Log positioning method and device, computer equipment and storage medium

By using masking characters and hash algorithms to process sensitive user information in the log database, the problem of low location accuracy caused by traditional log desensitization methods is solved, and efficient and secure log problem location is achieved.

CN120909999APending Publication Date: 2025-11-07CHINA PING AN PROPERTY INSURANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510851831.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Traditional log anonymization methods prevent sensitive information in logs from being used for subsequent problem localization and analysis, resulting in low accuracy in log-based problem localization.

Method used

The target location field of sensitive user information is masked and replaced using a preset masking character, and the target hash value is calculated using a preset hash algorithm. This allows the target de-identified log file to be located in the log database, and the query is performed using the combined structure of the masking value and the hash value.

Benefits of technology

This improved the efficiency and accuracy of log-based problem location, ensuring that insurance back-office staff could quickly and accurately locate problems while meeting security and personal information protection requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120909999A_ABST
    Figure CN120909999A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of artificial intelligence and information security, and relates to a log positioning method, which comprises the following steps: obtaining user sensitive information for query; determining an information type of the user sensitive information, and determining a target position field in the user sensitive information according to the information type; carrying out covering replacement on the target position field by adopting a preset covering character to obtain a target covering value; carrying out Hash calculation on the user sensitive information by adopting a preset Hash algorithm to obtain a target Hash value; and positioning the target desensitized log file from the log library according to the target covering value and the target hash value. The invention further provides a log positioning device, computer equipment and a storage medium. The method and the device can be applied to a business management program system of financial science and technology, and can solve the problem of low accuracy of log problem positioning based on dual mechanisms of fast screening of the covering values and accurate matching of the hash values.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of artificial intelligence and information security, and is applied to the online processing business scenario of financial technology, and particularly relates to a log positioning method and device, a computer device and a storage medium. BACKGROUND

[0002] Log systems are increasingly widely used in the fields of finance and insurance, etc. However, since the logs may contain sensitive information of users, such as mobile phone numbers, ID numbers, license plate numbers, etc., in order to protect the privacy of users and meet the requirements of relevant laws and regulations, it is necessary to perform desensitization processing on the sensitive information of users in the log generation process.

[0003] However, although the traditional log desensitization method can effectively protect the privacy of users, it will cause the sensitive information in the logs to be unable to be used for subsequent problem positioning and analysis. The commonly used log desensitization method is to mask with specific characters (such as an asterisk "*"), such as masking and replacing the mobile phone number 13012345678 into 130****5678, and masking and replacing the license plate number YueA12345 into YueA*****. These log information masked with specific characters will have difficulties in daily analysis and positioning of problems. In particular, in the financial insurance system, when a customer reports a problem, the technical personnel often need to retrieve relevant logs through the sensitive information such as the mobile phone number and license plate number provided by the customer, so as to quickly position and solve the problem. However, since the sensitive information has been desensitized, the sensitive information cannot be directly used as a retrieval condition in retrieval and analysis, resulting in low accuracy of log problem positioning. SUMMARY

[0004] The purpose of the embodiments of the present application is to propose a log positioning method, device, computer device and storage medium, aiming to solve the problem of low accuracy of log problem positioning.

[0005] In a first aspect, a log positioning method is provided, which adopts the technical solution as follows:

[0006] Obtaining user sensitive information for query;

[0007] Determining the information type of the user sensitive information, and determining the target position field in the user sensitive information according to the information type;

[0008] Masking and replacing the target position field with a preset masking character to obtain a target masking value;

[0009] Performing hash calculation on the user sensitive information by using a preset hash algorithm to obtain a target hash value;

[0010] According to the target masking value and the target hash value, a target desensitization log file is located from a log library.

[0011] The log library stores a plurality of desensitization log files, and user sensitive information in the desensitization log files is represented in a combined structure of a masking value and a hash value.

[0012] In a second aspect, a log locating device is provided, which adopts the technical scheme as follows:

[0013] An information acquisition module is configured to acquire user sensitive information for query;

[0014] A position determination module is configured to determine an information type of the user sensitive information, and determine a target position field in the user sensitive information according to the information type;

[0015] A field masking module is configured to mask and replace the target position field by using a preset masking character to obtain a target masking value;

[0016] A hash calculation module is configured to perform hash calculation on the user sensitive information by using a preset hash algorithm to obtain a target hash value;

[0017] A log locating module is configured to locate a target desensitization log file from a log library according to the target masking value and the target hash value;

[0018] The log library stores a plurality of desensitization log files, and user sensitive information in the desensitization log files is represented in a combined structure of a masking value and a hash value.

[0019] In a third aspect, a computer device is provided, which includes a memory and a processor. The memory stores computer readable instructions. When the processor executes the computer readable instructions, the steps of the log locating method are implemented.

[0020] In a fourth aspect, a computer readable storage medium is provided, which stores computer readable instructions. When the processor executes the computer readable instructions, the steps of the log locating method are implemented.

[0021] Compared with the prior art, the embodiments of the present application have the following beneficial effects:

[0022] The embodiment of the present application can help to determine the masking strategy and the masking replacement part corresponding to the type of sensitive information by acquiring the user sensitive information for query, determining the information type of the user sensitive information, and determining the target position field in the user sensitive information according to the information type; the target position field can be masked and replaced by using the preset masking character to obtain the target masking value, which helps to generate the search condition meeting the log library query requirement; the target hash value can be obtained by using the preset hash algorithm to perform hash calculation on the user sensitive information, which helps to use the uniqueness and irreversibility of the hash value to perform accurate matching, and ensures the accuracy of the log positioning result; the target desensitization log file can be positioned from the log library according to the target masking value and the target hash value, which can use the double mechanism of masking value quick screening and hash value accurate matching to effectively improve the efficiency and accuracy of log problem positioning. Based on the scheme of the present application, the safety of financial transaction and the related requirements of personal information protection of supervision can be met, and the insurance background personnel can quickly and accurately locate the problem through log search and analysis. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to more clearly illustrate the scheme in the present application, the drawings needed in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0024] Figure 1 is an exemplary system architecture diagram to which the present application can be applied;

[0025] Figure 2 is a flowchart of one embodiment of the log positioning method according to the present application;

[0026] Figure 3 is a flowchart of one embodiment of the present application before step S201;

[0027] Figure 4 is a flowchart of one embodiment of step S205 of the present application;

[0028] Figure 5 is a structural diagram of one embodiment of the log positioning device according to the present application;

[0029] Figure 6 is a structural diagram of one embodiment of the computer device according to the present application. DETAILED DESCRIPTION

[0030] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terms used in the specification are intended to describe the particular embodiments and are not intended to limit the application; the terms "include" and "have" and their any variations used in the specification and the claims and the above description of drawings are intended to cover the non-exclusive inclusion; the terms "first", "second" and the like used in the specification and the claims and the above description of drawings are intended to distinguish different objects, not to describe a particular order.

[0031] Reference herein to "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment can be included in at least one embodiment of the application. The appearances of the phrase in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily mutually exclusive or alternative embodiments. It is expressly understood that the embodiments described herein are combinable with each other.

[0032] In order to make the person skilled in the art better understand the scheme of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely in conjunction with the drawings below.

[0033] As shown in Figure 1 The system architecture 100 can include a terminal device 101, a network 102 and a server 103, and the terminal device 101 can be a notebook computer 1011, a tablet computer 1012 or a mobile phone 1013. The network 102 is a medium for providing a communication link between the terminal device 101 and the server 103. The network 102 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0034] The user can use the terminal device 101 to interact with the server 103 through the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.

[0035] The terminal device 101 can be various electronic devices with a display screen and supporting web browsing, in addition to the notebook computer 1011, the tablet computer 1012 or the mobile phone 1013, the terminal device 101 can also be an electronic book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer and a desktop computer, etc.

[0036] The server 103 can be a server providing various services, for example, a background server providing support for a page displayed on the terminal device 101.

[0037] It should be noted that the log positioning method provided by the embodiments of the present application is generally executed by a server / terminal device, and accordingly, the log positioning apparatus is generally arranged in a server / terminal device.

[0038] It should be understood that, Figure 1 The number of terminal devices, networks and servers in

[0039] With reference to Figure 2 , a flow chart of one embodiment of the log positioning method according to the present application is shown. The log positioning method comprises the following steps:

[0040] In step S201, user sensitive information for query is acquired.

[0041] In the present embodiment, the electronic device (for example, the server / terminal device shown in Figure 1 The server / terminal device can acquire the user sensitive information for query through a wired connection mode or a wireless connection mode. It should be noted that the wireless connection mode can include but is not limited to 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection and other now known or future developed wireless connection modes.

[0042] In the embodiment, a log library is constructed in advance, and a plurality of desensitization log files are stored in the log library. The desensitization log file is a log file generated by the log system after desensitization processing of user sensitive information in the generation process. After the desensitization processing, the sensitive information in the log file is stored in a desensitized form, while other key information of the log is retained. The sensitive information in the desensitization log file is masked or encrypted, and cannot be directly restored to the original data, so as to meet the requirement of reducing the risk of data leakage.

[0043] Specifically, when it is necessary to query the desensitization log file related to the user sensitive information, for example, in a financial insurance system, when a customer reports a problem, the technical personnel need to query the related log by using the user sensitive information such as the mobile phone number and the license plate number provided by the customer, so as to quickly locate and solve the problem from the log library.

[0044] Specifically, the user sensitive information can include but is not limited to the name, the mobile phone number, the ID card number, the bank card number, the license plate number, the address, the transaction amount and the like.

[0045] In step S202, the information type of the user sensitive information is determined, and a target position field in the user sensitive information is determined according to the information type.

[0046] In the embodiment, for the obtained user sensitive information, the information type of the user sensitive information is determined, wherein the determination of the information type can be realized by using a preset regular expression, rule matching, machine learning and the like. The information type can be divided into fixed format information and non-fixed format information; and can also be divided into types such as name, mobile phone number, ID card number, bank card number, license plate number, address, transaction amount and the like according to attributes. Different masking strategies are set for different information types, and the masking strategy can include a masking symbol and a masking replacement part (such as masking and replacing a specific position field).

[0047] Specifically, for the information type of the user sensitive information, a target position field is determined from the user sensitive information according to the masking strategy corresponding to the information type. For example, if the information type is a mobile phone number, the middle 4 fields of the mobile phone number are determined as the target position field; if the information type is an ID card number, the middle 8 fields of the ID card number are determined as the target position field.

[0048] In step S203, a preset masking character is used to mask and replace the target position field, and a target masking value is obtained.

[0049] Specifically, a preset masking character is used to mask and replace a target position field in the user sensitive information, and other characters except the target position field can be reserved as they are to generate a target masking value. The masking character can be a star symbol (*), a cross symbol (x), a hash symbol (#), etc.

[0050] At step S204, a preset hash algorithm is used to perform hash calculation on the user sensitive information to obtain a target hash value.

[0051] Specifically, a preset hash algorithm is obtained, where the hash algorithm can include a national cryptographic hash algorithm (SM3), a national cryptographic symmetric encryption algorithm (SM4), a SHA-256 hash function, etc. The user sensitive information is input into the hash algorithm for data preprocessing, padding, block division, iterative compression, etc. to generate a target hash value. The target hash value has uniqueness and irreversibility.

[0052] At step S205, the target de-sensitization log file is located from the log library according to the target masking value and the target hash value.

[0053] The log library stores a plurality of de-sensitization log files, and the user sensitive information in the de-sensitization log files is represented in a combined structure of a masking value and a hash value.

[0054] In this embodiment, the log library stores a plurality of de-sensitization log files, and the user sensitive information in the de-sensitization log files is represented in a combined structure of a masking value and a hash value. That is, in the de-sensitization log generation process, the user sensitive information in the log file is converted into a corresponding masking value and hash value, and then the masking value and the hash value are combined according to a specific rule to obtain a corresponding combined structure. The combined structure replaces the user sensitive information in the log file to obtain the de-sensitization log file. Further, to realize the query and retrieval function of the log library, the masking value, the hash value, or the combined structure of the masking value and the hash value of the user sensitive information is used to establish an inverted index to support the query and positioning of the corresponding de-sensitization log file from the log library based on the masking value, the hash value, or the combined structure.

[0055] Specifically, the target de-sensitization log file is located from the log library according to the target masking value and the target hash value of the user sensitive information. For example, the target de-sensitization log file can be located from the log library in combination with the inverted index based on the masking value and the target masking value, and the target de-sensitization log file is obtained by verifying the plurality of de-sensitization log files using the target hash value. Alternatively, the target de-sensitization log file can be located from the log library in combination with the inverted index based on the hash value and the target hash value, and the target de-sensitization log file is obtained by verifying the plurality of de-sensitization log files using the target masking value. Alternatively, the target masking value and the target hash value are combined according to a specific rule to obtain a target combined structure, and the target de-sensitization log file is located from the log library in combination with the inverted index based on the combined structure of the masking value and the hash value and the target combined structure.

[0056] In the embodiment, the user sensitive information for query is obtained, the information type of the user sensitive information is determined, the target position field in the user sensitive information is determined according to the information type, which helps to determine the masking strategy and the masking replacement part corresponding to the sensitive information of the type; the target position field is replaced by the preset masking character to obtain the target masking value, which helps to generate the search condition meeting the log library query requirement; the target hash value is obtained by performing hash calculation on the user sensitive information using the preset hash algorithm, which helps to perform accurate matching by using the uniqueness and irreversibility of the hash value, and ensures the accuracy of the log positioning result; the target de-sensitization log file is located from the log library according to the target masking value and the target hash value, which can use the dual mechanism of fast screening by the masking value and accurate matching by the hash value to effectively improve the efficiency and accuracy of log problem positioning. Based on the scheme of the present application, the safety of financial transactions and the related requirements of personal information protection are met, and the insurance back-end personnel can quickly and accurately locate the problem through log search and analysis.

[0057] In some optional implementation manners of the embodiment, the target de-sensitization log file is located from the log library according to the target masking value and the target hash value of the user sensitive information. Figure 3 Before step S201, that is, before the user sensitive information for query is obtained, the electronic device can further perform the following steps:

[0058] In step S101, a sensitive field in to-be-generated log information is detected, and an information type of the sensitive field is determined.

[0059] Specifically, in the log generation process, the log system detects a sensitive field in to-be-generated log information, and determines an information type of the sensitive field. For example, the log system identifies that the sensitive field contained in the log is a user ID number "AAAAAAAAAAAAAAAAAA", and determines that the information type is an ID number type.

[0060] Step S102, according to the information type of the sensitive field, determining a specific position field in the sensitive field, and using the masking character to mask and replace the specific position field to obtain a to-be-merged masked value;

[0061] Specifically, according to the information type of the sensitive field, a specific position field in the sensitive field is determined, wherein different masking strategies are set for different information types, and the masking strategies can include a masking symbol and a masking replacement part (such as masking and replacing a specific position field). For the information type of the sensitive field, a specific position field is determined from the sensitive field according to the masking strategy corresponding to the information type.

[0062] It should be noted that the masking strategy set for the information type of the sensitive field is consistent with the masking strategy set for the information type of the user sensitive information.

[0063] Specifically, the specific position field is masked and replaced by using a masking character, and other characters except the specific position field can be reserved as they are to generate a to-be-merged masked value. For example, for a user ID number, a field of 8 middle bits (i.e., a birth date part) is determined as the specific position field, and after the specific position field is replaced by using a masking character (such as a star symbol *), a to-be-merged masked value "AAAAAA********AAAA" is obtained.

[0064] Step S103, using the hash algorithm to perform hash calculation on the sensitive field to obtain a to-be-merged hash value;

[0065] Specifically, a preset hash algorithm is used to perform data preprocessing, padding, block division, iterative compression, and other hash calculation processes on the sensitive field to obtain a to-be-merged hash value. The hash algorithm used for the sensitive field is consistent with the hash algorithm used for the user sensitive information. For example, a SM3 hash algorithm is used to perform SM3 hash calculation on a user ID number "AAAAAAAAAAAAAAAAAA" to obtain a to-be-merged hash value "a1b2c3d4e5f6g7h8i9j0" (the hash value is an example, and the actual value can be calculated according to the specific algorithm).

[0066] Step S104, obtaining a preset merging structure template, wherein the merging structure template includes a masked value placeholder and a hash value placeholder;

[0067] Specifically, a preset merging structure template is acquired, the merging structure template including a masking value placeholder and a hash value placeholder. For example, the template can be "[time][event] identity card number=[masking value]|[hash value]" or "[masking value|hash value]", where "masking value" is the masking value placeholder and "hash value" is the hash value placeholder.

[0068] In step S105, the to-be-merged masking value is filled into the masking value placeholder and the to-be-merged hash value is filled into the hash value placeholder to generate a merging structure.

[0069] Specifically, the to-be-merged masking value is filled into the masking value placeholder and the to-be-merged hash value is filled into the hash value placeholder to generate a merging structure. For example, assuming that the merging structure template is "[masking value|hash value]", the to-be-merged masking value "AAAAAA********AAAA" and the to-be-merged hash value "a1b2c3d4e5f6g7h8i9j0" are filled into the corresponding placeholders of the merging structure template respectively to obtain the merging structure: "[AAAAAA********AAAA|a1b2c3d4e5f6g7h8i9j0]".

[0070] In step S106, the merging structure is used to replace the sensitive field in the to-be-generated log information to generate a desensitized log file, which is stored in the log library.

[0071] Specifically, the merging structure is used to replace the sensitive field in the to-be-generated log information to generate a desensitized log file, which is stored in the log library. For example, the original log information "user AAAAAAAAAAAAAAAAAAA has performed a login operation" is converted into the desensitized log file: "user [AAAAAA********AAAA|a1b2c3d4e5f6g7h8i9j0] has performed a login operation".

[0072] In this embodiment, by detecting the sensitive field and determining the information type thereof, a differentiated masking strategy can be adopted for different types of data; by determining the specific position field according to the information type, character masking is adopted for the specific position field to retain part of the original information form, balancing the recognizability and security; by performing hash calculation on the sensitive field as a whole to generate a unique and irreversible hash value, data uniqueness association (such as log positioning) is realized, while avoiding original data leakage; by adopting a preset template to merge the masking value and the hash value, the desensitization structure mode is unified, facilitating subsequent analysis or query retrieval.

[0073] In some optional implementations of the embodiment, the information type described above can include fixed format information, and the step S202, i.e., determining the target position field in the user sensitive information according to the information type, can include the following steps:

[0074] If the information type is fixed format information, a format type of the fixed format information is determined.

[0075] Specifically, the fixed format information refers to information that conforms to a unified format specification in terms of structure, field, arrangement, etc., such as an ID number, a mobile phone number, a bank card number, etc. If the information type of the user sensitive information is fixed format information, the format type of the fixed format information is determined. For example, when it is identified that the user sensitive information for the query is an 18-digit combination of numbers and letters, it is determined that the information is an ID number; when it is identified that the user sensitive information is 11 digits and starts with 1, it is determined that the information is a mobile phone number.

[0076] A target regular expression corresponding to the format type is matched from a preset regular expression library, and the target regular expression includes a masking position for the format type.

[0077] The target position field in the user sensitive information is located according to the masking position.

[0078] Specifically, different regular expressions are set in advance for different format types, and the regular expressions are used to define the masking positions corresponding to the information of the format types. After the format type is determined, the target regular expression corresponding to the format type is matched from the preset regular expression library. For example, the regular expression of the ID number can be "^(\d{6})(\d{8})(\d{3}[0-9Xx])$ ", where the regular expression includes the masking position information for the ID number, indicating that the middle birth date part and the last check code part should be masked. According to the masking position defined in the regular expression, the target position field in the user sensitive information is located. For example, for the ID number "AAAAAAAAAAAAAAAAAA", the "AAAAAAAA" of the birth date part and the "AAAA" of the last check code part are determined as the target position field through the regular expression.

[0079] In the embodiment, by judging whether the sensitive information is in a fixed format (such as an ID number, a credit card number, a date, etc.), the standardized structure of the data can be determined; by matching the target regular expression corresponding to the format type from the preset regular expression library, the target field in the sensitive information is automatically located according to the masking position in the target regular expression, which reduces manual intervention and improves processing efficiency.

[0080] In some optional implementations of the embodiment, the information type described above can include non-fixed format information, and the step S202, i.e., determining the target position field in the user sensitive information according to the information type, can include the following steps.

[0081] If the information type is non-fixed format information, the character length of the non-fixed format information is obtained.

[0082] A preset masking ratio is obtained, and the number of masking characters is determined according to the character length and the masking ratio.

[0083] The last N fields in the user sensitive information are determined as the target position field.

[0084] Specifically, the non-fixed format information is information without strict structure restriction and flexible content, such as name, address, transaction amount, etc. If the information type of the user sensitive information is non-fixed format information, the character length of the non-fixed format information is obtained. For example, for the name "Zhang Sanfeng", the character length is calculated to be 3 characters. A preset masking ratio, such as 50%, is obtained, and the number of characters to be masked, i.e., N, is determined according to the character length and the masking ratio. For "Zhang Sanfeng", the number of characters to be masked is 3*50%=1.5, which is rounded up to 2 characters. Then, the last N fields in the user sensitive information are determined as the target position field, i.e., the last two characters "Sanfeng" of the name are determined as the target position field.

[0085] In the embodiment, the number of characters to be masked is dynamically calculated according to the character length and the masking ratio, instead of relying on fixed format rules, so that irregular sensitive information (such as user name, address, etc.) can be processed, and desensitization failure caused by missing format is avoided. Only the masking ratio needs to be configured, and regular expressions or rules do not need to be written for each non-fixed format, so that the flexibility of desensitization processing is improved, and the maintenance complexity is reduced.

[0086] In some optional implementations of the embodiment, the step S203, i.e., masking and replacing the target position field with a preset masking character to obtain a target masking value, can include the following steps.

[0087] The user sensitive information is divided into the target position field and other fields except the target position field.

[0088] The target position field is replaced with a preset masking character, and the other fields are kept, to obtain a target masking value.

[0089] Specifically, after determining the target position field, the user sensitive information is divided into the target position field and other fields except the target position field. For example, for the identity card number "AAAAAAAAAAAAAAAAAA", the target position field is "AAAAAAAA" of the birth date part and "AAAA" of the last check code part, and the other field is "AAAAAA" except the target position field.

[0090] Specifically, the target position field is replaced by a preset masking character (such as an asterisk "*"), and the other fields are kept, to obtain a target masking value. For example, after the identity card number "AAAAAAAAAAAAAAAAAA" is subjected to masking processing, the obtained target masking value is "AAAAAA************". For the name "Zhang Sanfeng", the target position field is "Sanfeng", and after the masking processing, the obtained target masking value is "Zhang**".

[0091] In some optional implementations of the embodiment, the hash algorithm includes a national secret hash algorithm, and the step S204, that is, performing hash calculation on the user sensitive information by using the preset hash algorithm to obtain a target hash value, can include the following steps:

[0092] performing data cleaning on the user sensitive information to obtain cleaned data;

[0093] performing hash calculation on the cleaned data by using the national secret hash algorithm to obtain a target hash value.

[0094] In the embodiment, in order to ensure data security and query efficiency, the user sensitive information needs to be subjected to hash processing. The embodiment uses a national secret hash algorithm (such as SM3) as the hash algorithm.

[0095] Specifically, the user sensitive information is subjected to data cleaning to remove special characters such as spaces and punctuation marks that can affect the consistency of hash results, to obtain cleaned data. For example, for the bank card number "6222 0000 11112222" with spaces, the cleaned data is "6222000011112222".

[0096] Specifically, the cleaned data is subjected to data padding, block division, iterative compression and other calculations by using the national secret hash algorithm, to obtain a target hash value with a fixed character length. For example, for the cleaned bank card number "6222 0000 11112222", after the hash calculation by using the SM3 algorithm, the obtained target hash value is "k1l2m3n4o5p6q7r8s9t0" (the hash value is an example, and the actual value can be calculated according to the specific algorithm).

[0097] In some optional implementations of the present embodiment, referring to Figure 4 The step S205, i.e., locating the target de-identification log file from the log library according to the target masking value and the target hash value, can include the following steps:

[0098] S2051, querying candidate de-identification log files containing the target masking value from the log library according to the target masking value;

[0099] Specifically, in the log library, a plurality of de-identification log files are stored, and user sensitive information in the de-identification log files is represented in a combined structure of a masking value and a hash value. For example, a de-identification log containing user ID information can be represented as “user [AAAAAA************ | a1b2c3d4e5f6g7h8i9j0] performed login operation”, wherein the front half of the bracket is a masking value, and the rear half is a hash value.

[0100] Further, to achieve fast and accurate log positioning, an inverted index is established using the masking value of the user sensitive information, so that the system can quickly query and locate the corresponding de-identification log file from the log library based on the masking value.

[0101] Specifically, in the log query process, candidate de-identification log files containing the target masking value are queried from the log library according to the target masking value. For example, the system will find all candidate de-identification log files containing the target masking value “AAAAAA************”.

[0102] S2052, extracting a to-be-verified hash value combined with the target masking value from the candidate de-identification log file;

[0103] Specifically, from the plurality of candidate de-identification log files queried, a to-be-verified hash value combined with the target masking value is extracted. For example, the hash value “a1b2c3d4e5f6g7h8i9j0” is extracted from the above candidate de-identification log file and used as the to-be-verified hash value.

[0104] S2053, calculating the similarity between the to-be-verified hash value and the target hash value;

[0105] Specifically, the similarity between the to-be-verified hash value and the target hash value is calculated for the to-be-verified hash value and the target hash value. The similarity calculation can use character matching rate, edit distance, etc. For example, for two hash values-the to-be-verified hash value “a1b2c3d4e5f6g7h8i9j0” and the target hash value “a1b2c3d4e5f6g7h8i9j0”, their similarity is 100%.

[0106] S2054, if the similarity is greater than a preset threshold, determining the candidate de- sensitized log file as a target de-sensitized log file.

[0107] Specifically, if the calculated similarity is greater than a preset threshold (such as 90%), the candidate de-sensitized log file satisfying the preset threshold is determined as the target de-sensitized log file. In this way, the system successfully locates the target de-sensitized log file matching the user sensitive information for query from the log library.

[0108] In this embodiment, the target masking value is used as an index key to quickly locate the candidate log file containing the value from the log library, effectively reducing the calculation amount; by extracting the to-be-verified hash value combined with the target masking value from the candidate log, and calculating the similarity thereof with the target hash value, the accuracy of log problem positioning is improved. The masking value may be repeated due to format or partial field difference, and only masking value matching may misselect similar logs, while combined hash value similarity verification can ensure the uniqueness of matching. In addition, even if the masking value is partially tampered, the hash value can still confirm the data correlation through similarity calculation, improving the security of log problem positioning. Based on this embodiment, combined with the double conditions of masking value and hash value, through masking value quick screening + hash value similarity verification, efficient and accurate retrieval of de-sensitized logs is realized, balancing the efficiency and security of problem positioning.

[0109] Further reference Figure 5 , as an implementation of the method shown in the above Figure 2 , the present application provides an embodiment of a log positioning device, which corresponds to the method embodiment shown in Figure 2 , and the device can be applied in various electronic devices.

[0110] As shown in Figure 5 , the log positioning device 400 described in this embodiment includes an information acquisition module 401, a position determination module 402, a field masking module 403, a hash calculation module 404, and a log positioning module 405. Among them:

[0111] The information acquisition module 401 is configured to acquire user sensitive information for query;

[0112] The position determination module 402 is configured to determine the information type of the user sensitive information, and determine the target position field in the user sensitive information according to the information type;

[0113] The field masking module 403 is configured to mask and replace the target position field with a preset masking character to obtain a target masking value;

[0114] The hash calculation module 404 is configured to perform hash calculation on the user sensitive information by using a preset hash algorithm to obtain a target hash value.

[0115] The log positioning module 405 is configured to position a target de-sensitization log file from a log library according to the target masking value and the target hash value.

[0116] The log library stores a plurality of de-sensitization log files, and the user sensitive information in the de-sensitization log files is represented in a combined structure of a masking value and a hash value.

[0117] In this embodiment, a log library is constructed in advance, and the log library stores a plurality of de-sensitization log files. The de-sensitization log file is a log file generated by the log system in the generation process after the user sensitive information is de-sensitized. After the de-sensitization, the sensitive information of the log file is stored in a de-sensitized form, and other key information of the log is retained. The sensitive information in the de-sensitization log file is masked or encrypted, and cannot be directly restored to the original data, so as to meet the requirement of reducing the risk of data leakage.

[0118] Specifically, when it is necessary to query the de-sensitization log file related to the user sensitive information, for example, in a financial insurance system, when a customer reports a problem, the technical personnel need to query the related log by using the user sensitive information such as the mobile phone number and license plate number provided by the customer, so as to quickly locate and solve the problem from the log library. At this time, the information acquisition module 401 is configured to acquire the user sensitive information provided by the customer for query.

[0119] Specifically, the user sensitive information can include but is not limited to the name, mobile phone number, ID number, bank card number, license plate number, address, transaction amount and the like.

[0120] Specifically, the position determination module 402 is configured to determine the information type of the acquired user sensitive information, and the determination of the information type can be implemented by using a preset regular expression, rule matching, machine learning and the like. The information type can be divided into fixed format information and non-fixed format information, and can also be divided into types such as name, mobile phone number, ID number, bank card number, license plate number, address, transaction amount and the like according to attributes. Different masking strategies are set for different information types, and the masking strategy can include a masking symbol and a masking replacement part (such as masking and replacing a specific position field). For the information type of the user sensitive information, the target position field is determined from the user sensitive information according to the masking strategy corresponding to the information type. For example, if the information type is a mobile phone number, the middle 4 fields of the mobile phone number are determined as the target position field; if the information type is an ID number, the middle 8 fields of the ID number are determined as the target position field.

[0121] Specifically, the field masking module 403 is configured to mask and replace a target position field in the user sensitive information with a preset masking character, and other characters except the target position field can be reserved as they are to generate a target masking value. The masking character can be a star symbol (*), a cross symbol (x), a hash symbol (#), etc.

[0122] Specifically, the hash calculation module 404 is configured to obtain a preset hash algorithm, where the hash algorithm can include a SM3 (SM3 is a national standard hash algorithm), a SM4 (SM4 is a national standard symmetric encryption algorithm), a SHA-256 hash function, etc. The user sensitive information is input into the hash algorithm for data preprocessing, padding, block division, iterative compression, etc. to generate a target hash value. The target hash value has uniqueness and irreversibility.

[0123] In this embodiment, a plurality of desensitization log files are stored in the log library, and the user sensitive information in the desensitization log files is represented in a combined structure of a masking value and a hash value. That is, in the desensitization log generation process, the user sensitive information in the log file is converted into a corresponding masking value and hash value, and then the masking value and the hash value are combined according to a specific rule to obtain a corresponding combined structure, the user sensitive information in the log file is replaced by the combined structure to obtain the desensitization log file. Further, to realize the query and retrieval function of the log library, the masking value, the hash value, or the combined structure of the masking value and the hash value of the user sensitive information is used to establish an inverted index to support the query and positioning of the corresponding desensitization log file from the log library based on the masking value, the hash value, or the combined structure.

[0124] Specifically, the log positioning module 405 is configured to locate a target desensitization log file from the log library according to the target masking value and the target hash value of the user sensitive information. For example, a plurality of desensitization log files can be located from the log library in combination with the inverted index based on the masking value and the target masking value, and the target desensitization log file is obtained by verifying the plurality of desensitization log files with the target hash value. Alternatively, a plurality of desensitization log files can be located from the log library in combination with the inverted index based on the hash value and the target hash value, and the target desensitization log file is obtained by verifying the plurality of desensitization log files with the target masking value. Alternatively, the target masking value and the target hash value are combined according to a specific rule to obtain a target combined structure, and the target desensitization log file is located from the log library in combination with the inverted index based on the combined structure of the masking value and the hash value and the target combined structure.

[0125] The log positioning device 400 of the present application, by acquiring user sensitive information for query, determining the information type of the user sensitive information, determining the target position field in the user sensitive information according to the information type, helping to determine the masking strategy and the masking replacement part corresponding to the type of sensitive information; by using the preset masking character, the target position field is masked and replaced to obtain the target masking value, which helps to generate the search condition meeting the log library query requirement; by using the preset hash algorithm, the user sensitive information is hashed to obtain the target hash value, which helps to use the uniqueness and irreversibility of the hash value for accurate matching to ensure the accuracy of the log positioning result; by positioning the target desensitization log file from the log library according to the target masking value and the target hash value, the dual mechanism of quick screening using the masking value and accurate matching using the hash value can be used to effectively improve the efficiency and accuracy of log problem positioning. Based on the scheme of the present application, while meeting the requirements of supervision on the safety of financial transactions and personal information protection, it ensures that the insurance back-end personnel can quickly and accurately locate the problem through log search and analysis.

[0126] In some optional implementations of the present embodiment, the log positioning device further comprises a log desensitization module, wherein:

[0127] The log desensitization module is configured to detect a sensitive field in the to-be-generated log information, and determine an information type of the sensitive field;

[0128] According to the information type of the sensitive field, a specific position field in the sensitive field is determined, and the specific position field is masked and replaced by using the masking character to obtain a to-be-merged masking value;

[0129] The hash algorithm is used to perform hash calculation on the sensitive field to obtain a to-be-merged hash value;

[0130] A preset merging structure template is acquired, and the merging structure template includes a masking value placeholder and a hash value placeholder;

[0131] The to-be-merged masking value is filled into the masking value placeholder, and the to-be-merged hash value is filled into the hash value placeholder to generate a merging structure;

[0132] The merging structure replaces the sensitive field in the to-be-generated log information to generate the desensitization log file, and the desensitization log file is stored in the log library.

[0133] In this embodiment, the log desensitization module is configured to, in a log generation process, detect a sensitive field in log information to be generated by a log system, and determine an information type of the sensitive field. For example, the log system identifies that the sensitive field contained in the log is a user ID number "AAAAAAAAAAAAAAAAAA", and determines that the information type of the sensitive field is an ID number type.

[0134] Specifically, according to the information type of the sensitive field, a specific position field in the sensitive field is determined, wherein different masking strategies are set for different information types, and the masking strategies can include a masking symbol and a masking replacement part (such as masking and replacing a specific position field). For the information type of the sensitive field, a specific position field is determined from the sensitive field according to the masking strategy corresponding to the information type.

[0135] It should be noted that the masking strategy set for the information type of the sensitive field is consistent with the masking strategy set for the information type of the user sensitive information.

[0136] Specifically, the specific position field is replaced by a masking character, and other characters except the specific position field are retained as they are to generate a to-be-merged masking value. For example, for a user ID number, the field of the middle 8 bits (i.e., the date of birth part) is determined as the specific position field, and after the specific position field is replaced by a masking character (such as a star symbol "*"), a to-be-merged masking value "AAAAAA********AAAA" is obtained.

[0137] Specifically, a preset hash algorithm is used to perform data preprocessing, padding, block division, and iterative compression on the sensitive field to obtain a to-be-merged hash value. The hash algorithm used for the sensitive field is consistent with the hash algorithm used for the user sensitive information. For example, the SM3 hash algorithm is used to perform SM3 hash calculation on the user ID number "AAAAAAAAAAAAAAAAAA" to obtain a to-be-merged hash value "a1b2c3d4e5f6g7h8i9j0" (the hash value is an example, and the actual value is calculated according to the specific algorithm).

[0138] Specifically, a preset merging structure template is obtained, and the merging structure template includes a masking value placeholder and a hash value placeholder. For example, the template can be "[time][event] ID number = [masking value]|[hash value]" or "[masking value|hash value]", wherein "masking value" is a masking value placeholder, and "hash value" is a hash value placeholder.

[0139] Specifically, the to-be-merged masking value is filled into the masking value placeholder, and the to-be-merged hash value is filled into the hash value placeholder, to generate the merged structure. For example, assuming that the merged structure template is "[masking value | hash value]", the to-be-merged masking value "AAAAAA********AAAA" and the to-be-merged hash value "a1b2c3d4e5f6g7h8i9j0" are filled into the placeholders corresponding to the merged structure template, respectively, to obtain the merged structure: "[AAAAAA*******AAAA | a1b2c3d4e5f6g7h8i9j0]".

[0140] Specifically, the sensitive field in the to-be-generated log information is replaced by the merged structure, to generate the desensitized log file, and the desensitized log file is stored into the log library. For example, the original log information "a user AAAAAAAAAAAAAAA performed a login operation" is converted into the desensitized log file: "a user [AAAAAA********AAAA | a1b2c3d4e5f6g7h8i9j0] performed a login operation".

[0141] In some optional implementations of the embodiment, the position determining module includes a format determining submodule, an expression matching submodule, and a first position determining submodule, wherein:

[0142] The format determining submodule is configured to determine a format type of the fixed format information if the information type is the fixed format information.

[0143] The expression matching submodule is configured to match a target regular expression corresponding to the format type from a preset regular expression library, the target regular expression including a masking position for the format type.

[0144] The first position determining submodule is configured to locate a target position field in the user sensitive information according to the masking position.

[0145] Specifically, the fixed format information refers to information that is in a unified format specification, such as a structure, a field, an arrangement manner, and the like, for example, an ID card number, a mobile phone number, a bank card number, and the like. The format determining submodule is configured to determine a format type of the fixed format information if the information type of the user sensitive information is the fixed format information. For example, when it is identified that the user sensitive information for the query is an 18-digit combination of numbers and letters, it is determined that the information is an ID card number; when it is identified that the user sensitive information is an 11-digit number and starts with 1, it is determined that the information is a mobile phone number.

[0146] Specifically, different regular expressions are set in advance for different format types, and the regular expressions are used to define the masking positions corresponding to the information of the format types. An expression matching submodule is configured to match a target regular expression corresponding to the format type from a preset regular expression library after the format type is determined. For example, the regular expression of an ID number can be "^(\d{6})(\d{8})(\d{3}[0-9Xx])$". The regular expression contains the masking position information for the ID number, indicating that the middle birth date part and the last check code part should be masked. A first position determining submodule is configured to locate the target position field in the user sensitive information according to the masking positions defined in the regular expression. For example, for the ID number "AAAAAAAAAAAAAAAAAA", the "AAAAAAAA" of the birth date part and the "AAAA" of the last check code part are determined as the target position fields through the regular expression.

[0147] In some optional implementations of the embodiment, the position determining module includes a length determining submodule, a word number determining submodule, and a second position determining submodule, wherein:

[0148] The length determining submodule is configured to acquire the character length of the non-fixed format information if the information type is the non-fixed format information.

[0149] The word number determining submodule is configured to acquire a preset masking proportion, and determine the masking word number according to the character length and the masking proportion.

[0150] The second position determining submodule is configured to determine the masking word number of fields arranged at the back of the user sensitive information as the target position fields.

[0151] Specifically, the non-fixed format information is information without strict structure limitation and flexible content, such as a name, an address, a transaction amount, and the like. The length determining submodule is configured to acquire the character length of the non-fixed format information if the information type of the user sensitive information is the non-fixed format information. For example, the character length of the name "Zhang Sanfeng" is calculated to be 3 characters. The word number determining submodule is configured to acquire a preset masking proportion, such as 50%, and determine the masking word number according to the character length and the masking proportion, that is, the masking word number N. For "Zhang Sanfeng", the masking word number is 3*50% = 1.5, and the up-rounding is 2 characters. Then, the second position determining submodule is configured to determine the masking word number (N) of fields arranged at the back of the user sensitive information as the target position fields, that is, the last two fields "Sanfeng" of the name are determined as the target position fields.

[0152] In some optional implementation forms of the present embodiment, the field masking module comprises a field division submodule and a field replacement submodule, wherein:

[0153] The field division submodule is configured to divide the user sensitive information into the target position field and other fields except the target position field.

[0154] The field replacement submodule is configured to replace the target position field with a preset masking character and keep the other fields, to obtain a target masking value.

[0155] Specifically, the field division submodule is configured to divide the user sensitive information into the target position field and other fields except the target position field after determining the target position field. For example, for an ID number "AAAAAAAAAAAAAAAAAA", the target position field is "AAAAAAAA" of the birth date part and "AAAA" of the last check code part, and the other fields are "AAAAAA" except the target position field.

[0156] Specifically, the field replacement submodule is configured to replace the target position field with a preset masking character (such as an asterisk "*") and keep the other fields, to obtain a target masking value. For example, for the ID number "AAAAAAAAAAAAAAAAAA", the target masking value obtained after the masking processing is "AAAAAA************". For a name "Zhang Sanfeng", the target position field is "Sanfeng", and the target masking value obtained after the masking processing is "Zhang**".

[0157] In some optional implementation forms of the present embodiment, the hash calculation module comprises a data cleaning submodule and a field replacement submodule, wherein:

[0158] The data cleaning submodule is configured to clean the user sensitive information, to obtain cleaned data.

[0159] The hash calculation submodule is configured to calculate a target hash value by using the national secret hash algorithm on the cleaned data.

[0160] In the present embodiment, in order to ensure data security and query efficiency, the user sensitive information needs to be processed by a hash algorithm. The present embodiment adopts a national secret hash algorithm (such as SM3) as the hash algorithm.

[0161] Specifically, the data cleaning submodule is configured to clean the user sensitive information, remove special characters such as spaces and punctuation marks that may affect the consistency of the hash result, and obtain cleaned data. For example, the bank card number with spaces "6222 0000 11112222" is cleaned to obtain "6222000011112222".

[0162] Specifically, the hash calculation submodule is configured to perform data padding, block division, and iterative compression on the cleaned data by using a national secret hash algorithm to obtain a target hash value with a fixed character length. For example, the cleaned bank card number "6222 0000 1111 2222" is subjected to hash calculation by the SM3 algorithm to obtain a target hash value "k1l2m3n4o5p6q7r8s9t0" (the hash value is an example, and the actual value is calculated according to the specific algorithm).

[0163] In some optional implementations of the embodiment, the log positioning module includes a candidate query submodule, a hash value extraction submodule, a similarity calculation submodule, and a target determination submodule, wherein:

[0164] The candidate query submodule is configured to query, according to the target masking value, a candidate de-identification log file containing the target masking value from the log library;

[0165] The hash value extraction submodule is configured to extract, from the candidate de-identification log file, a to-be-inspected hash value combined with the target masking value;

[0166] The similarity calculation submodule is configured to calculate the similarity between the to-be-inspected hash value and the target hash value;

[0167] The target determination submodule is configured to determine the candidate de-identification log file as a target de-identification log file if the similarity is greater than a preset threshold.

[0168] Specifically, in the log library, a plurality of de-identification log files are stored, and the user sensitive information in the de-identification log files is represented in a combined structure of a masking value and a hash value. For example, a de-identification log containing user identity card information can be represented as "user [AAAAAA************|a1b2c3d4e5f6g7h8i9j0] performed a login operation", wherein the first half of the bracket is a masking value, and the second half is a hash value.

[0169] Further, to achieve fast and accurate log positioning, an inverted index is established using the masking value of the user sensitive information, so that the system can quickly query and locate the corresponding de-identification log file from the log library based on the masking value.

[0170] Specifically, the candidate query submodule is configured to query candidate de-identification log files containing the target masking value from the log library according to the target masking value in the log query process. For example, the system searches for all candidate de-identification log files containing the target masking value "AAAAAA************".

[0171] Specifically, the hash value extraction submodule is configured to extract the to-be-verified hash value combined with the target masking value from the plurality of candidate de-identification log files. For example, the hash value "a1b2c3d4e5f6g7h8i9j0" is extracted from the candidate de-identification log file as the to-be-verified hash value.

[0172] Specifically, the similarity calculation submodule is configured to calculate the similarity between the to-be-verified hash value and the target hash value for the to-be-verified hash value and the target hash value. The similarity calculation can use character matching rate, edit distance, etc. For example, for two hash values-the to-be-verified hash value "a1b2c3d4e5f6g7h8i9j0" and the target hash value "a1b2c3d4e5f6g7h8i9j0", the similarity is 100%.

[0173] Specifically, the target determination submodule is configured to determine the candidate de-identification log file meeting the preset threshold as the target de-identification log file if the calculated similarity is greater than the preset threshold (such as 90%). In this way, the system successfully locates the target de-identification log file matched with the user sensitive information used for query from the log library.

[0174] To solve the above technical problems, the embodiment of the present application further provides a computer device. For details, please refer to Figure 6 , Figure 6 The basic structure block diagram of the computer device of the present embodiment is shown in FIG. 1.

[0175] The computer device 6 comprises a memory 61, a processor 62, and a network interface 63 which are communicatively connected by a system bus. It should be noted that the computer device 6 is only shown with the memory 61, the processor 62, and the network interface 63, but it should be understood that not all of the shown components are required to be implemented, and more or less components can be alternatively implemented. Among them, those skilled in the art can understand that the computer device herein is a device capable of automatically performing numerical calculation and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0176] The computer device can be a desktop computer, a notebook computer, a palm computer, a cloud server, and the like. The computer device can interact with a user through a keyboard, a mouse, a remote controller, a touchpad, a voice control device, and the like.

[0177] The memory 61 comprises at least one type of readable storage medium, including a flash memory, a hard disk, a multimedia card, a card-type memory (e.g., an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, and the like. In some embodiments, the memory 61 can be an internal storage unit of the computer device 6, such as a hard disk or a memory of the computer device 6. In other embodiments, the memory 61 can also be an external storage device of the computer device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like. Of course, the memory 61 can also include both the internal storage unit and the external storage device of the computer device 6. In the present embodiment, the memory 61 is generally used to store an operating system and various application software installed in the computer device 6, such as computer readable instructions of the log positioning method, and the like. In addition, the memory 61 can also be used to temporarily store various data that have been output or will be output.

[0178] The processor 62 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 62 is generally used to control the overall operation of the computer device 6. In the present embodiment, the processor 62 is configured to run computer-readable instructions stored in the memory 61 or process data, such as computer-readable instructions for running the log positioning method.

[0179] The network interface 63 may include a wireless network interface or a wired network interface, and is generally used to establish a communication connection between the computer device 6 and other electronic devices.

[0180] The present application also provides another implementation, i.e., a computer-readable storage medium storing computer-readable instructions executable by at least one processor to cause the at least one processor to perform the steps of the log positioning method as described above.

[0181] The computer device and the computer-readable storage medium provided by the embodiments of the present application can obtain user sensitive information for query by a processor, determine the information type of the user sensitive information, determine the target position field in the user sensitive information according to the information type, help to determine the masking strategy and the masking replacement part corresponding to the type of sensitive information, mask and replace the target position field by using a preset masking character, help to generate a search condition meeting the log library query requirement, perform hash calculation on the user sensitive information by using a preset hash algorithm, obtain a target hash value, help to perform accurate matching by using the uniqueness and irreversibility of the hash value, and ensure the accuracy of the log positioning result. The target desensitized log file is positioned from the log library according to the target masking value and the target hash value, the dual mechanism of quick screening by using the masking value and accurate matching by using the hash value can be used, and the efficiency and accuracy of log problem positioning can be effectively improved. Based on the present application, the safety of financial transactions and the related requirements of personal information protection can be met, and the insurance back-end personnel can quickly and accurately locate the problem by log search and analysis.

[0182] Those skilled in the art can clearly understand the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, also can be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of software product, and the computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a plurality of instructions to make a terminal device (may be a mobile phone, computer, server, air conditioner, or network device, etc.) execute the method described in each embodiment of the present application.

[0183] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all the embodiments, and the preferred embodiments of the present application are given in the drawings, but do not limit the patent scope of the present application. The present application can be realized in many different forms, and conversely, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions recorded in the foregoing specific embodiments, or make equivalent replacements to some technical features. Any equivalent structure made by using the contents of the specification and drawings, directly or indirectly applied to other related technical fields, is also within the scope of the patent protection of the present application.

[0184] The non-company software tools or components appearing in the embodiments of the present application are only examples for introduction, not representing actual use.

Claims

1. A log positioning method, characterized by, The method comprises the following steps: obtaining user sensitive information for query; determining the information type of the user sensitive information, and determining the target position field in the user sensitive information according to the information type; adopting a preset masking character to mask and replace the target position field to obtain a target masking value; adopting a preset hash algorithm to perform hash calculation on the user sensitive information to obtain a target hash value; locating a target desensitization log file from a log library according to the target masking value and the target hash value; wherein the log library stores a plurality of desensitization log files, and the user sensitive information in the desensitization log file is represented in a combined structure of a masking value and a hash value.

2. The log positioning method according to claim 1, characterized in that, The information type includes fixed format information, and the step of determining the target position field in the user sensitive information according to the information type comprises: if the information type is fixed format information, determining the format type of the fixed format information; matching a target regular expression corresponding to the format type from a preset regular expression library, wherein the target regular expression includes a masking position for the format type; locating the target position field in the user sensitive information according to the masking position.

3. The log positioning method of claim 1, wherein, The information type includes non-fixed format information, and the step of determining the target position field in the user sensitive information according to the information type comprises: if the information type is non-fixed format information, obtaining the character length of the non-fixed format information; obtaining a preset masking ratio, and determining the number of masking characters according to the character length and the masking ratio; determining the last number of fields in the user sensitive information as the target position field.

4. The log positioning method of claim 1, wherein, The step of adopting a preset masking character to mask and replace the target position field to obtain a target masking value comprises: dividing the user sensitive information into the target position field and other fields except the target position field; adopting a preset masking character to replace the target position field and retaining the other fields to obtain a target masking value.

5. The log positioning method of claim 1, wherein, The hash algorithm includes a national secret hash algorithm, and the step of adopting a preset hash algorithm to perform hash calculation on the user sensitive information to obtain a target hash value comprises: performing data cleaning on the user sensitive information to obtain cleaned data; adopting the national secret hash algorithm to perform hash calculation on the cleaned data to obtain a target hash value.

6. The log positioning method according to any one of claims 1-5, characterized by, The step of locating a target desensitization log file from a log library according to the target masking value and the target hash value comprises: querying a candidate desensitization log file containing the target masking value from the log library according to the target masking value; extracting a to-be-verified hash value combined with the target masking value from the candidate desensitization log file; calculating the similarity between the to-be-verified hash value and the target hash value; if the similarity is greater than a preset threshold, determining the candidate desensitization log file as the target desensitization log file.

7. The log positioning method of claim 1, wherein, Before the step of obtaining user sensitive information for query, the method further comprises: detect a sensitive field in to-be-generated log information, determine an information type of the sensitive field; determine a specific position field in the sensitive field according to the information type of the sensitive field, and perform masking replacement on the specific position field by using the masking character to obtain a to-be-merged masking value; perform hash calculation on the sensitive field by using the hash algorithm to obtain a to-be-merged hash value; obtain a preset merging structure template, the merging structure template including a masking value placeholder and a hash value placeholder; fill the to-be-merged masking value into the masking value placeholder and fill the to-be-merged hash value into the hash value placeholder to generate a merging structure; replace the sensitive field in the to-be-generated log information with the merging structure to generate the desensitized log file and store the desensitized log file in the log library.

8. A log positioning device, characterized by comprise: an information obtaining module configured to obtain user sensitive information for query; a position determining module configured to determine an information type of the user sensitive information and determine a target position field in the user sensitive information according to the information type; a field masking module configured to perform masking replacement on the target position field by using a preset masking character to obtain a target masking value; a hash calculation module configured to perform hash calculation on the user sensitive information by using a preset hash algorithm to obtain a target hash value; a log positioning module configured to position a target desensitized log file from a log library according to the target masking value and the target hash value. The log library stores a plurality of desensitized log files, and user sensitive information in the desensitized log files is represented by a merging structure of a masking value and a hash value.

9. A computer device, comprising: comprise a memory and a processor, the memory stores computer readable instructions, and the processor implements the steps of the log positioning method according to any one of claims 1 to 7 when executing the computer readable instructions.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by the processor to implement the steps of the log positioning method according to any one of claims 1 to 7.