TWM547135U - File management server - Google Patents

File management server Download PDF

Info

Publication number
TWM547135U
TWM547135U TW106206328U TW106206328U TWM547135U TW M547135 U TWM547135 U TW M547135U TW 106206328 U TW106206328 U TW 106206328U TW 106206328 U TW106206328 U TW 106206328U TW M547135 U TWM547135 U TW M547135U
Authority
TW
Taiwan
Prior art keywords
report
masking
sample
mask
unit
Prior art date
Application number
TW106206328U
Other languages
Chinese (zh)
Inventor
林進旺
林繼彥
Original Assignee
兆豐國際商業銀行股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 兆豐國際商業銀行股份有限公司 filed Critical 兆豐國際商業銀行股份有限公司
Priority to TW106206328U priority Critical patent/TWM547135U/en
Publication of TWM547135U publication Critical patent/TWM547135U/en

Links

Abstract

A file management server for managing output of files having identified number is provided. The file management server has processing unit, mask samples database and translating unit. The translating unit is coupled to the processing unit and the mask setting database. When the processing unit receives an instruction of outputting the file, the translating unit reads a file mask sample corresponding to the identified number of the file from the mask samples database. The translating unit translates the file according to the file mask sample, and sends the translated file to the processing unit. The processing unit output the translated file.

Description

報表管理伺服器Report management server

本揭露是有關於一種報表管理伺服器。The disclosure is related to a report management server.

現代社會裡,網路的發達大幅地提升資料獲取的便利性。相對地,個人資料及隱私則為日趨重要的議題。為了順應社會需求,我國於民國九十九年大幅的修訂個資法,並於民國一百零一年開始施行。因此,各企業也著手進行系統、設備的更新,以符合法規的配套方案。In modern society, the development of the Internet has greatly improved the convenience of data acquisition. In contrast, personal data and privacy are increasingly important issues. In order to comply with the needs of the society, China revised the capital law in 1999 in the Republic of China and implemented it in the Republic of China in 2001. Therefore, each company has also started to update the system and equipment to comply with the regulations.

然而,在多數個資外洩的案件中,最常導致個資外洩的情形並非系統遭受網路的攻擊,而是在於內部文件的控管不完善,導致機密資料從組織內部流傳出去。特別是針對敏感性業務的組織,例如,金融企業、身分機關、帳務組織等,更需要完善的文件管理機制。因此,如何能夠妥善的進行文件管理成為本領域技術人員所致力的目標。However, in most cases of foreign capital leakage, the most common situation that leads to the leakage of funds is not that the system is attacked by the network, but because the internal documents are not well controlled, resulting in the transmission of confidential information from within the organization. In particular, organizations that target sensitive businesses, such as financial companies, identity agencies, and accounting organizations, need more sophisticated document management mechanisms. Therefore, how to properly manage files becomes a goal of those skilled in the art.

本揭露提供一種報表管理伺服器,以管理報表的輸出。The disclosure provides a report management server for managing the output of a report.

本揭露的報表管理伺服器是用以管理報表的輸出。此報表具有報表識別編號。報表管理伺服器具有處理單元、遮蔽樣本資料庫以及遮蔽轉譯單元。處理單元用以接收報表輸出指令。遮蔽樣本資料庫用以儲存報表遮蔽樣本。遮蔽轉譯單元耦接於處理單元與遮蔽樣本資料庫。當處理單元接收報表輸出指令時,遮蔽轉譯單元讀取對應報表識別編號的報表遮蔽樣本,並依據報表遮蔽樣本轉譯報表,報表遮蔽單元傳送轉譯後的報表至處理單元,處理單元輸出轉譯後的報表。The report management server disclosed herein is used to manage the output of the report. This report has a report identification number. The report management server has a processing unit, a masking sample database, and a masking translation unit. The processing unit is configured to receive a report output instruction. The mask sample database is used to store report mask samples. The masking translation unit is coupled to the processing unit and the masking sample database. When the processing unit receives the report output instruction, the masking translation unit reads the report masking sample corresponding to the report identification number, and masks the sample translation report according to the report, the report masking unit transmits the translated report to the processing unit, and the processing unit outputs the translated report. .

基於上述,本揭露提供了一種報表管理伺服器,以管理報表的輸出。在本揭露的報表管理伺服器中設置了自動報表遮蔽機制,當使用者欲輸出報表時,遮蔽轉譯單元會自動遮蔽報表的部分內容,以限制報表輸出的內容。藉此,即便雇員違背規範導致資料外洩,他人仍無法透過報表的內容獲知機密資料。Based on the above, the present disclosure provides a report management server for managing the output of a report. In the report management server of the present disclosure, an automatic report masking mechanism is set. When the user wants to output a report, the masking and translating unit automatically masks part of the report to limit the content of the report output. In this way, even if the employee breaches the specification and causes the data to leak, others cannot obtain the confidential information through the contents of the report.

為讓本新型創作的上述特徵和優點能更明顯易懂,下文特舉實施例,並配合所附圖式作詳細說明如下。The above described features and advantages of the present invention will become more apparent and understood from the following description.

圖1繪示了本揭露一實施例的報表管理伺服器的架構圖。FIG. 1 is a block diagram of a report management server according to an embodiment of the present disclosure.

一般而言,在組織內部管理中,都會針對雇員設立一系列規範,要求雇員不得洩漏客戶的資料,並列出相關懲戒。然而,相較於文件而言,人是相對難控制與管理的。即便設立了規範與懲戒,當雇員違背規範導致資料洩漏的情形發生時,往往已造成不可回復的損害。因此,本揭露於報表管理伺服器中設置了自動報表遮蔽機制,以限制報表輸出的內容。藉此,即便雇員違背規範導致資料外洩,他人仍無法透過報表的內容獲知機密資料。In general, in the internal management of the organization, a series of regulations are set up for employees, requiring employees not to disclose customer information and to list relevant disciplinary actions. However, people are relatively difficult to control and manage compared to documents. Even if regulation and disciplinary action are established, when an employee violates the norm and causes a data leakage, it often causes irreparable damage. Therefore, the present disclosure discloses an automatic report masking mechanism in the report management server to limit the content of the report output. In this way, even if the employee breaches the specification and causes the data to leak, others cannot obtain the confidential information through the contents of the report.

請參照圖1,本揭露的報表管理伺服器100是用於管理報表的輸出,例如,當使用者欲透過列印裝置170(例如:影印機)列印報表,或者是從報表管理伺服器100下載此報表至使用者的終端裝置180(例如:電腦或手機)時,報表管理伺服器100會對此報表的內容進行控管。Referring to FIG. 1 , the report management server 100 of the present disclosure is configured to manage the output of a report, for example, when a user wants to print a report through the printing device 170 (eg, a photocopying machine), or from the report management server 100. When the report is downloaded to the user's terminal device 180 (for example, a computer or a mobile phone), the report management server 100 controls the contents of the report.

此報表管理伺服器100具有處理單元110、儲存單元120、遮蔽轉譯單元130、遮蔽樣本資料庫140、遮蔽位置設定單元150及報表樣本資料庫160。處理單元110會接收來自使用者終端裝置180所傳送的報表輸出指令,並傳送經遮蔽的報表至列印裝置170或使用者終端裝置180。處理單元110可以是中央處理單元(Central Processing Unit,CPU),或是其他可程式化之一般用途或特殊用途的微處理器(Microprocessor)、數位信號處理器(Digital Signal Processor,DSP)、可程式化控制器、特殊應用積體電路(Application Specific Integrated Circuit,ASIC)或其他類似元件或上述元件的組合,本揭露不限於此。The report management server 100 has a processing unit 110, a storage unit 120, a shadow translation unit 130, a mask sample database 140, a mask position setting unit 150, and a report sample database 160. The processing unit 110 receives the report output command transmitted from the user terminal device 180 and transmits the masked report to the printing device 170 or the user terminal device 180. The processing unit 110 can be a central processing unit (CPU), or other programmable general purpose or special purpose microprocessor (Microprocessor), digital signal processor (DSP), programmable The controller, the Application Specific Integrated Circuit (ASIC) or the like or a combination of the above elements, the disclosure is not limited thereto.

儲存單元120儲存了操作處理單元110、遮蔽轉譯單元130、遮蔽位置設定單元150所需要的必要儲存空間。儲存單元120可以是任何型態的固定或可移動隨機存取記憶體(Random Access Memory,RAM)、唯讀記憶體(Read-Only Memory,ROM)、快閃記憶體(flash memory)、硬碟(Hard Disk Drive,HDD)、固態硬碟(Solid State Drive,SSD)或類似元件或上述元件的組合。The storage unit 120 stores necessary storage spaces required by the operation processing unit 110, the occlusion translation unit 130, and the occlusion position setting unit 150. The storage unit 120 can be any type of fixed or removable random access memory (RAM), read-only memory (ROM), flash memory, hard disk. (Hard Disk Drive, HDD), Solid State Drive (SSD) or the like or a combination of the above.

遮蔽轉譯單元130耦接於處理單元110,遮蔽轉譯單元130會將輸入的報表轉譯成被遮蔽的報表。遮蔽位置設定單元150耦接於遮蔽樣本資料庫140與報表樣本資料庫160,遮蔽位置設定單元150接收來自使用者的設定指令,並根據設定指令產生報表遮蔽樣本。遮蔽位置設定單元150並將報表遮蔽樣本儲存於遮蔽樣本資料庫140中。遮蔽轉譯單元130與遮蔽位置設定單元150可以以硬體或韌體的方式進行實作。若以硬體的方式進行實作,遮蔽轉譯單元130與遮蔽位置設定單元150可以是獨立的電路晶片或電路結構,例如:與處理單元110相同類型的元件組合。在本揭露其他的實施例中,遮蔽轉譯單元130、遮蔽位置設定單元150亦可以與處理單元110封裝於同一個晶片當中,本揭露不限於此。The masking translation unit 130 is coupled to the processing unit 110, and the masking translation unit 130 translates the input report into a masked report. The masking position setting unit 150 is coupled to the masking sample database 140 and the report sample database 160. The masking position setting unit 150 receives the setting instruction from the user, and generates a report masking sample according to the setting instruction. The mask position setting unit 150 stores the report mask samples in the mask sample database 140. The masking translation unit 130 and the masking position setting unit 150 can be implemented in a hard or tough manner. If implemented in a hardware manner, the masking translation unit 130 and the masking position setting unit 150 may be separate circuit chips or circuit structures, such as the same type of component combination as the processing unit 110. In other embodiments of the disclosure, the masking and translating unit 130 and the masking position setting unit 150 may also be packaged in the same chip as the processing unit 110. The disclosure is not limited thereto.

遮蔽樣本資料庫140是用以儲存報表遮蔽樣本。報表樣本資料庫160則是用以儲存多個報表樣本。在本實施例中,遮蔽樣本資料庫140與報表樣本資料庫160可以為以結構化查詢語言(Structured Query Language,SQL)為介面進行資料存取的資料庫,或者是以Apache Cassandra™為基準的查詢語言(Cassandra Query Language,CQL)為介面,以進行資料存取的資料庫。並且,遮蔽樣本資料庫140與報表樣本資料庫160可以存放於任何型態的固定或可移動隨機存取記憶體(Random Access Memory,RAM)、唯讀記憶體(Read-Only Memory,ROM)、快閃記憶體(flash memory)、硬碟(Hard Disk Drive,HDD)、固態硬碟(Solid State Drive,SSD)或類似元件或上述元件的組合。在本揭露其他的實施例中,遮蔽樣本資料庫140、報表樣本資料庫160亦可以存放於儲存單元120中,本揭露不限於此。The mask sample database 140 is used to store report mask samples. The report sample database 160 is used to store multiple report samples. In this embodiment, the occlusion sample database 140 and the report sample database 160 may be a database for data access using a Structured Query Language (SQL) interface, or based on Apache CassandraTM. The Cassandra Query Language (CQL) is an interface for data access. Moreover, the mask sample database 140 and the report sample database 160 can be stored in any type of fixed or removable random access memory (RAM), read-only memory (ROM), A flash memory, a Hard Disk Drive (HDD), a Solid State Drive (SSD) or the like or a combination of the above elements. In other embodiments of the disclosure, the mask sample database 140 and the report sample database 160 may also be stored in the storage unit 120. The disclosure is not limited thereto.

請參照圖2,圖2為本揭露一實施例的報表樣本檔。在本揭露中,使用者可以預先設計多個報表樣本檔,以因應不同的業務需求產生不同的報表。以圖2為例,報表樣本檔200顯示了同一客戶於同一營業日現金存提在新台幣100萬元(含)以上且交易時間相距1小時內的交易報表的樣本檔。此報表樣本檔200具有報表編號DT1-D100。在實際的運用中,不同的客戶於同一營業日現金存提在新台幣100萬元(含)以上且交易時間相距1小時內的交易報表,都是以相同的報表編號DT1-D100的報表樣本檔作為預設樣式,但會依據不同客戶與日期載入不同的資料內容。不同報表編號的報表樣本檔會針對不同業務類型而設計不同類型的欄位與版面,本揭露所繪示的報表樣本檔的欄位的類型(例如:客戶證號)以及排版僅為示例,本揭露並不以欄位的類型、所呈現的資料內容以及版面為限。Please refer to FIG. 2. FIG. 2 is a sample sample file according to an embodiment of the disclosure. In this disclosure, a user can pre-design multiple report sample files to generate different reports in response to different business needs. Taking Figure 2 as an example, the report sample file 200 shows a sample file of the transaction statement of the same customer on the same business day with a cash deposit of NT$1 million or more and a transaction time of one hour apart. This report sample file 200 has report numbers DT1-D100. In actual operation, the transaction statements of different customers on the same business day in cash of NT$1 million (inclusive) and trading hours within one hour are all the same report number DT1-D100. The file is a preset style, but different content is loaded according to different customers and dates. The report sample files of different report numbers will design different types of fields and layouts for different business types. The types of fields of the report sample files (for example, customer identification numbers) and the typesetting are only examples, Disclosure is not limited to the type of field, the content of the material presented, and the layout.

報表樣本檔200分為表頭區210、資料區220以及表尾區230,表頭區210的欄位顯示了與此張報表相關的資料,例如,報表用途、使用單位、保管單位、資料日期、製表日期、保管期限以及報表頁數等。資料區220則顯示了此張報表欲呈現的資料內容,例如,執行現金存提操作的櫃員代號、主管卡號、與客戶相關的帳號/對方科目、客戶證號及客戶名稱以及與交易相關的交易序號/會計套號、交易時間、幣別、借方金額、貸方金額以及交易代號。表尾區230則顯示了與本報表相關的操作人員,例如,經辦、科(股)長以及經副襄理。這些欄位的選擇為使用者在設定報表樣本時,依照需求所選擇的項目,本揭露中並不以此為限。The report sample file 200 is divided into a header area 210, a data area 220, and a footer area 230. The field of the header area 210 displays information related to the report, for example, the purpose of the report, the unit of use, the storage unit, and the date of the data. , tabulation date, retention period, and number of report pages. The data area 220 displays the contents of the information to be presented in the report, for example, the teller code for performing the cash deposit operation, the supervisor card number, the account/party account associated with the customer, the customer number and the customer name, and the transaction related transaction. Serial number/accounting set number, trading time, currency, debit amount, credit amount, and transaction code. The end of the table 230 shows the operators associated with this report, for example, the manager, the head of the department, and the vice-minister. The selection of these fields is the item selected by the user according to the requirements when setting the sample of the report, and the disclosure is not limited thereto.

除了不同類型的欄位以外,報表樣本檔並記載了不同欄位所對應的資料類型。以客戶證號為例,客戶證號的預設資料類型為1個英文字母與9個數字,共10個位元。又或者是,以借方金額為例,由於金額的大小並不為固定的位元數,因此,資料類型可以是1至10位元之間,本揭露並不以此為限。In addition to the different types of fields, the report sample file records the data types corresponding to different fields. Taking the customer ID number as an example, the default data type of the customer ID number is 1 English letter and 9 numbers, for a total of 10 bits. Alternatively, the debit amount is taken as an example. Since the amount of the amount is not a fixed number of bits, the data type may be between 1 and 10 bits, and the disclosure is not limited thereto.

在本實施例中,具有報表遮蔽權限的報表遮蔽設計者可以透過報表管理伺服器100的遮蔽位置設定單元150設定報表樣本檔200中欲遮蔽的欄位與位元,並儲存為報表遮蔽樣本。藉此,當具有使用權限的使用者欲輸出報表時,報表管理伺服器100可以依據報表遮蔽樣本轉譯報表,以遮蔽敏感的資料,並將轉譯後的報表輸出。In this embodiment, the report masking designer having the report obscuration authority can set the field and the bit to be obscured in the report sample file 200 through the mask position setting unit 150 of the report management server 100, and store it as a report mask sample. Thereby, when the user having the usage right wants to output the report, the report management server 100 can mask the sample translation report according to the report to mask the sensitive data, and output the translated report.

[設定報表遮蔽樣本][Set report masking sample]

請參照圖1至圖3,圖3繪示本揭露一實施例的遮蔽位置設定介面。遮蔽位置設定單元150會提供遮蔽位置設定介面300給使用者,以讓使用者選取並設定欲遮蔽的資料位元。具體來說,遮蔽位置設定單元150會讀取報表樣本檔200的每個欄位類型320及其對應的資料類型330,並顯示於遮蔽位置設定介面300中。當使用者欲遮蔽特定欄位的特定位元時,使用者可以勾選選取框310,並且在欲遮蔽的位元中輸入遮蔽字元,以取代實體資料位元。Please refer to FIG. 1 to FIG. 3 . FIG. 3 illustrates a mask position setting interface according to an embodiment of the present disclosure. The mask position setting unit 150 provides a mask position setting interface 300 to the user for the user to select and set the data bit to be masked. Specifically, the occlusion position setting unit 150 reads each field type 320 of the report sample file 200 and its corresponding data type 330, and displays it in the occlusion position setting interface 300. When the user wants to block a particular bit of a particular field, the user can check the box 310 and enter the masking character in the bit to be masked to replace the entity data bit.

舉例而言,當使用者欲遮蔽客戶證號的欄位時,使用者可以點選選取框310a,並且在客戶證號320a對應的預設資料類型330a中,將原本10個位元中,欲遮蔽的位元以遮蔽字元取代,以下達設定指令。在本實施例中是以「*」字號做為遮蔽字元,但本揭露並不以此為限。於使用者以遮蔽字元取代欲遮蔽的位元後,遮蔽位置設定單元150會依據錨定位置,分析使用者所設定的遮蔽字元位置,以獲取位置設定規則。以交易序號/會計套號為例,遮蔽位置設定單元150會以左邊第1位位元為錨定位置,並分析使用者所設定的遮蔽字元是錨定位置向右第11-13個位元,並以此規則作為遮蔽位置樣本的設定指令。For example, when the user wants to hide the field of the customer identification number, the user can click the selection box 310a, and in the preset data type 330a corresponding to the customer identification number 320a, the original 10 bits will be The masked bits are replaced by masking characters, which are set to the following. In the embodiment, the "*" font is used as the mask character, but the disclosure is not limited thereto. After the user replaces the bit to be masked with the masking character, the masking position setting unit 150 analyzes the position of the masking character set by the user according to the anchoring position to obtain the position setting rule. Taking the transaction serial number/accounting suite number as an example, the masking position setting unit 150 takes the first digit of the left position as the anchoring position, and analyzes that the masking character set by the user is the eleventh to the right of the anchoring position. Yuan, and use this rule as a setting command to mask the position sample.

為了提升資料的安全性,在本實施例中,遮蔽位置設定單元150會限制與使用者個人資料相關的欄位必須被遮蔽。舉例來說,本實施例的報表樣本檔200具有與使用者相關的客戶證號與客戶名稱欄位。在設定遮蔽位置時,遮蔽位置設定單元150預設這兩個欄位會被勾選,且不得由使用者取消勾選。除此之外,遮蔽位置設定單元150會根據預設規則預設資料類型320中的特定位元為遮蔽字元。以客戶證號為例,遮蔽位置設定單元150預設以左邊第1位位元為錨定位置,並依據錨定位置向右起第5位開始,連續3個位元為欲遮蔽的位元的預設規則,將對應位置設定為遮蔽字元。即客戶證號中的第5位至第7位的位元為遮蔽字元。在不同實施例中,此預設規則與錨定位置可以依據實際情形進行調整,本揭露並不以此為限。使用者可以自行修改遮蔽字元的位置,然而,在儲存設定時,遮蔽位置設定單元150會判斷預設被勾選的欄位是否不存在任何的遮蔽字元,若不存在任何的遮蔽字元,則遮蔽位置設定單元150會依據預設規則設定遮蔽字元。In order to improve the security of the data, in the present embodiment, the mask position setting unit 150 restricts the field associated with the user profile from being obscured. For example, the report sample file 200 of the present embodiment has a customer identification number and a customer name field associated with the user. When the masking position is set, the mask position setting unit 150 presets that the two fields are checked, and may not be unchecked by the user. In addition, the mask position setting unit 150 presets a specific bit in the material type 320 as a mask character according to a preset rule. Taking the customer card number as an example, the mask position setting unit 150 presets that the first bit on the left side is the anchor position, and starts from the fifth position from the anchor position to the right, and the three consecutive bits are the bits to be masked. The preset rule sets the corresponding position as the masking character. That is, the 5th to 7th bits in the customer identification number are masked characters. In different embodiments, the preset rule and the anchor position may be adjusted according to actual situations, and the disclosure is not limited thereto. The user can modify the position of the masking character. However, when the setting is saved, the masking position setting unit 150 determines whether the preset checked field does not have any masking characters, if there is no hidden character. The mask position setting unit 150 sets the mask character according to the preset rule.

除此之外,遮蔽位置設定單元150並會預設此報表及經手人的資料不能被遮蔽,例如,經辦、科(股)長及經副襄理的欄位不能被遮蔽,以使輸出的報表的來源能夠被確認。須說明的是,在不同的實施例中,報表遮蔽設計者可以依據實際的需求設計遮蔽位置設定單元150所限制必須被遮蔽的欄位以及不能被遮蔽的欄位,本揭露並不限於此。In addition, the mask position setting unit 150 presupposes that the report and the data of the person handling the person cannot be obscured. For example, the fields of the manager, the department head, and the assistant manager cannot be obscured to make the output The source of the report can be confirmed. It should be noted that, in different embodiments, the report masking designer can design the field that the mask position setting unit 150 limits to be obscured and the field that cannot be obscured according to actual requirements, and the disclosure is not limited thereto.

在本實施例中,遮蔽位置設定單元150亦會提供控管參數輸入的欄位。由於在某些特殊報表中,必須要排除欄位遮蔽的功能。因此,報表遮蔽設計者可以藉由遮蔽位置設定單元150的控管參數輸入欄位輸入欲排除遮蔽的欄位及位元。In this embodiment, the mask position setting unit 150 also provides a field for controlling the parameter input. Because in some special reports, the role of field masking must be excluded. Therefore, the report masking designer can input the fields and the bits to be masked by the control parameter input field of the mask position setting unit 150.

在本實施例中,由於報表的表頭區210、資料區220及表尾區230的性質並不相同,例如,表頭區210呈現與表單相關的資料中,多為預設的資料類型以及系統所抓取的時間。資料區220所呈現的資料較為敏感,且會重複的呈現欄位類型相同,內容不同的資料。而表尾區230則呈現了與本報表相關的操作人員,且操作人員會隨著每一張報表而有所改變。因此,在此報表樣本檔中,遮蔽位置設定單元150會依據不同區域的資料提供單筆區域設定、重複區域設定以及重複次數等設定功能。此外,遮蔽位置設定單元150所設定遮蔽字元後所呈現資料類型的位數並不一定要與原始資料的總位元數相符,舉例來說,設定完的客戶證號的總位元數可以為15個位元數。遮蔽位置設定單元150也可以提供一筆資料在報表上顯示多行的遮蔽功能。藉由多元化的遮蔽設計方法,遮蔽位置設定單元150可以提供彈性的表單遮蔽設計方法。In this embodiment, since the properties of the header area 210, the data area 220, and the footer area 230 of the report are not the same, for example, the header area 210 presents the data related to the form, and is mostly a preset data type and The time the system crawled. The data presented in the data area 220 is relatively sensitive, and will repeatedly present data of the same type and content. The end of the table 230 presents the operators associated with this report, and the operator changes with each report. Therefore, in the report sample file, the mask position setting unit 150 provides a setting function such as a single area setting, a repeating area setting, and a repetition number according to the data of different areas. In addition, the number of bits of the data type presented after the masking character is set by the masking position setting unit 150 does not necessarily match the total number of bits of the original data. For example, the total number of bits of the set client number can be It is 15 bits. The mask position setting unit 150 can also provide a masking function for displaying a plurality of lines on the report. The mask position setting unit 150 can provide an elastic form mask design method by a plurality of mask design methods.

圖4繪示本揭露一實施例的報表遮蔽樣本。請參照圖4,報表設計者圈選完欲遮蔽的欄位與位元後,遮蔽位置設定單元150會將使用者的設定紀錄下來,並產生報表遮蔽樣本400,並儲存於遮蔽樣本資料庫140中。FIG. 4 illustrates a report masking sample according to an embodiment of the present disclosure. Referring to FIG. 4, after the report designer circled the fields and bits to be obscured, the mask position setting unit 150 records the user's settings, and generates a report mask sample 400, which is stored in the mask sample database 140. in.

圖5繪示本揭露一實施例的報表管理方法中,設定報表遮蔽樣本的流程圖。請同時參照圖1及圖5,於步驟S501中,遮蔽位置設定單元150接收來自使用者終端裝置180的設定指令。其中,設定指令是用以指示選取報表樣本檔中的多個欄位中的其中一個,並將多個欄位中的其中一個的選取位元取代為該遮蔽字元。使用者可以發送多個設定指令,本揭露並不以設定指令的數量及選取位元的數量為限。接著,遮蔽位置設定單元150會將報表樣本檔中對應多個欄位中的選取位元位置的位元設定為遮蔽字元,以產生該報表遮蔽樣本。具體來說,於步驟S503中,遮蔽位置設定單元150會於多個欄位中的其中一個的位元中選取錨定位置,並依據錨定位置分析使用者所設定的遮蔽字元位置,以產生設定規則。並且於步驟S505中,遮蔽位置設定單元150依據設定規則修改報表樣本檔,以將報表樣本檔中對應多個欄位中的選取位元的位元設定為遮蔽字元。最後,於步驟S507中,遮蔽位置設定單元150會將報表遮蔽樣本儲存於遮蔽樣本資料庫140。FIG. 5 is a flow chart of setting a report masking sample in a report management method according to an embodiment of the present disclosure. Referring to FIG. 1 and FIG. 5 simultaneously, in step S501, the mask position setting unit 150 receives the setting command from the user terminal device 180. The setting instruction is used to indicate one of the plurality of fields in the selected sample file file, and replace the selected bit of the plurality of fields with the selected character. The user can send multiple setting commands, and the disclosure is not limited to the number of setting instructions and the number of selected bits. Next, the mask position setting unit 150 sets the bit of the selected bit position in the corresponding plurality of fields in the report sample file as the mask character to generate the report mask sample. Specifically, in step S503, the mask position setting unit 150 selects an anchor position in the bit of one of the plurality of fields, and analyzes the position of the mask character set by the user according to the anchor position, Generate set rules. In the step S505, the mask position setting unit 150 modifies the report sample file according to the setting rule, so as to set the bit of the selected bit in the corresponding sample field in the report sample file as the mask character. Finally, in step S507, the mask position setting unit 150 stores the report mask sample in the mask sample database 140.

[轉譯報表][translation report]

在設定好報表遮蔽樣本之後,使用者若要輸出報表,遮蔽轉譯單元130會依據報表遮蔽樣本對使用者欲輸出的報表進行轉譯。After the report masking sample is set, if the user wants to output the report, the masking translation unit 130 translates the report that the user wants to output according to the report masking sample.

請同時參照圖4、圖6與圖7,圖6繪示本揭露一實施例中,使用者欲輸出的報表,圖7則繪示本揭露一實施例中,轉譯後的報表。Please refer to FIG. 4, FIG. 6, and FIG. 7. FIG. 6 is a diagram of a report that the user wants to output in an embodiment of the disclosure, and FIG. 7 shows a translated report in an embodiment of the disclosure.

在使用者欲輸出圖6的報表600時,處理單元110指示遮蔽轉譯單元130對報表400的內容遮蔽轉譯。此時,遮蔽轉譯單元130會於遮蔽樣本資料庫中讀取對應報表編號DT-D100的報表遮蔽樣本400,並根據報表遮蔽樣本400中所設定的遮蔽字元,將報表中對應遮蔽字元的位置的資料位元取代為遮蔽字元。舉例來說,於報表遮蔽樣本400中設定了三個設定了遮蔽字元的欄位,分別為:客戶證號,以左邊第一個位元為錨定位置,第5至7位元為欲遮蔽的位元;客戶名稱則是以左邊第一個位元為錨定位置,第2至3位元為欲遮蔽的位元;交易序號/會計套號則是以左邊第一個位元為錨定位置,第11至13位元為欲遮蔽的位元。因此,遮蔽轉譯單元130會依據上述的規則,對報表600中,對應上面三種欄位及遮蔽字元位置的位元取代為遮蔽字元,舉例來說,客戶證號會從A130000000轉譯成A130***000,客戶名稱會從測試戶轉譯為測**,而交易序號/會計套號則是由008XXF0005309轉譯為008XXF0000***9。當遮蔽轉譯單元130將所有對應遮蔽字元的位置的位元都取代為遮蔽字元後,遮蔽轉譯單元輸出轉譯完的報表700。When the user wants to output the report 600 of FIG. 6, the processing unit 110 instructs the occlusion translation unit 130 to mask the content of the report 400. At this time, the occlusion translation unit 130 reads the report occlusion sample 400 corresponding to the report number DT-D100 in the occlusion sample database, and according to the occlusion character set in the report occlusion sample 400, the corresponding occlusion character in the report is The data bit of the location is replaced by a masked character. For example, in the report masking sample 400, three fields for setting the masking characters are set, respectively: the customer identification number, the first bit on the left side is the anchor position, and the fifth to seventh bits are the desires. The masked bit; the customer name is the first bit on the left as the anchor position, the second to the third bit is the bit to be obscured; the transaction number/accounting set is the first bit on the left Anchor position, the 11th to 13th bits are the bits to be masked. Therefore, the mask translation unit 130 replaces the bit corresponding to the above three fields and the position of the mask character in the report 600 as a mask character according to the above rules. For example, the client number will be translated from A130000000 to A130*. **000, the customer name will be translated from the tester to test **, and the transaction serial number / accounting set number is translated from 008XXF0005309 to 008XXF0000***9. After the occlusion translation unit 130 replaces all the bits of the position corresponding to the occlusion character with the occlusion character, the occlusion translation unit outputs the translated report 700.

請同時參照圖1與圖8,圖8繪示本揭露一實施例的報表管理方法中,轉譯報表的流程圖。於步驟S801中,處理單元110接收報表輸出指令,以輸出報表。此時,處理單元110指示遮蔽轉譯單元130對報表進行遮蔽。遮蔽轉譯單元130會執行步驟S803,讀取對應報表識別編號的報表遮蔽樣本。接著,遮蔽轉譯單元130依據此報表遮蔽樣本轉譯報表。在轉譯報表的過程中,首先,遮蔽轉譯單元130會執行步驟S805辨識報表遮蔽樣本中多個欄位的遮蔽字元的位置。接著,遮蔽轉譯單元執行步驟S807,將報表中對應遮蔽字元的位置的位元取代為遮蔽字元。最後,遮蔽轉譯單元130執行步驟S809,輸出轉譯後的報表。處理單元110會將轉譯後的報表傳送至列印裝置170或使用者終端裝置180。Please refer to FIG. 1 and FIG. 8 simultaneously. FIG. 8 is a flow chart of the translation report in the report management method according to an embodiment of the disclosure. In step S801, the processing unit 110 receives a report output instruction to output a report. At this time, the processing unit 110 instructs the occlusion translation unit 130 to mask the report. The masking translation unit 130 performs step S803 to read the report masking sample corresponding to the report identification number. Next, the occlusion translation unit 130 masks the sample translation report according to the report. In the process of translating the report, first, the occlusion translation unit 130 performs step S805 to identify the position of the occlusion character of the plurality of fields in the report occlusion sample. Next, the masking translation unit performs step S807 to replace the bit in the report corresponding to the position of the masking character as the masking character. Finally, the occlusion translation unit 130 performs step S809 to output the translated report. The processing unit 110 transmits the translated report to the printing device 170 or the user terminal device 180.

值得一提的是,在本揭露的實施例中,若於步驟S803中,遮蔽轉譯單元無法讀取對應報表識別編號的報表遮蔽樣本時,為了避免資料外流,處理單元110會直接取消報表輸出指令。It is to be noted that, in the embodiment of the present disclosure, if the mask translation unit cannot read the report mask sample corresponding to the report identification number in step S803, the processing unit 110 directly cancels the report output instruction in order to avoid data outflow. .

綜上所述,本揭露提供了一種報表管理伺服器,以管理報表的輸出。在本揭露的報表管理伺服器中設置了自動報表遮蔽機制,當使用者欲輸出報表時,遮蔽轉譯單元會自動遮蔽報表的部分內容,以限制報表輸出的內容。藉此,即便雇員違背規範導致資料外洩,他人仍無法透過報表的內容獲知機密資料。In summary, the present disclosure provides a report management server for managing the output of a report. In the report management server of the present disclosure, an automatic report masking mechanism is set. When the user wants to output a report, the masking and translating unit automatically masks part of the report to limit the content of the report output. In this way, even if the employee breaches the specification and causes the data to leak, others cannot obtain the confidential information through the contents of the report.

雖然本新型創作已以實施例揭露如上,然其並非用以限定本新型創作,任何所屬技術領域中具有通常知識者,在不脫離本新型創作的精神和範圍內,當可作些許的更動與潤飾,故本新型創作的保護範圍當視後附的申請專利範圍所界定者為準。Although the present invention has been disclosed in the above embodiments, it is not intended to limit the novel creation, and any person skilled in the art can make some changes without departing from the spirit and scope of the novel creation. Retouching, the scope of protection of this new creation is subject to the definition of the scope of the patent application attached.

100‧‧‧報表管理伺服器100‧‧‧Report Management Server

110‧‧‧處理單元110‧‧‧Processing unit

120‧‧‧儲存單元120‧‧‧ storage unit

130‧‧‧遮蔽轉譯單元130‧‧ ‧ Shadowing translation unit

140‧‧‧遮蔽樣本資料庫140‧‧‧shadow sample database

150‧‧‧遮蔽位置設定單元150‧‧‧Shading position setting unit

160‧‧‧報表樣本資料庫160‧‧‧Report sample database

170‧‧‧列印裝置170‧‧‧Printing device

180‧‧‧使用者終端裝置180‧‧‧User terminal device

200‧‧‧報表樣本檔200‧‧‧Report sample file

210‧‧‧表頭區210‧‧‧ head area

220‧‧‧資料區220‧‧‧Information area

230‧‧‧表尾區230‧‧‧Tail area

300‧‧‧報表設定介面300‧‧‧Report setting interface

310、310a‧‧‧選取框310, 310a‧‧‧Selection box

320、320a‧‧‧欄位類型320, 320a‧‧‧ Field Type

330、330a‧‧‧資料類型330, 330a‧‧‧ data type

400‧‧‧報表遮蔽樣本400‧‧‧Report mask sample

600‧‧‧報表600‧‧‧Report

700‧‧‧轉譯後的報表700‧‧‧Translated reports

S501~S507、S801~S809‧‧‧步驟S501~S507, S801~S809‧‧‧ steps

圖1繪示本揭露一實施例的報表管理伺服器的架構圖。 圖2繪示本揭露一實施例的報表樣本檔。 圖3繪示本揭露一實施例的遮蔽位置設定介面。 圖4繪示本揭露一實施例的報表遮蔽樣本。 圖5繪示本揭露一實施例的報表管理方法中,設定報表遮蔽樣本的流程圖。 圖6繪示本揭露一實施例中,使用者欲輸出的報表。 圖7繪示本揭露一實施例中,轉譯後的報表。 圖8繪示本揭露一實施例的報表管理方法中,轉譯報表的流程圖。FIG. 1 is a block diagram of a report management server according to an embodiment of the disclosure. FIG. 2 illustrates a sample sample file of an embodiment of the present disclosure. FIG. 3 illustrates a mask position setting interface according to an embodiment of the present disclosure. FIG. 4 illustrates a report masking sample according to an embodiment of the present disclosure. FIG. 5 is a flow chart of setting a report masking sample in a report management method according to an embodiment of the present disclosure. FIG. 6 is a diagram showing a report that a user wants to output in an embodiment of the disclosure. FIG. 7 illustrates a translated report in an embodiment of the disclosure. FIG. 8 is a flow chart of translating a report in a report management method according to an embodiment of the present disclosure.

100‧‧‧報表管理伺服器 100‧‧‧Report Management Server

110‧‧‧處理單元 110‧‧‧Processing unit

120‧‧‧儲存單元 120‧‧‧ storage unit

130‧‧‧遮蔽轉譯單元 130‧‧ ‧ Shadowing translation unit

140‧‧‧遮蔽樣本資料庫 140‧‧‧shadow sample database

150‧‧‧遮蔽位置設定單元 150‧‧‧Shading position setting unit

160‧‧‧報表樣本資料庫 160‧‧‧Report sample database

170‧‧‧列印裝置 170‧‧‧Printing device

180‧‧‧使用者終端裝置 180‧‧‧User terminal device

Claims (5)

一種報表管理伺服器,用以管理報表的輸出,其中該報表具有報表識別編號,該報表管理伺服器包括: 處理單元,接收報表輸出指令; 遮蔽樣本資料庫,儲存報表遮蔽樣本;以及 遮蔽轉譯單元,耦接於該處理單元與該遮蔽樣本資料庫, 其中當該處理單元接收該報表輸出指令時,該遮蔽轉譯單元讀取對應該報表識別編號的報表遮蔽樣本,並依據該報表遮蔽樣本轉譯該報表,該報表遮蔽單元傳送轉譯後的報表至該處理單元,該處理單元輸出該轉譯後的報表。A report management server for managing output of a report, wherein the report has a report identification number, the report management server includes: a processing unit, receiving a report output instruction; masking a sample database, storing a report masking sample; and masking the translation unit And the masking sample database is coupled to the processing unit and the masking sample database, wherein when the processing unit receives the report output instruction, the masking translation unit reads a report masking sample corresponding to the report identification number, and translates the sample according to the report masking sample The report, the report masking unit transmits the translated report to the processing unit, and the processing unit outputs the translated report. 如申請專利範圍第1項的報表管理伺服器,更包括: 遮蔽位置設定單元,耦接於該遮蔽樣本資料庫,該遮蔽位置設定單元接收設定指令,其中該設定指令用以指示選取報表樣本檔中的多個欄位中的其中一個,並將該多個欄位中的其中一個的選取位元取代為遮蔽字元, 其中該遮蔽位置設定單元根據該設定指令,將該報表樣本檔中對應該些欄位中的該選取位元設定為該遮蔽字元,以產生該報表遮蔽樣本,並將該報表遮蔽樣本儲存於該遮蔽樣本資料庫。The report management server of claim 1, further comprising: a mask position setting unit coupled to the mask sample database, the mask position setting unit receiving a setting instruction, wherein the setting instruction is used to indicate that the report sample file is selected One of the plurality of fields in the field, and the selected bit of the one of the plurality of fields is replaced by a masking character, wherein the masking position setting unit pairs the report sample file according to the setting instruction The selected bit in the fields should be set as the masking character to generate the report masking sample, and the report masking sample is stored in the masking sample database. 如申請專利範圍第2項的報表管理伺服器,其中該遮蔽位置設定單元將該報表樣本檔中對應該些欄位中的該選取位元設定為該遮蔽字元時,該遮蔽位置設定單元於該些欄位中的其中一個的位元中選取錨定位置,並依據該錨定位置分析被取代為該遮蔽字元的位置,以產生設定規則, 其中該遮蔽位置設定單元並依據該設定規則修改該報表樣本檔,以將該報表樣本檔中對應該些欄位中的該選取位元設定為該遮蔽字元。The report management server of claim 2, wherein the mask position setting unit sets the selected bit in the field corresponding to the field in the report sample file as the mask character, the mask position setting unit An anchor position is selected from a bit of the one of the fields, and the position of the shadow character is replaced according to the anchor position analysis to generate a setting rule, wherein the shielding position setting unit is configured according to the setting rule Modify the report sample file to set the selected bit in the corresponding fields in the report sample file as the shadow character. 如申請專利範圍第1項的報表管理伺服器,其中於該遮蔽轉譯單元依據該報表遮蔽樣本轉譯該報表中,該遮蔽轉譯單元 依據該報表遮蔽樣本中的多個欄位中的遮蔽字元,將該報表中對應該遮蔽字元的位置的位元取代為該遮蔽字元。For example, in the report management server of claim 1, wherein the occlusion translation unit transposes the report according to the report occlusion sample, the occlusion translation unit masks the occlusion characters in the plurality of fields in the sample according to the report. The bit in the report that corresponds to the location of the masked character is replaced with the masked character. 如申請專利範圍第1項的報表管理伺服器,其中,當該遮蔽轉譯單元無法讀取對應該報表識別編號的該報表遮蔽樣本時,該處理單元取消該報表輸出指令。The report management server of claim 1, wherein the processing unit cancels the report output instruction when the occlusion translation unit cannot read the report occlusion sample corresponding to the report identification number.
TW106206328U 2017-05-05 2017-05-05 File management server TWM547135U (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW106206328U TWM547135U (en) 2017-05-05 2017-05-05 File management server

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW106206328U TWM547135U (en) 2017-05-05 2017-05-05 File management server

Publications (1)

Publication Number Publication Date
TWM547135U true TWM547135U (en) 2017-08-11

Family

ID=60188684

Family Applications (1)

Application Number Title Priority Date Filing Date
TW106206328U TWM547135U (en) 2017-05-05 2017-05-05 File management server

Country Status (1)

Country Link
TW (1) TWM547135U (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI684138B (en) * 2018-09-11 2020-02-01 南山人壽保險股份有限公司 Method for managing authority of output device and authority management system of output device
TWI707273B (en) * 2018-04-16 2020-10-11 中華電信股份有限公司 Method and system of obtaining resources using unified composite query language

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI707273B (en) * 2018-04-16 2020-10-11 中華電信股份有限公司 Method and system of obtaining resources using unified composite query language
TWI684138B (en) * 2018-09-11 2020-02-01 南山人壽保險股份有限公司 Method for managing authority of output device and authority management system of output device

Similar Documents

Publication Publication Date Title
WO2019091102A1 (en) Desensitization rule configuration method and program, application server and computer-readable storage medium
TWI641958B (en) File management server and file management method
US8355923B2 (en) Systems and methods for de-identification of personal data
US8949209B2 (en) Method and system for anonymizing data during export
US10318894B2 (en) Conformance authority reconciliation
CN110727954B (en) Data authorization desensitization automation method, device and storage medium
CA2907208C (en) System and method for developing business rules for decision engines
US7409388B2 (en) Generation of anonymized data records for testing and developing applications
US20040181670A1 (en) System and method for disguising data
JP5707250B2 (en) Database access management system, method, and program
US20100042643A1 (en) Virtual masked database
US20060074897A1 (en) System and method for dynamic data masking
US9047485B2 (en) Integrated masking for viewing of data
CN108960058B (en) Invoice method of calibration, device, computer equipment and storage medium
US11721116B2 (en) Managing camera actions
CN109033150A (en) Sensitive word verification method, device, computer equipment and storage medium
US11373006B2 (en) Processing system using natural language processing for performing dataset filtering and sanitization
TWM547135U (en) File management server
US20080010237A1 (en) System and Method for Managing Multi-Dimensional Data
US9853817B2 (en) Generating enhanced digital signatures for artifacts
KR20100138291A (en) Individual information conversion method, system and service test method using the same
JP2021103592A (en) Document management device and method for managing document
EP4131047A1 (en) Data obfuscation
US11593514B2 (en) System and method for the discovery and protection of sensitive data
KR102437712B1 (en) Time management apparatus and method