WO2019091102A1 - 脱敏规则配置方法、程序、应用服务器及计算机可读存储介质 - Google Patents

脱敏规则配置方法、程序、应用服务器及计算机可读存储介质 Download PDF

Info

Publication number
WO2019091102A1
WO2019091102A1 PCT/CN2018/089713 CN2018089713W WO2019091102A1 WO 2019091102 A1 WO2019091102 A1 WO 2019091102A1 CN 2018089713 W CN2018089713 W CN 2018089713W WO 2019091102 A1 WO2019091102 A1 WO 2019091102A1
Authority
WO
WIPO (PCT)
Prior art keywords
desensitization
rule
desensitization rule
cached
configuration
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/089713
Other languages
English (en)
French (fr)
Inventor
彭捷
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Ping An Technology Shenzhen Co Ltd
Original Assignee
Ping An Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ping An Technology Shenzhen Co Ltd filed Critical Ping An Technology Shenzhen Co Ltd
Publication of WO2019091102A1 publication Critical patent/WO2019091102A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules

Definitions

  • the present application relates to the field of communications technologies, and in particular, to a desensitization rule configuration method, a program, an application server, and a computer readable storage medium.
  • regular expressions also known as regular expressions (English: Regular Expression, often abbreviated as regex, regexp or RE in the code), is a concept of computer science. Regular tables are often used to retrieve and replace text that conforms to a pattern (rule). Many programming languages support the use of regular expressions for string operations. For example, a powerful regular expression engine is built into Perl, as well as the Java language. The concept of regular expressions was originally popularized by tools in Unix (such as sed and grep). Regular expressions are usually abbreviated as "regex”, singular with regexp, regex, plural with regexps, regexes, regexen.
  • desensitization design through regular expressions because it is too abstract, is not conducive to the user's intuitive understanding and configuration rules, which leads to the desensitization system is too complicated and difficult to maintain.
  • the present application proposes a desensitization rule configuration method, a program, an application server, and a computer readable storage medium, which can realize the visualization by desensitization rules and different desensitization rules for different user rights.
  • the intuitive and easy management of the sensitive rules improves the maintainability of the desensitization system.
  • the present application provides an application server, where the application server includes a memory, a processor, and a desensitization rule configuration program executable on the processor, where the desensitization is stored.
  • the rule configuration program is implemented by the processor to implement the following steps:
  • the desensitization rule of the data query subsystem is generated according to the selection masking original content and the rule type, and the desensitization rule corresponds to the user authority.
  • the present application further provides a desensitization rule configuration method, which is applied to an application server, and the method includes:
  • the desensitization rule of the data query subsystem is generated according to the selection masking original content and the rule type, and the desensitization rule corresponds to the user authority.
  • the present application further provides a desensitization rule configuration program, where the desensitization rule configuration program includes:
  • a parameter configuration module configured to enter a desensitization rule parameter configuration page, and select a data query subsystem
  • a selection module configured to select different shielding original content and a rule type for different user rights according to the mapping relationship table
  • a generating module configured to generate a desensitization rule of the data query subsystem according to the selected masked original content and a rule type, where the desensitization rule corresponds to the user right.
  • the present application further provides a computer readable storage medium storing a desensitization rule configuration program, the desensitization rule configuration program being executable by at least one processor, Taking the at least one processor to perform the following steps:
  • Desaturating rules of the data query subsystem are generated according to the selected masked original content and rule type, and the desensitization rule corresponds to the user authority.
  • the application server, the desensitization rule configuration method, the program, and the computer readable storage medium proposed by the present application firstly establish a mapping relationship table between sensitive fields, rule types and user rights in advance; secondly, enter the off-state Sensing the parameter parameter configuration page, selecting a data query subsystem; then, selecting different masking original content and rule type for different user rights according to the mapping relationship table; finally, generating the data query according to the selection masking original content and rule type a desensitization rule of the subsystem, the desensitization rule corresponding to the user authority.
  • 1 is a schematic diagram of an optional hardware architecture of an application server in the present application
  • FIG. 2 is a block diagram showing the program of the first embodiment of the desensitization rule configuration program of the present application
  • FIG. 3 is a block diagram showing a program of a second embodiment of the desensitization rule configuration program of the present application.
  • FIG. 4 is a flowchart of a first embodiment of a method for configuring a desensitization rule according to the present application
  • FIG. 5 is a flowchart of a second embodiment of a method for configuring desensitization rules according to the present application.
  • FIG. 1 it is a schematic diagram of an optional hardware architecture of the application server 1.
  • the application server 1 may be a computing device such as a rack server, a blade server, a tower server, or a rack server.
  • the application server 1 may be a stand-alone server or a server cluster composed of multiple servers.
  • the application server 1 may include, but is not limited to, the memory 11, the processor 12, and the network interface 13 being communicably connected to each other through a system bus.
  • the application server 1 connects to the network through the network interface 13 to obtain information.
  • the network may be an intranet, an Internet, a Global System of Mobile communication (GSM), a Wideband Code Division Multiple Access (WCDMA), a 4G network, or a 5G network.
  • Wireless or wired networks such as networks, Bluetooth, Wi-Fi, and call networks.
  • Figure 1 only shows the application server 1 with components 11-13, but it should be understood that not all illustrated components may be implemented, and more or fewer components may be implemented instead.
  • the memory 11 includes at least one type of readable storage medium including a flash memory, a hard disk, a multimedia card, a card type memory (eg, SD or DX memory, etc.), and a random access memory (RAM). , static random access memory (SRAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), programmable read only memory (PROM), magnetic memory, magnetic disk, optical disk, and the like.
  • the memory 11 may be an internal storage unit of the application server 1, such as a hard disk or memory of the application server 1.
  • the memory 11 may also be an external storage device of the application server 1, such as a plug-in hard disk equipped with the application server 1, a smart memory card (SMC), and a secure digital ( Secure Digital, SD) cards, flash cards, etc.
  • the memory 11 can also include both the internal storage unit of the application server 1 and its external storage device.
  • the memory 11 is generally used to store an operating system installed in the application server 1 and various types of application software, such as program code of the desensitization rule configuration program 200. Further, the memory 11 can also be used to temporarily store various types of data that have been output or are to be output.
  • the processor 12 may be a Central Processing Unit (CPU), controller, microcontroller, microprocessor, or other data processing chip in some embodiments.
  • the processor 12 is typically used to control the overall operation of the application server 1, such as performing data interaction or communication related control and processing, and the like.
  • the processor 12 is configured to run program code or process data stored in the memory 11, such as running the desensitization rule configuration program 200 and the like.
  • the network interface 13 may comprise a wireless network interface or a wired network interface, which is typically used to establish a communication connection between the application server 1 and other electronic devices.
  • the desensitization rule configuration program 200 is installed and run in the application server 1.
  • the sensitive field, the rule type, and the user are established in advance.
  • Permission mapping table enter the desensitization parameter parameter configuration page, select the data query subsystem; select different shielding original content and rule type for different user rights according to the mapping relationship table; generate shielding according to the original content and rule type
  • the present application proposes a desensitization rule configuration program 200.
  • FIG. 2 it is a program module diagram of the first embodiment of the present application based on the desensitization rule configuration procedure 200.
  • the desensitization rule configuration program 200 includes a series of computer program instructions stored on the memory 11, and when the computer program instructions are executed by the processor 12, the desensitization of the embodiments of the present application can be achieved.
  • the configuration operation of the rule can be divided into one or more modules based on the particular operations implemented by the various portions of the computer program instructions.
  • the desensitization rule configuration program 200 can be divided into a pre-establishment module 201, a parameter configuration module 202, a selection module 203, and a generation module 204. among them:
  • the pre-establishment module 201 is configured to pre-establish a mapping table of sensitive fields, rule types, and user rights.
  • the parameter configuration module 202 is configured to enter a desensitization rule parameter configuration page and select a data query subsystem.
  • the desensitization rule parameter configuration page is configured to input a function parameter for the desensitization function, and the desensitization function generates a desensitization rule according to the function parameter.
  • the desensitization function is an existing desensitization function, which can generate a visual interface for the user to input different function parameters according to requirements, thereby generating different desensitization rules.
  • the selecting module 203 is configured to select different masked original content and a rule type for different user rights according to the mapping relationship table.
  • the rule type includes an address, a mobile phone number, a fixed phone number, a name, a job number, and the like.
  • the rule type is not limited to the above several rule types.
  • the rule type also includes attendance information, overtime information, leave information, and employee organization structure. , department, seniority, and even salary, bonus and other information.
  • the specific rule type is determined according to the specific area of the subsystem, and the application is not limited.
  • the data type of the original text is determined by the desensitization rule according to the rule type. For example, if the rule type is a name and the original content is "Zhang San", then the generated desensitization rule shields the "Zhang San” character belonging to the nature of the name in the original content.
  • the rule type is a mobile phone number
  • the generated desensitization rule blocks the phone number character belonging to the nature of the mobile phone number in the original content, and the phone number character may be a phone number authenticated by the communication carrier, or may be The telephone number determined by the manager after the authentication is determined by the preset rule according to the arrangement rule of the existing telephone number.
  • the mobile terminal may be a mobile phone, a smart phone, a notebook computer, a digital broadcast receiver, a PDA (personal digital assistant), a PAD (tablet computer), a PMP (portable multimedia player), a navigation device, and a car.
  • a mobile device such as a device, and a fixed terminal such as a digital TV, a desktop computer, a notebook, a server, and the like.
  • the step of selecting different masking original content for different user rights specifically blocks the original content according to the sensitive field.
  • the user rights include a general employee, a department assistant, a junior manager, a middle manager, and a senior manager.
  • different shielding rules are automatically configured and generated for different user rights.
  • the content of the original text shielding and shielding rules are more than the higher-level management personnel, and then according to the corresponding
  • the content of the desensitization rule is more common to the average employee than the higher-level manager.
  • the general employee queries the data, and the desensitization rule generated according to the user authority may only display the data after the requested data is blocked.
  • Employee's own data, and its direct supervisor query data, matching the desensitization rules generated by its user rights to block the data it requests, the data it displays may include not only its own data, but also its jurisdiction. Data information of other employees.
  • HRM Human Resource Management
  • ordinary employees can only query their attendance information, overtime information, leave information, employee organization structure, department, seniority, etc., ordinary employees. Unable to query department colleagues and supervisor information.
  • the department assistant needs to assist the ordinary staff to handle the daily attendance affairs. Therefore, the department assistant can query the attendance information, overtime information, leave information, employee organization structure and department of the department, but the department assistant does not have the right to view the general employee's year. More intimate information such as capital, salary, and bonuses.
  • the junior management, middle management and senior management can only view the information of the subordinates, but not the information of the superior.
  • the selection module 203 blocks the original contents of the ordinary employee and the supervisor's information according to the user authority of the ordinary employee. .
  • the selection module 203 sends all the colleagues and supervisors' attendance information, overtime information, leave information, employee organization structure, and information outside the department. The original content is blocked. Further, when the user authority is an administrator, the selection module 203 blocks the original content of the information of the supervisor's superior supervisor according to the level of the manager.
  • the generating module 204 is configured to generate a desensitization rule of the data query subsystem according to the selected masked original content and a rule type.
  • the desensitization rule corresponds to the user authority.
  • the desensitization rule configuration program 200 proposed by the present application firstly establishes a mapping relationship table of sensitive fields, rule types and user rights in advance; secondly, enters the desensitization rule parameter configuration page, selects a data query. Subsystem; then, according to the mapping relationship table, different masking original content and rule type are selected for different user rights; finally, desensitization rules of the data query subsystem are generated according to the selection masking original content and rule type, The desensitization rule corresponds to the user authority.
  • the desensitization rule configuration program 200 of the present application further includes a judgment storage module 205 and an erase module 206.
  • the desensitization rule configuration program 200 of the present application further includes a judgment storage module 205 and an erase module 206.
  • the determining storage module 205 is configured to cache the generated desensitization rule, and compare the cached desensitization rule with a desensitization rule stored in the original database to determine whether the same desensitization rule exists.
  • the judgment storage module 205 is further configured to store the cached desensitization rule into the original database.
  • the erasing module 206 is configured to erase the cached desensitization rule when the same desensitization rule exists.
  • the desensitization rule configuration program 200 proposed by the present application can update the desensitization rules in real time by comparing the generated desensitization rules, and can also avoid a large number of repeated desensitizations. Rules appear, which in turn affects the efficiency of desensitization calculations.
  • the present application also proposes a desensitization rule configuration method.
  • FIG. 4 it is a schematic flowchart of the implementation of the first embodiment of the desensitization rule configuration method of the present application.
  • the order of execution of the steps in the flowchart shown in FIG. 4 may be changed according to different requirements, and some steps may be omitted.
  • Step S401 pre-establishing a mapping table of sensitive fields, rule types, and user rights.
  • Step S402 entering a desensitization rule parameter configuration page, and selecting a data query subsystem.
  • the desensitization rule parameter configuration page is configured to input a function parameter for the desensitization function, and the desensitization function generates a desensitization rule according to the function parameter.
  • the desensitization function is an existing desensitization function, which can generate a visual interface for the user to input different function parameters according to requirements, thereby generating different desensitization rules.
  • Step S403 selecting different masked original content and a rule type for different user rights according to the mapping relationship table.
  • the rule type includes an address, a mobile phone number, a fixed phone number, a name, a job number, and the like.
  • the rule type is not limited to the above several rule types.
  • the rule type also includes attendance information, overtime information, leave information, and employee organization structure. , department, seniority, and even salary, bonus and other information.
  • the specific rule type is determined according to the specific area of the subsystem, and the application is not limited.
  • the data type of the original text is determined by the desensitization rule according to the rule type. For example, if the rule type is a name and the original content is "Zhang San", then the generated desensitization rule shields the "Zhang San” character belonging to the nature of the name in the original content.
  • the rule type is a mobile phone number
  • the generated desensitization rule blocks the phone number character belonging to the nature of the mobile phone number in the original content, and the phone number character may be a phone number authenticated by the communication carrier, or may be The telephone number determined by the manager after the authentication is determined by the preset rule according to the arrangement rule of the existing telephone number.
  • the mobile terminal may be a mobile phone, a smart phone, a notebook computer, a digital broadcast receiver, a PDA (personal digital assistant), a PAD (tablet computer), a PMP (portable multimedia player), a navigation device, and a car.
  • a mobile device such as a device, and a fixed terminal such as a digital TV, a desktop computer, a notebook, a server, and the like.
  • the step of selecting different masking original content for different user rights specifically blocks the original content according to the sensitive field.
  • the user rights include a general employee, a department assistant, a junior manager, a middle manager, and a senior manager.
  • different shielding rules are automatically configured and generated for different user rights.
  • the original content of the selected content and the shielding rules are more than the higher-level management personnel, and then according to the corresponding
  • the content of the desensitization rule is more common to the average employee than the higher-level manager.
  • the general employee queries the data, and the desensitization rule generated according to the user's authority may only display the employee after shielding the requested data. Its own data, and its direct supervisor query data, matching the desensitization rules generated by its user rights to block the data it requests, the data it displays may include not only its own data, but also other jurisdictions with jurisdiction. Employee data information.
  • HRM Human Resource Management
  • ordinary employees can only query their attendance information, overtime information, leave information, employee organization structure, department, seniority, etc., ordinary employees. Unable to query department colleagues and supervisor information.
  • the department assistant needs to assist the ordinary staff to handle the daily attendance affairs. Therefore, the department assistant can query the attendance information, overtime information, leave information, employee organization structure and department of the department, but the department assistant does not have the right to view the general employee's year. More intimate information such as capital, salary, and bonuses.
  • the junior management, middle management and senior management can only view the information of the subordinates, but not the information of the superior.
  • the application server 1 blocks the original content of the ordinary employee and the supervisor's information according to the user authority of the ordinary employee. .
  • the application server 1 according to the user authority of the department assistant, the attendance information, the overtime information, the leave information, the employee organization structure, and the information other than the department in the department and the supervisors. The original content is blocked.
  • the application server 1 masks the original content of the information of the supervisor's superior supervisor according to the level of the manager.
  • Step S404 generating a desensitization rule of the data query subsystem according to the selected mask original content and the rule type.
  • the desensitization rule corresponds to the user authority.
  • the desensitization rule configuration method proposed by the present application firstly establishes a mapping relationship table between sensitive fields, rule types and user rights in advance; secondly, enters a desensitization rule parameter configuration page, and selects a data query subsystem. And then, according to the mapping relationship table, different masking original content and rule type are selected for different user rights; finally, desensitization rules of the data query subsystem are generated according to the selection masking original content and rule type, the desensitization rule The rule corresponds to the user right.
  • FIG. 5 it is a schematic flowchart of the implementation of the second embodiment of the desensitization rule configuration method of the present application.
  • the order of execution of the steps in the flowchart shown in FIG. 5 may be changed according to different requirements, and some steps may be omitted.
  • Step S501 a mapping table of sensitive fields, rule types, and user rights is established in advance.
  • Step S502 entering a desensitization rule parameter configuration page, and selecting a data query subsystem.
  • the desensitization rule parameter configuration page is configured to input a function parameter for the desensitization function, and the desensitization function generates a desensitization rule according to the function parameter.
  • the desensitization function is an existing desensitization function, which can generate a visual interface for the user to input different function parameters according to requirements, thereby generating different desensitization rules.
  • Step S503 selecting different masked original content and a rule type for different user rights according to the mapping relationship table.
  • Step S504 generating a desensitization rule of the data query subsystem according to the selected mask original content and the rule type.
  • the desensitization rule corresponds to the user authority.
  • Step S505 the generated desensitization rule is cached, and the cached desensitization rule is compared with the desensitization rule stored in the original database.
  • Step S506 judging whether there is the same desensitization rule according to the comparison result.
  • step S507 is performed, and conversely, when the same desensitization rule exists, step S508 is performed.
  • Step S507 storing the cached desensitization rule into the original database.
  • the database may be SQL Server, Oracle, MySQL, or the like.
  • Step S508 erasing the cached desensitization rule. In this way, a large number of repeated desensitization rules can be avoided, which in turn affects the efficiency of desensitization calculations.
  • the desensitization rule configuration method proposed by the present application can realize the intuitive and simple management of the desensitization rule by visualizing the desensitization rule configuration and assigning different desensitization rules to different user rights. Improves the maintainability of the desensitization system. At the same time, by comparing the generated desensitization rules, the desensitization rules can be updated in real time, and a large number of repeated desensitization rules can be avoided, thereby affecting the efficiency of desensitization calculation.
  • the present application further provides a computer readable storage medium storing a desensitization rule configuration program, the desensitization rule configuration program being executable by at least one processor, The step of causing the at least one processor to perform the desensitization rule configuration method as described above.
  • the foregoing embodiment method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be through hardware, but in many cases, the former is better.
  • Implementation Based on such understanding, the technical solution of the present application, which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a storage medium (such as ROM/RAM, disk,
  • the optical disc includes a number of instructions for causing a terminal device (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to perform the methods described in various embodiments of the present application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Health & Medical Sciences (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Bioethics (AREA)
  • Automation & Control Theory (AREA)
  • Storage Device Security (AREA)

Abstract

本申请公开了一种脱敏规则配置方法,所述方法包括:预先建立敏感字段、规则类型与用户权限的映射关系表;进入脱敏规则参数配置页面,选择数据查询子系统;依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。本申请还提供一种脱敏规则配置程序、应用服务器及计算机可读存储介质。本申请提供的脱敏规则配置方法、程序、应用服务器及计算机可读存储介质,可以通过脱敏规则配置的可视化,以及针对不同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。

Description

脱敏规则配置方法、程序、应用服务器及计算机可读存储介质
优先权申明
本申请基于巴黎公约申明享有2017年11月07日递交的申请号为CN201711086614.6、名称为“脱敏规则配置方法、应用服务器及计算机可读存储介质”中国专利申请的优先权,该中国专利申请的整体内容以参考的方式结合在本申请中。
技术领域
本申请涉及通信技术领域,尤其涉及一种脱敏规则配置方法、程序、应用服务器及计算机可读存储介质。
背景技术
随着互联网技术的飞速发展,政府及企业已经积累了大量的敏感信息和数据,而这些数据在很多工作场景中会得到使用,例如,业务分析(用户的精准定位、大数据商业价值的挖掘)、共享与交换、开发测试、甚至是一些外包业务,使用的都是真实的业务数据和信息。这些敏感数据一旦发生泄漏,不仅会给政府及企业本身带来巨大的损失,对个人及企业用户带来无法估量的损害。
当下,敏感的个人、财务和健康信息受到多种不同行业和政府数据隐私法规的管制。如果企业无法保持数据隐私,就会面临严重的财务和法律惩罚,同时还会在客户与市场信心方面蒙受可观损失。至关重要的是,企业既要保护数以百计的应用程序和数据库免受业务用户、生产支持团队、DBA、开发人员以及外包团队的不利影响,同时又要让他们完成他们的工作。因此,数据脱敏是亟待解决的难题。
而在现有的脱敏系统中,主要利用正则表达式来实现脱敏。其中正则表达式,又称规则表达式,(英语:Regular Expression,在代码中常简写为regex、regexp或RE),是计算机科学的一个概念。正则表通常被用来检索、替换那些符合某个模式(规则)的文本。许多程序设计语言都支持利用正则表达式进行字 符串操作。例如,在Perl中就内建了一个功能强大的正则表达式引擎,还有java语言自带的。正则表达式这个概念最初是由Unix中的工具软件(例如sed和grep)普及开的。正则表达式通常缩写成“regex”,单数有regexp、regex,复数有regexps、regexes、regexen。然而,通过正则表达式来进行脱敏设计,由于其过于抽象,而不利于用户的直观理解及配置规则,进而导致脱敏系统过于复杂且不易维护。
发明内容
有鉴于此,本申请提出一种脱敏规则配置方法、程序、应用服务器及计算机可读存储介质,可以通过脱敏规则配置的可视化,以及针对不同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。
首先,为实现上述目的,本申请提出一种应用服务器,所述应用服务器包括存储器、处理器,所述存储器上存储有可在所述处理器上运行的脱敏规则配置程序,所述脱敏规则配置程序被所述处理器执行时实现如下步骤:
预先建立敏感字段、规则类型与用户权限的映射关系表;
进入脱敏规则参数配置页面,选择数据查询子系统;
依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及
根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
此外,为实现上述目的,本申请还提供一种脱敏规则配置方法,该方法应用于应用服务器,所述方法包括:
预先建立敏感字段、规则类型与用户权限的映射关系表;
进入脱敏规则参数配置页面,选择数据查询子系统;
依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则 类型;及
根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
进一步地,为实现上述目的,本申请还提供一种脱敏规则配置程序,所述脱敏规则配置程序包括:
预先建立模块,用于预先建立敏感字段、规则类型与用户权限的映射关系表;
参数配置模块,用于进入脱敏规则参数配置页面,选择数据查询子系统;
选择模块,用于依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及
生成模块,用于根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
进一步地,为实现上述目的,本申请还提供一种计算机可读存储介质,所述计算机可读存储介质存储有脱敏规则配置程序,所述脱敏规则配置程序可被至少一个处理器执行,以使所述至少一个处理器执行如下步骤:
预先建立敏感字段、规则类型与用户权限的映射关系表;
进入脱敏规则参数配置页面,选择数据查询子系统;
依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及
根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
相较于现有技术,本申请所提出的应用服务器、脱敏规则配置方法、程序及计算机可读存储介质,首先,预先建立敏感字段、规则类型与用户权限的映射关系表;其次,进入脱敏规则参数配置页面,选择数据查询子系统;然后,依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规 则类型;最后,根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。这样,既可以避免现有技术中通过正则表达式来进行脱敏设计,过于抽象,而不利于用户的直观理解及配置规则,进而导致脱敏系统过于复杂且不易维护的弊端。又可以通过脱敏规则配置的可视化,以及针对不同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。
附图说明
图1是本申请中应用服务器一可选的硬件架构的示意图;
图2是本申请脱敏规则配置程序第一实施例的程序模块图;
图3是本申请脱敏规则配置程序第二实施例的程序模块图;
图4为本申请脱敏规则配置方法第一实施例的流程图;
图5为本申请脱敏规则配置方法第二实施例的流程图。
附图标记:
应用服务器 1
存储器 11
处理器 12
网络接口 13
脱敏规则配置程序 200
预先建立模块 201
参数配置模块 202
选择模块 203
生成模块 204
判断存储模块 205
擦除模块 206
本申请目的的实现、功能特点及优点将结合实施例,参照附图做进一步说明。
具体实施方式
为了使本申请的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本申请进行进一步详细说明。应当理解,此处所描述的具体实施例仅用以解释本申请,并不用于限定本申请。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
需要说明的是,在本申请中涉及“第一”、“第二”等的描述仅用于描述目的,而不能理解为指示或暗示其相对重要性或者隐含指明所指示的技术特征的数量。由此,限定有“第一”、“第二”的特征可以明示或者隐含地包括至少一个该特征。另外,各个实施例之间的技术方案可以相互结合,但是必须是以本领域普通技术人员能够实现为基础,当技术方案的结合出现相互矛盾或无法实现时应当认为这种技术方案的结合不存在,也不在本申请要求的保护范围之内。
参阅图1所示,是应用服务器1一可选的硬件架构的示意图。
所述应用服务器1可以是机架式服务器、刀片式服务器、塔式服务器或机柜式服务器等计算设备,该应用服务器1可以是独立的服务器,也可以是多个服务器所组成的服务器集群。
本实施例中,所述应用服务器1可包括,但不仅限于,可通过系统总线相互通信连接存储器11、处理器12、网络接口13。
所述应用服务器1通过网络接口13连接网络,获取资讯。所述网络可以是企业内部网(Intranet)、互联网(Internet)、全球移动通讯系统(Global System of Mobile communication,GSM)、宽带码分多址(Wideband Code Division Multiple Access,WCDMA)、4G网络、5G网络、蓝牙(Bluetooth)、Wi-Fi、通话网络等无线或有线网络。
需要指出的是,图1仅示出了具有组件11-13的应用服务器1,但是应理解的是,并不要求实施所有示出的组件,可以替代的实施更多或者更少的组件。
其中,所述存储器11至少包括一种类型的可读存储介质,所述可读存储介质包括闪存、硬盘、多媒体卡、卡型存储器(例如,SD或DX存储器等)、随机访问存储器(RAM)、静态随机访问存储器(SRAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、可编程只读存储器(PROM)、磁性存储器、磁盘、光盘等。在一些实施例中,所述存储器11可以是所述应用服务器1的内部存储单元,例如该应用服务器1的硬盘或内存。在另一些实施例中,所述存储器11也可以是所述应用服务器1的外部存储设备,例如该应用服务器1配备的插接式硬盘,智能存储卡(Smart Media Card,SMC),安全数字(Secure Digital,SD)卡,闪存卡(Flash Card)等。当然,所述存储器11还可以既包括所述应用服务器1的内部存储单元也包括其外部存储设备。本实施例中,所述存储器11通常用于存储安装于所述应用服务器1的操作系统和各类应用软件,例如脱敏规则配置程序200的程序代码等。此外,所述存储器11还可以用于暂时地存储已经输出或者将要输出的各类数据。
所述处理器12在一些实施例中可以是中央处理器(Central Processing Unit,CPU)、控制器、微控制器、微处理器、或其他数据处理芯片。该处理器12通常用于控制所述应用服务器1的总体操作,例如执行数据交互或者通信相关的控制和处理等。本实施例中,所述处理器12用于运行所述存储器11中存储的程序代码或者处理数据,例如运行所述的脱敏规则配置程序200等。
所述网络接口13可包括无线网络接口或有线网络接口,该网络接口13通常用于在所述应用服务器1与其他电子设备之间建立通信连接。
本实施例中,所述应用服务器1内安装并运行有脱敏规则配置程序200,当所述应用服务器1内安装并运行有脱敏规则配置程序200时,预先建立敏感字段、规则类型与用户权限的映射关系表;进入脱敏规则参数配置页面,选择数据查询子系统;依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。这样,既可以避免现有 技术中通过正则表达式来进行脱敏设计,过于抽象,而不利于用户的直观理解及配置规则,进而导致脱敏系统过于复杂且不易维护的弊端。又可以通过脱敏规则配置的可视化,以及针对不同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。
至此,己经详细介绍了本申请各个实施例的应用环境和相关设备的硬件结构和功能。下面,将基于上述应用环境和相关设备,提出本申请的各个实施例。
首先,本申请提出一种脱敏规则配置程序200。
参阅图2所示,是本申请基于脱敏规则配置程序200第一实施例的程序模块图。
本实施例中,所述的脱敏规则配置程序200包括一系列的存储于存储器11上的计算机程序指令,当该计算机程序指令被处理器12执行时,可以实现本申请各实施例的脱敏规则的配置操作。在一些实施例中,基于该计算机程序指令各部分所实现的特定的操作,所述脱敏规则配置程序200可以被划分为一个或多个模块。例如,在图2中,所述的脱敏规则配置程序200可以被分割成预先建立模块201、参数配置模块202、选择模块203及生成模块204。其中:
所述预先建立模块201,用于预先建立敏感字段、规则类型与用户权限的映射关系表。
所述参数配置模块202,用于进入脱敏规则参数配置页面,选择数据查询子系统。具体地,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
本实施例中,所述脱敏函数为现有的脱敏函数,其可以生成可视化界面,供用户根据需要输入不同的函数参数,进而生成不同的脱敏规则。
所述选择模块203,用于依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型。
本实施例中,所述规则类型包括地址、移动电话号码、固定电话号码、姓名、工号等。当然,在不同的子系统中,所述规则类型并不限于上述几种 规则类型,例如在下文的人力资源管理系统中,所述规则类型还包括考勤信息、加班信息、请假信息、员工组织架构、所在部门、年资,甚至是薪资、奖金等信息。具体的规则类型根据子系统具体涉及的领域而定,本申请并不作限定。
在本实施例中,根据所述规则类型确定脱敏规则对原文(或者原内容)中的何种数据类型进行屏蔽。比如,规则类型是姓名,原文内容是“张三”,那么生成的脱敏规则对原文内容中属于姓名性质的“张三”字符进行屏蔽。当规则类型是移动电话号码时,那么生成的脱敏规则对原文内容中属于移动电话号码性质的具有电话号码字符进行屏蔽,所述电话号码字符可以是通信运营商认证的电话号码,也可以是管理人员根据现有电话号码的排列规律通过预设规则进行认证后确定的电话号码。这样,用户通过移动终端获取的内容与原内容相比就会缺少相应规则类型的字符(如地址、移动电话号码、固定电话号码、姓名、工号等)。本实施例中,所述移动终端可以是移动电话、智能电话、笔记本电脑、数字广播接收器、PDA(个人数字助理)、PAD(平板电脑)、PMP(便携式多媒体播放器)、导航装置、车载装置等等的可移动设备,以及诸如数字TV、台式计算机、笔记本、服务器等等的固定终端。
另外,所述对不同的用户权限选择不同的屏蔽原内容的步骤具体依据敏感字段进行屏蔽原内容。
具体地,所述用户权限包括普通员工、部门助理、初级管理人员、中级管理人员和高级管理人员。
在本实施例中,针对不同的用户权限,自动配置并生成不同的屏蔽规则,比如,对于普通员工,对其选择的原文屏蔽内容和屏蔽规则要多于高一级的管理人员,进而依据相应的脱敏规则屏蔽的内容对普通员工而言要多于高一级的管理人员,比如普通员工查询数据,根据其用户权限生成的脱敏规则,对其所请求的数据屏蔽后可能只展示该员工自己的数据,而其直接主管查询数据,匹配其用户权限生成的脱敏规则对其请求的数据进行屏蔽后,其展现的数据可能不仅包括他自己的数据,也可能包括其有管辖权限的其他员工的数据信息。
下面,以一具体实施例进行说明:
例如,当员工访问公司的人力资源管理系统(Human Resource Management,HRM)时,普通员工只能查询自己的考勤信息、加班信息、请假信息、员工组织架构、所在部门、年资等信息,普通员工无法查询部门同事以及主管的信息。而部门助理需要协助普通员工处理日常考勤事务,因此,部门助理能够查询部门所有员工的考勤信息、加班信息、请假信息、员工组织架构及所在部门等信息,但是部门助理没有权限查看普通员工的年资、薪资、奖金等比较私密的信息。而初级管理人员、中级管理人员和高级管理人员分别只能查看下属的信息,而不能查阅上级主管的信息。
因此,当所述用户权限为普通员工,且当普通员工访问HRM系统时,所述选择模块203根据普通员工的用户权限,将所述普通员工外部门同事以及主管的信息的原内容均进行屏蔽。而,当所述用户权限为部门助理的时候,所述选择模块203根据部门助理的用户权限,将部门所有同事以及主管的考勤信息、加班信息、请假信息、员工组织架构及所在部门以外的信息的原内容均进行屏蔽。进一步地,当所述用户权限为管理人员的时候,所述选择模块203根据所述管理人员的级别将所述管理人员上级主管的信息的原内容均进行屏蔽。
所述生成模块204,用于根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则。所述脱敏规则对应所述用户权限。
通过上述程序模块201-204,本申请所提出的脱敏规则配置程序200,首先,预先建立敏感字段、规则类型与用户权限的映射关系表;其次,进入脱敏规则参数配置页面,选择数据查询子系统;然后,依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;最后,根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。这样,既可以避免现有技术中通过正则表达式来进行脱敏设计,过于抽象,而不利于用户的直观理解及配置规则,进而导致脱敏系统过于复杂且不易维护的弊端。又可以通过脱敏规则配置的可视化,以及针对不 同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。
进一步地,基于本申请的脱敏规则配置程序200的上述第一实施例,提出本申请的第二实施例(如图3所示)。本实施例中,本申请的脱敏规则配置程序200还包括判断存储模块205及擦除模块206。本实施例中:
所述判断存储模块205,用于将生成的所述脱敏规则进行缓存,并将缓存的所述脱敏规则与原数据库中存储的脱敏规则进行对比以判断是否存在相同的脱敏规则。
若不存在相同的脱敏规则时,所述判断存储模块205还用于将缓存的所述脱敏规则存储进原数据库。
所述擦除模块206,用于当存在相同的脱敏规则时,将缓存的所述脱敏规则进行擦除。
通过上述程序模块205-206,本申请所提出的脱敏规则配置程序200,通过对生成的脱敏规则进行比较处理,可以实时的对脱敏规则进行更新,同时也可以避免大量重复的脱敏规则出现,进而影响脱敏计算的效率。
此外,本申请还提出一种脱敏规则配置方法。
参阅图4所示,是本申请脱敏规则配置方法第一实施例的实施流程示意图。在本实施例中,根据不同的需求,图4所示的流程图中的步骤的执行顺序可以改变,某些步骤可以省略。
步骤S401,预先建立敏感字段、规则类型与用户权限的映射关系表。
步骤S402,进入脱敏规则参数配置页面,选择数据查询子系统。具体地,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
本实施例中,所述脱敏函数为现有的脱敏函数,其可以生成可视化界面,供用户根据需要输入不同的函数参数,进而生成不同的脱敏规则。
步骤S403,依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型。
本实施例中,所述规则类型包括地址、移动电话号码、固定电话号码、姓名、工号等。当然,在不同的子系统中,所述规则类型并不限于上述几种规则类型,例如在下文的人力资源管理系统中,所述规则类型还包括考勤信息、加班信息、请假信息、员工组织架构、所在部门、年资,甚至是薪资、奖金等信息。具体的规则类型根据子系统具体涉及的领域而定,本申请并不作限定。
在本实施例中,根据所述规则类型确定脱敏规则对原文(或者原内容)中的何种数据类型进行屏蔽。比如,规则类型是姓名,原文内容是“张三”,那么生成的脱敏规则对原文内容中属于姓名性质的“张三”字符进行屏蔽。当规则类型是移动电话号码时,那么生成的脱敏规则对原文内容中属于移动电话号码性质的具有电话号码字符进行屏蔽,所述电话号码字符可以是通信运营商认证的电话号码,也可以是管理人员根据现有电话号码的排列规律通过预设规则进行认证后确定的电话号码。这样,用户通过移动终端获取的内容与原内容相比就会缺少相应规则类型的字符(如地址、移动电话号码、固定电话号码、姓名、工号等)。本实施例中,所述移动终端可以是移动电话、智能电话、笔记本电脑、数字广播接收器、PDA(个人数字助理)、PAD(平板电脑)、PMP(便携式多媒体播放器)、导航装置、车载装置等等的可移动设备,以及诸如数字TV、台式计算机、笔记本、服务器等等的固定终端。
另外,所述对不同的用户权限选择不同的屏蔽原内容的步骤具体依据敏感字段进行屏蔽原内容。
具体地,所述用户权限包括普通员工、部门助理、初级管理人员、中级管理人员和高级管理人员。
在本实施例中,针对不同的用户权限,自动配置并生成不同的屏蔽规则,比如对于普通员工,对其选择的原文屏蔽内容和屏蔽规则要多于高一级的管理人员,进而依据相应的脱敏规则屏蔽的内容对普通员工而言要多于高一级的管理人员,比如普通员工查询数据,根据其用户权限生成的脱敏规则,对 其所请求的数据屏蔽后可能只展示该员工自己的数据,而其直接主管查询数据,匹配其用户权限生成的脱敏规则对其请求的数据进行屏蔽后,其展现的数据可能不仅包括他自己的数据,也可能包括其有管辖权限的其他员工的数据信息。
下面,以一具体实施例进行说明:
例如,当员工访问公司的人力资源管理系统(Human Resource Management,HRM)时,普通员工只能查询自己的考勤信息、加班信息、请假信息、员工组织架构、所在部门、年资等信息,普通员工无法查询部门同事以及主管的信息。而部门助理需要协助普通员工处理日常考勤事务,因此,部门助理能够查询部门所有员工的考勤信息、加班信息、请假信息、员工组织架构及所在部门等信息,但是部门助理没有权限查看普通员工的年资、薪资、奖金等比较私密的信息。而初级管理人员、中级管理人员和高级管理人员分别只能查看下属的信息,而不能查阅上级主管的信息。
因此,当所述用户权限为普通员工,且当普通员工访问HRM系统时,所述应用服务器1根据普通员工的用户权限,将所述普通员工外部门同事以及主管的信息的原内容均进行屏蔽。而,当所述用户权限为部门助理的时候,所述应用服务器1根据部门助理的用户权限,将部门所有同事以及主管的考勤信息、加班信息、请假信息、员工组织架构及所在部门以外的信息的原内容均进行屏蔽。进一步地,当所述用户权限为管理人员的时候,所述应用服务器1根据所述管理人员的级别将所述管理人员上级主管的信息的原内容均进行屏蔽。
步骤S404,根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则。所述脱敏规则对应所述用户权限。
通过上述步骤S401-404,本申请所提出的脱敏规则配置方法,首先,预先建立敏感字段、规则类型与用户权限的映射关系表;其次,进入脱敏规则参数配置页面,选择数据查询子系统;然后,依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;最后,根据选择屏蔽原内容 和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。这样,既可以避免现有技术中通过正则表达式来进行脱敏设计,过于抽象,而不利于用户的直观理解及配置规则,进而导致脱敏系统过于复杂且不易维护的弊端。又可以通过脱敏规则配置的可视化,以及针对不同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。
参阅图5所示,是本申请脱敏规则配置方法第二实施例的实施流程示意图。在本实施例中,根据不同的需求,图5所示的流程图中的步骤的执行顺序可以改变,某些步骤可以省略。
步骤S501,预先建立敏感字段、规则类型与用户权限的映射关系表。
步骤S502,进入脱敏规则参数配置页面,选择数据查询子系统。具体地,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
本实施例中,所述脱敏函数为现有的脱敏函数,其可以生成可视化界面,供用户根据需要输入不同的函数参数,进而生成不同的脱敏规则。
步骤S503,依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型。
步骤S504,根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则。所述脱敏规则对应所述用户权限。
步骤S505,将生成的所述脱敏规则进行缓存,并将缓存的所述脱敏规则与原数据库中存储的脱敏规则进行对比。
步骤S506,根据对比结果判断是否存在相同的脱敏规则。当不存在相同的脱敏规则时,执行步骤S507,反之,当存在相同的脱敏规则时,执行步骤S508。
步骤S507,将缓存的所述脱敏规则存储进原数据库。本实施例中,数据库可以为SQL Server、Oracle、MySQL等。
步骤S508,将缓存的所述脱敏规则进行擦除。这样,可以避免大量重复 的脱敏规则出现,进而影响脱敏计算的效率。
通过上述步骤S501-508,本申请所提出的脱敏规则配置方法,可以通过脱敏规则配置的可视化,以及针对不同用户权限赋予不同的脱敏规则,实现了脱敏规则的直观且简易的管理,提高了脱敏系统的可维护性。同时,通过对生成的脱敏规则进行比较处理,可以实时的对脱敏规则进行更新,也可以避免大量重复的脱敏规则出现,进而影响脱敏计算的效率。
进一步地,为实现上述目的,本申请还提供一种计算机可读存储介质,所述计算机可读存储介质存储有脱敏规则配置程序,所述脱敏规则配置程序可被至少一个处理器执行,以使所述至少一个处理器执行如上述的脱敏规则配置方法的步骤。
上述本申请实施例序号仅仅为了描述,不代表实施例的优劣。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
以上仅为本申请的优选实施例,并非因此限制本申请的专利范围,凡是利用本申请说明书及附图内容所作的等效结构或等效流程变换,或直接或间接运用在其他相关的技术领域,均同理包括在本申请的专利保护范围内。

Claims (20)

  1. 一种脱敏规则配置方法,应用于应用服务器,其特征在于,所述方法包括步骤:
    预先建立敏感字段、规则类型与用户权限的映射关系表;
    进入脱敏规则参数配置页面,选择数据查询子系统;
    依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及
    根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
  2. 如权利要求1所述的脱敏规则配置方法,其特征在于,所述方法还包括步骤:
    将生成的所述脱敏规则进行缓存,并将缓存的所述脱敏规则与原数据库中存储的脱敏规则进行对比以判断是否存在相同的脱敏规则;及
    若不存在相同的脱敏规则时,则将缓存的所述脱敏规则存储进原数据库。
  3. 如权利要求2所述的脱敏规则配置方法,其特征在于,所述方法还包括步骤:
    若存在相同的脱敏规则时,则将缓存的所述脱敏规则进行擦除。
  4. 如权利要求1所述的脱敏规则配置方法,其特征在于,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
  5. 如权利要求1所述的脱敏规则配置方法,其特征在于,所述用户权限包括普通员工、初级管理人员、中级管理人员和高级管理人员。
  6. 一种应用服务器,其特征在于,所述应用服务器包括存储器、处理器,所述存储器上存储有可在所述处理器上运行的脱敏规则配置程序,所述脱敏规则配置程序被所述处理器执行时实现如下步骤:
    预先建立敏感字段、规则类型与用户权限的映射关系表;
    进入脱敏规则参数配置页面,选择数据查询子系统;
    依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则 类型;及
    根据选择屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
  7. 如权利要求6所述的应用服务器,其特征在于,所述脱敏规则配置程序被所述处理器执行时,还实现如下步骤:
    将生成的所述脱敏规则进行缓存,并将缓存的所述脱敏规则与原数据库中存储的脱敏规则进行对比以判断是否存在相同的脱敏规则;及
    若不存在相同的脱敏规则时,则将缓存的所述脱敏规则存储进原数据库。
  8. 如权利要求7所述的应用服务器,其特征在于,所述脱敏规则配置程序被所述处理器执行时,还实现如下步骤:
    若存在相同的脱敏规则时,则将缓存的所述脱敏规则进行擦除。
  9. 如权利要求6所述的应用服务器,其特征在于,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
  10. 如权利要求6所述的应用服务器,其特征在于,所述用户权限包括普通员工、初级管理人员、中级管理人员和高级管理人员。
  11. 一种脱敏规则配置程序,其特征在于,所述脱敏规则配置程序包括:
    预先建立模块,用于预先建立敏感字段、规则类型与用户权限的映射关系表;
    参数配置模块,用于进入脱敏规则参数配置页面,选择数据查询子系统;
    选择模块,用于依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及
    生成模块,用于根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
  12. 如权利要求11所述的脱敏规则配置程序,其特征在于,所述脱敏规则配置程序还包括:
    判断存储模块,用于将生成的所述脱敏规则进行缓存,并将缓存的所述脱敏规则与原数据库中存储的脱敏规则进行对比以判断是否存在相同的脱敏 规则;及若不存在相同的脱敏规则时,则将缓存的所述脱敏规则存储进原数据库。
  13. 如权利要求12所述的脱敏规则配置程序,其特征在于,所述脱敏规则配置程序还包括:
    擦除模块,用于若存在相同的脱敏规则时,则将缓存的所述脱敏规则进行擦除。
  14. 如权利要求11所述的脱敏规则配置程序,其特征在于,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
  15. 如权利要求11所述的脱敏规则配置程序,其特征在于,所述用户权限包括普通员工、初级管理人员、中级管理人员和高级管理人员。
  16. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质存储有脱敏规则配置程序,所述脱敏规则配置程序可被至少一个处理器执行,以使所述至少一个处理器执行如下步骤:
    预先建立敏感字段、规则类型与用户权限的映射关系表;
    进入脱敏规则参数配置页面,选择数据查询子系统;
    依据所述映射关系表对不同的用户权限选择不同的屏蔽原内容以及规则类型;及
    根据选择的屏蔽原内容和规则类型生成所述数据查询子系统的脱敏规则,所述脱敏规则对应所述用户权限。
  17. 如权利要求16所述的计算机可读存储介质,其特征在于,所述脱敏规则配置程序被所述处理器执行时,还实现如下步骤:
    将生成的所述脱敏规则进行缓存,并将缓存的所述脱敏规则与原数据库中存储的脱敏规则进行对比以判断是否存在相同的脱敏规则;及
    若不存在相同的脱敏规则时,则将缓存的所述脱敏规则存储进原数据库。
  18. 如权利要求17所述的计算机可读存储介质,其特征在于,所述脱敏规则配置程序被所述处理器执行时,还实现如下步骤:
    若存在相同的脱敏规则时,则将缓存的所述脱敏规则进行擦除。
  19. 如权利要求16所述的计算机可读存储介质,其特征在于,所述脱敏规则参数配置页面用于为脱敏函数输入函数参数,所述脱敏函数根据所述函数参数生成脱敏规则。
  20. 如权利要求16所述的计算机可读存储介质,其特征在于,所述用户权限包括普通员工、初级管理人员、中级管理人员和高级管理人员。
PCT/CN2018/089713 2017-11-07 2018-06-03 脱敏规则配置方法、程序、应用服务器及计算机可读存储介质 Ceased WO2019091102A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201711086614.6A CN107871083A (zh) 2017-11-07 2017-11-07 脱敏规则配置方法、应用服务器及计算机可读存储介质
CN201711086614.6 2017-11-07

Publications (1)

Publication Number Publication Date
WO2019091102A1 true WO2019091102A1 (zh) 2019-05-16

Family

ID=61753718

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/089713 Ceased WO2019091102A1 (zh) 2017-11-07 2018-06-03 脱敏规则配置方法、程序、应用服务器及计算机可读存储介质

Country Status (2)

Country Link
CN (1) CN107871083A (zh)
WO (1) WO2019091102A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111488604A (zh) * 2020-04-07 2020-08-04 杭州迪普科技股份有限公司 数据脱敏系统和数据脱敏方法
CN113742763A (zh) * 2021-11-08 2021-12-03 中关村科技软件股份有限公司 一种基于政务敏感数据混淆加密方法及系统
CN118037469A (zh) * 2024-02-21 2024-05-14 柳州市德鲁克企业管理咨询有限公司 基于大数据的财务管理系统

Families Citing this family (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107871083A (zh) * 2017-11-07 2018-04-03 平安科技(深圳)有限公司 脱敏规则配置方法、应用服务器及计算机可读存储介质
CN108537062B (zh) * 2018-04-24 2022-03-22 山东华软金盾软件股份有限公司 一种数据库数据动态加密的方法
CN108664812B (zh) * 2018-05-14 2023-03-10 创新先进技术有限公司 信息脱敏方法、装置及系统
CN110489990B (zh) * 2018-05-15 2021-08-31 中国移动通信集团浙江有限公司 一种敏感数据处理方法、装置、电子设备及存储介质
CN108846292B (zh) * 2018-05-30 2021-08-17 中国联合网络通信集团有限公司 脱敏规则生成方法及装置
CN108959964A (zh) * 2018-06-29 2018-12-07 阿里巴巴集团控股有限公司 一种用于报文脱敏的方法、装置及计算机设备
CN110162993B (zh) * 2018-07-17 2024-01-05 腾讯科技(深圳)有限公司 脱敏处理方法、模型训练方法、装置和计算机设备
CN109522315B (zh) * 2018-10-26 2021-10-22 苏宁易购集团股份有限公司 一种数据库处理方法及系统
CN109740359B (zh) * 2018-12-28 2021-02-09 上海点融信息科技有限责任公司 用于数据脱敏的方法、装置及存储介质
CN109697367B (zh) * 2019-01-09 2021-08-24 腾讯科技(深圳)有限公司 显示区块链数据的方法、区块链浏览器、用户节点和介质
CN110008744B (zh) * 2019-03-28 2022-04-01 平安科技(深圳)有限公司 数据脱敏方法和相关装置
CN110532797A (zh) * 2019-07-24 2019-12-03 方盈金泰科技(北京)有限公司 大数据的脱敏方法和系统
CN110659441B (zh) * 2019-09-26 2024-01-12 腾讯科技(深圳)有限公司 一种基于区块链的信息发布管理方法及装置
CN111045720B (zh) * 2019-12-12 2024-01-02 广州品唯软件有限公司 代码管理方法、代码管理系统、服务器及介质
CN111125767A (zh) * 2019-12-26 2020-05-08 秒针信息技术有限公司 动态脱敏方法、装置、电子设备和计算机可读存储介质
CN111131488A (zh) * 2019-12-30 2020-05-08 武汉佰钧成技术有限责任公司 一种局域网身份识别单元的远程管理方法和系统
CN111475525A (zh) * 2020-03-05 2020-07-31 平安科技(深圳)有限公司 基于结构化查询语言的脱敏方法、及其相关设备
CN111770057B (zh) * 2020-05-29 2022-09-30 北京奇艺世纪科技有限公司 身份验证系统及身份验证方法
CN112131598B (zh) * 2020-07-17 2024-12-03 中信银行股份有限公司 数据脱敏方法、装置、电子设备以及存储介质
CN114239042A (zh) * 2020-09-09 2022-03-25 航天云网科技发展有限责任公司 工业数据脱敏方法、装置、计算机设备和可读存储介质
CN112000727B (zh) * 2020-10-27 2021-06-04 绿城科技产业服务集团有限公司 一种动态配置业务数据脱敏显示方法
CN112347511A (zh) * 2020-11-09 2021-02-09 平安普惠企业管理有限公司 基于权限的数据屏蔽方法、装置、计算机设备及存储介质
CN112667657A (zh) * 2020-12-24 2021-04-16 国泰君安证券股份有限公司 基于计算机软件实现数据脱敏的系统、方法、装置、处理器及其存储介质
CN112667624A (zh) * 2021-01-21 2021-04-16 厦门信息集团大数据运营有限公司 一种数据质量管理方法及其系统
CN113256301B (zh) * 2021-07-13 2022-03-29 杭州趣链科技有限公司 数据屏蔽方法、装置、服务器及介质
CN115114641A (zh) * 2022-06-27 2022-09-27 平安银行股份有限公司 一种基于后台管理界面的数据掩码方法及系统
CN118573478B (zh) * 2024-07-31 2024-12-06 恒生电子股份有限公司 访问验证系统、方法及装置
CN119622811A (zh) * 2024-11-29 2025-03-14 上海数禾信息科技有限公司 数据脱敏查询方法、装置、计算机设备和存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106228084A (zh) * 2016-07-19 2016-12-14 北京同余科技有限公司 基于角色的敏感字段动态调整的数据保护方法和系统
CN106407843A (zh) * 2016-10-17 2017-02-15 深圳中兴网信科技有限公司 数据脱敏方法和数据脱敏装置
CN107145799A (zh) * 2017-05-04 2017-09-08 山东浪潮云服务信息科技有限公司 一种数据脱敏方法及装置
CN107871083A (zh) * 2017-11-07 2018-04-03 平安科技(深圳)有限公司 脱敏规则配置方法、应用服务器及计算机可读存储介质

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130167192A1 (en) * 2011-12-27 2013-06-27 Wellpoint, Inc. Method and system for data pattern matching, masking and removal of sensitive data
CN106203170A (zh) * 2016-07-19 2016-12-07 北京同余科技有限公司 基于角色的数据库动态脱敏服务方法和系统
CN106326760B (zh) * 2016-08-31 2019-03-15 清华大学 一种用于数据分析的访问控制规则描述方法
CN106529329A (zh) * 2016-10-11 2017-03-22 中国电子科技网络信息安全有限公司 一种用于大数据的脱敏系统及脱敏方法
CN107194270A (zh) * 2017-04-07 2017-09-22 广东精点数据科技股份有限公司 一种实现数据脱敏的系统及方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106228084A (zh) * 2016-07-19 2016-12-14 北京同余科技有限公司 基于角色的敏感字段动态调整的数据保护方法和系统
CN106407843A (zh) * 2016-10-17 2017-02-15 深圳中兴网信科技有限公司 数据脱敏方法和数据脱敏装置
CN107145799A (zh) * 2017-05-04 2017-09-08 山东浪潮云服务信息科技有限公司 一种数据脱敏方法及装置
CN107871083A (zh) * 2017-11-07 2018-04-03 平安科技(深圳)有限公司 脱敏规则配置方法、应用服务器及计算机可读存储介质

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111488604A (zh) * 2020-04-07 2020-08-04 杭州迪普科技股份有限公司 数据脱敏系统和数据脱敏方法
CN113742763A (zh) * 2021-11-08 2021-12-03 中关村科技软件股份有限公司 一种基于政务敏感数据混淆加密方法及系统
CN118037469A (zh) * 2024-02-21 2024-05-14 柳州市德鲁克企业管理咨询有限公司 基于大数据的财务管理系统

Also Published As

Publication number Publication date
CN107871083A (zh) 2018-04-03

Similar Documents

Publication Publication Date Title
WO2019091102A1 (zh) 脱敏规则配置方法、程序、应用服务器及计算机可读存储介质
US11227068B2 (en) System and method for sensitive data retirement
US10789204B2 (en) Enterprise-level data protection with variable data granularity and data disclosure control with hierarchical summarization, topical structuring, and traversal audit
US11698890B2 (en) System and method for generating a column-oriented data structure repository for columns of single data types
US11386224B2 (en) Method and system for managing personal digital identifiers of a user in a plurality of data elements
US20220277023A1 (en) Aligned purpose disassociation in a multi-system landscape
US9087209B2 (en) Database access control
CN108874863B (zh) 一种数据访问的控制方法及数据库访问装置
CN109241358A (zh) 元数据管理方法、装置、计算机设备及存储介质
US20190163928A1 (en) System and method for managing enterprise data
US20120023586A1 (en) Determining privacy risk for database queries
US12505246B2 (en) Attribute-level access control for federated queries
US20170083722A1 (en) Dynamic data masking system and method
WO2019134339A1 (zh) 脱敏方法、程序、应用服务器及计算机可读存储介质
US11169997B1 (en) Centralized data access tool implementing resource governance
WO2019071967A1 (zh) 敏感信息屏蔽方法、程序、应用服务器及计算机可读存储介质
US12093242B2 (en) Online determination of result set sensitivity
WO2019205347A1 (zh) 报表模块创建方法、装置、计算机装置及存储介质
EP3188072B1 (en) Systems and methods for automatic and customizable data minimization of electronic data stores
WO2019071958A1 (zh) 基于云计算的薪资计算方法、应用服务器及计算机可读存储介质
CN116257876A (zh) 一种数据分级访问的处理方法、装置、设备及存储介质
WO2019071968A1 (zh) 薪资计算方法、应用服务器及计算机可读存储介质
JP2019503021A (ja) システム環境及びユーザ行動分析基盤の自己防御保安装置とその作動方法
TWI641958B (zh) 報表管理伺服器及報表管理方法
WO2019000996A1 (zh) 核保信息处理的装置、方法及计算机可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18875060

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 01/10/2020)

122 Ep: pct application non-entry in european phase

Ref document number: 18875060

Country of ref document: EP

Kind code of ref document: A1