applicable range specified by the desensitization rules. If the verification is yes, call the desensitization rules to perform desensitization operations on the read file data; if the verification is no, directly return the original content of the file, that is, the unprocessed file data obtained after executing the original reading logic.

[0031] Optionally, the specific steps of step S3 include:

[0032] S3.1. When the rule matching module determines that the file data needs to be desensitized, transfer the file content or data segment to the location of the module or function that performs the desensitization operation;

[0033] S3.2. This location determines the desensitization mode and the sensitive fields or content that need to be desensitized according to the desensitization rules matched by the file;

[0034] S3.3. Locate the sensitive data location in the file according to the sensitive fields or content in the desensitization rules;

[0035] S3.4. Process the sensitive data according to the matched desensitization mode to obtain the desensitized data.

[0036] Optionally, the specific steps of step S4 include:

[0037] S4.1. Package the file data after desensitization into the response body;

[0038] S4.2. Format the log information captured during the entire file desensitization process according to a predetermined format. The log information includes: trigger time, user, rule id, and whether desensitized;

[0039] S4.3. Rotate the log information recorded during the previous file desensitization operations regularly and compress it.

[0040] In a second aspect, the present invention provides a file desensitization device based on the linux file system. The technical solution adopted to solve the above technical problems is as follows:

[0041] A file desensitization device based on the linux file system, which includes:

[0042] A rule setting module, responsible for defining, configuring, and managing desensitization rules;

[0043] A rule matching module, when a user initiates a file reading request, is responsible for intercepting system calls at the Linux file system layer and matching the set files according to the predefined desensitization rules and verifying whether the user needs to perform a desensitization operation;

[0044] A file desensitization module, responsible for desensitizing the files that need to be desensitized according to the matched desensitization mode;

[0045] A return audit module, responsible for returning the desensitized file to the upper layer caller and recording the corresponding logs.

[0046] Optionally, the desensitization rules defined by the involved rule setting module include:

[0047] Define a unique rule identifier for each file or directory to be desensitized;

[0048] Identify the files or directories that need to be desensitized;

[0049] Specify the sensitive fields or content to be desensitized;

[0050] Select a desensitization mode, including seven desensitization modes: masking, replacement, hashing, encryption, generalization, deformation, and sampling;

[0051] Specify the users or user groups to which the rules apply;

[0052] The rule setting module configures the defined desensitization rules, and the specific configuration process is as follows:

[0053] Initial loading: When the system starts for the first time or the file desensitization module is enabled for the first time, load the rule setting module into the linux file system kernel. At the same time, create and initialize the / proc / file_masking_list file, which serves as the key entry for receiving configuration information; set the permissions of the / proc / file_masking_list file to allow only the root user or users with specified permissions to read and write, ensuring the security and accuracy of the configuration information;

[0054] Receive configuration instructions: The administrator uses a command-line tool or a script written to write the defined desensitization rules to the / proc / file_masking_list file or update the existing desensitization rules; each line of the written content represents a complete desensitization rule, and its format follows the previously defined desensitization rules;

[0055] Syntax and validity check: Automatically check the syntax of each written desensitization rule to ensure that the file or directory path conforms to the specified format requirements; for rules involving regular expression matching, check whether they conform to the regular expression specifications;

[0056] Path conflict and priority management: When adding a new desensitization rule, automatically check whether it conflicts with the existing desensitization rules; support setting rule priorities, enabling the administrator to clarify which desensitization rule takes precedence in case of conflicts according to business requirements, ensuring the accuracy and consistency of the execution of desensitization rules;

[0057] Parse the rules: Parse and convert the rules in text format read into an internal data structure for subsequent invocation and processing during the desensitization process;

[0058] Real-time update of rules: The desensitization rules that pass the syntax check, conflict check, and are parsed correctly will take effect immediately.

[0059] Optionally, the involved rule matching module specifically includes:

[0060] A request invocation unit, which is used to intercept system calls at the Linux file system layer through the kernel module when the user initiates a file reading request, obtain the parameters related to the read request, and obtain the user credentials of the current request invoker;

[0061] A call acquisition unit, which is used to call the original file reading function or mechanism of the Linux file system to obtain the requested file. If the request is successful, the requested file is obtained; if the request fails, the corresponding error code and error message are returned to the client;

[0062] An inspection and processing unit, which is used to check whether the file path matches the path pattern in the configured desensitization rule. If it matches, subsequent desensitization processing is performed; if it does not match, the file is directly released;

[0063] A verification and processing unit, which is used to perform user verification according to the matched desensitization rule, verify whether the user or user group information of the current request invoker is within the applicable range specified by the desensitization rule. If the verification is successful, the file desensitization module is called to desensitize the read file data; if the verification is unsuccessful, the original content of the file is directly returned, that is, the file data obtained after executing the original reading logic without desensitization processing.

[0064] Optionally, the involved file desensitization module specifically includes:

[0065] A data transfer unit, which is used to transfer the file content or data segment to the desensitization determination unit when the rule matching module determines that the file data needs to be desensitized;

[0066] A desensitization determination unit, which is used to determine the desensitization mode and the sensitive fields or content that need to be desensitized according to the desensitization rule matched by the file;

[0067] A location positioning unit, which is used to locate the position of sensitive data in the file according to the sensitive fields or content in the desensitization rule;

[0068] A file desensitization unit, which is used to process the sensitive data according to the matched desensitization mode to obtain desensitized data.

[0069] Optionally, the involved return audit module specifically includes:

[0070] A desensitization encapsulation unit, which is used to encapsulate the desensitized file data into the response body;

[0071] A log processing module, which is used to format the log information captured in the entire file desensitization process according to a predetermined format. The log information includes: trigger time, user, rule id, and whether desensitized;

[0072] A timing compression module, which is used to rotate the log information recorded during the previous file desensitization operation at regular intervals and compress it.

[0073] A file desensitization method and device based on the linux file system according to the present invention have the following beneficial effects compared with the prior art:

[0074] The present invention can implement desensitization operations on specified files / directories for specified users, providing more fine-grained control; by intercepting file data reading operations in the linux operating system to process sensitive fields, without affecting the original data content, the modified rules can take effect in real time, and there is no need to re-desensitize the data; it can adapt to multiple file systems without the need to process various file systems separately;

[0075] By performing real-time desensitization processing on sensitive data, the present invention can effectively protect data from unauthorized access and leakage, reduce the risk of data leakage. Even if the data is illegally accessed, the desensitized data cannot be utilized. At the same time, the data can maintain the original structure, retain data integrity, and ensure the accuracy of data analysis and mining. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] Attached Figure 1 is a flowchart of the method in Embodiment 1 of the present invention;

[0077] Attached Figure 2 is a block diagram of module connections in Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0078] To make the technical solutions, the technical problems to be solved, and the technical effects of the present invention clearer and more understandable, the following describes the technical solutions of the present invention clearly and completely in conjunction with specific embodiments.

[0079] Embodiment 1:

[0080] Combined with attached Figure 1 , this embodiment proposes a file desensitization method based on the linux file system, which includes the following steps:

[0081] S1. Define, configure, and manage desensitization rules.

[0082] The desensitization rules defined in this step include:

[0083] Define a unique rule identifier for each file or directory that needs to be desensitized; this identifier is unique throughout the system, facilitating subsequent management and differentiation of different desensitization rules. For example, UUID (Universally Unique Identifier) can be used as the rule identifier to ensure that different rules will not be confused;

[0084] Identify the files or directories that need to be desensitized; this can be a single file, all files in an entire directory, or even a group of files matched using wildcards or regular expressions. For example, / data / finance / *.csv can represent all CSV files in the / data / finance directory;

[0085] Specify the sensitive fields or content that need to be desensitized; for structured data files (such as CSV or JSON files), specific fields can be specified. For example, for user information files, it may be "ID number", "bank card number", "home address", etc.; for unstructured files (such as text files), specific text patterns or keywords can be specified as sensitive content;

[0086] Select the desensitization mode, including seven desensitization modes: masking, replacement, hashing, encryption, generalization, transformation, and sampling. Among them: ① Masking is to replace part or all of the sensitive information with specific masking characters. For example, replace some of the digits in the ID number 123456789012345678 with asterisks, becoming 123456******78; ② Replacement is to replace the sensitive information with pre-set alternative data. For example, replace the real name with a fictional name and the actual address with a fake address; ③ Hashing is to convert the sensitive data into a hash value using a hash function (such as SHA-256), making the original data irreversible. It is often used for password storage or the anonymization of unique identifiers. For example, hash the password password123 to

[0087] 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d858f253104989; ④ Encryption is to encrypt the sensitive data using an encryption algorithm (such as the AES encryption algorithm). Different from hashing, the encrypted data can be restored through the corresponding decryption key. It is suitable for scenarios where data needs to be securely transmitted or stored but also needs to be restored to the original data under certain conditions; ⑤ Generalization is to generalize the sensitive data into a range or category. For example, generalize the specific date of birth 1995-05-10 to May 1995 or the 1990s, which not only protects privacy but also retains certain data characteristics; ⑥ Transformation is to transform the sensitive data according to a specific rule. For example, transform the mobile phone number 138123456789 into 1381234xxxx, so that it retains some information to a certain extent but is difficult to directly identify the original data; ⑦ Sampling is to extract a part of a large amount of sensitive data for processing. For example, for a file containing a large number of transaction records, only 10% of them are desensitized, which can be used for testing or preliminary analysis;

[0088] Users or user groups to which the specified rules apply; specify which users or user groups need to follow the desensitization rules when accessing the corresponding files. For example, for financial files, only the user group in the finance department may be desensitized, while other user groups remain unchanged;

[0089] Configure the defined desensitization rules. The specific configuration process is as follows:

[0090] Initial loading: When the system starts for the first time or the file desensitization module is enabled for the first time, load the rule setting module into the linux file system kernel. The kernel is the core part of the operating system, responsible for managing system resources and executing system functions; at the same time, create and initialize the / proc / file_masking_list file, which serves as the key entry for receiving configuration information; set the permissions of the / proc / file_masking_list file to allow only the root user or users with specified permissions to read and write, ensuring that the configuration information is not tampered with by unauthorized users and enhancing the security of the system;

[0091] Receive configuration instructions: The administrator uses a command-line tool or a script written to write the defined desensitization rules to the / proc / file_masking_list file or update the existing desensitization rules; each line of the written content represents a complete desensitization rule, and its format follows the desensitization rules defined above. For example: [rule identifier]|[file or directory path]|[sensitive field or content]|[desensitization mode]|[applicable users or user groups];

[0092] Syntax and validity check: Automatically check the syntax of each written desensitization rule to ensure that the file or directory path meets the specified format requirements; for rules involving regular expression matching, check whether they conform to the regular expression specification; this ensures that the system will not malfunction or perform incorrect desensitization operations due to incorrect rules during subsequent processing;

[0093] Path conflict and priority management: When adding a new desensitization rule, automatically check whether it conflicts with the existing desensitization rules. For example, two rules may apply to the same file, or the regular expression of the new rule covers part of the range of the existing rule. By supporting rule priority settings, the administrator can decide which rule takes precedence in this case according to business requirements, ensuring the orderliness and accuracy of rule execution;

[0094] Parse rules: Convert the text-format rules in the / proc / file_masking_list file into internal data structures, such as linked lists, trees, or hash tables, etc., to facilitate quick search and call during subsequent file processing; for example, store the rules in a hash table, using the file or directory path as the key and other information as the value for quick retrieval;

[0095] Real-time update rule: The desensitization rules that have passed grammar checking, conflict checking, and are parsed correctly will take effect immediately, enabling the system to respond instantaneously to new rule settings and ensuring the system's dynamic adjustment ability for rules.

[0096] S2. When a user initiates a file reading request, intercept the system call at the Linux file system layer, and match the set files according to the predefined desensitization rules and verify whether the user needs to perform desensitization operations, specifically including:

[0097] S2.1. When a user initiates a file reading request, the kernel module intercepts the system call at the Linux file system layer. The system call is the interface between the user program and the kernel, such as open(), read(), etc.; the kernel module will extract the relevant parameters of the request, such as the file path, read offset, read length, etc., and at the same time obtain the user credentials for the request, including information such as the user's UID (user identifier), GID (group identifier), etc.; these credentials can be used for subsequent permission verification and user identity confirmation;

[0098] For example, when a user uses the cat / data / finance / report.csv command, the kernel module will intercept the open() and read() system calls and obtain the file path information of / data / finance / report.csv and the user's UID and GID;

[0099] S2.2. Call the original file reading function or mechanism of the Linux file system to obtain the requested file, and try to obtain the requested file: if the request is successful, obtain the requested file, and if the request fails, return the corresponding error code and error message to the client;

[0100] For example, call the open() function to open the file. If the file does not exist, an ENOENT error will be returned, and the system will pass this error message to the client;

[0101] S2.3. Check whether the file path matches the path pattern in the configured desensitization rules. If it matches, perform subsequent desensitization processing; if it does not match, directly release the file;

[0102] For example, if the desensitization rule stipulates that / data / finance / *.csv needs to be desensitized, when the user requests

[0103] / data / finance / report.csv, subsequent desensitization processing will be triggered; while for the request

[0104] / data / hr / employee.txt, it will be directly released;

[0105] S2.4. Verify the user according to the matched desensitization rule, that is, verify whether the user or user group information of the current request invoker is within the applicable scope defined by the desensitization rule. If the verification result is yes, call the desensitization rule to desensitize the read file data. If the verification result is no, directly return the original content of the file, that is, the un-desensitized file data obtained after executing the original reading logic.

[0106] For example, if a rule stipulates that financial files are only desensitized for users in the finance group, when a finance group user reads a file, desensitization will be triggered; when a user in other groups reads the same file, the original file content will be directly obtained.

[0107] S3. Desensitize the files that need to be desensitized according to the matched desensitization mode, which specifically includes:

[0108] S3.1. When the rule matching module determines that the file data needs to be desensitized, transfer the file content or data segment to the location of the module or function that performs the desensitization operation.

[0109] For example, transfer the content of the file / data / finance / report.csv to a dedicated file desensitization function.

[0110] S3.2. Based on the desensitization rule matched by the file, determine the desensitization mode and the sensitive fields or content that need to be desensitized. This is based on the rules defined in step S1. For example, for a file containing user information, determine to use hash desensitization for the "ID number" field.

[0111] S3.3. Locate the position of the sensitive data in the file according to the sensitive fields or content in the desensitization rule.

[0112] For structured data, it can be located according to the field name or column index; for unstructured data, text search or regular expression matching can be used. For example, in a CSV file, find the column containing the "ID number" field; in a text file, find the text segment that conforms to the ID number format.

[0113] S3.4. Process the sensitive data according to the matched desensitization mode to obtain the desensitized data. Different desensitization modes will have different operations, such as using a hash function to hash the ID number, or replacing part of the phone number with asterisks. For example, hash the ID number 123456789012345678 using SHA-256 to obtain an irreversible hash value.

[0114] S4. Return the desensitized file to the upper-layer invoker and record the corresponding log, which specifically includes:

[0115] S4.1. Package the desensitized file data into the response body. The response body is the data returned to the user, wrapped for easy reception and processing by the user program. For different application programs or system services, the format of the response body may vary. For example, an HTTP service will package the file data in the HTTP response message body. For example, for a file reading service, put the desensitized file data into the response message body, add the corresponding HTTP status code (such as 200 OK), and return it to the client.

[0116] S4.2. Format the log information captured during the entire file desensitization process according to a predetermined format. The log information includes: trigger time (accurate to milliseconds), user (user identifier), rule id (used to associate the corresponding desensitization rule), and whether desensitized (yes or no). This helps the system administrator view the operation records of file desensitization and audit the usage of the system.

[0117] For example, the log record can be [2025-01-16 10:30:00.123][user123][rule-001]

[0118] [true], indicating that at 10:30:00.123 milliseconds on January 16, 2025, the user user123 triggered the desensitization operation of rule rule-001.

[0119] S4.3. Rotate the log information recorded during previous file desensitization operations regularly and compress it.

[0120] Rotation can be performed according to time (such as daily or weekly) or size (such as exceeding 100MB). At the same time, compress the old log files, such as using gzip compression. For example, rename and compress the log file of the previous day to file_masking_log_2025-01-15.gz every day at midnight to facilitate the storage and management of log files.

[0121] Example 2:

[0122] Combined with the appendix Figure 2 , this example proposes a file desensitization device based on the linux file system, which includes:

[0123] A rule setting module responsible for defining, configuring, and managing desensitization rules;

[0124] A rule matching module responsible for intercepting system calls at the Linux file system layer when the user initiates a file reading request, and matching the set files according to the predefined desensitization rules and verifying whether the user needs to perform a desensitization operation;

[0125] The file desensitization module is responsible for desensitizing the files that need to be desensitized according to the matched desensitization mode.

[0126] The return audit module is responsible for returning the desensitized files to the upper-level caller and recording the corresponding logs.

[0127] In this embodiment, the desensitization rules defined by the rule setting module include:

[0128] Define a unique rule identifier for each file or directory that needs to be desensitized;

[0129] Determine the files or directories that need to be desensitized;

[0130] Specify the sensitive fields or content that need to be desensitized;

[0131] Select the desensitization mode, including seven desensitization modes: masking, replacement, hashing, encryption, generalization, deformation, and sampling;

[0132] Specify the users or user groups to which the rules apply;

[0133] The rule setting module involved configures the defined desensitization rules. The specific configuration process is as follows:

[0134] Initialization and loading: When the system starts for the first time or the file desensitization module is enabled for the first time, load the rule setting module into the linux file system kernel. At the same time, create and initialize the / proc / file_masking_list file, which serves as the key entry for receiving configuration information; set the permissions of the / proc / file_masking_list file to allow only the root user or users with specified permissions to read and write, ensuring the security and accuracy of the configuration information;

[0135] Receive configuration instructions: The administrator uses the command-line tool or the written script to write the defined desensitization rules to the / proc / file_masking_list file or update the existing desensitization rules; each line of the written content represents a complete desensitization rule, and its format follows the previously defined desensitization rules;

[0136] Syntax and validity check: Automatically check the syntax of each written desensitization rule to ensure that the file or directory path conforms to the specified format requirements; for the rules involving regular expression matching, check whether they conform to the regular expression specifications;

[0137] Path Conflict and Priority Management: When adding a new desensitization rule, automatically check whether there is a conflict with existing desensitization rules; support rule priority setting, enabling administrators to clarify which desensitization rule takes precedence in case of conflicts according to business requirements, ensuring the accuracy and consistency of desensitization rule execution;

[0138] Parsing Rules: Parse and convert the text-format rules read into an internal data structure for subsequent invocation and processing during the desensitization process;

[0139] Real-time Rule Update: Desensitization rules that pass syntax checks, conflict checks, and are parsed correctly will take effect immediately.

[0140] In this embodiment, the involved rule matching module specifically includes:

[0141] Request Invocation Unit, used to intercept system calls at the Linux file system layer through the kernel module when the user initiates a file reading request, obtain relevant parameters of the read request, and obtain the user credentials of the current request invoker;

[0142] Invocation Acquisition Unit, used to call the original file reading function or mechanism of the Linux file system to obtain the requested file. If the request is successful, obtain the requested file; if the request fails, return the corresponding error code and error message to the client;

[0143] Check Processing Unit, used to check whether the file path matches the path pattern in the configured desensitization rules. If it matches, perform subsequent desensitization processing; if it does not match, directly release the file;

[0144] Verification Processing Unit, used to perform user verification according to the matched desensitization rules, verify whether the user or user group information of the current request invoker is within the applicable range specified by the desensitization rules. If the verification is successful, call the file desensitization module to perform desensitization operations on the read file data; if the verification is unsuccessful, directly return the original content of the file, that is, the unprocessed file data obtained after executing the original reading logic.

[0145] In this embodiment, the involved file desensitization module specifically includes:

[0146] Data Transfer Unit, used to transfer the file content or data segment to the desensitization determination unit when the rule matching module determines that desensitization processing of the file data is required;

[0147] Desensitization Determination Unit, used to determine the desensitization mode and the sensitive fields or content that need to be desensitized according to the desensitization rules matched by the file;

[0148] Location Locating Unit, used to locate the position of sensitive data in the file according to the sensitive fields or content in the desensitization rules;

[0149] A file desensitization unit, which is used to process sensitive data according to the matched desensitization pattern to obtain desensitized data.

[0150] In this embodiment, the involved return audit module specifically includes:

[0151] A desensitization encapsulation unit, which is used to encapsulate the desensitized file data into the response body;

[0152] A log processing module, which is used to format the log information captured in the entire file desensitization process according to a predetermined format. The log information includes: trigger time, user, rule id, and whether desensitized;

[0153] A timed compression module, which is used to rotate the log information recorded in the previous file desensitization operation regularly and compress it.

[0154] In summary, by using the file desensitization method and device based on the linux file system of the present invention, the requirement for efficient, safe and flexible desensitization processing of sensitive data in the Linux environment is solved.

[0155] The above applications have elaborated in detail the principle and implementation manner of the present invention through specific examples. These examples are only used to help understand the core technical content of the present invention. Based on the above specific embodiments of the present invention, those skilled in the art of this technology, without departing from the principle of the present invention, any improvements and modifications made to the present invention shall fall within the scope of patent protection of the present invention.

Claims

1. A file desensitization method based on the linux file system, characterized in that, The steps include: S1. Define, configure and manage desensitization rules; S2. When a user initiates a file read request, the system call is intercepted at the Linux file system layer, and the set file is matched according to the pre-defined desensitization rules and the user verifies whether the desensitization operation needs to be performed; S3, desensitizing the files that need to be desensitized according to the desensitization mode; S4. Return the desensitized file to the upper-level caller and record the corresponding log.

2. The file desensitization method based on the linux file system according to claim 1, wherein, Execute step S1, and define the desensitization rules including: Define a unique rule identifier for each file or directory that needs to be desensitized; Determine the files or directories that need to be desensitized; Specify sensitive fields or content that need to be desensitized; Select the desensitization mode, including shielding, replacement, hashing, encryption, generalization, deformation and sampling; Specify the users or user groups to which the rule applies; Configure the defined desensitization rules. The specific configuration process is as follows: Initialization loading: When the system is started for the first time or the file masking module is enabled for the first time, the rule setting module is loaded into the Linux file system kernel. At the same time, the / proc / file_masking_list file is created and initialized, which serves as the key entry for receiving configuration information. The permissions of the / proc / file_masking_list file are set to allow only the root user or users with specified permissions to perform read and write operations, ensuring the security and accuracy of the configuration information. Receiving configuration instructions: The administrator uses command line tools or scripts to write defined masking rules to the / proc / file_masking_list file or update existing masking rules. Each line of content written represents a complete masking rule, and its format follows the masking rules defined above. Syntax and validity check: Automatically perform syntax check on each desensitization rule written to ensure that the file or directory path meets the specified format requirements; for rules involving regular expression matching, check whether they meet the regular expression specifications; Path conflict and priority management: When adding a new desensitization rule, it will automatically check whether it conflicts with the existing desensitization rules; and support rule priority setting, so that administrators can clearly specify which desensitization rule will be executed first in the case of a conflict according to business needs, ensuring the accuracy and consistency of desensitization rule execution; Parsing rules: Parse and convert the rules in the read text format into internal data structures for subsequent calling and processing in the desensitization process; Real-time rule update: Anonymous rules that have been syntax checked, conflict checked, and parsed correctly will take effect immediately.

3. A file desensitization method based on the linux file system according to claim 2, characterized in that, The step S2 specifically includes: S2.

1. When a user initiates a file read request, the kernel module intercepts the system call at the Linux file system layer, extracts the relevant parameters of the read request, and obtains the credentials of the user who initiated the request, and identifies the user identity and corresponding permissions through the user credentials; S2.

2. Call the original file reading function or mechanism of the Linux file system to obtain the requested file. If the request is successful, obtain the requested file; if the request fails, return the corresponding error code and error message to the client. S2.

3. Check whether the file path matches the path pattern in the configured desensitization rule. If it matches, perform subsequent desensitization processing; if it does not match, directly release the file. S2.

4. According to the matched desensitization rule, perform user verification to check whether the user or user group information of the current request invoker is within the applicable range specified in the desensitization rule. If the verification is successful, call the desensitization rule to perform desensitization operations on the read file data; if the verification fails, directly return the original content of the file, that is, the file data that has not been desensitized after performing the original reading logic.

4. A file desensitization method based on the linux file system according to claim 3, characterized in that, The specific steps of step S3 include: S3.

1. When the rule matching module determines that the file data needs to be desensitized, transfer the file content or data segment to the location of the module or function that performs the desensitization operation. S3.

2. Based on the desensitization rule matched by the file, determine the desensitization mode and the sensitive fields or content that need to be desensitized. S3.

3. Locate the sensitive data position in the file according to the sensitive fields or content in the desensitization rule. S3.

4. Process the sensitive data according to the matched desensitization mode to obtain the desensitized data.

5. A file desensitization method based on the linux file system according to claim 4, characterized in that, The specific steps of step S4 include: S4.

1. Package the desensitized file data into the response body. S4.

2. Format the log information captured during the entire file desensitization process in a predetermined format. The log information includes: trigger time, user, rule id, and whether desensitized. S4.

3. Regularly rotate and compress the log information recorded during previous file desensitization operations.

6. A file desensitization device based on the linux file system, characterized in that, It includes: A rule setting module, responsible for defining, configuring, and managing desensitization rules. A rule matching module, which is responsible for intercepting system calls at the Linux file system layer when the user initiates a file reading request, and matching the set files and user verification according to the predefined desensitization rules to determine whether desensitization operations need to be performed. A file desensitization module, responsible for desensitizing the files that need to be desensitized according to the matched desensitization mode. A return audit module, responsible for returning the desensitized file to the upper-layer invoker and recording the corresponding logs.

7. The file desensitization device based on the linux file system according to claim 6, characterized in that, The desensitization rules defined by the rule setting module include: Define a unique rule identifier for each file or directory that needs to be desensitized. Determine the files or directories that need to be desensitized. Specify the sensitive fields or content that need to be desensitized. Select a desensitization mode, including seven desensitization modes: masking, replacement, hashing, encryption, generalization, deformation, and sampling. Specify the users or user groups to which the rule applies. The rule setting module configures the defined desensitization rules. The specific configuration process is as follows: Initial loading: When the system starts for the first time or the file desensitization module is enabled for the first time, the rule setting module is loaded into the Linux file system kernel. At the same time, the / proc / file_masking_list file is created and initialized. This file serves as the key entry for receiving configuration information. Set the permissions of the / proc / file_masking_list file to allow only the root user or users with specified permissions to perform read and write operations, ensuring the security and accuracy of the configuration information. Receiving configuration instructions: The administrator uses the command-line tool or the script written to write the defined desensitization rules or update the existing desensitization rules to the / proc / file_masking_list file. Each line of the written content represents a complete desensitization rule, and its format follows the previously defined desensitization rules. Syntax and validity check: Automatically perform a syntax check on each written desensitization rule to ensure that the file or directory path conforms to the specified format requirements. For rules involving regular expression matching, check whether they conform to the regular expression specification. Path conflict and priority management: When adding a new desensitization rule, automatically check whether there is a conflict with the existing desensitization rules. Support rule priority setting, enabling the administrator to clarify which desensitization rule takes precedence in case of conflict according to business requirements, ensuring the accuracy and consistency of the execution of desensitization rules. Parsing rules: Parse and convert the rules in text format read into an internal data structure for subsequent invocation and processing during the desensitization process. Real-time rule update: The desensitization rules that pass the syntax check, conflict check, and are parsed correctly will take effect immediately.

8. The file desensitization device based on the linux file system according to claim 7, characterized in that, The rule matching module specifically includes: Request invocation unit, used to intercept system calls at the Linux file system layer through the kernel module when the user initiates a file reading request, obtain the relevant parameters of the read request, and obtain the user credentials of the current request invoker. Invocation acquisition unit, used to call the original file reading function or mechanism of the Linux file system to obtain the requested file. If the request is successful, the requested file is obtained; if the request fails, the corresponding error code and error information are returned to the client. Check processing unit, used to check whether the file path matches the path pattern in the configured desensitization rules. If it matches, subsequent desensitization processing is performed; if it does not match, the file is directly released. Verification processing unit, used to perform user verification according to the matched desensitization rules, verify whether the user or user group information of the current request invoker is within the applicable range specified by the desensitization rules. If the verification is successful, the file desensitization module is called to perform desensitization operations on the read file data; if the verification fails, the original content of the file is directly returned, that is, the file data that has not been desensitized obtained after performing the original reading logic.

9. The file desensitization device based on the linux file system according to claim 8, characterized in that, The file desensitization module specifically includes: Data transfer unit, used to transfer the file content or data segment to the desensitization determination unit when the rule matching module determines that the file data needs to be desensitized. Desensitization determination unit, used to determine the desensitization mode and the sensitive fields or content that need to be desensitized according to the desensitization rules matched by the file. A location positioning unit, configured to locate the positions of sensitive data in a file according to sensitive fields or content in the desensitization rules; A file desensitization unit, configured to process the sensitive data according to the matched desensitization mode to obtain desensitized data.

10. The file desensitization device based on the linux file system according to claim 9, characterized in that, The returned audit module specifically includes: A desensitization encapsulation unit, configured to encapsulate the file data after desensitization processing into a response body; A log processing module, configured to format the log information captured in the entire file desensitization process according to a predetermined format. The log information includes: trigger time, user, rule id, and whether desensitized; A timed compression module, configured to periodically rotate and compress the log information recorded during previous file desensitization operations.

Citation Information

Patent Citations

  • Big data non-structured file dynamic desensitization method and system

    CN107315972A