Updated on 2026-07-07 GMT+08:00

Scenario 4: Configuring Desensitization Policy

Overview

Data desensitization is a security measure designed to remove or replace personally identifiable information from sensitive data, thereby reducing the risk of data breaches. By processing personal information in a manner that complies with privacy regulations and security policies, it enables the data to be used for analysis, sharing, and storage. The desensitized data retains its analytical value while protecting individual privacy, which is crucial for maintaining data security and user trust.

Configuring Desensitization Policy

  1. Logging In to the Database Encryption System using the system administrator sysadmin account.
  2. Encrypt data: (For details, refer to the Scenario 1: Configuring and Operating Encryption Functions) Configure data sources, create projects, and select appropriate fields for encryption.
  3. Configuring Masking Algorithms: In the left navigation tree, choose Rule Management > Masking Algorithm, select the algorithm.

    Figure 1 Desensitization algorithm
    Table 1 Table1 Desensitization configuration parameter description

    Parameter

    Description

    Algorithm Name

    Customize the string based on your actual business needs.

    Expression

    Run the rule formula required for desensitization. Click the Test button to view the actual effect.

    Default Rule

    There is only one, applied to discovery tasks and configurable in batches for discovery results.

  4. Enter Desensitization Management: In the left menu, select Project Management, enter the desired project .
  5. In the left navigation tree, choose Desensitization Strategy and click Add Strategy to create a desensitization policy.

    Figure 2 Desensitization policy management

  6. Enter a policy name as prompted and click Next.

    Figure 3 Add policy 1
    Table 2 Table2 Description of new desensitization policy parameters

    Parameter

    Description

    Policy Names

    Customize the string based on your specific business needs, such as name anonymization or bank number anonymization.

    Remark

    Optional. Enter remarks for the business.

  7. Select the table to be added and click Setting in the Operation column.

    Figure 4 Add policy 2

  8. Open the Set Desensitization Rule dialog box, select the data domain and field desensitization rule, then click Confirm Rule.

    Figure 5 Setting desensitization rule

  9. After configuration, click Confirm to save.

    Figure 6 Add policy 3

  10. On the Desensitization Strategy Management page, click Enable in the operation column to activate the masking strategy.

    Figure 7 Desensitization policy management

Effect Overview

Actual data in the database Comparison: Final displayed data:

Truthful data:

Figure 8 View real data

Customer terminal effect:

Figure 9 Application access data results (decrypted and anonymized)

Other Notes

  1. In this system, the plugin enables data decryption and desensitization, while the encryption proxy module performs similar functions.
  2. There may be a slight delay when newly enabled or disabled desensitization policies are synchronized to the client, and changes may not take effect immediately.
  3. For detailed configuration of the desensitization strategy, refer to the Masking Algorithm, and Desensitization Strategy Management.