Security access method for database

Through a multi-level verification mechanism, including detailed information verification of devices and users, the security and flexibility of traditional database security access methods are solved, and the security and flexibility of database access is improved, ensuring the access rights of legitimate users in special circumstances.

CN120277706APending Publication Date: 2025-07-08TIANJIN TIANKAI LAIYI TE TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510280954.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

Traditional database security access methods are low in security and are easy to be cracked. In special cases, temporary access cannot be granted quickly, conveniently and securely, affecting the normal business development and data processing.

Method used

A multi-level verification mechanism is adopted, including device verification, user verification and temporary access application form, and multiple verifications are carried out through detailed information such as device ID, MAC address, device data certificate, device type, user account, user password and user permissions to ensure access to legal devices and users.

Benefits of technology

Improve the security and flexibility of database access, prevent unauthorized access and disclosure, ensure that legitimate users can obtain access rights in a timely manner under special circumstances, and improve the availability and work efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277706A_ABST
    Figure CN120277706A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of database security, and discloses a secure access method for a database, comprising: receiving an access request sent by a client for a target database, and generating device verification data and user verification data; presetting a database comparison table and a user password comparison table; performing preliminary verification on the equipment verification data based on the database comparison table, performing final verification on the user verification data based on the database comparison table and the user password comparison table, and if the final verification is passed, allowing the client to access the target database; and if the preliminary verification or the final verification is not passed, obtaining a temporary access application form of the database management end, performing secondary verification on the equipment verification data and the user verification data based on the temporary access application form, and if the secondary verification is passed, allowing the client to access the target database. Through a multi-verification mechanism, the risk that illegal users access the database is greatly reduced, and the security of database access is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of database security, and particularly to a secure access method for a database. Background Art

[0002] In today's digital information age, the database, as a core component of various information systems, carries a vast amount of crucial data resources. Whether it is the key business data of enterprises, the sensitive information of government agencies, or the privacy data of individual users, they all highly rely on the database for secure and efficient storage and management.

[0003] With the rapid development and wide application of network technology, the security threats faced by databases are showing an increasingly complex and severe trend. There are endless network attack means, such as malicious hacker intrusion, wanton virus spread, stealthy Trojan implantation, and illegal operations by internal personnel. These are like hidden sharp blades that constantly threaten the security and stability of the database. Traditional database security access methods, such as simple username and password combinations, although playing a protective role to a certain extent, are difficult to effectively resist modern complex network security attacks due to their low security. For example, passwords are easily cracked by brute force or stolen through social engineering, allowing unauthorized users to easily break through the defense and obtain database access rights, thereby triggering a series of serious consequences such as data leakage and tampering.

[0004] Some existing more complex access methods often have the problem of insufficient flexibility. In specific scenarios, such as emergency maintenance and external audits where specific personnel need to be temporarily granted access rights, these traditional access authentication mechanisms cannot quickly, conveniently, and securely meet the requirements, resulting in difficulties in database access management in special situations and potentially affecting the normal operation of the business and the timely processing of data. Therefore, in view of the above problems, a secure access method for a database is proposed. Summary of the Invention

[0005] The purpose of the present invention is to provide a secure access method for a database, aiming to solve the above problems.

[0006] The present invention provides a secure access method for a database, including:

[0007] Receiving an access request sent by a client for a target database, and generating device verification data and user verification data according to the access request;

[0008] Pre-setting a database comparison table and a user password comparison table, where the database comparison table includes several databases and the allowed access device information and allowed access user information corresponding to each database, and the user password comparison table includes several user accounts and user passwords;

[0009] Based on the database comparison table, conduct a preliminary verification on the device verification data. If the preliminary verification passes, then based on the database comparison table and the user password comparison table, conduct a final verification on the user verification data. If the final verification passes, then allow the client to access the target database;

[0010] If the preliminary verification or the final verification fails, then obtain the temporary access application form of the database management terminal, and conduct a secondary verification on the device verification data and the user verification data based on the temporary access application form. If the secondary verification passes, then allow the client to access the target database.

[0011] Preferably, generating device verification data and user verification data according to the access request includes:

[0012] The access request includes the client device ID, MAC address, device data certificate, device type, user account, user password, and user permissions;

[0013] Classify the access request into device verification data and user verification data.

[0014] Preferably, conducting a preliminary verification on the device verification data based on the database comparison table includes:

[0015] The device verification data includes the client device ID, MAC address, device data certificate, and device type;

[0016] Filter the database comparison table according to the client device ID in the device verification data. If the client device ID is included in the database comparison table, then determine whether the remaining allowed access device information corresponding to the client device ID is the same as the device verification data;

[0017] If they are the same, then determine that the preliminary verification passes; if they are not the same, then determine that the preliminary verification fails.

[0018] Preferably, conducting a final verification on the user verification data based on the database comparison table and the user password comparison table includes: The user verification data includes the user account, user password, and user permissions;

[0019] Compare the user account with the allowed access user information in the database comparison table. If the user account exists in the allowed access user information, then match the user account and the user password based on the user password comparison table;

[0020] If it is determined that the user account and the user password in the user verification data match, then determine whether the final verification passes according to the user permissions;

[0021] If the user account and user password in the user verification data do not match, it is determined that the final verification fails.

[0022] Preferably, determining whether the final verification passes according to the user permissions includes:

[0023] Obtain the access user permissions of the target database;

[0024] Compare the user permissions with the access user permissions. If the user permissions are higher than or equal to the access user permissions, it is determined that the final verification passes;

[0025] If the user permissions are lower than the access user permissions, it is determined that the final verification fails.

[0026] Preferably, the temporary access application form includes application access device information and application access user information.

[0027] Preferably, based on the temporary access application form, perform secondary verification on the device verification data and user verification data, including:

[0028] Compare the application access device information in the temporary access application form with the device verification data. If the application access device information is consistent with the device verification data, then compare the user verification data with the application access user information in the temporary access application form, and determine whether the secondary verification passes according to the comparison result;

[0029] If the application access device information is inconsistent with the device verification data, it is determined that the secondary verification fails.

[0030] Preferably, comparing the user verification data with the application access user information in the temporary access application form, and determining whether the secondary verification passes according to the comparison result, includes:

[0031] If the user verification data is consistent with the application access user information, it is determined that the secondary verification passes;

[0032] If the user verification data is inconsistent with the application access user information, it is determined that the secondary verification fails.

[0033] Preferably, when allowing the client to access the target database, it includes:

[0034] There is a pre-set access duration comparison table, and the access duration comparison table includes several access permissions, and each access permission is set with a corresponding access duration;

[0035] Obtain the user permissions in the access request, match the user permissions with the access permissions, and determine the access duration corresponding to when the user permissions are the same as the access permissions;

[0036] Determine the allowed access duration when the client accesses the target database according to the access duration.

[0037] Compared with the prior art, the beneficial effect of the present invention is that a solid security barrier is formed through a multi-level architecture of device verification data, user verification data, and secondary verification. Even if a certain level of verification is breached, other levels can still continue to function, greatly reducing the risk of illegal users accessing the database and effectively protecting sensitive information in the database from unauthorized access, tampering, and leakage.

[0038] The pre-set database comparison table and user password comparison table provide accurate and detailed reference standards for the verification process. Each device and each user have corresponding unique identifiers and permission information, avoiding security vulnerabilities caused by fuzzy verification and ensuring that only authorized devices and users can access the corresponding database resources.

[0039] When the preliminary verification or the final verification fails, introduce the temporary access application form of the database management end for secondary verification. This design fully considers various special situations, such as temporary access requirements in emergency situations or verification failures due to special reasons. On the premise of ensuring database security, it provides a flexible solution for legitimate users to ensure that users can obtain database access permissions in a timely manner in special situations without affecting the normal business operation and data processing process. Brief Description of the Drawings

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to the provided drawings without creative efforts.

[0041] Figure 1 It is a schematic flowchart of a security access method for a database according to the present invention. Detailed Embodiments

[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0043] Such as Figure 1As shown in the figure, the present invention provides a secure access method for a database, including: receiving an access request sent by a client for a target database, and generating device verification data and user verification data according to the access request.

[0044] A database comparison table and a user password comparison table are preset. The database comparison table includes several databases and the allowed access device information and allowed access user information corresponding to each database. The user password comparison table includes several user accounts and user passwords.

[0045] Based on the database comparison table, a preliminary verification of the device verification data is performed. If the preliminary verification passes, then based on the database comparison table and the user password comparison table, a final verification of the user verification data is performed. If the final verification passes, the client is allowed to access the target database.

[0046] If the preliminary verification or the final verification fails, a temporary access application form of the database management terminal is obtained, and a secondary verification of the device verification data and the user verification data is performed based on the temporary access application form. If the secondary verification passes, the client is allowed to access the target database.

[0047] The present invention effectively improves the security of database access through a multi-verification mechanism. First, the preliminary verification of the device verification data can screen out access requests that do not meet the conditions and prevent illegal devices from attempting to access the database. Second, the final verification of the user verification data further ensures that only legitimate users can access the target database, enhancing data protection. Finally, even if the preliminary or final verification fails, the secondary verification mechanism of the temporary access application form also provides an opportunity for legitimate devices or users with verification problems to access the database, increasing the flexibility and usability of the system. In addition, this secure access authentication method also simplifies the operations of the database management terminal, improves work efficiency, and reduces management costs.

[0048] In some embodiments of the present application, generating device verification data and user verification data according to the access request includes: the access request includes a client device ID, a MAC address, a device data certificate, a device type, a user account, a user password, and user permissions; classifying the access request into device verification data and user verification data.

[0049] It can be understood that by classifying the information in the access request in detail into device verification data and user verification data, the present invention can perform subsequent verification steps more precisely. The client device ID and MAC address, as key parts of the device verification data, ensure that the physical device from which the access request originates is known and authorized. The device data certificate and device type further enhance the accuracy and reliability of device verification. At the same time, the user account, user password, and user permissions, as user verification data, are important bases for verifying the user's identity and permissions. This meticulous classification not only improves the efficiency and accuracy of verification but also helps to quickly locate and solve problems during the verification process, thereby enhancing the performance and user experience of the entire secure access authentication method.

[0050] In some embodiments of the present application, the preliminary verification of the device verification data is performed based on the database comparison table, including: the device verification data includes the client device ID, MAC address, device data certificate, and device type; the database comparison table is filtered according to the client device ID in the device verification data. If the client device ID is included in the database comparison table, it is determined whether the remaining allowed access device information corresponding to the client device ID is the same as the device verification data; if they are the same, it is determined that the preliminary verification passes; if they are not the same, it is determined that the preliminary verification fails.

[0051] It can be understood that by comparing with the device information in the database, the present invention can quickly identify and verify whether the device in the access request is legal. This preliminary verification mechanism effectively reduces the potential threat of illegal devices to the database and improves the security of the system. At the same time, the detailed comparison of the device verification data ensures that only devices meeting the preset conditions can pass the verification, further enhancing the rigor and reliability of the verification.

[0052] In some embodiments of the present application, the final verification of the user verification data is performed based on the database comparison table and the user password comparison table, including: the user verification data includes the user account, user password, and user permissions; the user account is compared with the allowed access user information in the database comparison table. If the user account exists in the allowed access user information, the user account and user password are matched based on the user password comparison table; if it is determined that the user account and user password in the user verification data match, it is determined whether the final verification passes according to the user permissions; if the user account and user password in the user verification data do not match, it is determined that the final verification fails.

[0053] It can be understood that by combining the database comparison table and the user password comparison table, the present invention not only verifies the legality of the device, but also further verifies the identity and permissions of the user. This dual verification mechanism greatly enhances the security of database access, ensuring that only authorized users can access specific database resources. At the same time, the precise matching of user accounts and passwords effectively prevents unauthorized users from accessing the database by guessing or cracking passwords, further strengthening the security defense line of the system.

[0054] In some embodiments of the present application, determining whether the final verification passes according to the user permissions includes: obtaining the access user permissions of the target database; comparing the user permissions with the access user permissions, if the user permissions are higher than or equal to the access user permissions, it is determined that the final verification passes; if the user permissions are lower than the access user permissions, it is determined that the final verification fails.

[0055] It can be understood that by comparing the user permissions with the access user permissions of the target database, the present invention not only achieves precise control of user access permissions, but also further enhances the security of the system. Only when the user's permissions meet or exceed the access requirements of the target database can the user be authorized to access, which effectively avoids permission abuse and potential security risks. At the same time, this permission comparison mechanism enables system administrators to flexibly set the access permissions of different users, improving the flexibility and security of data management.

[0056] In some embodiments of the present application, the temporary access application form includes application access device information and application access user information.

[0057] It can be understood that through the temporary access application form including the application access device information and the application access user information, the present invention not only clarifies the source and identity of the access request, but also enhances the transparency and traceability of access approval. During the approval process, system administrators can clearly see which user and from which device initiated the access request, thus making more accurate approval decisions. This access application mechanism refined to devices and users further improves the security of the system and prevents unauthorized access attempts.

[0058] In some embodiments of the present application, performing secondary verification on the device verification data and the user verification data based on the temporary access application form includes: comparing the application access device information in the temporary access application form with the device verification data, if the application access device information is consistent with the device verification data, then comparing the user verification data with the application access user information in the temporary access application form, and determining whether the secondary verification passes according to the comparison result; if the application access device information is inconsistent with the device verification data, it is determined that the secondary verification fails.

[0059] It is understandable that by performing secondary verification on the device verification data and user verification data based on the temporary access application form, the present invention further enhances the security of access control. On the basis of the initial verification, the secondary verification ensures that the access request comes not only from a legitimate user but also from an expected device. This dual-verification mechanism greatly reduces the security risks caused by stolen or misused devices. At the same time, by comparing the device information for which access is applied with the device verification data and directly denying access when they are inconsistent, the present invention effectively prevents potential man-in-the-middle attacks or other forms of fraud.

[0060] In some embodiments of the present application, comparing the user verification data with the user information for which access is applied in the temporary access application form and determining whether the secondary verification passes according to the comparison result includes: if the user verification data is consistent with the user information for which access is applied, determining that the secondary verification passes; if the user verification data is inconsistent with the user information for which access is applied, determining that the secondary verification fails.

[0061] It is understandable that by precisely matching the user verification data with the user information for which access is applied in the temporary access application form, the present invention ensures the authenticity and accuracy of the access request. Access is allowed only when the user verification data is completely consistent with the user information for which access is applied, which further improves the security of the system. This mechanism effectively avoids illegal access caused by misappropriation or tampering of user information and provides another strong guarantee for the security of database resources.

[0062] In some embodiments of the present application, when allowing a client to access the target database, it includes: a access duration comparison table is preset, the access duration comparison table includes several access authorities, and each access authority is set with a corresponding access duration; obtaining the user authority in the access request, matching the user authority with the access authorities, and determining the access duration corresponding to when the user authority is the same as the access authority; determining the allowed access duration when the client accesses the target database according to the access duration.

[0063] It is understandable that by setting the access duration comparison table and matching the corresponding access duration according to the user authority, the present invention ensures the timeliness and reasonableness of database access. This mechanism not only improves the efficiency of resource utilization but also avoids security risks that may be brought about by improper access authority or too long access time. At the same time, it also provides a more flexible and personalized access experience for users, enhancing the usability of the system and user satisfaction.

[0064] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0065] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0066] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0067] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0068] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: still can modify the specific implementation manners of the present invention or make equivalent replacements, and any modification or equivalent replacement without departing from the spirit and scope of the present invention should be covered by the protection scope of the claims of the present invention.

Claims

1. A secure access method for a database, characterized in that, Including: Receiving an access request sent by a client for a target database, and generating device verification data and user verification data according to the access request; Presetting a database comparison table and a user password comparison table, where the database comparison table includes several databases and the allowed access device information and allowed access user information corresponding to each database, and the user password comparison table includes several user accounts and user passwords; Based on the database comparison table, performing a preliminary verification on the device verification data. If the preliminary verification passes, then based on the database comparison table and the user password comparison table, performing a final verification on the user verification data. If the final verification passes, then allowing the client to access the target database; If the preliminary verification or the final verification fails, then obtaining a temporary access application form from the database management end, and performing a secondary verification on the device verification data and the user verification data based on the temporary access application form. If the secondary verification passes, then allowing the client to access the target database.

2. The security access method for a database according to claim 1, wherein Generating device verification data and user verification data according to the access request, including: The access request includes a client device ID, a MAC address, a device data certificate, a device type, a user account, a user password, and user permissions; Classifying the access request into device verification data and user verification data.

3. The security access method for a database according to claim 2, characterized in that, Based on the database comparison table, performing a preliminary verification on the device verification data, including: The device verification data includes a client device ID, a MAC address, a device data certificate, and a device type; Filtering the database comparison table according to the client device ID in the device verification data. If the database comparison table includes the client device ID, then determining whether the remaining allowed access device information corresponding to the client device ID is the same as the device verification data; If they are the same, then determining that the preliminary verification passes; if they are not the same, then determining that the preliminary verification fails.

4. The secure access method for a database according to claim 3, wherein Based on the database comparison table and the user password comparison table, performing a final verification on the user verification data, including: The user verification data includes a user account, a user password, and user permissions; Comparing the user account with the allowed access user information in the database comparison table. If the user account exists in the allowed access user information, then matching the user account and the user password based on the user password comparison table; If it is determined that the user account and the user password in the user verification data match, then determining whether the final verification passes according to the user permissions; If the user account and the user password in the user verification data do not match, then determining that the final verification fails.

5. The secure access method for a database according to claim 4, wherein Determining whether the final verification passes according to the user permissions, including: Obtaining the access user permissions of the target database; Comparing the user permissions with the access user permissions. If the user permissions are higher than or equal to the access user permissions, then determining that the final verification passes; If the user permissions are lower than the access user permissions, then determining that the final verification fails.

6. The security access method for a database according to claim 1, wherein The temporary access application form includes application access device information and application access user information.

7. The secure access method for a database according to claim 6, wherein, Performing secondary verification on the device verification data and user verification data based on the temporary access application form, including: Comparing the device information for access application in the temporary access application form with the device verification data. If the device information for access application is consistent with the device verification data, then comparing the user verification data with the user information for access application in the temporary access application form, and determining whether the secondary verification passes according to the comparison result; If the device information for access application is inconsistent with the device verification data, determining that the secondary verification fails.

8. The security access method for a database according to claim 7, characterized in that, Comparing the user verification data with the user information for access application in the temporary access application form, and determining whether the secondary verification passes according to the comparison result, including: If the user verification data is consistent with the user information for access application, determining that the secondary verification passes; If the user verification data is inconsistent with the user information for access application, determining that the secondary verification fails.

9. The security access method for a database according to claim 1, wherein When allowing the client to access the target database, including: There is a preset access duration comparison table, and the access duration comparison table includes several access authorities, and each access authority is set with a corresponding access duration; Obtaining the user authority in the access request, matching the user authority with the access authority, and determining the access duration corresponding to when the user authority is the same as the access authority; Determining the allowed access duration when the client accesses the target database according to the access duration.

Citation Information

Cited By

  • Database autonomous protection method based on dual-system architecture

    CN121561920A