Data display method, system and equipment for interaction security and storage medium

By collecting user network parameters and interaction behavior data in real time, and combining environmental scores and user profiles to calculate a comprehensive weight, the data fuzziness level is dynamically adjusted, which solves the shortcomings of static data fuzzification methods and achieves data protection and user experience improvement under different environments and behaviors.

CN120973272AActive Publication Date: 2025-11-18XIAN SECLOVER INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510868650.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-11-18
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

Existing methods for blurring static data lack dynamic adjustment capabilities, cannot respond in real time to changes in user behavior and device environment, pose a risk of re-identification, and affect user experience and data security.

Method used

By collecting network parameters and interaction behavior data of target users in real time, environmental risk weights and user behavior risk weights are determined using an environmental scorer and user operation profiles. The comprehensive weight is calculated in combination with the data sensitivity level, the data fuzziness level is dynamically adjusted, and strategies such as data generalization processing, segmented masking processing, text replacement, and layer filters are used for data display.

Benefits of technology

It achieves dynamic blurring of data display, improves user experience and data security, reduces the risk of re-identification, and ensures data protection under different environments and behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120973272A_ABST
    Figure CN120973272A_ABST
Patent Text Reader

Abstract

The invention discloses an interaction security-oriented data display method, system and device and a storage medium, and relates to the technical field of data security, the method comprises the following steps: determining an environment risk weight at a current moment based on an environment scoring device according to network parameters of a target user in a current device environment collected in real time; determining a user behavior risk weight at the current moment based on the user operation portrait according to interaction behavior data, collected in real time, of the target user; according to the sensitivity level of the to-be-displayed data at the current moment, determining a data sensitivity weight at the current moment; determining a comprehensive weight according to the environment risk weight, the user behavior risk weight and the data sensitivity weight, and determining a fuzzy level of the to-be-displayed data at the current moment; and displaying the to-be-displayed data at the current moment according to a fuzzy strategy corresponding to the determined fuzzy level. According to the method, the visual fuzzy level of the data is dynamically adjusted in combination with multi-dimensional data such as the equipment environment, the user interaction behavior and the data sensitivity level.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, and in particular to an interactive security-oriented data display method, system, device and storage medium. BACKGROUND

[0002] At present, users often need to access content containing personal privacy or sensitive data in the process of using information systems. With the increasing requirements of data security and privacy protection, how to balance between user experience and privacy protection has become a key problem in actual business.

[0003] Traditional data desensitization and fuzzification display methods are mostly completed in the backend, only providing static processing results, which are difficult to adapt to changes in user behavior on the front-end page in real time, leading to a disconnection between the fuzziness of data display and the actual use scenario, affecting user experience, and possibly causing sensitive information leakage due to insufficient fuzziness of data display. Especially in medical, financial and social security scenarios, even if only part of the field information is exposed, combined with access mode, location and age information, there is still a risk that the fuzzified data can be re-identified. Therefore, we urgently need a dynamic adaptive data fuzzification display scheme. SUMMARY

[0004] The present application provides an interactive security-oriented data display method, system, device and storage medium, which solves the problems of lack of dynamic adjustment capability, lack of user behavior perception capability and risk of re-identification existing in the existing static data fuzzification mechanism.

[0005] To achieve the above purpose, the present application adopts the following technical solutions: In a first aspect, the present application provides an interactive security-oriented data display method, which comprises: determining the environmental risk weight at the current time based on an environment scorer according to the real-time collected network parameters of the target user in the current device environment; determining the user behavior risk weight at the current time based on a user operation portrait according to the real-time collected interaction behavior data of the target user; determining the data sensitivity weight at the current time according to the sensitive level of the data to be displayed at the current time; determining the comprehensive weight according to the environmental risk weight, the user behavior risk weight and the data sensitivity weight, and determining the fuzziness level of the data to be displayed at the current time according to the size of the comprehensive weight; the size of the comprehensive weight is positively correlated with the fuzziness level of the data to be displayed; According to the determined blur strategy corresponding to the blur level, the to-be-displayed data at the current moment is displayed; the size of the blur level is positively correlated with the preset data display blur degree in the blur strategy.

[0006] In a possible implementation, for each blur strategy corresponding to a blur level, when setting the data display blur degree, different preset processing manners are adopted for different types of sensitive data in the to-be-displayed data; the preset processing manners include data generalization processing, data segmentation masking processing, character replacement, and layer filter.

[0007] In a possible implementation, before the to-be-displayed data at the current moment is displayed according to the determined blur strategy corresponding to the blur level, the method further includes: obtaining a blur level customized by a user for sensitive data in the to-be-displayed data at the current moment; comparing the blur level determined according to the comprehensive weight and the customized blur level, and taking the blur level with a larger size as the final blur level.

[0008] In a possible implementation, when the to-be-displayed data at the current moment is displayed according to the determined blur strategy corresponding to the blur level, the method further includes: reading a blur strategy corresponding to the current rendering data in real time; determining whether the blur strategy corresponding to the current rendering data meets the requirement of the blur strategy corresponding to the determined blur level, to obtain a determination result; when the determination result is no, the current rendering data is forcibly switched to the blur strategy corresponding to the maximum blur level for display.

[0009] In a possible implementation, the method further includes: when the forced switching is performed, a gradual change animation or a mask layer is used to gradually increase the display blur degree of the current rendering data.

[0010] In a possible implementation, after the to-be-displayed data at the current moment is displayed according to the determined blur strategy corresponding to the blur level, the method further includes: monitoring the interactive behavior data of the target user collected in real time; when it is monitored that the target user is in an offline state, the blur level corresponding to the current displayed data is increased, and the display blur degree of the current displayed data is updated according to the blur strategy corresponding to the increased blur level; the offline state includes window defocus, tab switching, and no user interactive behavior within a preset time interval.

[0011] In a possible implementation, when the data display state is updated according to the blur strategy corresponding to the promoted blur level, the method specifically comprises the following steps. According to the blur strategy corresponding to the promoted blur level, the display blur degree of the current displayed data is gradually promoted by using a CSS level animation or a canvas level animation.

[0012] In a second aspect, the present application provides an interactive security-oriented data display system, which comprises: An environmental risk assessment module configured to determine an environmental risk weight at the current time based on an environmental score calculator according to real-time collected network parameters of a target user in a current device environment. A user behavior risk assessment module configured to determine a user behavior risk weight at the current time based on a user operation portrait according to real-time collected interactive behavior data of the target user. A data assessment module configured to determine a data sensitivity weight at the current time according to a sensitivity level of data to be displayed at the current time. A comprehensive weight determination module configured to determine a comprehensive weight according to the environmental risk weight, the user behavior risk weight, and the data sensitivity weight, and determine a blur level of the data to be displayed at the current time according to the size of the comprehensive weight; the size of the comprehensive weight is positively correlated with the blur level of the data to be displayed. A data display module configured to display the data to be displayed at the current time according to the blur strategy corresponding to the determined blur level; the size of the blur level is positively correlated with a preset data display blur degree in the blur strategy.

[0013] In a possible implementation, in the data display module, the blur strategy corresponding to each blur level is configured to, when setting a data display blur degree, adopt different preset processing modes for different types of sensitive data in the data to be displayed; the preset processing modes include data generalization processing, data segmentation masking processing, text replacement, and layer filter.

[0014] In a possible implementation, before the data display module displays the data to be displayed at the current time according to the blur strategy corresponding to the determined blur level, the data display module is further configured to perform the following steps: Obtain a blur level customized by a user for sensitive data in the data to be displayed at the current time. Compare the size of the blur level determined according to the comprehensive weight with the size of the customized blur level, and take the blur level with a larger size as the final blur level.

[0015] In a possible implementation, when the current data to be displayed is displayed according to the blur strategy corresponding to the determined blur level, the data display module is specifically configured to perform the following steps: reading a blur strategy corresponding to the current rendering data in real time; determining whether the blur strategy corresponding to the current rendering data meets the requirement of the blur strategy corresponding to the determined blur level, to obtain a determination result; when the determination result is no, forcibly switching the current rendering data to the blur strategy corresponding to the maximum blur level for display.

[0016] In a possible implementation, when the forced switching is performed, the data display module is configured to perform the following steps: gradually increasing the display blur degree of the current rendering data using a gradient animation or a mask layer.

[0017] In a possible implementation, the data display system further includes an off-site locking processing module, which is configured to perform the following steps after the current data to be displayed is displayed according to the blur strategy corresponding to the determined blur level: monitoring the interaction behavior data of the target user collected in real time; when it is monitored that the target user is in an offline state, increasing the blur level corresponding to the current displayed data, and updating the display blur degree of the current displayed data according to the blur strategy corresponding to the increased blur level; the offline state includes window defocus, tab switching, and no user interaction behavior within a preset time interval.

[0018] In a possible implementation, when the data display state is updated according to the blur strategy corresponding to the increased blur level, the off-site locking processing module is specifically configured to perform the following steps: according to the blur strategy corresponding to the increased blur level, gradually increasing the display blur degree of the current displayed data using a css level animation or a canvas level animation.

[0019] In a third aspect, the present application provides an electronic device, which includes a processor and a memory, the memory stores at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to realize the data display method for interaction security.

[0020] In a fourth aspect, the present application provides a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set are loaded and executed by a processor to implement the data display method for interaction security as described in any of the above aspects.

[0021] The data display method for interaction security provided by the embodiments of the present application can, in actual application, first determine an environment risk weight at the current time according to the network parameters of the target user in the current device environment collected in real time, determine a user behavior risk weight at the current time according to the interaction behavior data of the target user collected in real time, and determine a data sensitivity weight at the current time according to the sensitive level of the data to be displayed at the current time. Then, the comprehensive weight at the current time is determined according to the determined environment risk weight at the current time, the user behavior risk weight at the current time and the data sensitivity weight at the current time, and the fuzzy level of the data to be displayed at the current time is determined according to the comprehensive weight. Finally, the data to be displayed is displayed at a preset data blur degree according to the fuzzy strategy corresponding to the fuzzy level. The present application can dynamically adjust the visual blur level of the data in the process of the user interacting with the page, in combination with multi-dimensional data such as device environment, user interaction behavior and data sensitive level, so as to solve the problems of the existing static data blur mechanism, such as lack of dynamic adjustment ability, lack of user behavior perception ability and existence of re-identification risk. BRIEF DESCRIPTION OF DRAWINGS

[0022] Figure 1 A step flowchart of the data display method for interaction security provided by the embodiments of the present application; Figure 2 A structural block diagram of the data display system for interaction security provided by the embodiments of the present application. DETAILED DESCRIPTION

[0023] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the present application.

[0024] Hereinafter, the terms "first", "second", "third", etc. are used only for descriptive purposes and cannot be construed as indicating or implying relative importance or an indicated number of technical features. Therefore, the features defined with "first", "second", etc. can explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise stated, the meaning of "a plurality of" is two or more. In addition, the use of "based on" or "according to" means open and inclusive, because the process, step, calculation or other action based on one or more stated conditions or values can be based on additional conditions or values beyond those stated in practice.

[0025] Currently, the traditional data desensitization and fuzzing method has the problems of static fuzzing, lack of dynamic adjustment capability, lack of behavior perception mechanism, disconnection with system context, and difficulty in preventing re-identification attack.

[0026] Among them, the static fuzzing and lack of dynamic adjustment capability means that the existing data fuzzing display means are mostly based on the desensitization rules set by the backend, and the fuzzing degree of the display content is fixed, and the fuzzing degree of data display cannot be adjusted in real time according to user interaction behavior.

[0027] The lack of behavior perception mechanism means that the existing technology cannot monitor user interaction behavior data in real time, so as to dynamically adjust the fuzzing level of data according to the attention degree of the user to some data.

[0028] The disconnection with the system context means that the existing technology cannot dynamically adjust the fuzzing strategy in combination with the network parameters under the current device environment.

[0029] The difficulty in preventing re-identification attack means that even after the data desensitization processing, the combination of sensitive fields can be accurately inferred, and the existing technology cannot dynamically respond to improve the fuzzing level to block the data re-identification path.

[0030] In order to solve the problems of lack of dynamic adjustment capability, lack of user behavior perception capability and re-identification risk existing in the existing static data fuzzing mechanism, the embodiments of the present application provide a data display method, system, device and storage medium for interaction security.

[0031] As shown in Figure 1 The first aspect, the embodiments of the present application provide a data display method for interaction security, which comprises: Step 101, determining the environment risk weight at the current time based on the environment score according to the real-time collected network parameters of the target user under the current device environment.

[0032] Specifically, the network parameters of the target user in the current device environment collected in real time include, but are not limited to, a navigator.connection.effectiveType parameter for identifying whether the current device is connected to a 2G network, a 4G network or a WiFi network, a browser User-Agent parameter for identifying whether a regular browser is used by the current target user, a Data Saver parameter for identifying whether a data saving mode is enabled by the current target user, an IP address home location, whether a proxy or VPN behavior exists through browser fingerprinting or behavior characteristics, and a login parameter of a sensitive channel such as a remote desktop login, a cloud desktop, and an RDP environment (remote desktop environment). The collection of these parameters is for further judging the environment risk weight of the current device environment. In the embodiment, the real-time collection of the network parameters is specifically realized by an environment detector.

[0033] Then, the network parameters collected in real time are scored by an environment scorer to obtain the environment risk weight at the current time. The environment scorer has pre-defined environment parameter scoring rules. After receiving the network parameters collected in real time at the current time, the environment scorer determines the environment risk weight at the current time based on the pre-defined scoring rules. For example, when the network parameters at the current time indicate that the target user accesses data from a company intranet through a trusted browser, and the network delay is lower than a preset value, there is no proxy, and there is no VPN, the environment risk weight output by the environment scorer is relatively low, about 0.1, indicating that the environment risk at the current time is low risk. When it is detected that the user accesses data from an overseas proxy or there is a virtual desktop environment, and the network connection is unstable, the environment risk weight output by the environment scorer is relatively high, about 0.8 or even higher, indicating that the environment risk at the current time is high risk.

[0034] In the embodiment of the application, the environment scorer has pre-defined environment parameter scoring rules supporting configuration adjustment, that is, the user can adjust the trust network boundary of each network parameter and the corresponding scoring value according to the actual business demand of accessing data.

[0035] In the embodiment of the application, the environment scorer mainly evaluates the data risk brought by each network parameter collected in real time by the target user. For example, when it is detected that the current device environment: The data saving mode (Data Saver) is enabled, the scoring value of the environment risk weight is +0.2; It is in a remote desktop (RDP) or cloud desktop environment, the scoring value of the environment risk weight is +0.5; The browser used opens a traceless mode or a script interceptor plug-in, the scoring value of the environment risk weight is +0.3; If the IP address used is from a proxy / Tor / cloud host, the score of the environment risk weight is +0.4.

[0036] If the screen resolution of the device used is within a preset resolution range, the score of the environment risk weight is +0.2.

[0037] The environment scorer adds the scores according to the above evaluation rules, and outputs the total environment risk weight corresponding to the current device environment.

[0038] In addition, a risk judgment threshold can be preset in the environment scorer. According to the size of the output environment risk weight and the preset risk judgment threshold, the risk state of the current device environment is determined, which includes high risk and low risk, and a device environment warning is performed in the high risk state.

[0039] In step 102, according to the real-time collected interaction behavior data of the target user, the user behavior risk weight at the current time is determined based on the user operation portrait.

[0040] Specifically, a series of operation events of the target user on the data access page are collected in real time, including the hover time of the mouse, the number of clicks, the page switching frequency, whether it is the first access user, the interaction path in the page, etc., to obtain the interaction behavior data of the target user. In this embodiment, the collection of the interaction behavior data is realized by binding standard DOM events; wherein the DOM events include the events of mouseenter, mouseleave, click, and visibilitychange.

[0041] The real-time collected interaction behavior data of the target user at the current time is input into the user operation portrait constructed by the historical interaction behavior data, the interaction behavior of the target user at the current time is analyzed through the user operation portrait, so as to deduce the credibility or data use intention of the target user at the current time, and the interaction behavior data of the target user at the current time is scored to obtain the user behavior risk weight of the target user at the current time.

[0042] In this embodiment, the user operation portrait analysis obtains: If the data access page stays for less than 0.2s or the data access page is frequently refreshed, the score of the user behavior risk weight is +0.3; If the mouse movement trajectory is abnormal, such as straight or mechanical movement, the score of the user behavior risk weight is +0.3; If the data access page is only scrolled without clicking, the score of the user behavior risk weight is +0.2; If the sensitive field information such as the identity card number and the salary is frequently accessed, the scoring value of the user behavior risk weight is +0.4; If the browser tab is frequently switched or the focus is lost, the scoring value of the user behavior risk weight is +0.2.

[0043] The total user behavior risk weight corresponding to the current device environment is output by adding the scoring values according to the preset evaluation rules, and the data fuzzification degree defined should be higher for more abnormal behaviors when the data is fuzzified and displayed.

[0044] In actual application, the scoring rules and the scoring values set based on the user operation portrait can be customized according to actual business.

[0045] Step 103: determining the data sensitivity weight of the current moment according to the sensitive level of the data to be displayed at the current moment.

[0046] Specifically, since the sensitive degrees of different types of data in the data to be displayed are different, the data to be displayed is classified into different sensitive levels according to the sensitive degrees of different types of data in the present application, and different sensitive levels correspond to different predefined weight values.

[0047] In the present embodiment, the sensitive level of the mobile phone number, the identity card and the bank card number is S level, and the corresponding data sensitivity weight is +0.5; the sensitive level of the health information, the disease and the historical case is A level, and the corresponding data sensitivity weight is +0.4; the sensitive level of the address information, the consumption record and the visitor record is B level, and the corresponding data sensitivity weight is +0.3; the sensitive level of the age, the gender and the occupation is C level, and the corresponding data sensitivity weight is +0.2.

[0048] Therefore, in step 103, the data sensitivity weight corresponding to the type of data can be obtained according to the sensitive level of different types of data in the data to be displayed. And the sensitive level of different types of data and the corresponding data sensitivity weight can be adjusted according to the actual application scenario.

[0049] In the present embodiment, step 101, step 102 and step 103 are executed synchronously to obtain the environment risk weight, the user behavior risk weight and the data sensitivity weight of the current moment.

[0050] Step 104: determining the comprehensive weight according to the environment risk weight, the user behavior risk weight and the data sensitivity weight, and determining the fuzzification level of the data to be displayed at the current moment according to the size of the comprehensive weight.

[0051] The size of the comprehensive weight is positively correlated with the fuzzification level of the data to be displayed.

[0052] Specifically, the environment risk weight, the user behavior risk weight and the data sensitivity weight of the current moment determined in steps 101-103 are added to obtain a comprehensive weight. The blur level of the data to be displayed at the current moment is determined according to the size of the comprehensive weight and the preset threshold, and the greater the value of the comprehensive weight, the higher the blur level of the data to be displayed.

[0053] In the embodiment of the application, the blur level can be set as three levels of high blur level, medium blur level and low blur level, the preset threshold includes a first preset threshold and a second preset threshold, and the first preset threshold is greater than the second preset threshold. For example, the first preset threshold is 1.0, and the second preset threshold is 0.6; when the comprehensive weight is greater than or equal to 1.0, the blur level of the data to be displayed at the current moment is the high blur level; when the comprehensive weight is greater than or equal to 0.6 and less than 1.0, the blur level of the data to be displayed at the current moment is the medium blur level; and when the comprehensive weight is less than 0.6, the blur level of the data to be displayed at the current moment is the low blur level.

[0054] Step 105, displaying the data to be displayed at the current moment according to the blur strategy corresponding to the determined blur level.

[0055] The size of the blur level is positively correlated with the preset data display blur degree in the blur strategy.

[0056] The data display blur degree refers to the processing degree of converting the accurate value in the data into a fuzzy value, and the higher the blur level, the higher the data display blur degree.

[0057] Specifically, the blur strategy corresponding to the low blur level displays all the accurate data information completely; the blur strategy corresponding to the medium blur level displays the data with a sensitive level of C in plaintext, and performs data generalization processing on the data with a sensitive level of B and above; and the blur strategy corresponding to the high blur level performs data generalization processing on the data with a sensitive level of C and above, and the data generalization processing degree of the high blur level is greater than that of the medium blur level.

[0058] In this embodiment, the low blur level displays all the accurate information completely; the medium blur level displays the age as "33 years old", displays the address as "a city", and retains the integer part of the amount; and the high blur level displays the age as "30-40 years old", displays the address as "a province", and displays the amount as "1W-2W".

[0059] The method for data display facing interactive security provided by the embodiment of the application in practical application first determines the environment risk weight of the current moment according to the network parameters of the target user in the current device environment collected in real time, determines the user behavior risk weight of the current moment according to the interactive behavior data of the target user collected in real time, and determines the data sensitivity weight of the current moment according to the sensitive level of the data to be displayed at the current moment; then, the comprehensive weight of the current moment is determined according to the determined environment risk weight, user behavior risk weight and data sensitivity weight of the current moment, and the fuzzy level of the data to be displayed at the current moment is determined according to the comprehensive weight; finally, the data to be displayed is displayed at a preset data fuzzy degree according to the fuzzy strategy corresponding to the fuzzy level.

[0060] The application can dynamically adjust the visual fuzzy level of data in the process of user and page interaction, combining multi-dimensional data such as device environment, user interactive behavior and data sensitive level, so as to solve the problems of lack of dynamic adjustment ability, lack of user behavior perception ability and existence of re-identification risk in the existing static data fuzzy mechanism.

[0061] Further, for the fuzzy strategy corresponding to each fuzzy level, different preset processing methods are adopted for different types of sensitive data in the data to be displayed when setting the data display fuzzy degree.

[0062] The preset processing method includes data generalization processing, data segmentation mask processing, character replacement and layer filter.

[0063] Compared with the traditional fuzzy strategy, only character replacement (for example: *** ) is used to realize coarse-grained coding processing, the fuzzy strategy of the application provides diversified fuzzy strategies for different types of sensitive fields. For example, when displaying the age, according to the size of the comprehensive weight, the actual age "43" is generalized to "40~45", "40+", "middle-aged person" and other generalized expressions; when displaying the region information, the geographical space level fuzzy strategy is adopted, the actual address is displayed normally at a low fuzzy level, the address is generalized to "Haidian District, Beijing" at a medium fuzzy level, and the address is generalized to "Beijing" or "North China Region" at a high fuzzy level, realizing the data minimization principle and use scene compatibility.

[0064] In the display of the bank card number field, a rendering strategy is adopted to perform segmented fuzzy processing on the bank card number field in the manner of data segmentation mask processing, character replacement and layer filter according to the fuzzy level of the comprehensive weight. For example, the bank card number field "6222 8888 1234 5678" is displayed in full text at a low fuzzy level, is partially fuzzy processed into "6222 8888 1234 ****" or "6222 **** ****5678" at a medium fuzzy level, and is fully fuzzy processed into "**** **** **** ****" at a high fuzzy level.

[0065] Further, before displaying the data to be displayed at the current time according to the fuzzy strategy corresponding to the determined fuzzy level, the method further comprises: obtaining a fuzzy level customized by the user for the sensitive data in the data to be displayed at the current time.

[0066] comparing the fuzzy level determined according to the comprehensive weight and the customized fuzzy level, and taking the one with the larger fuzzy level as the final fuzzy level.

[0067] That is, the application further introduces a forced security strategy to limit the minimum threshold of data fuzzy display on the basis of dynamic weight judgment, so as to ensure that even if the user view bypasses the fuzzy limitation of the application through the behavior of "brushing credibility", the minimum accessible control of sensitive data can be realized.

[0068] Specifically, for each type of sensitive data in the data to be displayed, such as ID number, bank card, address, mobile phone number and other sensitive information, a set of independent fuzzy constraint rules can be separately set for each type of sensitive data, which customizes the fuzzy level of different sensitive data. Among the fuzzy level determined according to the comprehensive weight and the customized fuzzy level, the one with the larger fuzzy level is taken as the final fuzzy level of the sensitive data.

[0069] In this embodiment, the forced security strategy settings for the sensitive data in the data to be displayed include but are not limited to minimum fuzzy weight setting, internal network access setting, prohibition of full text display setting and mouse hovering time limit setting.

[0070] The minimum fuzzy weight setting refers to customizing the minimum fuzzy level of a certain sensitive data. For example, for a certain sensitive data, when the customized minimum fuzzy level is 0.7, even if the calculated comprehensive weight is only 0.3, the fuzzy level corresponding to 0.7 is taken as the final fuzzy level, and the sensitive data can only be displayed in a partially fuzzy state or a fully fuzzy state.

[0071] The intranet access setting refers to limiting a certain sensitive data to be displayed only in an intranet or a white list IP range. If it is detected that the current network environment is a public network, a VPN or a cloud host environment, the sensitive value is forced to be displayed in a blurred manner.

[0072] The full plaintext display prohibition setting refers to limiting a certain sensitive data to be displayed in a forced blurred manner such as a tail plaintext, a prefix blur or an interval value even in a trusted environment.

[0073] The mouse hovering time limit setting specifically refers to setting a maximum threshold for hovering to prevent a user from hovering for too long or an OCR tool from identifying data field information. When the threshold is exceeded, the field re-blurring mechanism is triggered, and an alarm prompt is displayed.

[0074] Further, when displaying the current time data to be displayed according to the blurring strategy corresponding to the determined blurring level, the method further comprises: reading the blurring strategy corresponding to the current rendering data in real time.

[0075] determining whether the blurring strategy corresponding to the current rendering data meets the requirements of the blurring strategy corresponding to the determined blurring level, to obtain a determination result.

[0076] When the determination result is no, the current rendering data is forced to be switched to the blurring strategy corresponding to the maximum blurring level for display.

[0077] In this embodiment, the front-end component reads the blurring strategy corresponding to the data in real time when rendering the current data, and determines whether the blurring strategy corresponding to the current rendering data meets the requirements of the blurring strategy corresponding to the determined blurring level. If the requirements are not met, the current rendering data is forced to be switched to the blurring strategy corresponding to the maximum blurring level for display, and the access behavior and the triggering time are recorded in the console log for subsequent security audit work.

[0078] Further, when forced switching is performed, a gradual transition animation or a mask layer is used to gradually increase the display blurring degree of the current rendering data.

[0079] That is, the present embodiment has a policy-level animation response mechanism. When forced switching occurs, a gradual transition animation or a mask layer is used for visual feedback to avoid instantaneous jumps in information and improve the naturalness of user experience. At the same time, the blurring animation distinguishes between "system active policy response" and "normal blur gradual display" in terms of behavior differences, further enhancing traceability.

[0080] The application can force switching of the blur strategy corresponding to the maximum blur level for display when it is monitored that the user is in a high-risk environment such as public Wi-Fi or remote desktop, to prevent user misoperation or tampering with the client state, thereby improving the anti-recognition ability and robustness of the system.

[0081] Further, after the current time to be displayed data is displayed according to the blur strategy corresponding to the determined blur level, the method further comprises: Monitoring the real-time collected interactive behavior data of the target user.

[0082] When it is monitored that the target user is in an offline state, the blur level of the current displayed data is improved, and the display blur degree of the current displayed data is updated according to the blur strategy corresponding to the improved blur level.

[0083] The offline state includes window defocus, tab switching, and no user interactive behavior within a preset time interval.

[0084] Further, when the data display state is updated according to the blur strategy corresponding to the improved blur level, the method specifically comprises: According to the blur strategy corresponding to the improved blur level, the display blur degree of the current displayed data is gradually improved by using a css level animation or a canvas level animation.

[0085] That is, in the actual data access process, the user's interruption operation in a short time, such as switching browser tabs, minimizing the window, leaving the keyboard, etc., will cause sensitive data to be exposed to others, forming a data leakage risk. Therefore, the application sets a "fallback blur animation mechanism", and uses the mechanism as the ending link of the dynamic data blur display scheme. When it is monitored that the user leaves the operation environment, that is, the user is in an offline state, the plaintext and low blur level data in all displayed data are automatically restored to a higher blur level, and the visual effect is over-prompted to ensure that the data returns to a high blur level by default in the state of no user interaction.

[0086] In the embodiment of the application, the fallback blur animation mechanism is realized based on the animation triggering system combined with the real-time monitoring of the interactive behavior data and the data blur level control state.

[0087] Specifically, the window defocus, tab switching, and no user interactive behavior within a preset time interval in the interactive behavior data are monitored to determine whether the user enters an offline state, and if the user enters an offline state, the blur fallback logic is triggered.

[0088] To avoid the impact of data mutation on user experience, the css level animation or canvas level animation is used to gradually change the displayed data from plaintext state or semiplaintext state to completely blurred state. The visualization gradient effect not only conforms to the current UI design trend, but also provides the user with a clear "security state switching" prompt.

[0089] Further, after the blur animation is executed, the data that has been displayed with the adjusted blur degree will not be immediately restored to plaintext display. Only when the user reenters the interactive state, for example, the cursor is moved above the data or actively clicked to view, will the original display blur degree be restored. This design aims to prevent the direct exposure of sensitive data caused by "mistaken return". The application also supports setting a "unlocking cooling period" for the data, that is, the original text cannot be directly viewed within a certain period of time after the blur rollback.

[0090] Further, each field of sensitive data maintains an independent animation state controller at the component level, supporting the animation triggering and termination of the field intensity. This design facilitates the extension of the blur logic of specific fields in the later stage, such as using a blur mask for identity information and using dynamic blur processing for amount fields.

[0091] The data display method for interactive security of the application can dynamically adjust the blur strategy according to the network parameters, interactive behavior data, and the sensitivity level of the data to be displayed at the current time, and customize the security level of the display, thereby improving the security of data display while ensuring the controllability and smoothness of user interaction experience.

[0092] When determining the user behavior risk weight, the application can perceive behavior characteristics such as dwell time, operation frequency, and click trajectory of user operations, and combine network environment states (for example, whether in an RDP remote environment, data saving mode, network fluctuation environment, etc.) to accurately assess the data display risk level.

[0093] The application determines the comprehensive weight by using the current time data of three dimensions of environmental risk weight, user behavior risk weight, and sensitivity level of the data to be displayed, thereby determining the blur level corresponding to the current time data, realizing dynamic allocation of the blur degree, and realizing automatic upgrading or downgrading of the blur measurement, thereby improving the self-adjusting and self-recovery ability of the scheme and reducing manual intervention.

[0094] The application inherits the comprehensive weight determination result, that is, the blur level of the data to be displayed corresponding to the result, through a backend interface, and feeds back the corresponding blur strategy; after the front-end component receives the above-mentioned instruction sent by the back-end component, the corresponding blur strategy is automatically rendered, and the "cloud unified management and front-end immediate response" of the blur strategy is truly realized.

[0095] The enforcement mechanism provided by the application can force the opening of the display mode corresponding to the highest blur level in a high-risk environment, prevent user misoperation or tampering with the client state, and thus improve the anti-recognition ability and robustness of the system.

[0096] The user offline automatic blur fallback mechanism provided by the application can immediately mask sensitive information based on a blur fallback animation when the user is offline, effectively prevent information leakage or bystander attacks, and guarantee the "leave immediately lock" security of the content.

[0097] In the embodiment of the application, the technical architecture of the data display scheme facing interactive security includes a perception layer, a decision layer and a display layer. The collection of network parameters in the current device environment and the collection of user interaction behavior data are both implemented in the perception layer, and the core goal of this layer is to provide trusted environment and behavior data to provide the basis for the blur strategy decision of the upper layer, and to ensure that the dynamic blur scheme of the application achieves intelligent balance between security and usability.

[0098] Among them, the collection of network parameters in the current device environment is realized through a network environment identification module, which identifies potential risk factors by monitoring the network environment accessed by the client in real time. Specifically, the module mainly collects information including the public IP address of the client, the low-bit region to which the IP belongs, whether it is linked through a proxy or a VPN, whether it is from a company intranet, the first network type (such as cellular mobile network, home broadband), etc. The front-end javascript script is used to preliminarily judge the network type (such as detecting the local area network address leaked by WebRTC, User-Agent information, etc.), and the back-end interface is called to further query the IP location, operator information and whether it hits the IP blacklist of VPN or anonymous proxy. That is, the network environment identification module in the perception layer of the application effectively identifies behaviors such as overseas malicious crawlers, users using VPN to disguise location, or temporary external device access behaviors with data leakage risks, thereby providing the basis for subsequent data blur degree.

[0099] The collection of the user's interaction behavior data is tracked by the user behavior monitoring module, which continuously tracks the user's interaction behavior in the page and evaluates the authenticity and risk of the access. Specifically, the module listens to a series of operation events of the user in the page, including the mouse hover event (hoverTime), the number of clicks (clickCount), the page switching frequency, whether it is the first access of the user, the interaction path in the page, etc. The collection of these behavior data is mainly realized by binding standard DOM events such as mouseenter, mouseleave, click, visibilitychange, etc. By collecting these data, a user operation portrait is constructed to determine whether the visitor is a real user with normal use intention or a script program simulating behavior using an automated tool. In some high-security scenarios, the module can also combine a behavior recognition model (such as sliding track stability judgment) to further enhance the accuracy of user credibility determination.

[0100] In summary, the perception layer is the infrastructure for collecting underlying data. Through real-time perception and quantification of two-dimensional data of network environment and user behavior, key inputs are provided for upper-layer dynamic fuzzy weight calculation and policy execution, enabling the entire fuzzy processing mechanism to have intelligent adjustment capabilities that are "different for different people, different for different times, and different for different environments". This perception-driven front-end fuzzy display method significantly improves the adaptive and security protection capabilities of the processing architecture, and is one of the basic supports for the technical innovation of the present application The decision layer is located above the perception layer and mainly undertakes the intelligent decision function of the fuzzy display degree. The core of the design of this layer is to combine multi-dimensional perception data such as user behavior and access environment, to dynamically adjust the display clarity of the front-end sensitive information through weight calculation and policy engine, so as to maximize the reduction of data leakage risk while ensuring user usability. That is, based on the comprehensive weight determined by the real-time collected network parameters, interaction behavior data and sensitive level of the display data, the data display fuzzy degree is dynamically adjusted. For example: when the system identifies that the user's current network environment is not intranet and there are proxy access features, even if the behavior trajectory of the user is displayed as a normal user, the corresponding comprehensive weight will control the final data to be displayed with highly fuzzy sensitive information interface; on the contrary, in a trusted network environment, such as when the user accesses the enterprise intranet and shows consistent, stable and credible interaction behavior, the display fuzzy degree of the data will be gradually reduced, so that the sensitive information can be normally used.

[0101] In addition to the comprehensive weight calculation, the decision layer also sets a policy enforcement mechanism, that is, a user-defined sensitive level is set for a certain sensitive data, and the front-end component will compare the current state with the policy before rendering. When the sensitive level corresponding to the comprehensive weight is lower than the user-defined sensitive level, the forced fuzzy display is automatically enabled to avoid data leakage caused by misjudgment.

[0102] Therefore, the decision layer not only realizes the "intelligent control" of the front-end layer, but also forms a closed-loop management and control system from data perception to policy landing through accurate inheritance of organizational strategies, has high practicality and engineering landing value, and is one of the key technical innovations of the application.

[0103] The display layer undertakes the key role of specifically visualizing the results of "security perception + risk decision". The core design is not only the traditional "code punching" process, but also a multi-level, semantic perception, and progressive fuzzy display scheme based on the determined comprehensive weight for multiple types of sensitive data. The display layer can make the content seen by the user in different access contexts present dynamic and controllable fuzzy visual feedback, thereby balancing the data use efficiency and the practical needs of privacy protection.

[0104] When performing graphic rendering, the display layer combines CSS mask and Canvas filter technology and supports high-security-level rendering modes to prevent screenshot recognition and OCR attacks. In addition, to enhance the dynamic nature of protection, the display layer integrates an animation rollback mechanism; when the user's mouse leaves the sensitive area, the page is switched, or the operation times out, the system will automatically trigger the onBlur animation to gradually restore the maximum blur, preventing information leakage caused by subsequent screen sharing, page screenshots, or front-end residues.

[0105] Therefore, the display layer not only embodies the fine adjustment of the blur granularity, but also builds a more humanized and intelligent visual privacy protection component through semantic understanding and data type adaptation, which is suitable for practical deployment in medical, financial, e-commerce, and other scenarios, and has significant technical promotion value and innovation.

[0106] Among the perception layer, decision layer, and display layer of the data display scheme technical architecture for interactive security, the perception layer is responsible for providing real-time data; the decision layer calls the data of the perception layer and outputs the comprehensive weight combined with the preset strategy; the display layer determines the blur degree of data display using the comprehensive weight and complex animation feedback. The entire technical architecture realizes the closed-loop control of "environment + behavior perception --> decision scoring --> visual output".

[0107] As shown in Figure 2 , in a second aspect, the embodiments of the application also provide a data display system for interactive security, which comprises: An environment risk assessment module 201 is configured to determine an environment risk weight at the current time based on an environment scorer according to the network parameters of a target user in a current device environment collected in real time; A user behavior risk assessment module 202 is configured to determine a user behavior risk weight at the current time based on a user operation portrait according to the interactive behavior data of the target user collected in real time; The data evaluation module 203 is configured to determine a data sensitivity weight of the current moment according to a sensitivity level of the data to be displayed at the current moment. The comprehensive weight determination module 204 is configured to determine a comprehensive weight according to the environmental risk weight, the user behavior risk weight, and the data sensitivity weight, and determine a blur level of the data to be displayed at the current moment according to the size of the comprehensive weight; the size of the comprehensive weight is positively correlated with the blur level of the data to be displayed. The data display module 205 is configured to display the data to be displayed at the current moment according to the blur strategy corresponding to the determined blur level; the size of the blur level is positively correlated with a preset data display blur degree in the blur strategy.

[0108] Further, in the data display module 205, the blur strategy corresponding to each blur level is configured to, when setting the data display blur degree, adopt different preset processing manners for different types of sensitive data in the data to be displayed; the preset processing manners include data generalization processing, data segmentation mask processing, character replacement, and layer filter.

[0109] Further, before displaying the data to be displayed at the current moment according to the blur strategy corresponding to the determined blur level, the data display module 205 is further configured to perform: Obtain a blur level of sensitive data in the data to be displayed at the current moment customized by the user; Compare the size of the blur level determined according to the comprehensive weight with the blur level customized by the user, and take the blur level with a larger size as the final blur level.

[0110] Further, when displaying the data to be displayed at the current moment according to the blur strategy corresponding to the determined blur level, the data display module 205 is specifically configured to perform: Real-time read the blur strategy corresponding to the current rendering data; Determine whether the blur strategy corresponding to the current rendering data meets the requirement of the blur strategy corresponding to the determined blur level, to obtain a determination result; When the determination result is no, forcibly switch the current rendering data to the blur strategy corresponding to the maximum blur level for display.

[0111] Further, when performing the forced switching, the data display module 205 is configured to perform: Use a gradual animation or a mask layer to gradually improve the display blur degree of the current rendering data.

[0112] Further, the data display system further includes an off-site locking processing module, which is configured to perform, after displaying the data to be displayed at the current moment according to the blur strategy corresponding to the determined blur level: Monitor the real-time collected interaction behavior data of the target user; When it is monitored that the target user is in an offline state, the blur level corresponding to the current displayed data is promoted, and the display blur degree of the current displayed data is updated according to the blur strategy corresponding to the promoted blur level; the offline state includes window defocus, tab switching, and no user interaction behavior within a preset time interval.

[0113] Further, when the data display state is updated according to the blur strategy corresponding to the promoted blur level, the off-site locking processing module is specifically configured to perform: According to the blur strategy corresponding to the promoted blur level, the display blur degree of the current displayed data is gradually promoted by using a CSS level animation or a canvas level animation.

[0114] The data display system for interaction security provided by the embodiments of the present application is used to execute the data display method for interaction security described above, and thus can achieve the same effects as the data display method for interaction security described above.

[0115] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the system, device and unit described above can refer to the corresponding processes in the foregoing method embodiments, which will not be described herein.

[0116] In a third aspect, the embodiments of the present application also provide an electronic device, which includes a processor and a memory, and the memory stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to realize the data display method for interaction security in the embodiments of the present application.

[0117] In a fourth aspect, the embodiments of the present application also provide a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to realize the data display method for interaction security in the embodiments of the present application.

[0118] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through a wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)) and the like.

[0119] The above description is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed by the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data display method for interactive security, characterized in that, include: Based on the network parameters of the target user in the current device environment collected in real time, the environmental risk weight at the current moment is determined based on the environmental scorer. Based on the real-time collected interaction behavior data of the target users, the risk weight of user behavior at the current moment is determined according to the user operation profile; Determine the data sensitivity weight at the current moment based on the sensitivity level of the data to be displayed at the current moment; A comprehensive weight is determined based on the environmental risk weight, the user behavior risk weight, and the data sensitivity weight, and the fuzziness level of the data to be displayed at the current moment is determined based on the magnitude of the comprehensive weight. The magnitude of the comprehensive weight is positively correlated with the fuzziness level of the data to be displayed; Based on the fuzzy strategy corresponding to the determined fuzziness level, the data to be displayed at the current moment is displayed; The magnitude of the fuzziness level is positively correlated with the preset fuzziness level of the data display in the fuzziness strategy.

2. The data display method for interactive security according to claim 1, characterized in that, For each blur level, different preset processing methods are used for different types of sensitive data in the data to be displayed when setting the blur level of data display. The preset processing methods include data generalization processing, data segmentation masking processing, text replacement and layer filters.

3. The data display method for interactive security according to claim 1, characterized in that, Before displaying the data to be displayed at the current moment according to the fuzzy strategy corresponding to the determined fuzziness level, the method further includes: Obtain the user-defined fuzziness level for sensitive data in the data to be displayed at the current moment; The fuzzy level determined based on the comprehensive weight is compared with the custom fuzzy level, and the fuzzy level with the larger fuzzy level is taken as the final fuzzy level.

4. The data display method for interactive security according to claim 1, characterized in that, When displaying the data to be displayed at the current moment according to the fuzzy strategy corresponding to the determined fuzziness level, the method further includes: Real-time reading of the blurring strategy corresponding to the current rendering data; Determine whether the blurring strategy corresponding to the current rendered data meets the requirements of the blurring strategy corresponding to the determined blur level, and obtain the determination result; If the judgment result is negative, the current rendering data will be forcibly switched to the blur strategy corresponding to the maximum blur level for display.

5. The data display method for interactive security according to claim 4, characterized in that, The method further includes: when performing a forced switch, using a gradient animation or a mask layer to gradually increase the display blur of the currently rendered data.

6. The data display method for interactive security according to claim 1, characterized in that, After displaying the data to be displayed at the current moment according to the fuzzy strategy corresponding to the determined fuzziness level, the method further includes: Monitor the interactive behavior data of the target user collected in real time; When the target user is detected to be offline, the blur level of the currently displayed data is increased, and the blur level of the currently displayed data is updated according to the blur strategy corresponding to the increased blur level. The offline state includes window out of focus, tab switching, and no user interaction within a preset time interval.

7. The data display method for interactive security according to claim 6, characterized in that, When updating the data display status according to the fuzzy strategy corresponding to the improved fuzziness level, the method is specifically as follows: Based on the blurring strategy corresponding to the improved blur level, the blur level of the currently displayed data is gradually increased using CSS layer animation or canvas layer animation.

8. A data display system for interactive security, characterized in that, include: The environmental risk assessment module is used to determine the environmental risk weight at the current moment based on the network parameters of the target user in the current device environment collected in real time and the environmental scorer. The user behavior risk assessment module is used to determine the user behavior risk weight at the current moment based on the user operation profile and the real-time collected interaction behavior data of the target user. The data evaluation module is used to determine the data sensitivity weight at the current moment based on the sensitivity level of the data to be displayed at the current moment; The comprehensive weight determination module is used to determine a comprehensive weight based on the environmental risk weight, the user behavior risk weight, and the data sensitivity weight, and to determine the fuzziness level of the data to be displayed at the current moment based on the magnitude of the comprehensive weight. The magnitude of the comprehensive weight is positively correlated with the fuzziness level of the data to be displayed; The data display module is used to display the data to be displayed at the current time according to the fuzziness strategy corresponding to the determined fuzziness level; the magnitude of the fuzziness level is positively correlated with the preset data display fuzziness degree in the fuzziness strategy.

9. An electronic device, characterized in that, The electronic device includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the data display method for interactive security as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement the data display method for interactive security as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Data access management method and device

    CN118138256A

  • Sensitive data protection method and device, equipment and storage medium

    CN120046182A

  • Progressive display alteration in real-time to effect desirable behavior

    US20180190175A1