Data masking method and apparatus
By dividing two handshakes in dynamic data desensitization technology, data collection, processing, cache and position conversion are carried out, the problem of insufficient real-time data desensitization in the prior art is solved, and a more efficient data desensitization process is achieved.
Patent Information
- Application Number
- PCT/CN2024/137089
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-12-05
- Publication Date
- 2025-06-19
AI Technical Summary
The existing dynamic data desensitization technology has insufficient real-time performance in the cache and extraction of desensitized locations, which leads to a long time-consuming process and the inability to promptly feedback on the desensitized page, and the page may be stuttered.
By dividing two handshakes between the Lua and the desensitized parties, data collection, processing, cache and position conversion are performed to reduce component dependence, and avoid bursting of memory and improve real-time performance by first cached the previous packet and its desensitized location.
This method greatly improves the real-time and efficiency of data desensitization, avoids page lag, and effectively deals with the situation where truncated information cannot be desensitized, avoids the situation of memory explosion.
Smart Images

Figure CN2024137089_19062025_PF_FP_ABST
Abstract
Description
Data desensitization method and device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 13, 2023, with application number 2023117145666, entitled “A Data Desensitization Method and Device,” the entire contents of which are incorporated herein by reference. Technical Field
[0002] The present application belongs to the field of data processing technology, and in particular relates to a data desensitization method and device. Background Art
[0003] With the rapid development of information technology and the widespread use of data, people are increasingly concerned about personal privacy and data protection. Over the past few years, numerous large-scale data breaches have occurred, including leaks of sensitive data such as personal information, credit card details, and medical records. Data desensitization is a common technique used in data security to protect sensitive information.
[0004] In the related art, the existing desensitization technology has two methods: static data desensitization and dynamic data desensitization. Static desensitization technology requires obtaining the data exported from the database at one time and then desensitizing the data, while dynamic desensitization technology is performed in real time when the data is read. With the development of big data, most of the current patents adopt the dynamic desensitization method, and the dynamic desensitization method will first cache the package, then extract the desensitized position, and finally desensitize. The real-time performance of this desensitization order is poor. If it needs to be cached all the time and if the amount of cached data is large at the end, this will not only make the extraction of the desensitized position process more time-consuming, but also fail to provide timely feedback to the user on the desensitized page, which may cause page freezes. Therefore, how to better implement data desensitization has become an urgent problem to be solved. Summary of the Invention
[0005] In view of the above deficiencies in the prior art, the purpose of the invention is to provide a data desensitization method and device, which reduces the dependency between components and avoids memory overflow, and also greatly improves real-time performance and efficiency.
[0006] In a first aspect of the present application, a data desensitizing method is proposed, which is applied to a Lua party and includes: obtaining multiple data packets and sending a location request to a desensitizing party, wherein the location request is used to request the desensitized locations of the multiple data packets; upon receiving the desensitized locations of the multiple data packets, caching the multiple data packets and the desensitized locations of the multiple data packets; converting or splicing the multiple data packets to obtain the target desensitized locations of the multiple data packets, and sending a desensitizing request to the desensitizing party, wherein the desensitizing request is used to request desensitization of the multiple data packets; upon receiving the desensitized multiple data packets, sending the desensitized multiple data packets to a user.
[0007] Furthermore, multiple data packets are obtained and location requests are sent to the desensitizing party, and the location requests are used to request the desensitized locations of the multiple data packets, including: obtaining the first data packet for the first time and sending a first location request to the desensitizing party, and the first location request is used to request the desensitized location of the first data packet; obtaining the second data packet for the second time and sending a second location request to the desensitizing party, and the second location request is used to request the desensitized location of the second data packet; obtaining the third data packet for the third time and sending a third location request to the desensitizing party, and the third location request is used to request the desensitized location of the third data packet.
[0008] Furthermore, the multiple data packets are converted or spliced to obtain target desensitized positions of the multiple data packets, including: converting the desensitized position of the first data packet and the desensitized position of the second data packet to obtain the target desensitized position of the first data packet; splicing the desensitized position of the second data packet and the desensitized position of the third data packet to obtain the spliced data packet and the target desensitized position corresponding to the spliced data packet.
[0009] Furthermore, the desensitizing position of the first data packet and the desensitizing position of the second data packet are converted to obtain the target desensitizing position of the first data packet, including: when it is determined that the value corresponding to the desensitizing starting position of the second data packet is greater than the length of all processed packets, the desensitizing position of the first data packet is used as the target desensitizing position of the first data packet; when it is determined that the value corresponding to the desensitizing starting position of the second data packet is less than the length of all processed packets, the desensitizing position of the first data packet is converted, and the converted desensitizing position is used as the target desensitizing position of the first data packet.
[0010] According to a second aspect of the present application, a data desensitization method is proposed, which is applied to a desensitizing party and includes: receiving a location request sent by a Lua party, the location request being used to request desensitized locations of a plurality of data packets; determining the desensitized locations of the plurality of data packets, and sending the desensitized locations of the plurality of data packets to the Lua party; receiving a desensitization request sent by the Lua party, the desensitization request being used to request desensitization of the plurality of data packets; desensitizing the plurality of data packets according to the desensitization request, and sending the desensitized plurality of data packets to the Lua party.
[0011] Furthermore, determining the desensitization positions of the multiple data packets includes: obtaining the multiple data packets; and determining the desensitization position of each data packet based on the multiple data packets and desensitization rules.
[0012] Furthermore, the multiple data packets are desensitized according to the desensitization request, and the desensitized multiple data packets are sent to the Lua party, including: determining the type of data in each data packet; desensitizing each data packet according to the data type and the desensitization algorithm; and sending each desensitized data packet to the Lua party.
[0013] The third aspect of the present application proposes a data desensitizing device, which is applied to the Lua party and includes: an acquisition module, used to acquire multiple data packets and send a location request to the desensitizing party, wherein the location request is used to request the desensitized locations of the multiple data packets; a cache module, used to cache the multiple data packets and the desensitized positions of the multiple data packets when the desensitized positions of the multiple data packets are received; a first sending module, used to convert or splice the multiple data packets to obtain the target desensitized positions of the multiple data packets, and send a desensitizing request to the desensitizing party, wherein the desensitizing request is used to request desensitization of the multiple data packets; a second sending module, used to send the desensitized multiple data packets to the user when the desensitized multiple data packets are received.
[0014] In the fourth aspect of the present application, a data desensitizing device is proposed, which is applied to a desensitizing party and includes: a first receiving module for receiving a location request sent by a Lua party, wherein the location request is used to request the desensitized locations of multiple data packets; a third sending module for determining the desensitized locations of the multiple data packets and sending the desensitized locations of the multiple data packets to the Lua party; a second receiving module for receiving a desensitizing request sent by the Lua party, wherein the desensitizing request is used to request desensitization of the multiple data packets; and a fourth sending module for desensitizing the multiple data packets according to the desensitizing request and sending the desensitized multiple data packets to the Lua party.
[0015] In the fifth aspect of the present application, an electronic device is proposed, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute any method in the first aspect of the present application or execute any method in the second aspect of the present application.
[0016] The beneficial effects of this application are as follows:
[0017] The method and device described in this application are divided into two handshake parties during the entire data desensitization process: the Lua party for data collection, processing, caching and position conversion, and the desensitization party for obtaining the desensitized position and desensitization, which reduces the dependency between the various components. And by caching the previous package and its desensitized position first, the problem that the truncated information cannot be obtained in the complete desensitized position is solved. Only a small part of the truncation situation cannot be completely desensitized, but this can avoid the situation of memory explosion, and also greatly improve the real-time performance and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings are only for the purpose of illustrating specific embodiments and are not to be considered as limiting the present application. Throughout the drawings, the same reference numerals represent the same components. Obviously, the drawings described below are only some of the embodiments described in the present application. Those skilled in the art can also obtain other drawings based on these drawings.
[0019] FIG1 is a hardware structure block diagram of a terminal device of a data desensitization method according to an embodiment of the present application;
[0020] FIG2 is a flow chart of a data desensitization method according to an embodiment of the present application;
[0021] FIG3 is a flow chart of a data desensitization method according to another embodiment of the present application;
[0022] FIG4 is a schematic diagram of a data desensitization method according to a specific embodiment of the present application;
[0023] FIG5 is a structural block diagram of a data desensitization device according to an embodiment of the present application;
[0024] FIG6 is a structural block diagram of a data desensitization device according to another embodiment of the present application. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present application, the technical solutions of the present application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work should fall within the scope of protection of this application.
[0026] Furthermore, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts disclosed in this application.
[0027] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "center", "up", "down", "left", "right", "vertical", "horizontal", "inside", "outside" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application. In addition, the terms "first", "second" and "third" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance. The terms "installed", "connected" and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or an indirect connection through an intermediate medium, or it can be a communication between the internal parts of two elements. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0028] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of methods and systems consistent with certain aspects of the present application, as detailed in the appended claims.
[0029] According to one aspect of an embodiment of the present application, a data desensitization method is provided, which can be executed in a terminal device or a similar computing device. Taking operation on a terminal device as an example, FIG1 is a hardware structure block diagram of an electronic device of a data desensitization method according to an embodiment of the present application. As shown in FIG1 , the terminal device may include one or more (only one is shown in FIG1 ) processors 102 (the processor 102 may include but is not limited to a microprocessor (Microprocessor Unit, referred to as MPU) or a programmable logic device (Programmable logic device, referred to as PLD)) and a memory 104 for storing data. In an exemplary embodiment, the terminal device may also include a transmission device 106 and an input / output device 108 for communication functions. It will be understood by those skilled in the art that the structure shown in FIG1 is only illustrative and does not limit the structure of the terminal device. For example, the terminal device may also include more or fewer components than those shown in FIG1 , or have a different configuration with equivalent functions or more functions than those shown in FIG1 .
[0030] The memory 104 can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the level determination method in the embodiments of the present application. The processor 102 executes the computer program stored in the memory 104 to execute various functional applications and data processing, thereby implementing the above-mentioned method. The memory 104 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the terminal device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0031] The transmission device 106 is used to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by a communications provider of a switching device. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0032] A Web Application Firewall (WAF) is a firewall specifically designed to protect web applications. OpenResty is a powerful web platform based on Nginx and a selection of modules, including Lua scripting modules for high concurrency, non-blocking I / O, and dynamic content generation. OpenResty is often used as a reverse proxy, load balancer, and many other purposes. Many WAFs are currently implemented based on OpenResty.
[0033] However, directly returning the response page after Nginx reverse proxy to the user may lead to the leakage of sensitive information. Furthermore, with the rapid development of information technology and the widespread use of data, people are increasingly concerned about personal privacy and data protection. In the past few years, there have been numerous large-scale data breaches, including leaks of sensitive data such as user personal information, credit card details, and medical records. Therefore, it is now generally necessary to desensitize the returned response page. Data desensitization is a common technique in the data security field used to protect sensitive information. It processes the original data by replacing, masking, randomizing, or otherwise processing it to reduce the risk of data leakage.
[0034] Existing desensitization technologies include static data desensitization and dynamic data desensitization. Static desensitization requires obtaining data from the database once and then desensitizing it, while dynamic desensitization is performed in real time as the data is read. With the development of big data, most current patents use dynamic desensitization.
[0035] CN112541196A proposes a dynamic data desensitization method and system that desensitizes different types of data in real time based on data access requirements and visitor identities, setting different desensitization levels based on different access levels, and thus implementing access control for different visitors to sensitive data. CN108683643A proposes a data desensitization system and desensitization method based on streaming processing, which includes an acquisition module for acquiring data, a desensitization module for desensitizing the data, and a sending module for sending the desensitized data. It also includes a cache module and a judgment module for determining whether one or more currently received data packets contain complete record rows and storing the collected one or more data packets in the cache module.
[0036] However, 1) using a cache to store streaming data packets and then desensitizing them to avoid truncated information and being unable to desensitize is a common idea. However, the existing solution will determine whether to stop caching based on the completeness of the received data packets when caching. The problem with this is that if an attacker deliberately splits a packet into several times and sends it, or if each received streaming packet is truncated and divided into two packets, then this will lead to "infinite" caching. The worst case scenario is that all packets need to be cached before desensitization, which is no different from static desensitization, and if the packet is very large, it may cause memory overflow; 2) Cache the packet first, then extract the desensitized location, and finally desensitize. This desensitization order has poor real-time performance. If it needs to be cached all the time and if the amount of cached data is very large, not only will the extraction of the desensitized location be time-consuming, but the desensitized page will not be fed back to the user in a timely manner, and the page may become stuck.
[0037] To this end, the present application proposes a data desensitization method, device and electronic equipment.
[0038] In this embodiment, a data desensitization method is provided, which can be applied to the above-mentioned terminal device or configured in a server. The terminal device can be a PC or a mobile terminal. This embodiment of the application is not limited to this. Figure 2 is a flow chart of the data desensitization method according to an embodiment of the application, which includes the following steps:
[0039] S210, obtaining multiple data packets and sending a location request to the desensitizing party, where the location request is used to request the desensitized locations of the multiple data packets.
[0040] In the embodiments of the present application, the data in the multiple data packets can be understood as privacy data and other security data related to information, such as personal identity information, mobile phone numbers, bank card information and other sensitive data collected by institutions and enterprises.
[0041] Among them, multiple data packets can be obtained through Lua.
[0042] Specifically, the Lua party may obtain the first data packet for the first time and send a first location request to the desensitizing party, and the first location request is used to request the desensitized location of the first data packet; obtain the second data packet for the second time and send a second location request to the desensitizing party, and the second location request is used to request the desensitized location of the second data packet; obtain the third data packet for the third time and send a third location request to the desensitizing party, and the third location request is used to request the desensitized location of the third data packet.
[0043] S220 , when desensitized positions of multiple data packets are received, cache the multiple data packets and the desensitized positions of the multiple data packets.
[0044] That is to say, when the Lua party obtains multiple data packets and sends a location request to the desensitizing party, the desensitizing party can determine the desensitized positions of the multiple data packets based on the location request, and then the desensitizing party sends the desensitized positions of the multiple data packets to the Lua party, so that the Lua party receives the desensitized positions of the multiple data packets and caches the multiple data packets and the desensitized positions of the multiple data packets.
[0045] S230, convert or splice the multiple data packets to obtain target desensitization positions of the multiple data packets, and send a desensitization request to the desensitization party, where the desensitization request is used to request desensitization of the multiple data packets.
[0046] In an embodiment of the present application, when caching multiple data packets and desensitized positions of multiple data packets, the desensitized position of the first data packet and the desensitized position of the second data packet are converted to obtain the target desensitized position of the first data packet; the desensitized position of the second data packet and the desensitized position of the third data packet are spliced to obtain the spliced data packet and the target desensitized position corresponding to the spliced data packet.
[0047] Among them, when it is determined that the value corresponding to the desensitization starting position of the second data packet is greater than the length of all processed packets, the desensitization position of the first data packet is used as the target desensitization position of the first data packet; when it is determined that the value corresponding to the desensitization starting position of the second data packet is less than the length of all processed packets, the desensitization position of the first data packet is converted, and the converted desensitization position is used as the target desensitization position of the first data packet.
[0048] Among them, when it is determined that the value corresponding to the desensitization starting position of the second data packet is equal to the length of all processed packets, assuming that the packet length is 20, the desensitization position of the second data packet is [20,23]. Because the offset starts from 0, when the value corresponding to the desensitization starting position of the second data packet is equal to the length of all processed packets, it is equivalent to the position of the second data packet.
[0049] That is to say, when the target desensitization location of the data packet is determined, a desensitization request can be sent to the desensitization party.
[0050] S240: When receiving the multiple desensitized data packets, send the multiple desensitized data packets to the user.
[0051] In an embodiment of the present application, when a desensitizing request is sent to the desensitizing party, the desensitizing party may desensitize multiple data packets based on the desensitizing request, and send the desensitized multiple data packets to the Lua party. When the Lua party receives the desensitized multiple data packets, it sends the desensitized multiple data packets to the user in real time.
[0052] In order to make it easier for those skilled in the art to understand the present application, as shown in Figure 3, another data desensitization method is provided, which can be applied to the above-mentioned terminal device or configured in a server. The terminal device can be a PC or a mobile terminal. The present embodiment of the application is not limited to this. Figure 3 is a flow chart of the data desensitization method according to an embodiment of the present application, which includes the following steps:
[0053] S310: Receive a location request sent by the Lua side, where the location request is used to request desensitized locations of multiple data packets.
[0054] In an embodiment of the present application, the Lua party may send a location request requesting the desensitized locations of multiple data packets to the desensitizing party, so that the desensitizing party receives the location request sent by the Lua party.
[0055] S320, determine the desensitization positions of the multiple data packets, and send the desensitization positions of the multiple data packets to the Lua side.
[0056] In an embodiment of the present application, when the desensitizing party receives a location request sent by the Lua party, the desensitizing party may determine the desensitized locations of multiple data packets based on the location request, and send the desensitized locations of the multiple data packets to the Lua party.
[0057] The location request sent by the Lua side carries multiple data packets.
[0058] In an embodiment of the present application, multiple data packets are obtained; based on the multiple data packets and the desensitization rules, the desensitization position of each data packet is determined. For example, the data packets can be matched with the desensitization rules to determine the desensitization position of each data packet.
[0059] S330: Receive a desensitization request sent by the Lua party, where the desensitization request is used to request desensitization of multiple data packets.
[0060] In an embodiment of the present application, when the desensitizing party determines the desensitizing position of each data packet, it may send the desensitizing position of each data packet to the Lua party. When the Lua party receives the desensitizing position of each data packet, the Lua party may send a desensitizing request to the desensitizing party, and the desensitizing party then receives the desensitizing request sent by the Lua party.
[0061] S340: Desensitize the multiple data packets according to the desensitization request, and send the desensitized multiple data packets to the Lua party.
[0062] In an embodiment of the present application, when the desensitizing party receives a desensitizing request sent by the Lua party, the desensitizing party may desensitize multiple data packets according to the desensitizing request and send the desensitized multiple data packets to the Lua party.
[0063] According to the data desensitization method of the embodiment of the present application, multiple data packets are obtained, and a position request is sent to the desensitization party, and the position request is used to request the desensitization position of multiple data packets; When the desensitization position of multiple data packets is received, the desensitization position of multiple data packets and multiple data packets is cached; Multiple data packets are converted or spliced to obtain the target desensitization position of multiple data packets, and a desensitization request is sent to the desensitization party, and the desensitization request is used to request desensitization of multiple data packets; When multiple data packets after desensitization are received, the multiple data packets after desensitization are sent to the user. The method is divided into two handshake parties in the process of whole data desensitization, the Lua party for data collection, processing, caching and position conversion and the desensitization party for obtaining desensitization position and desensitization, which reduces the dependency between each component. And by caching the previous packet and its desensitization position first, the problem that the truncated information cannot be obtained from the complete desensitization position is solved, and only a small part of the truncation situation cannot be completely desensitized, but this can avoid the situation of bursting memory, and it also greatly improves real-time performance and is more efficient.
[0064] In a specific embodiment of the present application, this application takes entering body_filter three times as an example, as shown in Figure 4, when the Lua party enters body_filter for the first time, it first obtains the current response body block packet1 (assuming the packet length is 20), and then sends a location request to the desensitizing party to request the desensitizing location LOC of the first data packet.
[0065] Among them, body_filter is a stage for processing HTTP response body.
[0066] When receiving the location request, the desensitizing party may match the first data packet with the desensitizing rule to obtain the desensitized location of the first data packet, and send the desensitized location of the first data packet to the Lua party.
[0067] For example, the desensitization position of the first data packet is a two-dimensional array, where the first column represents the desensitization starting position (from) and the second dimension represents the desensitization ending position (to). This means the desensitization position LOC (loc1) of the first data packet is [{0,11},{-1,-1}]. It should be noted that the final {-1,-1} is set to allow Lua to more efficiently convert and replace the two data packet positions. Only one pair of {-1,-1} is set because for packets with truncation, there is only one possible desensitization position at the end, and this value can be directly replaced, thereby reducing memory waste and improving performance.
[0068] When the Lua side receives the desensitized position of the first data packet sent by the desensitizing party, it can cache the first data packet and the desensitized position of the first data packet. The Lua side enters the body_filter for the second time and requests the desensitized position of the second data packet (assuming it is packet2) from the desensitizing party again. When the desensitizing party receives the position request, it can determine the desensitized position of the second data packet according to the position request and send the desensitized position of the second data packet to the Lua side. For example, the desensitized position LOC (loc2) of the second data packet is: [{17,29},{-1,-1}]. It should be noted that all desensitized positions are offsets relative to the entire response page, not the offset of the current packet.
[0069] When Lua receives the desensitized position LOC(loc1) of the first data packet and the desensitized position LOC(loc2) of the second data packet, it processes LOC(loc1) and LOC(loc2). There are two cases: Case 1: The value corresponding to the desensitized starting position in the first from_to of LOC(loc2) is greater than the length of all previously processed packets, then the desensitized position of the cached data packet is still LOC(loc1); Case 2: The value corresponding to the desensitized starting position in the first from_to of LOC(loc2) is less than the length of all previously processed packets, then it is necessary to convert this from_to. For example, the target desensitized position of the first data packet, that is, the final desensitized position of packet1 is: [{0,11},{17,20}], and LOC(loc2) is processed as: [{20,29},{-1,-1}]. In other words, because LOC(loc2) is at [{17,29},{-1,-1}] and the packet length is 20, [17,29] contains the position in the first packet, LOC(loc1), that needs to be desensitized. Therefore, we take the first from_to of LOC(loc2) and divide it into two parts, [17,20] and [20,29], based on the packet length. It's important to note that the desensitization position in the from_to is closed on the left and open on the right, meaning that position 20 is not desensitized for the first packet, LOC(loc1).
[0070] The Lua party sends the converted data packet and the target desensitizing position corresponding to the data packet to the desensitizing party to request desensitization. After the desensitizing party desensitizes the first data packet according to the target desensitizing position of the first data packet, it returns the desensitized first data packet to the Lua party, and the Lua party then sends the desensitized first data packet to the user.
[0071] The Lua client enters body_filter for the third time and requests the desensitizing location of the third packet (assuming it's packet3) from the desensitizing client. Upon receiving the location request, the desensitizing client determines the desensitizing location of the third packet based on the location request and sends the desensitized location to the Lua client. For example, the desensitizing location of the third packet, LOC(loc3), is [{37,49},{-1,-1}]. The Lua client then concatenates the processed LOC(loc2) and LOC(loc3) to obtain [{20,29},{37,49},{-1,-1}]. The desensitizing client then desensitizes the packet and its corresponding target desensitizing location to the desensitizing client. The desensitizing client then desensitizes the packet and returns the desensitized packet to the Lua client. The Lua client then sends the desensitized packet to the user.
[0072] It can be seen that the above process only caches the last data packet and its desensitization position, and only splices the penultimate packet at the end, and returns the desensitized data to the user directly each time it is obtained. This not only greatly improves the real-time response of the page, but also can handle the situation where the truncated sensitive information cannot be desensitized, and avoids the situation of memory explosion. Even if this will cause some truncated sensitive information to be unable to be completely desensitized (because even if a certain sensitive information is divided into many body_filters for sending, the penultimate packet where the sensitive information appears can still be desensitized), but this application believes that this impact is very small, because even if a certain sensitive information is divided into many body_filters for sending, the penultimate packet where the sensitive information appears can still be desensitized, and the knowledge desensitization is incomplete (but still desensitized to a certain extent), which has a very small impact on the entire response page.
[0073] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of each embodiment of the present application.
[0074] FIG5 is a structural block diagram of a data desensitization device according to an embodiment of the present application; the device is applied to the Lua method, as shown in FIG5 , and includes:
[0075] An acquisition module 510 is configured to acquire multiple data packets and send a location request to a desensitizing party, wherein the location request is configured to request desensitized locations of the multiple data packets;
[0076] a cache module 520 for caching the plurality of data packets and the desensitized positions of the plurality of data packets upon receiving the desensitized positions of the plurality of data packets;
[0077] A first sending module 530 is configured to convert or splice the multiple data packets to obtain target desensitization positions of the multiple data packets, and send a desensitization request to the desensitization party, wherein the desensitization request is used to request desensitization of the multiple data packets;
[0078] The second sending module 540 is configured to send the desensitized data packets to the user upon receiving the desensitized data packets.
[0079] Furthermore, the acquisition module 510 is specifically used to acquire the first data packet for the first time and send a first location request to the desensitizing party, wherein the first location request is used to request the desensitized location of the first data packet; acquire the second data packet for the second time and send a second location request to the desensitizing party, wherein the second location request is used to request the desensitized location of the second data packet; acquire the third data packet for the third time and send a third location request to the desensitizing party, wherein the third location request is used to request the desensitized location of the third data packet.
[0080] Furthermore, the first sending module 530 is specifically used to convert the desensitized position of the first data packet and the desensitized position of the second data packet to obtain the target desensitized position of the first data packet; splice the desensitized position of the second data packet and the desensitized position of the third data packet to obtain the spliced data packet and the target desensitized position corresponding to the spliced data packet.
[0081] Furthermore, the first sending module 530 is specifically used to use the desensitizing position of the first data packet as the target desensitizing position of the first data packet when it is determined that the value corresponding to the desensitizing starting position of the second data packet is greater than the length of all processed packets; and to convert the desensitizing position of the first data packet and use the converted desensitizing position as the target desensitizing position of the first data packet when it is determined that the value corresponding to the desensitizing starting position of the second data packet is less than the length of all processed packets.
[0082] FIG6 is a structural block diagram of a device for intelligently partitioning load information according to an embodiment of the present application; the device is applied to a desensitization method, as shown in FIG6 , and includes:
[0083] A first receiving module 610 is configured to receive a location request sent by a Lua client, wherein the location request is configured to request desensitized locations of multiple data packets;
[0084] A third sending module 620 is used to determine the desensitized positions of the multiple data packets and send the desensitized positions of the multiple data packets to the Lua party;
[0085] A second receiving module 630 is configured to receive a desensitization request sent by the Lua party, wherein the desensitization request is used to request desensitization of the multiple data packets;
[0086] The fourth sending module 640 is used to desensitize the multiple data packets according to the desensitization request and send the desensitized multiple data packets to the Lua party.
[0087] Furthermore, the third sending module 620 is specifically used to obtain the multiple data packets; and determine the desensitization position of each data packet according to the multiple data packets and the desensitization rules.
[0088] Furthermore, the fourth sending module 640 is specifically used to determine the type of data in each data packet; desensitize each data packet according to the data type and the desensitization algorithm; and send each desensitized data packet to the Lua party.
[0089] The present application proposes a computer-readable storage medium having a computer program stored thereon, which can be loaded and executed by a processor using the data desensitization method described in the first aspect or the data desensitization method described in the second aspect.
[0090] The applicant of this application has made detailed explanations and descriptions of the implementation examples of this application in conjunction with the drawings in the specification. However, those skilled in the art should understand that the above implementation examples are only preferred implementation plans of this application, and the detailed description is only to help readers better understand the spirit of this application, and is not a limitation on the scope of protection of this application. On the contrary, any improvements or modifications based on the inventive spirit of this application should fall within the scope of protection of this application.
[0091] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of this application, and are not intended to limit them. Although this application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some of the technical features therein with equivalents; and these modifications or replacements do not deviate from the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of this application. Any changes or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be covered by the scope of protection of this application.
Claims
1. A data desensitization method, the method being applied to Lua method, comprising: S1, obtaining multiple data packets and sending a location request to the desensitizing party, wherein the location request is used to request the desensitized locations of the multiple data packets; S2, upon receiving the desensitized positions of the multiple data packets, cache the multiple data packets and the desensitized positions of the multiple data packets; S3, converting or splicing the multiple data packets to obtain target desensitization positions of the multiple data packets, and sending a desensitization request to the desensitization party, wherein the desensitization request is used to request desensitization of the multiple data packets; S4, when receiving the multiple data packets after desensitization, sending the multiple data packets after desensitization to the user.
2. The data desensitization method according to claim 1, wherein: Acquire multiple data packets and send a location request to the desensitizing party, wherein the location request is used to request the desensitized locations of the multiple data packets, including: Acquire a first data packet for the first time, and send a first location request to the desensitizing party, where the first location request is used to request a desensitized location of the first data packet; Acquire the second data packet for the second time, and send a second location request to the desensitizing party, where the second location request is used to request the desensitized location of the second data packet; The third data packet is obtained for the third time, and a third location request is sent to the desensitizing party, where the third location request is used to request the desensitized location of the third data packet.
3. The data desensitization method according to claim 2, wherein: Converting or concatenating the multiple data packets to obtain target desensitization positions of the multiple data packets includes: Converting the desensitized position of the first data packet and the desensitized position of the second data packet to obtain a target desensitized position of the first data packet; The desensitized position of the second data packet and the desensitized position of the third data packet are spliced to obtain a spliced data packet and a target desensitized position corresponding to the spliced data packet.
4. The data desensitization method according to claim 3, wherein: Converting the desensitized position of the first data packet and the desensitized position of the second data packet to obtain a target desensitized position of the first data packet includes: In the case where it is determined that the value corresponding to the desensitization starting position of the second data packet is greater than the length of all processed packets, the desensitization position of the first data packet is used as the target desensitization position of the first data packet; When it is determined that the value corresponding to the desensitization starting position of the second data packet is smaller than the length of all processed packets, the desensitization position of the first data packet is converted, and the converted desensitization position is used as the target desensitization position of the first data packet.
5. A data desensitization method, the method being applied to a desensitization party, comprising: Receive a location request sent by the Lua party, where the location request is used to request desensitized locations of multiple data packets; Determine the desensitized positions of the multiple data packets, and send the desensitized positions of the multiple data packets to the Lua party; Receive a desensitization request sent by the Lua party, where the desensitization request is used to request desensitization of the multiple data packets; The multiple data packets are desensitized according to the desensitization request, and the desensitized multiple data packets are sent to the Lua party.
6. The data desensitization method according to claim 5, wherein: Determining the desensitization positions of the multiple data packets includes: Acquire the multiple data packets; According to the multiple data packets and desensitization rules, the desensitization position of each data packet is determined.
7. The data desensitization method according to claim 5, wherein: Desensitizing the multiple data packets according to the desensitization request, and sending the desensitized multiple data packets to the Lua party, including: Determine the type of data in each packet; Desensitizing each of the data packets according to the data type and the desensitization algorithm; Each desensitized data packet is sent to the Lua party.
8. A data desensitization device, the device being applied to Lua method, comprising: An acquisition module, used for acquiring a plurality of data packets and sending a location request to a desensitizing party, wherein the location request is used for requesting desensitized locations of the plurality of data packets; A cache module, configured to cache the multiple data packets and the desensitized positions of the multiple data packets upon receiving the desensitized positions of the multiple data packets; A first sending module, used for converting or splicing the multiple data packets to obtain target desensitization positions of the multiple data packets, and sending a desensitization request to the desensitizing party, wherein the desensitization request is used to request desensitization of the multiple data packets; The second sending module is used to send the multiple desensitized data packets to the user when receiving the multiple desensitized data packets.
9. A data desensitization device, the device being applied to a desensitization party, comprising: A first receiving module, used for receiving a location request sent by the Lua party, wherein the location request is used for requesting desensitized locations of multiple data packets; A third sending module, used for determining the desensitized positions of the multiple data packets, and sending the desensitized positions of the multiple data packets to the Lua party; A second receiving module is used to receive a desensitization request sent by the Lua party, wherein the desensitization request is used to request desensitization of the multiple data packets; The fourth sending module is used to desensitize the multiple data packets according to the desensitization request, and send the desensitized multiple data packets to the Lua party.
10. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method of any one of claims 1-4 or the method of any one of claims 5-7.
Citation Information
Patent Citations
Data masking system based on streaming and masking method thereof
CN108683643A
Data processing method and device
CN113761566A
File desensitization method and device, electronic equipment and storage medium
CN114898373A
Data stream real-time desensitization method and system based on big data technology
CN115600241A
Data desensitization method and device
CN117874803A