Sensitive Information Protection Tool - GBase Data Masking System Introduction
Product Overview
The GBase Data Masking System is developed in accordance with the security regulations of China's national information security authorities on unified enterprise data management, integrating the requirements of users across various industries. It is a universal, highly efficient, high-performance, and highly secure data masking system, and a fully homegrown data masking product.
Product Architecture
Product Features
The GBase Data Masking System adopts a low-coupling functional module architecture with an integrated workflow, enabling users to quickly operate and master it. Product functional modules and business processes:
The management platform of the GBase Data Masking System primarily covers four aspects:
Accurately discover sensitive data by automatically scanning sensitive fields in database tables based on predefined discovery rules.
Integrated workflow, rapid masking processing, and a flexible scheduling mechanism suitable for various masking requirements and business scenarios of enterprises.
A robust business support system that supports data masking for generic databases and text files.
A comprehensive workflow and audit system, enabling quick review of historical operation information through reports and logs.
Core Technical Advantages
Accurate Automatic Discovery of Sensitive Data
The product has built-in discovery rules for sensitive information, screening and filtering sensitive data through Java regular expressions and built-in Java algorithms. The supported discovery rules encompass common sensitive information types such as personal names, company names, addresses, phone numbers, ID card numbers, emails, account numbers, dates, monetary amounts, bank card numbers, and credit card numbers. Custom discovery rules are also supported.
Rich Data Masking Algorithms
The product includes dozens of masking algorithms such as Hash, Random, generic account processing, truncation, retention, replacement, and concatenation algorithms. It supports reversible and irreversible algorithms, slicing algorithms, and allows custom and freely combined algorithms. Users can also select external code tables as the generation scope for data masking.
In-Place Data Masking Technology
The in-place database masking approach of the GBase Data Masking System is a highly efficient masking technology. This method is more efficient than pure in-memory masking, as data is not transmitted over the network to a masking server, ensuring absolute data security.
Real-Time Monitoring of Data Masking Server Resources
The GBase Data Masking System provides a comprehensive monitoring interface. Users can perform batch scheduling of tasks or masking processing for individual tables via the monitoring page.
Support for Multiple Database Sources
Supports GBase 8a MPP Cluster, GP, Vertica, Hadoop, GBase 8t/s, PostgreSQL, MySQL, DB2, SQL-Server, Oracle, remote files, and many other data sources.
Application Scenarios
Common data masking scenarios are as follows:
Scenario 1: Development and Testing. In development and testing, real data is required for testing to ensure functional completeness and performance benchmarks of the system.
Scenario 2: Business Training. Real data is needed in business training to guarantee the authentic training effectiveness.
Scenario 3: Data Exchange Between Industries and Departments. Due to business needs, real data is necessary for data exchange between industries and departments to ensure smooth business operations.
Scenario 4: Government Data Disclosure. Critical core business and classified departmental data cannot be disclosed in public scenarios.
In the above scenarios, the masking system can be used to fully safeguard the security of real data.