Log Desensitization Rules for Secure Multi-Party Query Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to systematically and efficiently accommodate the diverse demands of various log requesters while controlling log information query access to prevent sensitive data leakage.
Innovation Solution
A method and apparatus that determine the source of a structured log using a log software development kit (SDK), apply a log desensitization policy based on log registration information, and perform desensitization processing on variable items according to user business attributes to provide a desensitized log.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If log information is transmitted to various log demanders, then log data demands are met, but sensitive data leakage occurs
Solution Approach 1:
The patent applies preliminary action by performing desensitization processing on log information before transmission to log demanders. The system identifies sensitive data in logs and masks or removes it in advance, ensuring that sensitive information cannot be leaked during subsequent transmission and querying operations. This pre-processing step resolves the contradiction by maintaining data utility while eliminating security risks.
Solution Approach 2:
The patent introduces an intermediary mechanism - a desensitization processing system that acts as a mediator between the log generation source and log demanders. This intermediary automatically processes log information to remove or mask sensitive data while preserving non-sensitive useful information, allowing log demanders to access processed logs without exposing sensitive data. The intermediary resolves the contradiction by enabling data sharing while protecting sensitive information.
2Object-affected harmful factors
If manual desensitization processing is performed on log data, then sensitive data is protected, but processing time and cost increase
Solution Approach 1:
The patent applies self-service by implementing an automated desensitization processing system that operates independently without requiring manual intervention. The system automatically identifies sensitive data patterns in logs, applies appropriate desensitization rules, and generates processed log information. This automation eliminates time-consuming manual processing while maintaining effective sensitive data protection, resolving the contradiction between security and efficiency.
Solution Approach 2:
The patent applies parameter changes by transforming the desensitization process from a manual operation to an automated computational process. The system uses configurable desensitization rules and parameters to automatically process different types of sensitive data (such as personal information, passwords, account numbers) according to predefined policies. This parameter-driven automation dramatically reduces processing time while maintaining comprehensive sensitive data protection.
3Measurement precision
If log desensitization rules are manually configured, then desensitization accuracy is improved, but system complexity and maintenance effort increase
Solution Approach 1:
The patent applies universality by designing a unified desensitization processing system that handles multiple types of sensitive data through a single configurable framework. The system uses universal desensitization rules that can be applied across different log sources, formats, and sensitive data types. This universal approach maintains high desensitization accuracy while reducing system complexity compared to having separate manual configuration systems for each data type.
Solution Approach 2:
The patent applies parameter changes by implementing a configurable rule-based system where desensitization parameters (such as sensitivity levels, masking patterns, and rule priorities) can be adjusted without changing the underlying system structure. This allows the system to maintain high accuracy through precise parameter configuration while keeping the overall system architecture simple and maintainable. The parameter-driven approach enables flexible adaptation to different requirements without increasing structural complexity.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Embodiments of the present invention provides a log information processing method and apparatus, a device, a storage medium, and a program product. The method comprises: determining a source of a target log in response to a log query request, wherein the log query request is used for instructing a target user to query the target log; determining a log desensitization strategy corresponding to the source of the target log, the log desensitization strategy being determined on the basis of log registration information associated with the source, and the log registration information being used for indicating the physical meaning of a variable item in the target log; and desensitizing, according to service attribute information of the target user, the log desensitization strategy, and service permission information, a variable item related to the target user in the target log, so as to provide the desensitized target log to the target user. According to the facts of the present invention, requirements of different log service parties are systematically and efficiently compatible, and the query and access of log information can be controlled, so as to avoid breach of sensitive data.