当前位置:网站首页>DGC best practice: how to ensure that confidential data is not leaked when entering the lake?
DGC best practice: how to ensure that confidential data is not leaked when entering the lake?
2022-07-19 02:06:00 【Hua Weiyun】
background :
In the business database, some table data belong to very confidential data , such as , Quotation information 、 Wages . If this batch of data is leaked , It will seriously affect the management of enterprises 、 Production and operation , Usually, it is only allowed to be used by high-level data analysts or data Owner visit , General Data Engineer 、 Average analyst , Do not allow access or only allow desensitization 、 Encrypted or aggregated data . that , How to be in DGC This kind of data is strictly controlled in ?
programme :
Introduce a good practical scheme , First map

Solutions that :
1、 stay DWS( Here to DWS For example ,DLI、MRS Also can reference ) Create a secret in Schema, Strictly control access . Be able to access this Schema Your account and password need to be strictly controlled .
2、DGC Create a separate secret space on , Configure sensitive business database connections in this space 、 Have access to DWS confidential Schema The connection of ( The connection account usually also needs to have a common Schema Access rights of , Facilitate the correlation analysis of confidential data ). Because in DGC Of workspace Inside , Generally, the developer role can use the data source connection to access data without distinction , And can modify and execute scripts and jobs , therefore , The workspace All members of the must be confidential personnel who can access confidential data .
3、 confidential Schema Table data in , Space developers can customize UDF Encrypt confidential fields , Ensure that the confidential field of the disk is the ciphertext storage , When accessing sensitive fields, use UDF Decrypt . actually , use UDF Encryption is optional , Only do it before removing the data from the data area , such as , Use CDM Migrate the table to the normal data warehouse schema Before , You need to encrypt the data first .
4、DGC If ordinary space developers need to use desensitized or aggregated confidential data , The developer of the confidential space needs to export the desensitization results . Cross space dependency can be established between jobs to coordinate operation .
边栏推荐
- Oozie 集成 Shell
- 博客里《DSAA》相关文章的代码
- Original code, inverse code, complement code
- [literature reading] multi state MRAM cells for hardware neural computing
- Remote sensing submission process
- Fisher线性判别分析Fisher Linear Distrimination
- Fairness in Deep Learning: A Computational Perspective
- Static library and dynamic library
- 指針常量與常量指針愛恨情仇
- vscode+ros2环境配置
猜你喜欢

二階邊緣檢測 - Laplacian of Guassian 高斯拉普拉斯算子

Recursive and recursive learning notes

Can protocol communication

Powerful chart component library scottplot

高斯分布的性质(含代码)

Owl Eyes: Spotting UI Display Issues via Visual Understanding
![[literature reading] counting integer points in parametric polymers using barvinok's rational functions](/img/a2/3e1b248c7cd853ffea7a835111db65.png)
[literature reading] counting integer points in parametric polymers using barvinok's rational functions

IGBT 直通短路过程问题分析

Hands on deep learning - deep learning computing

Opengauss Developer Day 2022 dongfangtong sincerely invites you to visit the "dongfangtong ecological tools sub forum"
随机推荐
Labelme 的简单用法和界面介绍
性能强悍的图表组件库 ScottPlot
Characteristics and application points of electrolytic capacitor
YYDS!阿里技术官最新总结的分布式核心技术笔记已上线,堪称福音
01基于RFID的智能仓储管理系统设计
gdb+vscode进行调试7——程序出现segmentation default/段错误,如何进行调试?
Switch details
Array definition format
Build Ozzie environment
switch详解
Determine whether two arrays are exactly equal
MATLAB :Warning: the font “Times” is not available
CAN协议通信
Monitor browser return operation - prohibit returning to the previous page
[literature reading] mcunet: tiny deep learning on IOT devices
01 design of intelligent warehouse management system based on RFID
MATLAB :Warning: the font “Times” is not available
Oozie 集成 Shell
偏差(bias)和方差(variance)
搭建Hue环境