Interface data desensitization method and device based on dynamic strategy engine and electronic equipment
Through the interface data desensitization method of the dynamic policy engine, the hot update mechanism and multi-layer detection model are used to solve the business interruption problem of the traditional desensitization system during policy updates, and realize the flexibility and real-time response capability of the system.
Patent Information
- Application Number
- CN202510937569.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-03
AI Technical Summary
The existing desensitization system needs to restart the service when the policy is updated, resulting in business continuity interruption and making it difficult to adapt to interface data scenarios with high real-time requirements.
An interface data desensitization method based on a dynamic policy engine is adopted. The hot update mechanism is supported by a preset policy decision engine, and the changed data processing strategy is dynamically loaded. The secondary cache mechanism and multi-layer detection model are used to identify and desensitize sensitive data, and parallel processing is achieved in combination with a lock-free circular queue.
It effectively avoids service restart issues caused by policy updates, ensures that the system can respond to policy changes in real time during runtime, improves the system's flexibility and response efficiency, and ensures that desensitization rules are iterated synchronously with business needs.
Smart Images

Figure CN120744978A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and in particular to an interface data desensitization method, device and electronic device based on a dynamic policy engine. Background Art
[0002] With the widespread adoption of big data and cloud services, cloud migration and data sharing have become mainstream trends. The increasing complexity of data usage scenarios has led to a heightened risk of privacy leaks. When providing external data through interfaces, sensitive information (such as identity data, mobile phone numbers, and bank card numbers) must be distorted or masked to comply with privacy protection regulations.
[0003] In related technologies, the desensitizing system needs to restart the service when the policy is updated, resulting in interruption of business continuity, making it difficult for the desensitizing system to adapt to interface data scenarios with high real-time requirements. Summary of the Invention
[0004] In order to solve or partially solve the problems existing in the related technologies, the present application provides an interface data desensitization method, device and electronic device based on a dynamic policy engine, which can enable the system to dynamically load the changed data processing strategy during operation, effectively avoiding the service restart problem caused by policy updates in traditional solutions, and improving system flexibility.
[0005] The first aspect of the present application provides an interface data desensitization method based on a dynamic policy engine, comprising: Get the interface data to be processed; The preset policy execution engine obtains the data processing policy from the preset policy decision engine, and performs corresponding data desensitization processing on the interface data to be processed according to the data processing policy to obtain the desensitized target interface data; wherein, the preset policy decision engine is configured to hot update the corresponding data processing policy according to the input policy change data.
[0006] In some embodiments, the preset policy decision engine updates the data processing policy in the following manner, including: A policy change request is received, incremental policy data in the input policy change data is obtained, and a data processing policy stored in a preset policy decision engine is hot-updated according to the incremental policy data.
[0007] In some embodiments, obtaining incremental policy data from the input policy change data and hot-updating the data processing policy stored in the preset policy decision engine according to the policy change data includes: Decompose the input policy change data into atomic rule units and obtain the change nodes corresponding to the incremental policy data; Incremental bytecode is generated according to the changed node, and the incremental bytecode is injected into the running environment of the data processing strategy in the preset strategy decision engine based on a preset dynamic modification method.
[0008] In some embodiments, the data processing strategy of the preset policy decision engine is stored using a secondary cache mechanism; wherein, the secondary cache mechanism includes a first cache layer and a second cache layer; the first cache layer is used to cache the bytecode data of the hotspot strategy, and the second cache layer is used to cache the policy package data of the versioned strategy.
[0009] In some embodiments, performing corresponding data desensitization processing on the interface data to be processed according to the data processing strategy to obtain desensitized target interface data includes: According to the identification scope in the data processing strategy, a corresponding sensitive data identification operation is performed on the interface data to be processed through a preset multi-layer detection model to obtain the desensitized data to be processed; wherein the preset multi-layer detection model includes at least: a static rule matching layer, a field semantic feature analysis layer, and a dynamic named entity recognition layer; According to the desensitization strategy in the data processing strategy, corresponding sensitive data processing operations are performed on the desensitized data to be processed through a preset parallel execution pipeline to obtain desensitized target interface data.
[0010] In some embodiments, performing corresponding sensitive data identification operations on the interface data to be processed by using a preset multi-layer detection model to obtain desensitized data to be processed includes: Performing a first recognition process on the interface data to be processed according to a preset static rule matching layer to obtain a first recognition result; Performing a second recognition process on the interface data to be processed according to the first recognition result and a preset field semantic feature analysis layer to obtain a second recognition result; Performing a third recognition process on the interface data to be processed according to the first recognition result, the second recognition result, and a preset dynamic named entity recognition layer to obtain a third recognition result; According to the first recognition result, the second recognition result and the third recognition result, the desensitized data to be processed is obtained from the interface data to be processed.
[0011] In some embodiments, the method of performing corresponding sensitive data processing operations on the desensitized data to be processed through a preset parallel execution pipeline according to the desensitization strategy in the data processing strategy to obtain desensitized target interface data includes: Matching and executing tasks according to the desensitized data to be processed, obtaining a set of tasks to be executed; the set of tasks to be executed includes at least one independent task; According to the preset delivery method, the set of tasks to be executed is delivered to the corresponding sensitive data processing operation of the lock-free circular queue to obtain the desensitized target interface data.
[0012] A second aspect of the present application provides an interface data desensitization device based on a dynamic policy engine, comprising: Data acquisition module, used to obtain interface data to be processed; A data processing module is used to obtain a data processing strategy from a preset strategy decision engine through a preset strategy execution engine, and perform corresponding data desensitization processing on the interface data to be processed according to the data processing strategy to obtain the desensitized target interface data; wherein, the preset strategy decision engine is configured to hot-update the corresponding data processing strategy according to the input policy change data.
[0013] A third aspect of the present application provides an electronic device, including: processor; and The memory stores executable codes thereon, and when the executable codes are executed by the processor, the processor is caused to execute the method described above.
[0014] A fourth aspect of the present application provides a computer-readable storage medium having executable code stored thereon. When the executable code is executed by a processor of an electronic device, the processor is caused to execute the method described above.
[0015] The technical solution provided by this application may have the following beneficial effects: The technical solution of the present application obtains data processing strategies from a preset strategy decision engine, wherein the strategy decision engine supports a hot update mechanism, so that the system can dynamically load the changed data processing strategies during operation, effectively avoiding the service restart problem caused by strategy updates in traditional solutions, and enabling the system to respond to strategy change data in real time, ensuring that desensitization rules are iterated synchronously with business needs, and improving system flexibility.
[0016] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The above and other objects, features and advantages of the present application will become more apparent by describing in more detail exemplary embodiments of the present application in conjunction with the accompanying drawings, wherein the same reference numerals generally represent the same components in the exemplary embodiments of the present application.
[0018] Figure 1 This is a flow chart of an interface data desensitization method based on a dynamic policy engine according to an embodiment of the present application; Figure 2This is a flow chart of updating the data processing strategy of the preset strategy decision engine in the interface data desensitization method based on the dynamic strategy engine shown in an embodiment of the present application; Figure 3 This is another flow chart of updating the data processing strategy of the preset strategy decision engine in the interface data desensitization method based on the dynamic strategy engine shown in an embodiment of the present application; Figure 4 This is another flow chart of the interface data desensitization method based on the dynamic policy engine shown in an embodiment of the present application; Figure 5 Schematic diagram of the structure of the interface data desensitization device based on the dynamic policy engine shown in an embodiment of the present application; Figure 6 It is a structural diagram of an electronic device shown in an embodiment of the present application. DETAILED DESCRIPTION
[0019] The following describes embodiments of the present application in more detail with reference to the accompanying drawings. Although the accompanying drawings illustrate embodiments of the present application, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments described herein. Rather, these embodiments are provided to make the present application more thorough and complete, and to fully convey the scope of the present application to those skilled in the art.
[0020] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. As used in this application and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0021] It should be understood that although the terms "first", "second", "third", etc. may be used in this application to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.
[0022] With the widespread adoption of big data and cloud services, cloud migration and data sharing have become mainstream trends. The increasing complexity of data usage scenarios has led to a heightened risk of privacy leaks. When providing external data through interfaces, sensitive information must be distorted or masked to comply with privacy protection regulations.
[0023] In related technologies, masking systems require service restarts when updating policies, disrupting business continuity and making them difficult to adapt to real-time interface data scenarios. For example, in financial trading systems, when new sensitive data formats need to be detected, traditional masking systems require maintenance downtime to load the new policies. This can easily lead to transaction backlogs or interruptions.
[0024] To address the above problems, an embodiment of the present application provides an interface data desensitization method based on a dynamic policy engine, which enables the system to dynamically load the changed data processing strategy during runtime, effectively avoiding the service restart problem caused by policy updates in traditional solutions and improving system flexibility.
[0025] The technical solutions of the embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0026] Figure 1 This is a flow chart of the interface data desensitization method based on the dynamic policy engine shown in an embodiment of the present application.
[0027] See also Figure 1 The interface data desensitization method based on the dynamic policy engine of this application includes: S110: Obtain interface data to be processed.
[0028] The interface data to be processed may be an interface data stream input from an interface. The interface data to be processed may include, but is not limited to, data in one of the formats of JSON and XML.
[0029] S120, obtain the data processing strategy from the preset strategy decision engine through the preset strategy execution engine, and perform corresponding data desensitization processing on the interface data to be processed according to the data processing strategy to obtain the desensitized target interface data; wherein, the preset strategy decision engine is configured to hot-update the corresponding data processing strategy according to the input strategy change data.
[0030] The preset policy execution engine may refer to a policy execution unit independent of the business system. The preset policy execution engine may be implemented as an independent container in a microservice architecture, responsible for receiving policy instructions issued by the policy decision engine and executing data operations.
[0031] The preset policy decision engine may refer to a policy management center that supports dynamic updates. The preset policy decision engine may be implemented using a Java virtual machine that supports hot replacement of bytecodes.
[0032] Among them, the preset strategy execution engine and the preset strategy decision engine are decoupled through the event bus.
[0033] The data processing policy process corresponding to the hot update may refer to updating policy content without interrupting service.
[0034] In this application, when the interface data to be processed is received, a policy query request is initiated to the preset policy decision engine through the preset policy execution engine. The preset policy decision engine returns the currently effective data processing policy version, where the returned data processing policy may include the policy content after the latest hot update. The preset policy execution engine performs data desensitization processing on the interface data to be processed, including but not limited to sensitive data identification and sensitive data desensitization, based on the sensitive data identification rules and desensitization processing rules defined in the data processing policy, and finally obtains the desensitized target interface data.
[0035] Upon receiving a policy change request, the pre-set policy decision engine uses class redefinition technology to inject the new policy into the running virtual machine based on the input policy change data, creating a new policy version. The execution engine automatically retrieves the updated policy version the next time the policy is invoked, without stopping services or redeploying applications.
[0036] It should be understood that the desensitized target interface data includes the data portion that needs to be desensitized and the data portion that does not need to be desensitized.
[0037] Among them, in the method of the present application, the data part that needs to be desensitized in the interface data to be processed can be identified first according to the data processing strategy, and then the data part that needs to be desensitized is desensitized, and then the data part that has been desensitized is integrated with the data part that does not need to be desensitized to obtain the final desensitized target interface data.
[0038] In this embodiment, the interface data desensitization method based on the dynamic policy engine of the present application obtains the data processing policy from the preset policy decision engine, wherein the preset policy decision engine supports a hot update mechanism. The hot update mechanism ensures that the policy change process of the preset policy decision engine does not affect the system's execution of the desensitization task, so that the system can dynamically load the changed data processing policy during operation, effectively avoiding the service restart problem caused by policy updates in traditional solutions, and enabling the system to respond to policy change data in real time, ensuring that the desensitization rules are iterated synchronously with business needs, and improving system flexibility.
[0039] Figure 2 This is a flow chart of the preset policy decision engine updating the data processing policy in the interface data desensitization method based on the dynamic policy engine shown in the embodiment of the present application. Figure 1 Based on the illustrated embodiment, the data processing strategy updating process of the preset strategy decision engine in this application is further explained.
[0040] See also Figure 2 , the preset policy decision engine of this application can update the data processing policy in the following ways, including: S210: Receive a policy change request.
[0041] The policy change request may be sent by a user in a front-end application.
[0042] S220 , obtaining incremental policy data from the input policy change data, and hot-updating the data processing policy stored in the preset policy decision engine according to the incremental policy data.
[0043] The policy change data may be input in the form of a hot patch file.
[0044] The incremental policy data may refer to the policy data of the portion that needs to be changed carried in the policy change data. The incremental policy data may be obtained by extracting the policy difference portion before and after the change by comparing data differences.
[0045] It should be understood that hot update can refer to dynamically loading new policy requirements without interrupting system operation. Hot update can be achieved through dynamic class loading mechanism or memory replacement technology in related technologies.
[0046] In this embodiment, the interface data desensitization method based on the dynamic policy engine of the present application adopts an incremental hot update method to dynamically replace only the parts of the data processing policy that need to be changed, completes the policy upgrade while maintaining the continuous operation of the service, effectively solves the problem of business interruption, and compared with the full data update method, can effectively reduce resource consumption and improve response efficiency.
[0047] Figure 3 This is another flow chart of updating the data processing strategy of the preset strategy decision engine in the interface data desensitization method based on the dynamic strategy engine shown in the embodiment of the present application. Figure 2 Based on the illustrated embodiment, the data processing strategy updating process of the preset strategy decision engine in this application is further explained.
[0048] See also Figure 3 , the preset policy decision engine of this application can update the data processing policy in the following ways, including: S310: Receive a policy change request.
[0049] S320 , decomposing the input policy change data into atomic rule units to obtain change nodes corresponding to the incremental policy data.
[0050] The atomic rule unit refers to the smallest indivisible policy logic unit. The input policy change data can be decomposed into the smallest independently changeable operation unit using regular expression matching or syntax tree parsing. After comparing the difference with the current version of the data processing policy, the corresponding change node of the incremental policy data is determined.
[0051] It should be understood that during the difference comparison process, the data processing strategy of the current version needs to be decomposed into independently changeable minimum operation units (such as syntax trees) in the same way, so as to achieve rapid positioning through difference nodes.
[0052] S330, generating incremental bytecode according to the changed node, and injecting the incremental bytecode into the running environment of the data processing strategy in the preset strategy decision engine based on the preset dynamic modification method.
[0053] Among them, incremental bytecode can refer to the compiled instruction fragment that only contains the policy change logic. Among them, using incremental bytecode to implement policy data changes has higher execution efficiency than traditional configuration file update methods. The incremental bytecode can be generated by using a Java compiler or an ASM bytecode operation framework.
[0054] Among them, the preset dynamic modification method can realize the technology of modifying the loaded class bytecode in real time without affecting the system operation.
[0055] Among them, the preset dynamic modification method can be implemented using one of the Java Instrumentation API and the JVM TI tool interface, so that the incremental bytecode can be injected into the running environment of the preset policy decision engine through the preset hot deployment method, ensuring that the updated policy can take effect without restarting the service.
[0056] Among them, after completing the incremental bytecode injection, the dependency graph corresponding to the data processing strategy in the preset strategy decision engine can also be updated to ensure that the subsequent preset strategy execution engine can execute the strategy according to the updated dependency graph.
[0057] Among them, the data processing strategy of the preset policy decision engine can be stored using a secondary cache mechanism; wherein, the secondary cache mechanism includes a first cache layer and a second cache layer; the first cache layer is used to cache the bytecode data of the hot spot strategy, and the second cache layer is used to cache the policy package data of the versioned strategy.
[0058] It can be understood that the first cache layer can be used to store hot update strategies that have been compiled into bytecodes and other strategy data with high-frequency update requirements, to support fast reading and replacement operations of strategy data; the second cache layer can be used to store a persistent storage area for strategy sets divided by version, to provide a version isolation mechanism to retain historical strategy states, so that version rollback and multi-version coexistence can be supported. By separating high-frequency update strategy data from versioned strategy data, the strategy changes in this application can take effect without restarting the service, and at the same time retain the complete version of historical strategy data, which can meet the real-time requirements of high-frequency strategy modifications and ensure the controllability and traceability of strategy versions. In this embodiment, this solution atomically breaks down policy changes and replaces only the bytecode of the smallest affected logical units. This reduces the system resource usage of policy updates to a localized level while maintaining service continuity. For example, when only the phone number desensitization rules need to be modified, traditional solutions require reloading the entire policy and restarting the system. However, this solution only replaces the class methods related to phone number processing, while other policy logic continues to operate normally.
[0059] Through the above technical solution, the interface data desensitization method based on the dynamic policy engine of the present application, by atomically disassembling the policy update content and using the smallest logical unit for bytecode replacement, can reduce the system resource occupation of the policy content that needs to be updated to a local range while maintaining the continuity of system services. For example, when only the mobile phone number desensitization rules need to be modified, only the class methods related to mobile phone number processing are replaced, and other policy logics maintain normal operation. It can effectively realize the dynamic hot update capability of the data processing strategy, complete the policy change operation during the continuous processing of interface data, and effectively avoid the business interruption problem caused by the need to restart the service when updating the strategy in the traditional solution.
[0060] Figure 4 This is another flow chart of the interface data desensitization method based on the dynamic policy engine shown in the embodiment of the present application. Figure 1 The embodiment shown is further described.
[0061] The interface data desensitization method based on the dynamic policy engine of this application includes: S410: Obtain interface data to be processed.
[0062] S420: Obtain the data processing strategy from the preset strategy decision engine via the preset strategy execution engine.
[0063] The data processing policy obtained from the preset policy decision engine may include the identification scope of the corresponding sensitive data and the desensitization policy of the corresponding sensitive data. It should be understood that the data processing policy may limit the type of sensitive data and limit the different types of sensitive data.
[0064] S430, according to the identification scope in the data processing strategy, performs corresponding sensitive data identification operations on the interface data to be processed through a preset multi-layer detection model to obtain desensitized data to be processed; wherein the preset multi-layer detection model includes at least: a static rule matching layer, a field semantic feature analysis layer, and a dynamic named entity recognition layer.
[0065] The static rule matching layer can refer to a sensitive data identification layer that performs pattern recognition based on predefined regular expressions or keyword lists. The static rule matching layer can be implemented using a regular expression engine combined with a sensitive field dictionary to quickly locate sensitive information within interface data that conforms to a fixed format. The static rule matching layer can also include a pre-configured data identification template library based on common sensitive data types.
[0066] For example, the static rule matching layer presets 10+ types of regular template libraries (such as ID card numbers and bank card numbers) to cover common sensitive data types.
[0067] The field semantic feature analysis layer can refer to a sensitive data identification layer that mines and identifies potentially sensitive information through contextual semantic relevance calculations. This layer can be implemented using a neural network model based on an attention mechanism to identify sensitive data fields that have no fixed format but possess sensitive semantic features. This layer can identify deformed field data that the static rule matching layer cannot, such as identifying the "card_num" field, which is equivalent to the "user_bank_card" field.
[0068] For example, the field semantic feature analysis layer can detect that the "identifier" field value matches the characteristics of an ID card number (18 digits + check digit). Another example is that the field semantic feature analysis layer can determine that the "phone" field is equivalent to the preset "mobile" field based on the cosine similarity of 0.87 between the two field names.
[0069] The dynamic named entity recognition layer can refer to a sensitive data identification layer that uses real-time data distribution characteristics to identify entity types. This layer can be implemented using a transfer learning-based entity recognition algorithm to capture sensitive information in complex business scenarios. For example, named entity recognition (NER) detection can be implemented based on a natural language processing (NLP) model to identify private fields within nested JSON.
[0070] For example, the dynamic named entity recognition layer can predict the field "622848199909097890" as "ID card number" (with a 99.2% probability). Another example is that the dynamic named entity recognition layer can predict the field "13887658000" as "mobile phone number" (with a 98.5% probability).
[0071] Among them, the static rule matching layer, field semantic feature analysis layer and dynamic named entity recognition layer in the preset multi-layer detection model can work synchronously or in an associated progressive recognition manner.
[0072] For example, when interface data to be processed is input into the desensitizing system, it first undergoes preliminary screening through the static rule matching layer, using regular expressions to match fixed-format data such as ID card numbers and bank card numbers. Unmatched data enters the field semantic feature analysis layer, which analyzes the semantic relevance of field contexts, such as identifying administrative division codes implicit in address fields. Finally, the dynamic named entity recognition layer captures sensitive entities in unstructured text, such as identifying "contact" field values that are equivalent to mobile phone number patterns.
[0073] In some embodiments, performing corresponding sensitive data identification operations on the interface data to be processed using a preset multi-layer detection model may include the following steps: S431 , performing a first recognition process on the interface data to be processed according to a preset static rule matching layer to obtain a first recognition result.
[0074] S432 , performing a second recognition process on the interface data to be processed according to the first recognition result and a preset field semantic feature analysis layer to obtain a second recognition result.
[0075] S433 , performing a third recognition process on the interface data to be processed according to the first recognition result, the second recognition result, and a preset dynamic named entity recognition layer to obtain a third recognition result.
[0076] S434, obtaining the desensitized data to be processed from the interface data to be processed according to the first recognition result, the second recognition result, and the third recognition result.
[0077] It is understood that the three data recognition layers in the pre-defined multi-layer detection model of this application—the static rule matching layer, the field semantic feature analysis layer, and the dynamic named entity recognition layer—can operate in a progressive manner to form a complementary detection mechanism. The static rule matching layer performs a preliminary screening of explicit sensitive fields in the interface data, for example, by matching the fixed format of ID card numbers or bank card numbers using regular expressions. The field semantic feature analysis layer, based on the initial recognition results (i.e., after the static rule matching layer's recognition processing), further combines the contextual semantics of the field name and adjacent data items to identify fields such as "user ID" and "contact information" that are not explicitly labeled but have sensitive attributes. The dynamic named entity recognition layer then uses the results of the first two recognitions to detect unstructured sensitive information such as names and addresses hidden in the text. The results of the three detection layers are then combined to form the final desensitized dataset through a union operation. Static rule matching ensures rapid capture of basic sensitive fields, semantic analysis enhances adaptability to business scenarios, and dynamic entity recognition resolves the fuzzy boundaries of complex text.
[0078] S440: According to the desensitization strategy in the data processing strategy, corresponding sensitive data processing operations are performed on the desensitized data to be processed through a preset parallel execution pipeline to obtain desensitized target interface data.
[0079] The preset parallel execution pipeline may refer to a computing architecture that supports concurrent multi-tasking. The preset parallel execution pipeline may be implemented using a lock-free circular queue, and the preset parallel execution pipeline may be used to split the desensitization task into independently executable atomic operation units.
[0080] Among them, the desensitized data to be processed output after identification by the preset multi-layer detection model is split into independent task units. For example, the desensitization operations of different fields are split into independent thread tasks, and multi-threaded parallel processing is realized through a lock-free circular queue. For example, a hash sharding mechanism is used to evenly distribute tasks to different processing nodes, and finally the processing results are integrated through an asynchronous aggregation mechanism.
[0081] In some embodiments, performing corresponding sensitive data processing operations on the desensitized data to be processed through a preset parallel execution pipeline may include the following steps: S441, matching and executing tasks according to the desensitized data to be processed to obtain a set of tasks to be executed; the set of tasks to be executed includes at least one independent task.
[0082] The "to-be-executed task set" may refer to a set of independently executable task units that split the desensitized data to be processed. It should be understood that different desensitized data types can be matched with different execution tasks, and the execution tasks may include, but are not limited to, at least one of regular expression replacement, encryption, and format conversion.
[0083] S442: Deliver the set of tasks to be executed to the corresponding sensitive data processing operation of the lock-free circular queue according to the preset delivery method to obtain the desensitized target interface data.
[0084] A lock-free circular queue refers to a lock-free concurrent data structure implemented based on a circular array structure. As can be understood, a lock-free circular queue enables non-blocking access between producer and consumer threads through atomic pointer operations, avoiding the thread suspension and context switching overhead associated with traditional locking mechanisms. Because independent tasks lack data dependencies, the use of a lock-free circular queue allows for full parallelization of their processing.
[0085] The preset delivery method may refer to a distribution strategy for distributing a set of tasks to be executed to a lock-free circular queue.
[0086] Among them, the preset delivery method can be implemented by polling allocation or consistent hashing algorithm.
[0087] Sensitive data processing operations may include regular substitution, encryption, and semantic deformation, or a combination of two or more. After sensitive data processing operations are completed, each thread can write the results to a pre-set shared memory area, and ultimately merge them into the complete target interface data through an asynchronous aggregation mechanism. Asynchronous aggregation can refer to the integration of parallel processing results through a non-blocking task scheduling mechanism. This allows the result collection action to be triggered immediately after each independent task is processed, without waiting for other tasks to complete.
[0088] In this embodiment, the interface data desensitization method based on the dynamic policy engine of the present application sets up a static rule matching layer, a field semantic feature analysis layer and a dynamic named entity recognition layer that run in a progressive manner to identify the interface data to be processed, achieving full coverage from explicit rules to implicit semantics, from structured fields to unstructured text, thereby forming a complementary detection mechanism, effectively improving the accuracy of sensitive data identification, and at the same time setting up a parallel execution pipeline to realize task distribution through a lock-free circular queue, which can effectively avoid thread blocking problems, ensure the low latency characteristics of the task scheduling process, and ensure the execution efficiency of the desensitization operation; through the above-mentioned identification mechanism and task distribution execution mechanism, the two work together to enable the system to adapt to high concurrency and multi-change real-time data processing needs while maintaining business continuity.
[0089] Corresponding to the aforementioned application function implementation method embodiment, the present application also provides an interface data desensitization device, electronic device and corresponding embodiments based on a dynamic policy engine.
[0090] Figure 5 It is a structural diagram of an interface data desensitization device based on a dynamic policy engine shown in an embodiment of the present application.
[0091] See also Figure 5 The interface data desensitization device 500 based on the dynamic policy engine of the present application includes: a data acquisition module 510 and a data processing module 520.
[0092] The data acquisition module 510 is used to acquire the interface data to be processed.
[0093] The data processing module 520 is used to obtain the data processing strategy from the preset strategy decision engine through the preset strategy execution engine, and perform corresponding data desensitization processing on the interface data to be processed according to the data processing strategy to obtain the desensitized target interface data; wherein, the preset strategy decision engine is configured to hot-update the corresponding data processing strategy according to the input policy change data.
[0094] In some embodiments, the preset policy decision engine updates the data processing policy in the following manner, including: the data processing module 520 receives a policy change request, obtains incremental policy data in the input policy change data, and hot updates the data processing policy stored in the preset policy decision engine based on the incremental policy data.
[0095] In some embodiments, the data processing module 520 can decompose the input policy change data into atomic rule units to obtain the change nodes corresponding to the incremental policy data; generate incremental bytecode according to the change nodes, and inject the incremental bytecode into the operating environment of the data processing strategy in the preset policy decision engine based on a preset dynamic modification method.
[0096] In some embodiments, the data processing strategy of the preset policy decision engine is stored using a secondary cache mechanism; wherein the secondary cache mechanism includes a first cache layer and a second cache layer; the first cache layer is used to cache the bytecode data of the hotspot strategy, and the second cache layer is used to cache the policy package data of the versioned strategy.
[0097] In some embodiments, the data processing module 520 can perform corresponding sensitive data identification operations on the interface data to be processed through a preset multi-layer detection model according to the identification scope in the data processing strategy, and obtain desensitized data to be processed; wherein the preset multi-layer detection model at least includes: a static rule matching layer, a field semantic feature analysis layer, and a dynamic named entity recognition layer; according to the desensitization strategy in the data processing strategy, the corresponding sensitive data processing operations are performed on the desensitized data to be processed through a preset parallel execution pipeline to obtain the desensitized target interface data.
[0098] In some embodiments, the data processing module 520 can perform a first recognition process on the interface data to be processed according to a preset static rule matching layer to obtain a first recognition result; perform a second recognition process on the interface data to be processed according to the first recognition result and a preset field semantic feature analysis layer to obtain a second recognition result; perform a third recognition process on the interface data to be processed according to the first recognition result, the second recognition result and a preset dynamic named entity recognition layer to obtain a third recognition result; obtain the desensitized data to be processed from the interface data to be processed based on the first recognition result, the second recognition result and the third recognition result.
[0099] In some embodiments, the data processing module 520 may match the execution tasks according to the desensitized data to be processed to obtain a set of tasks to be executed; the set of tasks to be executed includes at least one independent task; According to the preset delivery method, the set of tasks to be executed is delivered to the corresponding sensitive data processing operation of the lock-free circular queue to obtain the desensitized target interface data.
[0100] In this embodiment, the interface data desensitization device based on the dynamic policy engine of the present application obtains the data processing policy from the preset policy decision engine, wherein the policy decision engine supports a hot update mechanism, so that the system can dynamically load the changed data processing policy during operation, effectively avoiding the service restart problem caused by policy updates in traditional solutions, and enabling the system to respond to policy change data in real time, ensuring that the desensitization rules are iterated synchronously with business needs, and improving system flexibility.
[0101] Regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated again here.
[0102] Figure 6 It is a structural diagram of an electronic device shown in an embodiment of the present application.
[0103] See also Figure 6 , the electronic device 1000 includes a memory 1010 and a processor 1020.
[0104] The processor 1020 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0105] Memory 1010 may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage. ROM may store static data or instructions required by processor 1020 or other computer modules. Permanent storage may be a readable and writable storage device. Permanent storage may be a non-volatile storage device that retains stored instructions and data even when the computer is powered off. In some embodiments, the permanent storage device utilizes a mass storage device (e.g., a magnetic or optical disk, flash memory). In other embodiments, the permanent storage device may be a removable storage device (e.g., a floppy disk, optical drive). System memory may be a readable and writable storage device or a volatile readable and writable storage device, such as dynamic random access memory (DRAM). System memory may store some or all instructions and data required by the processor during operation. Furthermore, memory 1010 may include any combination of computer-readable storage media, including various types of semiconductor memory chips (e.g., DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), as well as magnetic disks and / or optical disks. In some embodiments, the memory 1010 may include a readable and / or writable removable storage device, such as a compact disc (CD), a read-only digital versatile disc (e.g., DVD-ROM, double-layer DVD-ROM), a read-only Blu-ray disc, an ultra-density optical disc, a flash memory card (e.g., SD card, mini SD card, Micro-SD card, etc.), a magnetic floppy disk, etc. Computer-readable storage media do not include carrier waves and transient electronic signals transmitted wirelessly or wired.
[0106] The memory 1010 stores executable codes. When the executable codes are processed by the processor 1020 , the processor 1020 may execute part or all of the above-mentioned methods.
[0107] In addition, the method according to the present application may also be implemented as a computer program or a computer program product, which includes computer program code instructions for executing some or all of the steps in the above method of the present application.
[0108] Alternatively, the present application can also be implemented as a computer-readable storage medium (or non-transitory machine-readable storage medium or machine-readable storage medium) on which executable code (or computer program or computer instruction code) is stored. When the executable code (or computer program or computer instruction code) is executed by a processor of an electronic device (or server, etc.), the processor executes part or all of the steps of the above-mentioned method according to the present application.
[0109] The embodiments of the present application have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or improvements to the technology in the market, or to enable other persons skilled in the art to understand the embodiments disclosed herein.
Claims
1. An interface data desensitization method based on a dynamic policy engine, characterized in that: include: Get the interface data to be processed; The preset policy execution engine obtains the data processing policy from the preset policy decision engine, and performs corresponding data desensitization processing on the interface data to be processed according to the data processing policy to obtain the desensitized target interface data; wherein, the preset policy decision engine is configured to hot update the corresponding data processing policy according to the input policy change data.
2. The method according to claim 1, characterized in that The preset policy decision engine updates the data processing policy in the following ways, including: Receive policy change requests; Incremental policy data in the input policy change data is obtained, and a data processing policy stored in a preset policy decision engine is hot-updated according to the incremental policy data.
3. The method according to claim 2, characterized in that The step of obtaining incremental policy data from the input policy change data and hot-updating the data processing policy stored in the preset policy decision engine according to the incremental policy data includes: Decompose the input policy change data into atomic rule units and obtain the change nodes corresponding to the incremental policy data; Incremental bytecode is generated according to the changed node, and the incremental bytecode is injected into the running environment of the data processing strategy in the preset strategy decision engine based on a preset dynamic modification method.
4. The method according to claim 1, wherein The data processing strategy of the preset strategy decision engine is stored using a secondary cache mechanism; wherein, the secondary cache mechanism includes a first cache layer and a second cache layer; the first cache layer is used to cache the bytecode data of the hotspot strategy, and the second cache layer is used to cache the strategy package data of the versioned strategy.
5. The method according to claim 1, wherein The performing corresponding data desensitization processing on the interface data to be processed according to the data processing strategy to obtain the desensitized target interface data includes: According to the identification scope in the data processing strategy, a corresponding sensitive data identification operation is performed on the interface data to be processed through a preset multi-layer detection model to obtain the desensitized data to be processed; wherein the preset multi-layer detection model includes at least: a static rule matching layer, a field semantic feature analysis layer, and a dynamic named entity recognition layer; According to the desensitization strategy in the data processing strategy, corresponding sensitive data processing operations are performed on the desensitized data to be processed through a preset parallel execution pipeline to obtain desensitized target interface data.
6. The method according to claim 5, characterized in that The performing of corresponding sensitive data identification operations on the interface data to be processed by a preset multi-layer detection model to obtain desensitized data to be processed includes: Performing a first recognition process on the interface data to be processed according to a preset static rule matching layer to obtain a first recognition result; Performing a second recognition process on the interface data to be processed according to the first recognition result and a preset field semantic feature analysis layer to obtain a second recognition result; Performing a third recognition process on the interface data to be processed according to the first recognition result, the second recognition result, and a preset dynamic named entity recognition layer to obtain a third recognition result; According to the first recognition result, the second recognition result and the third recognition result, the desensitized data to be processed is obtained from the interface data to be processed.
7. The method according to claim 5, characterized in that The method of performing corresponding sensitive data processing operations on the desensitized data to be processed through a preset parallel execution pipeline to obtain desensitized target interface data includes: Matching and executing tasks according to the desensitized data to be processed, obtaining a set of tasks to be executed; the set of tasks to be executed includes at least one independent task; According to the preset delivery method, the set of tasks to be executed is delivered to the corresponding sensitive data processing operation of the lock-free circular queue to obtain the desensitized target interface data.
8. An interface data desensitization device based on a dynamic policy engine, characterized in that: include: Data acquisition module, used to obtain interface data to be processed; A data processing module is used to obtain a data processing strategy from a preset strategy decision engine through a preset strategy execution engine, and perform corresponding data desensitization processing on the interface data to be processed according to the data processing strategy to obtain the desensitized target interface data; wherein, the preset strategy decision engine is configured to hot-update the corresponding data processing strategy according to the input policy change data.
9. An electronic device, characterized in that: include: processor; as well as A memory having executable codes stored thereon, which, when executed by the processor, causes the processor to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having executable code stored thereon, characterized in that: When the executable code is executed by a processor of an electronic device, the processor is caused to perform the method according to any one of claims 1 to 7.