Updated on 2026-09-24 GMT+08:00

Masking Algorithm

In this product, "desensitization" refers to dynamic desensitization, which is used for dynamic data masking in business systems.

This product supports dynamic data masking implementation through both the Application-Plugin mode and the Proxy mode.

This facilitates the integration of sensitive data discovery with data masking processes. The data masking algorithm also utilizes a data domain for management and coordination; the sensitive data discovery mechanism identifies sensitive data domains, and dynamic data masking is then applied to users based on these identified domains.

As a data security management platform, its data domain specifically refers to the sensitive data domain – e.g., names, phone numbers, ID cards, etc.

  • The system incorporates built-in data masking algorithms for common data fields.
  • For security reasons and to mitigate unnecessary injection risks, the current cloud version does not support customizing data masking algorithms.

Prerequisites

The masking algorithm is designed for the desensitization of sensitive data fields. For example, ID card desensitization refers to the desensitization process applied to the data fields contained within an ID card.

For information on how to manage data domains, please refer to Data Domain Management.

Viewing and Testing Anonymization Algorithms

The masking algorithm is a core technology for data privacy and data security protection; it involves transforming sensitive data—such as ID cards, mobile phone numbers, and names—while preserving the data's usability and concealing the actual original information.

A data field can have one or more data masking algorithms; a default masking algorithm is then selected from among them. For example, mobile phone number masking, as shown in Table 1.

Table 1 Historical version parameter specifications

Initial Data

Desensitized Data

Usage Scenario

18604045636

186****5636

The customer service representative uses the last four digits to verify identity.

186********

Just determine which telecom operator this phone number belongs to.

This product supports dynamic data masking. It is common to see discussions comparing static data masking algorithms with dynamic data masking algorithms. Compared to static data masking, the dynamic data masking algorithm requires less complex implementation to meet practical usage requirements.

Procedure

  1. Logging In to the Database Encryption System using the system administrator (sysadmin) account.
  2. Select Rule Management > Masking Algorithm from the left navigation tree, as shown in Figure 1.

    Figure 1 Masking Algorithm

  3. Test Masking Algorithm: Click Test to test and verify the built-in Masking Algorithm, as shown in Figure 2.

    Figure 2 Testing the Masking Algorithm

    For example: Test the name anonymization algorithm.

    • Input: zhang
    • Click Test.
    • The execution result is shown in Figure 2: z**.