(projectId, string, alphabet, keyName, wrappedKey, surrogateType)
| 20 | // usage: node deidentifyWithFpe.js my-project "My SSN is 372819127" <YOUR_ENCRYPTED_AES_256_KEY> projects/my-project/locations/global/keyrings/my-keyring SSN_TOKEN |
| 21 | |
| 22 | function main(projectId, string, alphabet, keyName, wrappedKey, surrogateType) { |
| 23 | // [START dlp_deidentify_fpe] |
| 24 | // Imports the Google Cloud Data Loss Prevention library |
| 25 | const DLP = require('@google-cloud/dlp'); |
| 26 | |
| 27 | // Instantiates a client |
| 28 | const dlp = new DLP.DlpServiceClient(); |
| 29 | |
| 30 | // The project ID to run the API call under |
| 31 | // const projectId = 'my-project'; |
| 32 | |
| 33 | // The string to deidentify |
| 34 | // const string = 'My SSN is 372819127'; |
| 35 | |
| 36 | // The set of characters to replace sensitive ones with |
| 37 | // For more information, see https://cloud.google.com/dlp/docs/reference/rest/v2/organizations.deidentifyTemplates#ffxcommonnativealphabet |
| 38 | // const alphabet = 'ALPHA_NUMERIC'; |
| 39 | |
| 40 | // The name of the Cloud KMS key used to encrypt ('wrap') the AES-256 key |
| 41 | // const keyName = 'projects/YOUR_GCLOUD_PROJECT/locations/YOUR_LOCATION/keyRings/YOUR_KEYRING_NAME/cryptoKeys/YOUR_KEY_NAME'; |
| 42 | |
| 43 | // The encrypted ('wrapped') AES-256 key to use |
| 44 | // This key should be encrypted using the Cloud KMS key specified above |
| 45 | // const wrappedKey = 'YOUR_ENCRYPTED_AES_256_KEY' |
| 46 | |
| 47 | // (Optional) The name of the surrogate custom info type to use |
| 48 | // Only necessary if you want to reverse the deidentification process |
| 49 | // Can be essentially any arbitrary string, as long as it doesn't appear |
| 50 | // in your dataset otherwise. |
| 51 | // const surrogateType = 'SOME_INFO_TYPE_DEID'; |
| 52 | |
| 53 | async function deidentifyWithFpe() { |
| 54 | // Construct FPE config |
| 55 | const cryptoReplaceFfxFpeConfig = { |
| 56 | cryptoKey: { |
| 57 | kmsWrapped: { |
| 58 | wrappedKey: wrappedKey, |
| 59 | cryptoKeyName: keyName, |
| 60 | }, |
| 61 | }, |
| 62 | commonAlphabet: alphabet, |
| 63 | }; |
| 64 | if (surrogateType) { |
| 65 | cryptoReplaceFfxFpeConfig.surrogateInfoType = { |
| 66 | name: surrogateType, |
| 67 | }; |
| 68 | } |
| 69 | |
| 70 | // Construct deidentification request |
| 71 | const item = {value: string}; |
| 72 | const request = { |
| 73 | parent: `projects/${projectId}/locations/global`, |
| 74 | deidentifyConfig: { |
| 75 | infoTypeTransformations: { |
| 76 | transformations: [ |
| 77 | { |
| 78 | primitiveTransformation: { |
| 79 | cryptoReplaceFfxFpeConfig: cryptoReplaceFfxFpeConfig, |
no test coverage detected