sparknlp_jsl.annotator.deid.aux_encryption_params#
Module Contents#
Classes#
Encryption key for the mappings (aux) column. |
- class AuxEncryptionParams#
Encryption key for the mappings (aux) column.
The mappings column carries the original values so that
ReIdentificationcan restore the original text. Setting a key encrypts the sensitive fields of that column with AES-256-GCM, so it can be stored next to the de-identified data without exposing the original values.The same key must be set on both sides: on the de-identification annotator that produces the mappings column, and on the ReIdentification annotator that consumes it.
When the key is left unset (the default), nothing is encrypted and the mappings column keeps its plain behavior.
- Parameters:
auxEncryptionKey (str) – The key used to encrypt and decrypt the sensitive fields of the mappings (aux) column. When empty, the mappings column is not encrypted. Default: “”
- auxEncryptionKey#
- getAuxEncryptionKey()#
Returns the stored (wrapped) form of the aux encryption key, or an empty string when encryption is disabled.
- setAuxEncryptionKey(value: str)#
Sets the key used to encrypt and decrypt the mappings (aux) column.
When set on a de-identification annotator, the original values carried by the mappings column are encrypted.
ReIdentificationneeds the very same key to restore the original text. When left unset, the mappings column is produced in clear text.The key is never stored in clear text; it is wrapped before being kept in the annotator, so a saved pipeline never contains the raw value.
Examples
>>> de_identification = DeIdentification() \ ... .setReturnEntityMappings(True) \ ... .setMappingsColumn("aux") \ ... .setAuxEncryptionKey("my-secret-key") >>> re_identification = ReIdentification() \ ... .setAuxEncryptionKey("my-secret-key")
- Parameters:
value (str) – The key used to encrypt and decrypt the mappings column.