Updated on 2026-09-24 GMT+08:00

User-level Data Masking

This feature is designed to enable granular management of user data access permissions within business systems (systems where an encryption plugin has been deployed). It determines which users are permitted to view plaintext data and which users are allowed to access desensitized data. To implement this feature, the following system prerequisites must be met:

  • User information needs to be stored in Spring Security; the plugin retrieves this information by invoking the built-in methods provided by the Spring Security framework.
  • The user name in the business system and the user's unique identifier within this system must be configured.
  • Configure the plugin parameters to manually enable user-level data masking for the business system.

Since there are various ways to store user identities within business systems, user information needs to be stored in Spring Security; the plugin retrieves this user information by invoking the built-in methods provided by the Spring Security framework. A specific example is as follows:

try {
loginUser = SecurityUtils.getSubject().getPrincipal();
if (loginUser == null) {
return username;
}
// Obtain the current username using reflection
Class c = loginUser.getClass();
userName = (String) c.getDeclaredMethod("getLoginName").invoke(loginUser);;
} catch (Exception e) {
return username;
} // Get sample

Procedure

  1. To configure application users from your business system for the database encryption system, select User Management > Application User from the left-side navigation tree. For detailed instructions, please refer to the App Users.
  2. Download the plugin for this project; for detailed instructions, please refer to the Downloading the Plugin.
  3. Configure encrypted dependency components and adapt them to your runtime environment; for detailed instructions, please refer to the Configuration Dependency.
  4. In the gatewayconfig directory within the encryption-proxy.jar package, change the value of the maskingRule attribute in the config.properties file from 0 to 1.

    Modification method:

    1. Left-click on the encryption-proxy.jar file to select it.
    2. Right-click, then select Open With> WinRAR from the pop-up menu; click the gatewayconfig directory with the left mouse button and double-click it.
      Figure 1 Gateway config
    3. Select the config.properties file and double-click it.
      Figure 2 config.properties
    4. In the pop-up dialog box, select the Notepad++ editor; if it is not available, you may choose another text editor, such as the built-in Notepad, and then click Just once.
      Figure 3 Selecting the notepad++ editor
    5. Change the value of the maskingRule attribute in the file from 0 to 1; the updated value is: maskingRule=1.
      Figure 4 Masking rule
    6. Press the CTRL + S key combination to save the file content, then close the window to return to the WinRAR software interface.
    7. WinRAR will display a prompt asking whether to update; clicking Yes will modify and update the encryption-proxy.jar file. To prevent potential update failures, it is recommended to reopen the config.properties file as described above and verify that the property value has been changed to 1.
      Figure 5 Confirming the modification

  5. Set the environment variables required for the plugin (Application-Plugin); for detailed instructions, please refer to the Configuring Environment Variables.
  6. Modify the database connection and driver settings for the integrated system; for detailed instructions, please refer to the Modifying Database Connection and Driver.
  7. Modify the application execution command; for detailed instructions, please refer to Modifying the Application Execution Command.
  8. Run the test application; for detailed instructions, please refer to the Testing the Application.