Masking ID Numbers in ID Card Images Stored in OBS
Scenarios
To ensure that images in PNG, JPG, JPEG, BMP, or WEBP format containing Chinese mainland ID card information stored in specific folders in a private OBS bucket are not disclosed when being shared with other users, you can use DSC image masking. DSC can mask ID numbers. The masked images will be saved to the specified storage path.
Solution Architecture
The following figure shows the image masking process.

To mask and share images, perform the following steps:
- Creating an OBS bucket and uploading files: Create an OBS bucket with private read and write permissions, and upload an image containing the Chinese mainland ID card information to a folder in the OBS bucket. The image in the folder inherits the private permissions of the bucket.
- Authorizing access to OBS buckets and interconnecting with DSC: You can perform operations on OBS data only after the authorization.
- Creating and starting a masking task: Create an image masking task, set the OBS bucket file path of the image to be masked, identify and mask the image in the OBS bucket, and save the masked image to the target storage path.
- Configuring IAM users to access masked images: Use a bucket policy to grant specified IAM users the read-only permission to access the folder where the masked image is stored. Masked images can be shared this way.
Prerequisites
- You have purchased DSC.
- You have enabled OBS.
Creating an OBS Bucket
- Go to the OBS console, and choose Buckets from the navigation pane on the left.
- Click Create Bucket in the upper right corner.
- On the Create Bucket page, set the parameters below, retain default settings for other parameters, and click Create Now.
Set Region to that of the purchased DSC, disable Block Public Access, and set Bucket Policy to Private.
For details about how to create an OBS bucket, see Creating an OBS Bucket.
Uploading Images to a Folder in an OBS Bucket
- Click the OBS bucket name in the bucket list on OBS Console.
- On the Objects page, click Create Folder, enter a folder name (for example, imgtest), and click OK.
- Go to the imgtest folder and click Upload Object.
- On the Upload Object page, click Add File, select a local image, click Open, and wait until the file is uploaded. Retain default settings for other parameters and click OK.
The upload path is OBS://[<bucket-name>]/imgtest/. The Storage Class of the file is Inherit from bucket.
Step 2: Authorize Access to the OBS Bucket and Interconnect with DSC
- Log in to the DSC console.
- Choose . In the upper left corner of the displayed page, click Modify next to Cloud Asset Authorization. The Authorize Access to Cloud Assets page is displayed.
- On the displayed page, enable OBS asset authorization.
- Return to the Asset Management page, and click OBS under OBS. The OBS asset list is displayed.
- Click Add User-built Bucket in the upper left corner. In the displayed dialog box, select the OBS buckets to be added.
- Click OK. If the added OBS bucket is displayed in the list, the adding is successful.
Step 3: Create and Start a Masking Task
- In the navigation pane on the left, choose .
- Switch to the OBS tab, click Create Task, and set parameters under Configure Data Source.
- Enter a custom task name.
- Select Data Source: Select OBS.
- Data Source: Select the OBS bucket name and file path of the image uploaded in Step 1: Create an OBS Bucket and Upload Files, and set File Type to Image.
- Click Next and set parameters under Set Masking Algorithm.
Under Objects, enable ID card number (Chinese mainland) (
), and set Masked by to White block. - Click Next, and retain the default settings.
- Click Next, configure the storage path of the masked image, and set OBS File Path to the root directory.
- Click Finish. The masking task is displayed in the task list.
- Locate the target task, ensure the status is
in the Enable/Disable column, and click Execute in the Operation column. - Wait until Status changes to Completed and view the information about the masked image.
- Verify the masking result.
- Go to the OBS console, and choose Buckets from the navigation pane on the left.
- Click the OBS bucket name, open the storage path of the masked image set in 5, and view the masked image. The ID card number is masked.
In the masked ID card.png image, the name is also replaced with a placeholder, and the ID card photo is masked by an avatar icon.
Step 4: Configure a Specific IAM User to Access the Masked Image
- Go to the OBS console, and choose Buckets from the navigation pane on the left.
- Click the OBS bucket name, open the storage path of the masked image set in 5, locate the masked image, and choose in the Operation column.
- Enter a custom policy name.
- Effect: Select Allow.
- Principal: Select Other accounts and enter the account ID and IAM user ID or name. For details about how to obtain the account ID and IAM user ID, click Learn how to find an account ID, IAM user ID, or IAM username.
- Retain default settings for other parameters.
- Click Create.
- The authorized IAM user can access the masked image on the OBS console via the OBS access address of the authorized image.
The masked image file ID card.png is displayed in the file list. The IAM user has accessed the authorized image.
Summary
For images containing Chinese mainland ID card information stored in OBS buckets, you can mask the ID card number before sharing them. This prevents property loss, reputation loss, and identity spoofing caused by ID card number leakage.
References
DSC can also mask images containing license plate and facial information stored in OBS buckets. This meets the image masking requirements in various service scenarios and ensures secure sharing of image data in OBS. For more information, see Creating and Running an OBS Masking Task.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot