Updated on 2026-09-24 GMT+08:00

Adding a Desensitization Strategy

To configure dynamic data masking for a business system, you need to define data masking policies for the corresponding tables and columns.

Procedure

  1. Logging In to the Database Encryption System using the system administrator (sysadmin) account.
  2. Select Project Management from the left navigation tree.
  3. Select the project you wish to configure; hover your mouse over the project – the relevant buttons will appear on the project card; click Enter to access the project.
  4. Select Desensitization Strategy from the left-side navigation tree (as shown in Figure 1); the parameter descriptions for Data Masking Strategy Management are provided in Table 1.

    Figure 1 Desensitization strategy management
    Table 1 Desensitization strategy management parameters explanation

    Parameter

    Description

    Policy Names

    The name specified when creating a Strategy; it is recommended to use a meaningful name, such as "CRM System Anonymization Strategy".

    Creation Time

    Strategy creation time.

    Created By

    The strategy creator.

    State

    Strategy current status: Enabled, Disabled.

    Action

    Certain operations for the Strategy, including: View Details, Edit, Delete, and Enable.

  5. Click Add Strategy in the top-right corner.
  6. In the pop-up window, enter the Policy Names and Remark fields, as shown in Figure 2; the parameter descriptions are provided in Table 2.

    Figure 2 Adding strategy 1
    Table 2 Adding strategy parameter instructions 1

    Parameter

    Description

    Policy Names

    When naming a desensitization strategy, it is advisable to use a meaningful name.

    For example: CRM system dynamic data masking strategy.

    Remark

    Optional: Add a note for clarification.

  7. Click Next, then sequentially select Asset Database, Schema, and Table, and finally click Desensitization Algorithm Configuration. The system display is shown in Figure 3; the description of the desensitization algorithm configuration parameters is provided in Table 3.

    Figure 3 Adding strategy 2
    Table 3 Masking Algorithm configuration parameters explanation

    Parameter

    Description

    Column Name

    The field name of a table in the database.

    Notes

    The built-in comment associated with a database field.

    Data Domain

    Specifies the data field type for the current field (used in conjunction with the data masking algorithm); e.g., company name.

    Masking Algorithm

    The Masking Algorithm currently in use. To add a new Masking Algorithm, please refer to the Masking Algorithm.

    Actions

    Performable action.

    • detailed information
    • edit
    • start using
    • delete

  8. Click Settings in the operation column of the above image; the system will then display a window for selecting the data domain and the Masking Algorithm for the field. As shown in Figure 4, this window allows you to select the data domain to which the field belongs, as well as the corresponding Masking Algorithm for that data domain.

    Figure 4 Setting the Masking Algorithm

  9. Click Confirm to configure the Masking Algorithm for the corresponding field, as shown in Figure 5.

    • Reset: Used to revert the Masking Algorithm settings for the current column.
    • Cancel: Use this to exit without making any changes.
    Figure 5 Viewing the list

  10. Configure a Masking Algorithm for each field that requires desensitization; once all configurations are complete.
  11. Click Save. A system exit pop-up window will appear (as shown in Figure 6); the Masking Algorithm has now been configured for this project.

    Figure 6 Desensitization strategy management