Data storage method and system, computer equipment and readable storage medium

By desensitizing user information in target-sensitive areas in application servers in non-target sensitive areas, the high cost problems caused by multinational enterprises deploying business systems in areas with strict personal information control are solved, and lightweight system settings and localized storage are realized.

CN120523398APending Publication Date: 2025-08-22KINGDEE SOFTWARE(CHINA) CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510551769.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

Multinational enterprises deploy business systems in countries and regions with strict personal information control, resulting in high system deployment costs, and high system complexity and operation and maintenance costs.

Method used

The application server in the non-target sensitive area desensitizes user information in the target sensitive area, obtains the desensitization value information, and stores it in the target sensitive area to avoid deploying business systems in the target sensitive area.

Benefits of technology

Localized storage of user information in target-sensitive areas is achieved, reducing system deployment costs and simplifying system settings, and reducing the need for business systems transformation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120523398A_ABST
    Figure CN120523398A_ABST
Patent Text Reader

Abstract

The invention relates to a data storage method and system, computer equipment, a computer readable storage medium and a computer program product. The method is applied to an application server, and the application server is not located in a target sensitive area. The method comprises the following steps: acquiring target user information of a target user; under the condition that the target user is identified to belong to the user of the target sensitive area according to the target user information, performing desensitization processing on the target user information to obtain desensitization value information of the target user information; and storing the desensitization value information and the target user information in the target sensitive area. By adopting the method, the system deployment cost can be reduced while the data localization storage is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and in particular to a data storage method, system, computer device, computer-readable storage medium, and computer program product. Background Art

[0002] Currently, some countries and regions around the world have established extremely high standards for cross-border data transfer and impose severe penalties. Multinational companies often need to operate business systems in multiple countries and regions around the world and access business data from other regions from headquarters. Deploying a distributed business system in each location and integrating these systems to achieve data connectivity across them based on the requirements of centralized headquarters operations management would result in high system complexity and significant server, application, and labor costs. Therefore, multinational companies typically establish several core data centers around the world and, based on business, compliance, and cost requirements, establish multiple sub-centers for localized data processing and storage. In countries and regions with stricter personal information controls, cross-border companies will deploy localized personal information storage systems.

[0003] Traditional technologies require the deployment of partial or complete business systems in countries and regions with stricter control over personal information, resulting in high system deployment costs. Summary of the Invention

[0004] Based on this, it is necessary to provide a data storage method, system, computer device, computer-readable storage medium and computer program product that can reduce system deployment costs in response to the above technical problems.

[0005] In a first aspect, the present application provides a data storage method, which is applied to an application server that is not located in a target sensitive area; the method comprises:

[0006] Obtain target user information of target users;

[0007] When the target user is identified as a user in a target sensitive area based on the target user information, desensitization processing is performed on the target user information to obtain desensitized value information of the target user information;

[0008] The desensitized value information and target user information are stored in the target sensitive area.

[0009] In a second aspect, the present application further provides a data storage method, which is applied to a processing server; the method comprises:

[0010] Obtaining target user information sent by the application server; the target user information is sent to the processing server by the application server after the application server obtains the target user information and identifies the target user as a user in the target sensitive area based on the target user information;

[0011] Desensitizing the target user information to obtain desensitized value information of the target user information;

[0012] The desensitized value information and target user information are stored in the target sensitive area.

[0013] In a third aspect, the present application further provides a data storage system, including an application server, wherein the application server is not located in a target sensitive area;

[0014] The application server is used to obtain the target user information of the target user, and when it is identified that the target user belongs to a user in a target sensitive area based on the target user information, desensitize the target user information to obtain desensitized value information of the target user information, and store the desensitized value information and the target user information in the target sensitive area.

[0015] In a fourth aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the data storage method provided in the first aspect or the second aspect are implemented.

[0016] In a fifth aspect, the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the data storage method provided in the first aspect or the second aspect.

[0017] In a sixth aspect, the present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the data storage method provided in the first aspect or the second aspect.

[0018] The above-mentioned data storage method, system, computer device, computer-readable storage medium, and computer program product obtain target user information of a target user through an application server that is not located in the target sensitive area, and when the target user is identified as a user in the target sensitive area based on the target user information, desensitize the target user information to obtain desensitized value information of the target user information, and store the desensitized value information and the target user information in the target sensitive area. It is possible to desensitize the target user information of a user in the target sensitive area through an application server that is not located in the target sensitive area to obtain desensitized value information, and then store the desensitized value information and the target user information that has not been desensitized in the target sensitive area. Local storage of user information in the target sensitive area can be achieved without deploying a business system in the target sensitive area, thereby achieving a lightweight system setting in the target sensitive area and reducing system deployment costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A diagram illustrating an application environment of a data storage method according to an embodiment;

[0021] Figure 2 A schematic diagram of a flow chart of a data storage method in one embodiment;

[0022] Figure 3 A schematic flow chart of a data storage method according to another embodiment;

[0023] Figure 4 is a structural block diagram of a data storage system in one embodiment;

[0024] Figure 5 is a structural block diagram of a data storage system in another embodiment;

[0025] Figure 6 is a structural block diagram of a data storage system in another embodiment;

[0026] Figure 7 A schematic diagram of data flow when a user terminal sends a first acquisition request in one embodiment;

[0027] Figure 8 A schematic diagram of data flow when a user terminal sends a second acquisition request in one embodiment;

[0028] Figure 9 is a structural block diagram of a data storage system in another embodiment;

[0029] Figure 10 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0031] Among the numerous countries and regions around the world, over half have enacted laws related to privacy or data security, setting extremely high standards and imposing significant penalties for cross-border data transfers. Overseas users are highly aware of privacy protection and are highly sensitive to cross-border data transfers and offshore storage, resulting in significant data compliance and public opinion risks for multinational companies.

[0032] Multinational corporations often need to utilize business systems in multiple countries and regions around the world and access business data from other regions from headquarters. Deploying a distributed business system in each location and integrating these systems to achieve data connectivity across them based on headquarters' centralized business management requirements would result in increased system complexity and significant server, application, and labor costs. Therefore, multinational corporations typically establish several core data centers around the world and, based on business, compliance, and cost requirements, establish multiple sub-centers for localized data processing and storage. In countries with strict personal information controls, cross-border companies will deploy localized personal information storage systems and employ encryption, desensitization, and other protective measures to meet local data security and compliance requirements.

[0033] The data localization solutions in traditional technologies are mainly divided into localized storage buckets, edge data nodes, and local data centers according to the complexity of system deployment. Among them, the localized storage bucket is to export and encrypt personal data in increments, and then host the corresponding storage bucket. It is suitable for scenarios with small data volumes; the edge data node is to deploy specific modules locally (such as modules involving personal data) and regularly aggregate data to the core database. It is suitable for scenarios with medium data volumes; the local data center is to deploy a full-scale data center locally to provide local users with a full range of services. It is suitable for scenarios with large data volumes. In traditional technologies, it is necessary to deploy part or all of the business systems in countries or regions with high data compliance requirements. This requires not only a large amount of computing, storage, and network resources, but also continuous operation and maintenance support, resulting in high system deployment costs.

[0034] In response to the technical problem of high system deployment costs mentioned above, an embodiment of the present application provides a data storage method, which desensitizes the target user information in the target sensitive area through an application server in a non-target sensitive area to obtain desensitized value information, and then stores the desensitized value information and the target user information in the target sensitive area. This achieves local storage of target user data without deploying an application business system in the target sensitive area, realizes lightweight system steps in the target sensitive area, and reduces system deployment costs.

[0035] The data storage method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, terminal 102 communicates with application server 104 via a network. A data storage system can store data that server 104 needs to process. The data storage system can be integrated with server 104, or located in the cloud or on another network server. Terminal 102, where a target user is located, can send a service request to application server 104. Based on the service request, application server 104 obtains the target user's target user information. If the target user is identified as being in a target sensitive area based on the target user information, application server 104 desensitizes the target user information to obtain desensitized value information for the target user information. The desensitized value information and the target user information are stored in the target sensitive area. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart car devices, projectors, etc. Portable wearable devices can include smart watches, smart bracelets, head-mounted devices, etc. Head-mounted devices can include virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The server 104 may be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.

[0036] In some exemplary embodiments, Figure 2 As shown, a data storage method is provided, which is described by taking the method applied to an application server that is not located in a target sensitive area as an example. The method includes the following steps 202 to 206. Among them:

[0037] Step 202: Obtain target user information of the target user.

[0038] Sensitive regions refer to countries or regions that require localized data storage. The target sensitive region can be any sensitive region, which is a legally sovereign entity or an independent sovereign political entity. For example, a target sensitive region refers to a country that requires localized data storage. Data localization requirements refer to requirements that require specific data to be transmitted and processed within its territory or that restrict cross-border transmission. Application servers refer to servers used to implement application business services, such as cloud servers that provide cloud services, servers that provide shopping services, etc. The application server is not located in the target sensitive region. The application server can be located in other regions other than the target sensitive region, that is, the target server can be located in other sensitive regions other than the target sensitive region or in non-sensitive regions.

[0039] In actual application scenarios, for cross-border business, application servers will be deployed in specific areas that meet the configuration requirements. Application servers can be set up in sensitive or non-sensitive areas. For example, application servers can be set up in sensitive areas other than the target sensitive area. The application server can process business data from multiple different regions. When the target user is processing business, they can initiate an access request to the application server through their terminal. The application server can obtain the target user's target user information from the corresponding access request. Target user information generally refers to the target user's personal information. Target user information may include, for example, the target user's name, address (i.e., location), language type, and other information. Target user information is used to represent the target user's original data, that is, user data that has not been desensitized.

[0040] Step 204 , when it is identified based on the target user information that the target user belongs to a user in a target sensitive area, desensitization processing is performed on the target user information to obtain desensitized value information of the target user information.

[0041] Desensitization refers to the process of deforming, replacing, or encrypting sensitive information, making it unrecognizable in non-production environments while maintaining data availability. Desensitized value information is used to represent the data information after desensitization of the target user information. The desensitized value information at least includes the desensitized value of the target user information. The desensitized value of the target user information can have the same data format as the target user information before desensitization. This enables the application server to process the desensitized value information according to the original logic (such as verification, storage, or display) without modifying the business system configuration, thereby reducing the cost of system modification. At the same time, it can reduce the user's cognitive burden, avoid misunderstandings caused by format confusion, and improve the system usage experience.

[0042] For example, desensitization can be implemented through masking, replacement, generalization, perturbation, encryption, hashing, and format-preserving encryption. The implementation of desensitization is shown in Table 1 below.

[0043] Table 1

[0044]

[0045] It is easy to understand that the data desensitization scheme shown in Table 1 is only used as an example, and this embodiment does not limit it. The desensitization process can also be achieved through other methods.

[0046] For example, after obtaining the target user information of the target user, the application server identifies the target user information to determine whether the target user belongs to a user in a target sensitive area. If the target user is identified as a user in a target sensitive area, the target user information of the target user is desensitized to obtain desensitized value information of the target user information.

[0047] Step 206: store the desensitized value information and target user information in the target sensitive area.

[0048] For example, the application server may send the desensitized value information and the target user information to a target storage in the target sensitive area, and the target storage may store the target user information and the desensitized value information of the target user in the target sensitive area. Alternatively, the application server may directly store the desensitized value information and the target user information in a first database in the target sensitive area.

[0049] In an exemplary embodiment, the target user information may be encrypted to obtain the encrypted target user information, and the encrypted target user information, the desensitized value information, and the corresponding acquisition time information may be stored in a target memory or a first database in the target sensitive area. The acquisition time information indicates the time when the application server acquired the target user information.

[0050] In an exemplary embodiment, the application server may store the desensitized value information of the target user information in a second database in the region where the application server is located. The second database may belong to the application server or exist independently of the application server. By storing the desensitized value information in the region where the application server is located, when a user terminal accesses the application server and needs to obtain the desensitized value information of the target user information, the application server can directly obtain the desensitized value information from the second database and promptly return the desensitized value information to the corresponding user terminal, thereby improving business processing efficiency.

[0051] In this embodiment, the target user information of the target user is obtained through an application server that is not in the target sensitive area. When the target user is identified as a user in the target sensitive area based on the target user information, the target user information is desensitized to obtain desensitized value information of the target user information. The desensitized value information and the target user information are stored in the target sensitive area. This can achieve local storage of user information in the target sensitive area without deploying a business system in the target sensitive area, thereby realizing a lightweight system setting in the target sensitive area and reducing system deployment costs.

[0052] In some embodiments, when the target user is identified as a user in a target sensitive area based on the target user information, step 204 of performing desensitization processing on the target user information to obtain desensitized value information of the target user information includes:

[0053] When the target user is identified as a user in the target sensitive area based on the target user information, the target user information is sent to the processing server to instruct the processing server to desensitize the target user information and obtain the desensitized value information of the target user information; the desensitized value information of the target user information sent by the processing server is received.

[0054] The processing server is in communication with the application server and can be located in or outside the target sensitive area. For example, the processing server can be located in the same area as the application server, or in an area other than the target sensitive area and the area where the application server is located.

[0055] For example, in an actual application scenario, after the application server obtains the target user information of the target user, when it identifies that the target user belongs to a user in a target sensitive area based on the target user information, the target user information is sent to the processing server to instruct the processing server to desensitize the target user information and obtain the desensitized value information of the target user information. The processing server sends the desensitized value information of the target user information to the application server. The application server receives the desensitized value information of the target user information sent by the processing server, and the application server can obtain the desensitized value information of the target user information.

[0056] In some examples, the processing server can be located in the same region as the application server. As will be readily understood, the processing server can also be located in regions other than the target sensitive region and the region where the application server is located. By deploying the processing server and the application server in the same region, the processing server can quickly obtain the target user information sent by the application server, thereby achieving rapid desensitization of the target user information and reducing the processing latency of the target user information.

[0057] In some exemplary embodiments, the processing server desensitizes the target user information to obtain the desensitized value information of the target user information, which may include: the processing server performs language detection on the target user information to obtain the target language to which the target user information belongs, and performs length detection on the target user information to obtain the target data length of the target user information; desensitizes the target user information according to the target language and the target data length to obtain the initial desensitized value of the target user information. When it is identified that there is a stored desensitized value that is the same as the initial desensitized value, the target user information is desensitized again to obtain a new desensitized value of the target user information, until there is no stored desensitized value that is the same as the new desensitized value, and the target desensitized value of the target user information is obtained; when it is identified that there is no stored desensitized value that is the same as the initial desensitized value, the initial desensitized value is used as the target desensitized value; a desensitized data identifier of the target desensitized value is generated, and the desensitized data identifier and the target desensitized value are used as the desensitized value information.

[0058] In this embodiment, when the application server identifies that the target user belongs to a target sensitive area based on the target user information, the target user information is sent to the processing server to instruct the processing server to desensitize the target user information and obtain the desensitized value information of the target user information. The application server receives the desensitized value information of the target user information sent by the processing server, and deploys an additional processing server on the basis of the application server, and desensitizes the target user information through the processing server. That is, by lightweight deployment of the processing server and reducing the scope of modification to the application server, the user data of the target sensitive area can be localized for storage, thereby reducing the system deployment cost.

[0059] In some embodiments, the above method further comprises:

[0060] In response to a first acquisition request of the user terminal for the target user information, the stored desensitized value information of the target user information is sent to the user terminal.

[0061] The user terminal may be a user terminal in any area. That is, the user terminal is not limited to a user terminal corresponding to a target user in a target sensitive area, but may also be a user terminal in other areas except the target sensitive area.

[0062] In actual application scenarios, the application server can save the obtained desensitized value information of the target user in the second database. Alternatively, after obtaining the desensitized value information, the processing server sends the desensitized value information to the application server, and the application server saves the desensitized value information sent by the processing server in the second database. In response to the first acquisition request of the user terminal for the target user information, the application server sends the desensitized value information of the target user information stored in the second database to the corresponding user terminal. In other words, the first acquisition request refers to the acquisition request of the user terminal to obtain the desensitized value information of the target user information. The second database can be used to save the desensitized value information of the target user information, the target sensitive area where the target user is located, and the corresponding saved time information, etc. In other words, the second database can be used to store the desensitized value information of the target user information, but not to store the original data corresponding to the target user information.

[0063] In this embodiment, when responding to the user terminal's first acquisition request for target user information, the application server sends the stored desensitized value information of the target user information to the user terminal, thereby being able to quickly respond to the user terminal's first acquisition request and improving application service processing efficiency.

[0064] In some embodiments, the above method further comprises:

[0065] In response to the second acquisition request of the user terminal for the target user information, an original data acquisition request is generated according to the second acquisition request, and the original data acquisition request is sent to the processing server; the original data of the target user information sent by the processing server according to the original data acquisition request is received, and the original data of the target user information is sent to the user terminal; wherein, the original data of the target user information is obtained from the target sensitive area after the processing server performs identity verification on the application server after receiving the original data acquisition request and passes the identity verification.

[0066] The second acquisition request refers to a request from the user terminal to the application server to obtain the original data of the target user information. The original data acquisition request refers to a request from the application server to the processing server to obtain the original data of the target user information. The original data of the target user information refers to the data before desensitization processing.

[0067] Exemplarily, the user terminal sends a second acquisition request to the application server to obtain the original data of the target user information. The application server responds to the second acquisition request sent by the user terminal, generates an original data acquisition request based on the second acquisition request sent by the user terminal, and sends the original data acquisition request to the processing server. After receiving the original data acquisition request, the processing server performs identity verification on the application server. After the identity verification passes, the original data of the target user information can be searched in the target memory or the first database through the desensitized data identifier, and then the original data of the target user information is sent to the application server. The application server then sends the original data of the target user information to the user terminal. Among them, the processing server performs identity verification on the application server, which can be an original data acquisition permission verification, a data transmission environment security verification, etc. The specific verification method can be set according to the actual application scenario and is not specifically limited here.

[0068] In this embodiment, in response to the second acquisition request sent by the user terminal to obtain the target user information, the original data acquisition request is sent to the processing server, and the processing server performs identity verification on the application server. After the identity verification is passed, the original data of the target user information is sent to the application server, and the application server sends the original data of the target user information to the user terminal, thereby realizing closed-loop transmission of the original data of the target user information and improving the transmission security of the original data.

[0069] In some embodiments, the processing server includes multiple processing servers; in response to the second acquisition request of the user terminal for the target user information, generating an original data acquisition request according to the second acquisition request, and sending the original data acquisition request to the processing server, including:

[0070] In response to a second acquisition request of the user terminal for target user information, generating an original data acquisition request according to the second acquisition request, and simultaneously sending the original data acquisition request of the target user information to multiple processing servers;

[0071] Send the original data of the target user information to the user terminal, including:

[0072] The earliest received original data of the target user information is sent to the user terminal.

[0073] Among them, multiple processing servers can be set up in the same area or in different areas. In actual application scenarios, after responding to the second request for target user information from the user terminal, the application server generates a request to obtain the original data of the target user information, and sends the original data acquisition request to multiple processing servers at the same time. After receiving the original data acquisition request, the multiple processing servers will perform identity verification on the application server, and after the identity verification is passed, obtain the original data of the target user information from the target sensitive area, and send the original data of the target user information to the application server. The application server sends the original data of the target user information sent by the processing server that receives the data first to the user terminal, and destroys the original data sent by other processing servers subsequently received.

[0074] In this embodiment, by configuring multiple processing servers, after the application server receives the second acquisition request sent by the user terminal, it generates an original data acquisition request, and sends the original data acquisition request to multiple processing servers at the same time, and sends the original data of the target user information received earliest to the user terminal, which can improve the response speed to the second acquisition request sent by the user terminal and improve the stability of the data storage system.

[0075] In some exemplary embodiments, Figure 3 As shown, a data storage method is provided, which is described by taking the method applied to a processing server as an example. The method includes the following steps 302 to 306. Among them:

[0076] Step 302, obtaining target user information sent by the application server; wherein, the target user information is sent to the processing server after the application server obtains the target user information of the target user and identifies that the target user belongs to the target sensitive area based on the target user information.

[0077] The target user information sent by the application server and obtained by the processing server is user information of users in the target sensitive area.

[0078] Step 304: desensitize the target user information to obtain desensitized value information of the target user information.

[0079] Step 306: store the desensitized value information and target user information in the target sensitive area.

[0080] It should be noted that the meanings, processing procedures and effects achieved of the corresponding terms and steps in the above steps 302 to 308 can be found in the descriptions and explanations of the corresponding terms and steps and the corresponding effects in the above embodiment of the data storage method applied to the application server, and will not be repeated here.

[0081] In some embodiments, the desensitized value information includes an initial desensitized value; and step 304 of performing desensitization processing on the target user information to obtain the desensitized value information of the target user information includes:

[0082] Perform language detection on the target user information to obtain the target language of the target user information, and perform length detection on the target user information to obtain the target data length of the target user information; perform desensitization processing on the target user information according to the target language and target data length to obtain the initial desensitization value of the target user information.

[0083] The target language refers to the language of the target user information. For example, the target language can be English, Japanese, German, or Vietnamese. The target data length refers to the data length of the target user information. The data length can be represented by the amount of space occupied by the data during storage or transmission. For example, the data length can be represented by bytes or characters. As will be readily understood, the methods for language detection and length detection are not specifically limited in this embodiment.

[0084] Exemplarily, the processing server performs language detection on the target user information to obtain the target language of the target user information. For example, the language of the target user information can be detected based on UTF-8 (8-bit Unicode Transformation Format), ASCII (American Standard Code for Information Interchange), Unicode, etc. For example, the Unicode of the target user information can be matched with the Unicode intervals of various languages ​​to obtain the language corresponding to the Unicode interval, such as the Unicode interval 0102-1EF1 for Vietnamese and the Unicode interval 0400-052f for Russian. The processing server can also perform data type detection on the target user information to obtain the target data type of the target user information. For example, the data type of the target user information can be detected using regular expressions corresponding to bank cards, phone numbers, or dates. The processing server performs data length detection on the target user information to obtain the target data length of the target user information. Based on the target language or target data type, the target user information can then be desensitized to obtain an initial desensitized value for the target data length.

[0085] In one example, the target user information can be desensitized according to the target language and target data length to obtain an initial desensitized value of the target language and target data length, that is, the language and data length of the initial desensitized value obtained by the desensitization process are consistent with the language and data length of the target user information before the desensitization process.

[0086] In this embodiment, the processing server performs language detection and length detection on the target user information, and obtains the corresponding target language and target data length. The target user information is desensitized according to the target language and target data length to obtain an initial desensitized value, thereby maintaining the data format consistency of the initial desensitized value and the target user information, eliminating the leakage of data length features, improving the security of the desensitization processing, and reducing the storage pressure of the initial desensitized value.

[0087] In some embodiments, the above method further comprises:

[0088] When it is identified that there is a stored desensitized value that is identical to the initial desensitized value, the target user information is desensitized again to obtain a new desensitized value of the target user information, until there is no stored desensitized value that is identical to the new desensitized value, and the target desensitized value of the target user information is obtained; when it is identified that there is no stored desensitized value that is identical to the initial desensitized value, the initial desensitized value is used as the target desensitized value; a desensitized data identifier of the target desensitized value is generated, and the desensitized data identifier and the target desensitized value are used as the desensitized value information.

[0089] The stored desensitized value refers to the desensitized value of the user information that has been stored, and the stored desensitized value can be stored in the target memory or the first database of the target sensitive area. It is easy to understand that the stored desensitized value is a valid desensitized value.

[0090] Exemplarily, after the processing server desensitizes the target user information and obtains the initial desensitized value of the target user information, it identifies whether there is a stored desensitized value that is identical to the initial desensitized value. If there is a stored desensitized value that is identical to the initial desensitized value, the target user information is desensitized again to generate a new desensitized value for the target user information. The new desensitized value is compared with the stored desensitized value until there is no stored desensitized value that is identical to the new desensitized value, thereby using the new desensitized value that is different from the stored desensitized value as the target desensitized value for the target user information. If there is no stored desensitized value that is identical to the initial desensitized value, the initial desensitized value is used as the target desensitized value. After obtaining the target desensitized value, a desensitized data identifier for the target desensitized value is generated, and the desensitized data identifier is bound to the target desensitized value as desensitized value information. Among them, the desensitized data identifier is a data identifier used to uniquely identify the target desensitized value. For example, the desensitized data identifiers of the target desensitized values ​​can be generated in sequence according to the generation order of the target desensitized values.

[0091] In this embodiment, by processing the server to perform repeatable verification on the generated initial desensitized value, it is possible to ensure that the generated desensitized value is different from the stored desensitized value, maintain the uniqueness of the generated desensitized value, and facilitate the establishment of a one-to-one correspondence between the desensitized value and the original data, thereby improving the accuracy of data storage. In addition, the target desensitized value and the corresponding desensitized data identifier are stored as desensitized value information, which can improve the accuracy of data storage.

[0092] In some embodiments, the above method further comprises:

[0093] The desensitized value information is sent to the application server to instruct the application server to save the desensitized value information; wherein the application server is used to send the saved desensitized value information of the target user information to the user terminal in response to the user terminal's first acquisition request for the target user information.

[0094] In some embodiments, the above method further comprises:

[0095] Receive an original data acquisition request for target user information sent by an application server; the original data acquisition request is generated by the application server based on a second acquisition request for target user information in response to a second acquisition request for target user information from a user terminal; perform identity verification on the application server, and after the identity verification passes, send the original data of the target user information stored in the target sensitive area to the application server to instruct the application server to send the original data of the target user information to the user terminal.

[0096] It is easy to understand that the meanings and effects of the terms and steps in the above-mentioned data storage method applied to the processing server can be found in the description of the corresponding terms and steps and the implementation effects in the data storage method applied to the application server in the above-mentioned embodiment, and will not be repeated here.

[0097] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0098] In some exemplary embodiments, Figure 4As shown, a data storage system is provided, which includes an application server 12, and the application server 12 is not located in a target sensitive area; wherein the application server 12 is used to obtain target user information of a target user 16, and when the target user 16 is identified as a user in a target sensitive area based on the target user information, the target user information is desensitized to obtain desensitized value information of the target user information, and the desensitized value information and the target user information are stored in the target sensitive area.

[0099] In actual application scenarios, for cross-border business, application servers will be configured in specific areas that meet the configuration conditions. Application servers can be set up in sensitive areas or non-sensitive areas. For example, application servers can be set up in sensitive areas other than the target sensitive area. The application server can process business data from multiple different areas. In the process of processing business data from different areas, if the application server 12 identifies that the target user belongs to a user in the target sensitive area, the target user's target user information is desensitized to obtain desensitized value information, and then the desensitized value information and the target user information are stored in the target memory or the first database in the target sensitive area.

[0100] For example, the application server 12 may also be configured to store the desensitized value information in a second database 18 located in a region other than the target sensitive region. The second database 18 may belong to the application server 12 or be independent of the application server 12. That is, the second database 18 may be located in the same region as the application server 12 or in a different region. When a user terminal accesses the application server 12 to obtain the desensitized value information of the target user information, the application server 12 may directly obtain the desensitized value information from the second database 18 and return the corresponding desensitized value information to the corresponding user terminal.

[0101] In an exemplary embodiment, the application server 12 is configured to obtain target user information of a target user 16 and identify the target user information. If the target user is identified as a user in a target sensitive area, the target user information is desensitized to obtain desensitized value information of the target user information. The desensitized value information and the target user information are then sent to the target storage 14 in the target sensitive area for storage. For example, the target user information can be encrypted to obtain encrypted target user information. The encrypted target user information, desensitized value information, and acquisition time information are then stored in the target storage 14. The acquisition time information indicates the time when the application server 12 acquired the target user information.

[0102] It is easy to understand that the meanings and corresponding effects of the terms involved in the above data storage system embodiment can be found in the descriptions and implementation effects of the corresponding terms in the above data storage method embodiment, and will not be repeated here.

[0103] In this embodiment, the target user information of the target user is obtained through an application server that is not in the target sensitive area, and when the target user is identified as a user in the target sensitive area based on the target user information, the target user information is desensitized to obtain desensitized value information, and the desensitized value information and the target user information are stored in the target sensitive area. It is possible to desensitize the target user information of the target user in the target sensitive area to obtain desensitized value information, and then store the desensitized value information after desensitization and the target user information that has not been desensitized in the target sensitive area. There is no need to deploy a business system in the target sensitive area, and the user information in the target sensitive area can be locally stored, thereby realizing a lightweight system setting in the target sensitive area and reducing the system deployment cost.

[0104] In some embodiments, the data storage system also includes a processing server 13, and the application server 12 is also used to send the target user information to the processing server 13 when it is identified that the target user belongs to a user in the target sensitive area based on the target user information. The processing server 13 is used to desensitize the target user information sent by the application server 12, obtain desensitized value information of the target user information, and store the desensitized value information and the target user information in the target sensitive area.

[0105] For example, Figure 5 As shown, processing server 13 is located in the target sensitive area. Application service 12 is configured to identify the acquired user information of target user 16 to determine whether target user 16 is located in the target sensitive area. If target user 16 is identified as being located in the target sensitive area, the target user information is sent to processing server 13. Processing server 13 is configured to desensitize the target user information sent by application server 12, obtain desensitized value information of the target user information, and store the desensitized value information and the target user information in target storage 14 in the target sensitive area.

[0106] Exemplarily, the processing server 13 desensitizes the target user information sent by the application server 12 to obtain desensitized value information of the target user information. The processing server 13 may send the desensitized value information of the target user information to the application server 12, and the application server 12 may store the desensitized value information sent by the processing server 13 in the second database 18. The desensitized value information at least includes the desensitized value of the target user information, and the desensitized value of the target user information has the same data format as the target user information before desensitization. This enables the application server 12 to process the desensitized value information in accordance with the original logic (such as verification, storage, or display) without modifying the business system configuration, thereby reducing the cost of system modification. At the same time, it can reduce the user's cognitive burden, avoid misunderstandings caused by format confusion, and improve the system usage experience.

[0107] In this embodiment, the processing server desensitizes the target user information sent by the application server to obtain the desensitized value information of the target user information, and then stores the target user information and the desensitized value information in the target memory, which can reduce the impact of the application server on normal business processing. By deploying a lightweight processing server, the user data of users in the target sensitive area can be locally stored, which can reduce the system deployment cost.

[0108] In some embodiments, as Figure 6 As shown, processing server 13 can be located in the same region as application server 12, i.e., processing server 13 is not located in the target sensitive area. It will be readily understood that processing server 13 can also be located in a region other than the target sensitive area and the region where application server 12 is located. By deploying processing server 13 and application server 12 in the same region, the processing server can quickly obtain the target user information sent by the application server, thereby achieving rapid desensitization of the target user information and reducing the processing latency of the target user information.

[0109] In some embodiments, the processing server 13 is also used to perform language detection on the target user information to obtain the target language to which the target user information belongs, and to perform length detection on the target user information to obtain the target data length of the target user information, and to desensitize the target user information according to the target language and target data length to obtain the initial desensitized value of the target user information.

[0110] In this embodiment, the processing server performs language detection and length detection on the target user information, and obtains the corresponding target language and target data length. The target user information is desensitized according to the target language to obtain the initial desensitized value of the target data length, thereby maintaining the consistency of the data format of the initial desensitized value and the target user information, eliminating the leakage of data length features, improving the security of the desensitization processing, and reducing the storage pressure of the initial desensitized value.

[0111] In some embodiments, the processing server 13 is also used to desensitize the target user information and obtain the initial desensitized value of the target data length. When it is identified that there is a stored desensitized value that is the same as the initial desensitized value, the target user information is desensitized again to obtain a new desensitized value of the target user information, until there is no stored desensitized value that is the same as the new desensitized value, and the target desensitized value of the target user information is obtained; when it is identified that there is no stored desensitized value that is the same as the initial desensitized value, the initial desensitized value is used as the target desensitized value; a desensitized data identifier of the target desensitized value is generated, and the desensitized data identifier and the target desensitized value are used as desensitized value information.

[0112] In some embodiments, the processing server 13 is also used to send the desensitized value information to the application server 12; the application server 12 is also used to save the desensitized value information sent by the processing server 13, and in response to the user terminal's first acquisition request for the target user information, send the saved desensitized value information of the target user information to the user terminal.

[0113] In actual application scenarios, such as Figure 7 As shown, the processing server 13 is also used to send the desensitized value information to the application server 12 after obtaining the desensitized value information, and the application server 12 is used to save the desensitized value information sent by the processing server 13 in the second database 18. In response to the first acquisition request of the user terminal for the target user information, the application server 12 sends the desensitized value information of the target user information saved in the second database 18 to the user terminal. In other words, the first acquisition request refers to the acquisition request of the user terminal to obtain the desensitized value information of the target user information. The second database 18 can be used to save the desensitized value information of the target user information, the target sensitive area where the target user is located, and the corresponding saved time information, etc. In other words, the second database 18 can be used to store the desensitized value information of the target user information, but not to store the original data corresponding to the target user information.

[0114] In this embodiment, the processing server sends the desensitized value information to the application server for storage. When the user terminal sends a first acquisition request for the target user information to the application server, the application server sends the saved desensitized value information of the target user information to the user terminal, and can quickly respond to the first acquisition request of the user terminal.

[0115] In some embodiments, the application server 12 is also used to respond to a second acquisition request for the target user information from the user terminal, generate an original data acquisition request based on the second acquisition request, and send the original data acquisition request for the target user information to the processing server 13; the processing server 13 is also used to perform identity verification on the application server 12 after receiving the original data acquisition request, and after the identity verification is passed, send the original data of the target user information stored in the target sensitive area to the application server 12; the application server 12 is also used to send the original data of the target user information sent by the processing server 13 to the user terminal.

[0116] For example, Figure 8 As shown, the user terminal sends a second acquisition request to the application server 12 to obtain the original data of the target user information. The application server 12 responds to the second acquisition request sent by the user terminal, generates an original data acquisition request based on the second acquisition request sent by the user terminal, and sends the original data acquisition request to the processing server 13. After receiving the original data acquisition request, the processing server 13 performs identity verification on the application server 12. After the identity verification is passed, the original data of the target user information can be searched in the target memory 14 through the desensitized data identifier, and then the original data of the target user information is sent to the application server 12. The application server 12 then sends the original data of the target user information to the user terminal. Among them, the processing server 13 performs identity verification on the application server 12, which can be original data acquisition authority verification, data transmission environment security verification, etc.

[0117] In this embodiment, based on the second acquisition request for obtaining the target user information sent by the user terminal to the application server, the application server sends an original data acquisition request to the processing server, the processing server performs identity verification on the application server, and after the verification is passed, sends the original data of the target user information to the application server, and the application server then sends the original data of the target user information to the user terminal, thereby realizing closed-loop transmission of the original data of the target user information and improving the transmission security of the original data.

[0118] In some embodiments, the processing server 13 includes multiple; the application server 12 is also used to respond to the second acquisition request of the user terminal for the target user information, generate an original data acquisition request according to the second acquisition request, and then send the original data acquisition request of the target user information to multiple processing servers at the same time, and send the earliest received original data of the target user information to the user terminal.

[0119] In this embodiment, by configuring multiple processing servers, after the application server receives the second acquisition request sent by the user terminal, it generates an original data acquisition request, and sends the original data acquisition request to multiple processing servers at the same time, and sends the original data of the target user information received earliest to the user terminal, which can improve the response speed to the second acquisition request sent by the user terminal and improve the stability of the data storage system.

[0120] In an exemplary embodiment, a data storage system such as Figure 9 As shown. The data storage system includes an application server 12, a processing server 13 and a target memory 14. The target memory 14 is set in a target sensitive area, and the application server 12 and the processing server 13 are in the same area, but the area where the application server 12 and the processing server 13 are located does not belong to the target sensitive area. Among them, the application server 12 is used to obtain the target user information of the target user, and identify the target user information to determine whether the target user belongs to the user in the target sensitive area. If the target user belongs to the user in the target sensitive area, the target user information is sent to the processing server 13. The processing server 13 desensitizes the target user information sent by the application server 12, obtains the desensitized value information of the target user information, and saves the desensitized value information and the target user information in the target memory 14. It is easy to understand that the desensitized value information and the target user information can also be stored in the first database in the target sensitive area. The processing server 13 can also send the desensitized value information of the target user information to the application server 12, and the application server 12 can save the desensitized value information of the target user information in the second database 18.

[0121] If the user terminal sends a first acquisition request for the target user information to the application server 12, the application server 12 responds to the user terminal's first acquisition request for the target user information, obtains the desensitized value information of the target user information corresponding to the first acquisition request from the second database 18, and sends the desensitized value information of the target user information to the user terminal.

[0122] If the user terminal sends a second request to obtain target user information to the application server 12, the application server 12 responds to the second request by generating an original data acquisition request based on the second acquisition request and sends the original data acquisition request to the processing server 13. The processing server 13 verifies the identity of the application server 12. After the identity verification is passed, the processing server 13 obtains the encrypted target user information corresponding to the original data acquisition request from the target storage 14. The processing server 13 decrypts the encrypted target user information to obtain the decrypted target user information and sends the decrypted target user information (i.e., the original data of the target user information) to the application server 12. The application server 12 then returns the original data of the target user information to the user terminal.

[0123] In the above embodiment, by configuring a target memory in the target sensitive area, desensitizing the target user information of the users in the target sensitive area through the application server and the processing server to obtain desensitized value information, and then storing the desensitized value information after desensitization and the target user information that has not been desensitized in the target memory in the target sensitive area, there is no need to deploy a business system in the target sensitive area. By adding a lightweight processing server on the basis of the original application server, the user information in the target sensitive area can be stored locally, and a lightweight system setting in the target sensitive area can be achieved, thereby reducing the system deployment cost. At the same time, the data is stored locally in the target sensitive area to avoid the cross-border transmission of the original data and reduce the security risk of data transmission. The valid data stored in the target memory are all related to the target user information in the target sensitive area, which can maximize the use of storage resources and avoid the waste of storage resources.

[0124] It is easy to understand that the meanings and corresponding effects of the terms involved in the above data storage system embodiment can be found in the descriptions and implementation effects of the corresponding terms in the above data storage method embodiment, and will not be repeated here.

[0125] Based on the same inventive concept, embodiments of the present application further provide a data storage device for implementing the aforementioned data storage method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more data storage device embodiments provided below can be found in the above-described limitations of the data storage method and are not further elaborated here.

[0126] In an exemplary embodiment, a data storage device is provided, which is applied to an application server that is not located in a target sensitive area; the device includes an information acquisition module, a desensitization processing module, and a data storage module, wherein:

[0127] A first information acquisition module is used to acquire target user information of a target user;

[0128] A first desensitization processing module is used to perform desensitization processing on the target user information when the target user is identified as a user in a target sensitive area based on the target user information, so as to obtain desensitized value information of the target user information;

[0129] The first data storage module is used to store the desensitized value information and target user information in the target sensitive area.

[0130] In some embodiments, the first desensitizing processing module is also used to: when the target user is identified as a user in a target sensitive area based on the target user information, send the target user information to the processing server to instruct the processing server to desensitize the target user information and obtain the desensitized value information of the target user information; receive the desensitized value information of the target user information sent by the processing server.

[0131] In some embodiments, the above-mentioned device further includes a first data sending module, which is used to send the stored desensitized value information of the target user information to the user terminal in response to a first acquisition request of the target user information by the user terminal.

[0132] In some embodiments, the above-mentioned device also includes a second data sending module, which is used to respond to the second acquisition request of the user terminal for the target user information, generate an original data acquisition request according to the second acquisition request, and send the original data acquisition request to the processing server; receive the original data of the target user information sent by the processing server according to the original data acquisition request, and send the original data of the target user information to the user terminal; the original data of the target user information is obtained from the target sensitive area after the processing server performs identity verification on the application server after receiving the original data acquisition request, and passes the identity authentication.

[0133] In some embodiments, the processing server includes multiple; the second data sending module is also used to respond to the second acquisition request of the user terminal for the target user information, generate an original data acquisition request based on the second acquisition request, and simultaneously send the original data acquisition request of the target user information to multiple processing servers; and send the original data of the target user information received earliest to the user terminal.

[0134] In an exemplary embodiment, a data storage device is provided, which is applied to a processing server and includes: a second information acquisition module, a second desensitization processing module, and a second data storage module, wherein:

[0135] The second information acquisition module is used to acquire the target user information sent by the application server; the target user information is sent to the processing server by the application server after acquiring the target user information and identifying the target user as a user in the target sensitive area based on the target user information;

[0136] The second desensitization processing module is used to perform desensitization processing on the target user information to obtain desensitized value information of the target user information;

[0137] The second data storage module is used to store the desensitized value information and target user information in the target sensitive area.

[0138] In some embodiments, the desensitized value information includes an initial desensitized value; the second desensitization processing module is also used to: perform language detection on the target user information to obtain the target language to which the target user information belongs, and perform length detection on the target user information to obtain the target data length of the target user information; perform desensitization processing on the target user information according to the target language and target data length to obtain the initial desensitized value of the target user information.

[0139] In some embodiments, the second desensitizing processing module is also used to: when it is identified that there is a stored desensitized value that is identical to the initial desensitized value, re-desensitize the target user information to obtain a new desensitized value of the target user information, until there is no stored desensitized value that is identical to the new desensitized value, and obtain the target desensitized value of the target user information; when it is identified that there is no stored desensitized value that is identical to the initial desensitized value, use the initial desensitized value as the target desensitized value; generate a desensitized data identifier for the target desensitized value, and use the desensitized data identifier and the target desensitized value as desensitized value information.

[0140] In some embodiments, the above-mentioned data desensitizing device also includes a third data sending module, which is used to send the desensitized value information to the application server to instruct the application server to save the desensitized value information; the application server is used to send the saved desensitized value information of the target user information to the user terminal in response to the user terminal's first acquisition request for the target user information.

[0141] In some embodiments, the above-mentioned data desensitizing device also includes a fourth data sending module, which is used to receive the original data acquisition request for the target user information sent by the application server; the original data acquisition request is generated by the application server according to the second acquisition request in response to the second acquisition request for the target user information by the user terminal; the identity of the application server is verified, and after the identity verification is passed, the original data of the target user information stored in the target sensitive area is sent to the application server to instruct the application server to send the original data of the target user information to the user terminal.

[0142] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 10 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data related to target user information. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a data storage method is implemented.

[0143] Those skilled in the art will understand that Figure 10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0144] In an exemplary embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps of the data storage method in the above embodiment when executing the computer program.

[0145] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the data storage method in the above embodiment are implemented.

[0146] In one embodiment, a computer program product is provided, comprising a computer program, which implements the steps of the data storage method in the above embodiment when executed by a processor.

[0147] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0148] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.

[0149] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0150] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A data storage method, characterized in that: Applied to an application server, the application server is not located in a target sensitive area; the method comprises: Obtain target user information of target users; In a case where the target user is identified as a user in the target sensitive area according to the target user information, desensitizing the target user information to obtain desensitized value information of the target user information; The desensitized value information and the target user information are stored in the target sensitive area.

2. The method according to claim 1, characterized in that In the case where the target user is identified as a user in the target sensitive area according to the target user information, performing desensitization processing on the target user information to obtain desensitized value information of the target user information includes: If the target user is identified as a user in the target sensitive area based on the target user information, the target user information is sent to a processing server to instruct the processing server to perform desensitization processing on the target user information to obtain desensitized value information of the target user information; Receive the desensitized value information of the target user information sent by the processing server.

3. The method according to claim 1 or 2, characterized in that The method further comprises: In response to a first acquisition request of the target user information by the user terminal, the stored desensitized value information of the target user information is sent to the user terminal.

4. The method according to claim 2, characterized in that The method further comprises: In response to a second acquisition request from a user terminal for the target user information, generating an original data acquisition request according to the second acquisition request, and sending the original data acquisition request to the processing server; Receive the original data of the target user information sent by the processing server according to the original data acquisition request, and send the original data of the target user information to the user terminal; the original data of the target user information is obtained from the target sensitive area after the processing server performs identity verification on the application server after receiving the original data acquisition request and passes the identity verification.

5. The method according to claim 4, characterized in that The processing server includes a plurality of processing servers; the responding to the second acquisition request of the target user information by the user terminal, generating an original data acquisition request according to the second acquisition request, and sending the original data acquisition request to the processing server, including: In response to a second acquisition request of the target user information by the user terminal, generating an original data acquisition request according to the second acquisition request, and simultaneously sending the original data acquisition request of the target user information to the plurality of processing servers; The sending the original data of the target user information to the user terminal includes: The earliest received original data of the target user information is sent to the user terminal.

6. A data storage method, characterized in that: Applied to a processing server; the method comprises: Obtaining target user information sent by the application server; the target user information is sent to the processing server by the application server after the application server obtains the target user information and identifies that the target user belongs to a user in a target sensitive area based on the target user information; Performing desensitization processing on the target user information to obtain desensitized value information of the target user information; The desensitized value information and the target user information are stored in the target sensitive area.

7. The method according to claim 6, characterized in that The desensitized value information includes an initial desensitized value; the desensitizing process is performed on the target user information to obtain the desensitized value information of the target user information, including: Performing language detection on the target user information to obtain a target language of the target user information, and performing length detection on the target user information to obtain a target data length of the target user information; The target user information is desensitized according to the target language and the target data length to obtain an initial desensitized value of the target user information.

8. The method according to claim 7, characterized in that The method further comprises: When it is identified that there is a stored desensitized value that is the same as the initial desensitized value, re-desensitizing the target user information to obtain a new desensitized value of the target user information, until there is no stored desensitized value that is the same as the new desensitized value, thereby obtaining a target desensitized value of the target user information; In the case of identifying that there is no stored desensitization value identical to the initial desensitization value, using the initial desensitization value as the target desensitization value; Generate a desensitized data identifier of the target desensitized value, and use the desensitized data identifier and the target desensitized value as the desensitized value information.

9. The method according to claim 6, characterized in that The method further comprises: The desensitized value information is sent to the application server to instruct the application server to save the desensitized value information; the application server is used to send the saved desensitized value information of the target user information to the user terminal in response to the user terminal's first acquisition request for the target user information.

10. The method according to claim 6, characterized in that The method further comprises: receiving an original data acquisition request for the target user information sent by the application server; the original data acquisition request is generated by the application server according to the second acquisition request in response to the second acquisition request of the user terminal for the target user information; The application server is identity verified, and after the identity verification passes, the original data of the target user information stored in the target sensitive area is sent to the application server to instruct the application server to send the original data of the target user information to the user terminal.

11. A data storage system, characterized in that: The invention comprises an application server, which is not located in a target sensitive area; the application server is used to obtain target user information of a target user, and when it is identified from the target user information that the target user belongs to a user in the target sensitive area, desensitize the target user information to obtain desensitized value information of the target user information, and store the desensitized value information and the target user information in the target sensitive area.

12. The data storage system according to claim 11, wherein: The system further includes a processing server; the application server is further configured to send the target user information to the processing server when the target user is identified as a user in the target sensitive area based on the target user information; The processing server is used to perform desensitization processing on the target user information sent by the application server, obtain desensitized value information of the target user information, and store the desensitized value information and the target user information in the target sensitive area.

13. The data storage system according to claim 12, wherein: The processing server is further configured to send the desensitized value information to the application server; The application server is further configured to save the desensitized value information sent by the processing server, and in response to a first acquisition request of the target user information by the user terminal, send the saved desensitized value information of the target user information to the user terminal.

14. The data storage system according to claim 12, wherein: The application server is further configured to respond to a second acquisition request from the user terminal for the target user information, generate an original data acquisition request according to the second acquisition request, and send the original data acquisition request to the processing server; The processing server is further configured to perform identity verification on the application server after receiving the original data acquisition request, and send the original data of the target user information stored in the target sensitive area to the application server after the identity verification passes; The application server is further configured to send the original data of the target user information sent by the processing server to the user terminal.

15. The data storage system according to claim 14, wherein: The processing servers include multiple ones; the application server is also used to, in response to the user terminal's second acquisition request for the target user information, generate an original data acquisition request based on the second acquisition request, and then simultaneously send the original data acquisition request for the target user information to the multiple processing servers, and send the earliest received original data of the target user information to the user terminal.

16. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 or 6 to 10 are implemented.

17. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 or 6 to 10 are implemented.

18. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 or 6 to 10 are implemented.

Citation Information

Patent Citations

  • Data processing method, device and system

    CN113642036A

  • Data processing method and device, storage medium and program product

    CN115329177A

  • Data processing method and device

    CN116467738A

  • Data processing method, system and equipment and storage medium

    CN117633017A

  • Data desensitization system

    CN207489017U