Data processing method and device and electronic equipment

By using multiple data dictionaries and offsets in data processing, the problem of low data desensitization in the prior art is solved, and a safer and more flexible data processing is achieved.

CN120579211APending Publication Date: 2025-09-02INDUSTRIAL AND COMMERCIAL BANK OF CHINA +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510752025.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

The existing data desensitization methods are relatively single, resulting in low data security after desensitization.

Method used

By determining the target data dictionary from multiple data dictionaries according to the type of the target data element, desensitized data elements are determined using storage locations and offsets, and desensitized data is generated, data restoration is supported.

Benefits of technology

It improves the diversity and security of data desensitization, while supporting data restoration to ensure data integrity and authenticity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120579211A_ABST
    Figure CN120579211A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method which can be applied to the field of privacy computing. The data processing method comprises the steps that a target data dictionary is determined from a plurality of different data dictionaries according to the type of a target data element in first data, the data dictionary comprises a plurality of data elements, and the data elements are obtained by segmenting data; determining a desensitized data element according to the storage position and the offset of the target data element in the target data dictionary; and generating second data according to the desensitized data elements. The invention further provides a data processing device and equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of privacy computing, and specifically to a data processing method, device, and electronic device. Background Art

[0002] Sensitive data is required in many data usage scenarios. However, to maintain the security of sensitive data, it must be desensitized before being provided to users. Relevant desensitization methods are relatively simple, and the security of the desensitized data is not high.

[0003] To this end, a new data processing method is needed. Summary of the Invention

[0004] In view of the above problems, the present application provides a data processing method, apparatus, device, medium and program product.

[0005] According to the first aspect of the present application, a data processing method is provided, comprising: determining a target data dictionary from a plurality of different data dictionaries according to the type of a target data element in first data, the data dictionary including a plurality of data elements, the data elements being obtained by segmenting the data; determining a desensitized data element according to the storage position and offset of the target data element in the target data dictionary; and generating second data according to the desensitized data element.

[0006] According to an embodiment of the present application, a target data dictionary is determined from multiple different data dictionaries based on the type of the target data element in the first data, including: determining a corresponding target data dictionary based on the character type or meaning type of the target data element, where the meaning type is the meaning of the target data element at the corresponding position in the first data.

[0007] According to an embodiment of the present application, it also includes: in response to a data restoration request, determining a negative offset according to the opposite number of the offset; modifying the second data according to the storage position of the desensitized data element in the target data dictionary and the negative offset to obtain the first data.

[0008] According to an embodiment of the present application, determining a data dictionary based on the type of a target data element in the first data includes: when the type of the target data element is a number and it is the first data element in the first data, determining a target data dictionary including non-zero integers.

[0009] According to an embodiment of the present application, the storage position of the target data element in the data dictionary is the first storage position, and the desensitized data element is determined based on the storage position and offset of the target data element in the target data dictionary, including: determining the second storage position of the desensitized data element in the target data dictionary based on the first storage position and the offset; and determining the desensitized data element from the target data dictionary based on the second storage position.

[0010] According to an embodiment of the present application, the desensitization of the desensitized data element at the second storage position of the target data dictionary is determined based on the first storage position and the offset, including: when the first numerical value determined based on the first storage position and the offset is greater than the target data dictionary length, determining the second numerical value based on the first numerical value and the digital dictionary length, the second numerical value being less than or equal to the target data dictionary length; and determining the second storage position based on the second numerical value.

[0011] According to an embodiment of the present application, the method further includes: determining a storage location of the target data element in the target data dictionary according to a dictionary index, wherein the dictionary index stores an index value representing an arrangement order of the data element in the target data dictionary.

[0012] According to an embodiment of the present application, the method further includes: obtaining a set desensitizing key; and determining an offset based on the desensitizing key.

[0013] According to an embodiment of the present application, generating second data based on the desensitized data element includes: replacing the target data element with the desensitized data element according to the position of the target data element in the first data to obtain the second data.

[0014] The second aspect of the present application provides a data processing device, including: a data dictionary module, used to determine a target data dictionary from multiple different data dictionaries based on the type of target data elements in the first data, the data dictionary including multiple data elements, and the data elements are generated by segmenting the data; a desensitized data element determination module, used to determine the desensitized data element based on the storage position and offset of the target data element in the target data dictionary; and a desensitized data generation module, used to generate second data based on the desensitized data element.

[0015] The third aspect of the present application provides an electronic device, comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0016] The fourth aspect of the present application further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the computer program or instructions are executed by a processor.

[0017] The fifth aspect of the present application further provides a computer program product, comprising a computer program or instructions, which implement the steps of the above method when executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The above contents and other objects, features and advantages of the present application will become more apparent through the following description of the embodiments of the present application with reference to the accompanying drawings, in which:

[0019] Figure 1 A diagram schematically illustrates an application scenario of the data processing method and device according to an embodiment of the present application;

[0020] Figure 2 A schematic diagram of a data desensitization process according to an embodiment of the present application is shown;

[0021] Figure 3 The following schematically shows a flow chart of a data processing method according to an embodiment of the present application;

[0022] Figure 4 The following schematically shows a structural block diagram of a data processing device according to an embodiment of the present application;

[0023] Figure 5 A block diagram of an electronic device suitable for implementing a data processing method according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION

[0024] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present application. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present application. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.

[0025] The terms used herein are only for describing specific embodiments and are not intended to limit this application. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0026] All terms used herein have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having the meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.

[0027] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0028] It should be noted that in the technical solution of this application, the user information involved (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc., the first data before desensitization in this application and the second data after desensitization) are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0029] In the scenario of using personal information for automated decision-making, the methods, devices, and systems provided in the embodiments of the present application all provide users with corresponding operation portals for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge and skills, and have reached a certain level of professionalism.

[0030] The embodiments of the present application provide a data processing method and apparatus. Figure 1 The following schematically illustrates an application scenario diagram of the data processing method and device according to an embodiment of the present application.

[0031] like Figure 1 As shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, and a server 105. A network 104 is used as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or optical fiber cables.

[0032] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0033] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0034] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.

[0035] It should be noted that the data processing method provided in the embodiment of the present application can generally be executed by the server 105. Accordingly, the data processing device provided in the embodiment of the present application can generally be set in the server 105. The data processing method provided in the embodiment of the present application can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the data processing device provided in the embodiment of the present application can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.

[0036] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0037] The following will be based on Figure 1 The scene described by Figures 2 to 5 The data processing method according to the embodiment of the present application is described in detail.

[0038] Figure 2 Schematic diagram of the data desensitization process according to one embodiment of the present application is shown. Figure 2 As shown, data source management and target source management can be performed in the data desensitization process 210. The data source is the source of the first data to be desensitized, and can be specifically implemented as a data source database. Figure 2A first data source database 202, a second data source database 203, and a third data source database 204 are shown. After desensitizing the first data, the second data can be obtained, and the second data is sent to the target source. The target source is the storage location of the second data, and the target source can be specifically implemented as a target source database. The target source database can be the same database as the data source database. When the target source database is the same as the data source database, the desensitization process is same-database desensitization; when the target source database is different from the data source database, the desensitization process is different-database desensitization. This application does not limit the number and type of data sources and target sources, and can be implemented as a relational database or a non-relational database, etc.

[0039] The data desensitization process 210 also includes desensitization discovery, which involves extracting data from the data source database, detecting sensitive data fields within the data, and determining that the data within these sensitive data fields is sensitive data. When this sensitive data is to be retrieved from the database, it is desensitized. According to one embodiment, sensitive data fields include mobile phone numbers, ID cards, addresses, email addresses, names, etc.

[0040] The data masking process 210 also includes masking configuration, which allows for configuring the data source and target source of sensitive data, as well as the applied masking algorithm. According to one embodiment, masking algorithms include, but are not limited to, random transformations, fixed transformations, fixed-value transformations, position masks, and reversible transformations. During masking configuration, a portion of the extracted data can be masked, and the masked results are displayed to facilitate user configuration of the desired algorithm.

[0041] According to one embodiment, different data require different desensitization times. Desensitization tasks can be set in the data desensitization process 210. Each desensitization task desensitizes data in one or more fields. Multiple desensitization tasks can also be executed in parallel to improve data processing efficiency.

[0042] According to one embodiment, after completing data desensitization, a data desensitization report can also be generated. The data desensitization report may include the desensitized data source, target source, number of databases used, number of data tables, data volume, and time required for the desensitization task, etc. This application does not limit the specific content included in the data desensitization report.

[0043] According to one embodiment, during the data masking process, task approval can also be performed for the masking task, that is, when acquiring data, an audit process is set up for the recipient of the acquired data and the data to be acquired, and users with approval qualifications audit the recipient of the acquired data and the data to be acquired; data masking is allowed only after the audit is passed.

[0044] According to one embodiment, when processing data, operation 220 is first performed to obtain first data to be desensitized from any of the first, second, or third data source databases. Operation 230 is then performed to obtain a key from key database 201 so as to determine an offset based on the key. Key database 201 stores a set key, which may be a string. This application does not limit the specific form of the key. Finally, operation 240 is performed to desensitize the first data based on the offset to obtain second data, which is then stored in at least one of the first, second, or third target source databases.

[0045] According to one embodiment, in order to ensure data security during the desensitization process, the first data to be desensitized can be restricted to be read into the internal memory, and the second data can be sent to another storage medium after being obtained. The entire desensitization process is completed in the internal memory, thereby improving the security of data desensitization.

[0046] Figure 3 The flowchart of the data processing method according to the embodiment of the present application is schematically shown. Figure 3 As shown, the data processing method 300 of this embodiment includes operations 310 to 330, and the data processing method can be executed in an electronic device.

[0047] In operation 310 , a target data dictionary is determined from a plurality of different data dictionaries according to the type of the target data element in the first data. The data dictionary includes a plurality of data elements, and the data elements are obtained by segmenting the data.

[0048] According to one embodiment, the present application maintains multiple data dictionaries, each of which stores a type of data element. A data element is a part of the data, and the data can be divided in a variety of ways. The specific division method selected depends on the meaning represented by the different parts of the data. For example, for a string of numbers without a specified encoding method, each digit in the number can be divided into a data element. There are as many data elements as there are digits arranged in sequence in the number, and each data element represents a number in the number. If multiple characters connected together in the data have a specific meaning in the data, such as representing an operator, a postal code, etc., the multiple characters connected together will be separated from the data as a data element.

[0049] If the data is a telephone number, the first three or four digits of the telephone number can be split into a data element, representing information such as the operator; if the data is an ID card number, it can be split into multiple data elements according to the encoding rules of the ID card number, and each data element represents the specific meaning encoded in the corresponding position, such as location, gender, etc.

[0050] If the data is a user name including letters, each letter in the user name may be divided into a data element, representing the letter in the corresponding position of the user name.

[0051] If the data is address information including a postal code, the postal code may be separated into a data element, which represents the postal code.

[0052] According to one embodiment, the data element may be specifically implemented as one or more characters. This application does not limit the specific implementation form of the data element and the data.

[0053] According to one embodiment, the multiple data dictionaries maintained by this application may include a dictionary of numeric characters, a dictionary of lowercase English, a dictionary of uppercase English, a dictionary of the first letter of a document, a dictionary of Chinese characters, a dictionary of national area codes, a dictionary of Chinese surnames, a dictionary of postal codes, a dictionary of mobile phone area codes, and a dictionary of mobile phone number codes including the first three or four digits of mobile phone numbers from different operators. This application does not impose any restrictions on the number or types of data dictionaries maintained. The following are some examples of data dictionaries:

[0054] Numeric character dictionary:

[0055] { '1', '3', '5', '8', '9', '0', '2', '6', '7', '4'}

[0056] Lowercase English dictionary:

[0057] {'m', 't', 'e', ​​'j', 'q', 'v', 'w', 'a', 'p', 'n', 'c', 'z', 'x', 'y', 'k', 'd', 'f', 'u', 'g', 'r', 'h', 'l', 'i', 's', 'o', 'b'}

[0058] Uppercase English dictionary:

[0059] {'M', 'V', 'D', 'W', 'C', 'F', 'Q', 'X', 'N', 'R', 'L', 'Y', 'A', 'S', 'E', 'J', 'U', 'B', 'P', 'H', 'G', 'I', 'K', 'T', 'O', 'Z'}

[0060] Dictionary of the first letter of a certificate (can be implemented as a dictionary of the first letter of an officer's certificate):

[0061] {'South', 'North', 'Shen', 'Cheng', 'Jin', 'Guang', 'Participate', 'Certification', 'Hou', 'Zhuang', 'Hai', 'Kong', 'Zheng', 'Civil', 'Zhi'}

[0062] Mobile phone number area code dictionary:

[0063] {'138', '183', '158', '177', '135', '159', '187', '185', '189', '147', '166', '178', '151', '182', '155', '133', '173', '153', '156', '198', '181', '188', '176', '180', '137', '134', '152', '145', '199', '149', '130', '186', '150', '157', '175', '136', '139', '131', '132'}

[0064] The first three to four digits of the mobile phone number encoding dictionary of the first operator:

[0065] {'1340', '1341', '1342', '1343', '1344', '1345', '1346', '1347', '1348', '135', '136', '137', '138', '139', '1440', '147', '148'}

[0066] The first three to four digits of the second operator's mobile phone number encoding dictionary:

[0067] {'130', '131', '132', '140', '145', '146', '155', '156', '166', '167', '1704', '1707', '1708', '1709', '171', '175', '176', '185'}

[0068] The first three to four digits of the third-party operator's mobile phone number encoding dictionary:

[0069] {'133', '1349', '1410', '149', '152', '162', '1700', '1701', '1702', '173', '1740', '1741', '177', '180', '181', '189', '190', '191'}

[0070] According to one embodiment of the present application, the first data can be divided into multiple data elements, and the data element to be converted can be used as the target data element. When determining the target data dictionary according to the type of the target data element, the corresponding target data dictionary can be determined according to the character type or meaning type of the target data element, and the meaning type is the meaning of the target data element at the corresponding position in the first data. If each character in the target data element has no specific meaning at the corresponding position and only takes a value at the corresponding position, the target data element can be divided into multiple single characters. When the target data element is a single character, the corresponding character type includes numeric characters, lowercase characters, uppercase characters, Chinese characters, special characters, etc. According to the character type, a data dictionary including a specific character type can be determined as the target data dictionary. Determining the target data dictionary in a variety of ways can improve the diversity of data desensitization methods.

[0071] If in the target data element, one or multiple characters connected together have specific meanings at corresponding positions and represent specific information at corresponding positions, then one or multiple characters connected together can be used as target data elements, and then the target data dictionary can be determined according to the meaning of the target data elements at corresponding positions in the first data. For example, 139 in the first to third positions of the first data represents the mobile phone number area code, then the mobile phone number area code dictionary is obtained as the target data dictionary.

[0072] According to one embodiment of the present application, after the data elements are divided, if the type of the target data element is a number and it is the first data element in the first data, a target data dictionary including non-zero integers is determined. By using the target data dictionary including non-zero integers to change the target data elements of the digital type, it is possible to avoid the transformed desensitized data elements being 0, prevent the second data after desensitization from missing digits and errors, and keep the length of the second data after desensitization consistent with that of the first data.

[0073] Subsequently, operation 220 is executed to determine the desensitized data element based on the target data element's storage location and offset in the target data dictionary. The target data element is stored at a first storage location in the data dictionary. In operation 220, a second storage location of the desensitized data element in the target data dictionary is determined based on the first storage location and the offset. The desensitized data element is then determined from the target data dictionary based on the second storage location. Using the offset allows for a relatively simple and rapid determination of the desensitized data element.

[0074] According to one embodiment of the present application, the first data is 1479, which includes four numeric characters: '1', '5', '7', and '8'. Each numeric character has no specific meaning in the corresponding position, so each numeric character is separated as a data element. When desensitizing the data element '5', it is used as the target data element, and the numeric character dictionary corresponding to the numeric character is determined as follows:

[0075] { '1', '3', '5', '8', '9', '0', '2', '6', '7', '4'}

[0076] Then, the position of the digital character '5' in the digital character dictionary is determined, that is, the first storage position is the third position; if the offset is 3, the first storage position and the offset are added to obtain the second storage position, which is the sixth position, and then the digital character '0' is obtained from the digital character dictionary according to the second storage position as the desensitized data element.

[0077] According to one embodiment of the present application, when determining the storage location of a target data element in a target data dictionary, the target data dictionary is traversed to determine its location. The storage location of the target data element in the target data dictionary can also be determined based on a dictionary index. The dictionary index stores an index value that represents the order in which the data element is arranged in the target data dictionary. Using the index value allows the storage location to be determined from the target data dictionary in a single step, improving the efficiency of determining the storage location.

[0078] According to one embodiment of the present application, the digital character dictionary corresponding to the digital character is:

[0079] { '1', '3', '5', '8', '9', '0', '2', '6', '7', '4'}

[0080] The dictionary index into the numeric character dictionary is:

[0081] {5, 0, 6, 1, 9, 2, 7, 8, 3, 4}

[0082] The numeric character dictionary can be stored in the form of an array. When the array starts counting from 0, the numeric character '1' is stored at position [0] and the numeric character '5' is stored at position [2]. Each digit in the numeric character dictionary represents the storage position of the 10 numeric characters 0-9 in the numeric character dictionary. For example, 5 indicates that the numeric character '0' is stored at position [5] of the numeric character dictionary, 0 indicates that the numeric character '1' is stored at position [0] of the numeric character dictionary, and so on. 4 indicates that the numeric character '9' is stored at position [4] of the numeric character dictionary. Therefore, the storage position of a data element in the target data dictionary can be quickly determined based on the dictionary index.

[0083] According to one embodiment of the present application, if a first value determined based on the first storage location and the offset is greater than the data dictionary length, a second value is determined based on the first value and the data dictionary length, where the second value is less than or equal to the data dictionary length; and a second storage location is determined based on the second value. This allows data elements in the data dictionary to be recycled, i.e., the data dictionary is implemented as a circular array.

[0084] When the first value determined by adding the first storage position and the offset is greater than the target data dictionary length, the first value is modulo operation performed according to the target data dictionary length; if the target data dictionary length is 10, the first storage position is the 8th, and the offset is 36, then the first value obtained by adding the first storage position and the offset is 44, which exceeds the target data dictionary length, and the first value is modulo operation performed according to the target data dictionary length to obtain the second value: 4; the second value is less than the target data dictionary length, and the 4th is used as the second storage position.

[0085] Subsequently, operation 230 is executed to generate second data based on the desensitized data element. In operation 230, the target data element is replaced with the desensitized data element based on its position in the first data, thereby obtaining the second data. The position of the target data element in the first data is the same as the position of the desensitized data element in the second data, ensuring that the data structure is not changed. After obtaining the second data, the data acquirer can process the desensitized second data normally.

[0086] According to one embodiment of the present application, the data processing method further includes: in response to a data restoration request, determining a negative offset based on the inverse of the offset; and modifying the second data based on the storage location of the desensitized data element in the target data dictionary and the negative offset to obtain the first data. By setting the negative offset, the second data can be quickly restored, making data restoration simple and convenient.

[0087] According to one embodiment of the present application, the data acquisition request may come from a requesting party with permission to obtain the original data. After receiving the data acquisition request, the opposite number of the offset, that is, the negative offset, may be determined to modify the second data to the first data.

[0088] According to one embodiment of the present application, the desensitized data element that currently needs to be restored in the second data is the digital character '0', and the offset when obtaining the second data is 3, then the negative offset when restoring the second data is -3, according to the second storage position of the digital character '0' in the digital character dictionary: the sixth position, and the negative offset, it can be determined that the storage position of the target data element is the third position, and the digital character '5' is determined as the target data element from the digital character dictionary.

[0089] According to one embodiment of the present application, the first data is "1390000000000000", and the type of the first data is a telephone number. Then, the first to third digits of the first data have a specific meaning, which is the mobile phone number area code. When the first data is divided, the first to third digits: '139', are separated from the first data as a data element. When '139' is processed as a target data element, its corresponding target data dictionary is first determined to be a mobile phone number area code dictionary, including:

[0090] {'138', '183', '158', '177', '135', '159', '187', '185', '189', '147', '166', '178', '151', '182', '155', '133', '173', '153', '156', '198', '181', '188', '176', '180', '137', '134', '152', '145', '199', '149', '130', '186', '150', '157', '175', '136', '139', '131', '132'}

[0091] The offset is then determined. According to one embodiment, when determining the offset, a pre-set desensitizing key is obtained; the offset is determined based on the desensitizing key. By setting the key, the offset can be flexibly set, improving the configurability of the data desensitization process. When determining the offset based on the desensitizing key, a hash value of the desensitizing key can be determined based on a pre-set and maintained hash table, and the offset can be calculated.

[0092] According to one embodiment, when the desensitizing key is uiiuioo, the hash value 31159 can be determined, and then a modulo operation is performed on 100000 based on the hash value 31159, and the maximum prime number is taken to obtain 31159 as the offset; taking the prime number can reduce data coupling.

[0093] According to one embodiment, after taking the maximum prime number, the maximum prime number may be added to the character length of the first data to be processed to obtain the offset.

[0094] According to one embodiment, an offset array may be provided, in which a plurality of offsets are stored, and a negative offset array may be provided, in which a negative offset corresponding to each offset is stored. The negative offset array is used to extract the negative offset for restoring the second data to the first data.

[0095] According to one embodiment, a hash value is determined, and a modulus operation is performed on a modulus (such as 100000) according to the hash value to obtain a maximum prime number; the maximum prime number is added to the character length of the first data to be processed, and then a modulus operation is performed on the length of the offset array to obtain the position of the offset in the offset array, and the offset is extracted from the offset array based on the position.

[0096] If the offset array is all prime numbers or several prime numbers within 100, such as: {59, 67, 11, 71}, if the position of the offset in the offset array is [2], then 11 is determined as the offset based on this position.

[0097] According to one embodiment, when '139' is determined as the target data element to be processed, if the offset is 11, the desensitized data element can be determined to be '189' according to the mobile phone number area code dictionary.

[0098] According to the data processing method of the present application, data can be transformed and processed under the premise of ensuring the integrity, validity and authenticity of the data, providing convenience for data security sharing, and also supporting data restoration.

[0099] Based on the above data processing method, this application also provides a data processing device. Figure 4 The device is described in detail. Figure 4 The structural block diagram of a data processing device according to an embodiment of the present application is schematically shown.

[0100] like Figure 4 As shown, the data processing device 400 of this embodiment includes a data dictionary module 410 , a desensitized data element determination module 420 and a desensitized data generation module 430 .

[0101] Data dictionary module 410 is configured to determine a target data dictionary from a plurality of different data dictionaries based on the type of the target data element in the first data. The data dictionary includes a plurality of data elements, each of which is obtained by segmenting the data. In one embodiment, data dictionary module 410 may be configured to perform operation 310 described above, and will not be further described herein.

[0102] The desensitized data element determination module 420 is used to determine the desensitized data element according to the storage location and offset of the target data element in the target data dictionary. In one embodiment, the desensitized data element determination module 420 can be used to perform the operation 330 described above, which will not be repeated here.

[0103] The desensitized data generating module 430 is used to generate the second data according to the desensitized data element. In one embodiment, the desensitized data generating module 430 can be used to perform the operation 330 described above, which will not be described in detail here.

[0104] According to an embodiment of the present application, any multiple modules among the data dictionary module 410, the desensitized data element determination module 420, and the desensitized data generation module 430 can be combined into one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present application, at least one of the data dictionary module 410, the desensitized data element determination module 420, and the desensitized data generation module 430 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or can be implemented in any one of the three implementation methods of software, hardware, and firmware, or in an appropriate combination of any of them. Alternatively, at least one of the data dictionary module 410 , the desensitized data element determination module 420 and the desensitized data generation module 430 may be at least partially implemented as a computer program module, which may perform corresponding functions when executed.

[0105] Figure 5 A block diagram of an electronic device suitable for implementing a data processing method according to an embodiment of the present application is schematically shown.

[0106] like Figure 5 As shown, an electronic device 500 according to an embodiment of the present application includes a processor 501, which can perform various appropriate actions and processes based on a program stored in a read-only memory (ROM) 502 or a program loaded from a storage unit 508 into a random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present application.

[0107] Various programs and data required for the operation of the electronic device 500 are stored in the RAM 503. The processor 501, ROM 502, and RAM 503 are connected to each other via a bus 504. The processor 501 performs various operations of the method flow according to the embodiment of the present application by executing the programs in the ROM 502 and / or RAM 503. It should be noted that the programs may also be stored in one or more memories other than the ROM 502 and the RAM 503. The processor 501 may also perform various operations of the method flow according to the embodiment of the present application by executing the programs stored in the one or more memories.

[0108] According to an embodiment of the present application, electronic device 500 may further include an input / output (I / O) interface 505, which is also connected to bus 504. Electronic device 500 may also include one or more of the following components connected to I / O interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 508 including a hard disk; and a communication section 509 including a network interface card such as a LAN card or modem. Communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to I / O interface 505 as needed. Removable media 511, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 510 as needed, so that computer programs read from the removable media can be installed into storage section 508 as needed.

[0109] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of this application is implemented.

[0110] According to an embodiment of the present application, a computer-readable storage medium may be a non-volatile computer-readable storage medium, such as, but not limited to, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present application, a computer-readable storage medium may include the ROM 502 and / or RAM 503 described above and / or one or more memories other than ROM 502 and RAM 503.

[0111] The embodiments of the present application also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the data processing method provided in the embodiments of the present application.

[0112] The computer program executes the above functions defined in the system / device of the embodiment of the present application when the computer program is executed by the processor 501. According to the embodiment of the present application, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0113] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 509, and / or installed from a removable medium 511. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0114] In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 509, and / or installed from the removable medium 511. When the computer program is executed by the processor 501, the above-mentioned functions defined in the system of the embodiment of the present application are performed. According to the embodiment of the present application, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0115] According to an embodiment of the present application, the program code for executing the computer program provided by the embodiment of the present application can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0116] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0117] Those skilled in the art will appreciate that the features described in the various embodiments of this application may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in this application. In particular, the features described in the various embodiments of this application may be combined and / or coupled in various ways without departing from the spirit and teachings of this application. All such combinations and / or couplings fall within the scope of this application.

Claims

1. A data processing method, comprising: determining a target data dictionary from a plurality of different data dictionaries according to a type of a target data element in the first data, the data dictionary including a plurality of data elements obtained by segmenting the data; Determine the desensitized data element according to the storage position and offset of the target data element in the target data dictionary; Generate second data based on the desensitized data element.

2. The method of claim 1 , wherein determining the target data dictionary from a plurality of different data dictionaries based on the type of the target data element in the first data comprises: The corresponding target data dictionary is determined according to the character type or meaning type of the target data element, where the meaning type is the meaning of the target data element at the corresponding position in the first data.

3. The method of claim 1 , further comprising: In response to a data restoration request, determining a negative offset according to the inverse of the offset; The second data is modified according to the storage position and negative offset of the desensitized data element in the target data dictionary to obtain the first data.

4. The method according to claim 1, wherein determining the data dictionary according to the type of the target data element in the first data comprises: In a case where the type of the target data element is a number and it is the first data element in the first data, a target data dictionary including non-zero integers is determined.

5. The method according to any one of claims 1 to 4, wherein the storage location of the target data element in the data dictionary is a first storage location, and determining the desensitized data element based on the storage location and offset of the target data element in the target data dictionary comprises: Determine a second storage location of the desensitized data element in the target data dictionary according to the first storage location and the offset; Determine a desensitized data element from the target data dictionary based on the second storage location.

6. The method of claim 5, wherein determining, based on the first storage location and the offset, that the desensitized data element is desensitized at the second storage location of the target data dictionary comprises: In a case where a first value determined according to the first storage location and the offset is greater than a target data dictionary length, determining a second value according to the first value and the digital dictionary length, the second value being less than or equal to the target data dictionary length; The second storage location is determined according to the second value.

7. The method according to any one of claims 1 to 4, further comprising: The storage location of the target data element in the target data dictionary is determined according to a dictionary index, wherein the dictionary index stores an index value representing an arrangement order of the data element in the target data dictionary.

8. The method according to any one of claims 1 to 4, further comprising: Get the set desensitization key; The offset is determined according to the desensitizing key.

9. The method according to any one of claims 1 to 4, wherein generating second data according to the desensitized data element comprises: The target data element is replaced with the desensitized data element according to the position of the target data element in the first data to obtain second data.

10. A data processing device, comprising: a data dictionary module, configured to determine a target data dictionary from a plurality of different data dictionaries according to a type of a target data element in the first data, wherein the data dictionary includes a plurality of data elements obtained by segmenting the data; a desensitized data element determination module, configured to determine the desensitized data element according to the storage position and offset of the target data element in the target data dictionary; The desensitized data generation module is used to generate second data based on the desensitized data elements.

11. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.

13. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.