Database encryption and decryption method and device, computing equipment and storage medium
By generating the target key in the database transaction engine and transparently encrypting and decrypting the database data page, the problem of incomplete data protection of cached pages in the existing technology is solved, database security and transaction processing efficiency are improved, and performance impact is reduced.
Patent Information
- Application Number
- CN202510413897.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-08-01
AI Technical Summary
Existing database encryption technology cannot fully protect cached page data, and has a great impact on database transaction processing performance, so it cannot effectively deal with the risks of network attacks and data leakage.
The target key is generated through the transaction engine, and based on the address information and initialization key of the data page, the target data page in the database is transparently encrypted and decrypted to ensure data security and reduce the impact on the database transaction processing performance.
It realizes transparent encryption and decryption of all logical storage objects in the database, prevents unauthorized access and cached data leakage, improves the overall security and transaction processing efficiency of the database system, and reduces the negative impact on database performance.
Smart Images

Figure CN120408658A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of database technology, and in particular to a database encryption and decryption method, apparatus, computing device, and storage medium. Background Art
[0002] With the continuous development of information technology and the industrialization and maturity of internet applications, databases are playing an increasingly prominent role in the digital transformation of various industries. However, with the increasing risk of data leaks and cyberattacks, databases face increasing security threats. In particular, the leakage and tampering of sensitive data can cause serious economic losses and reputational damage to businesses and individuals. Therefore, ensuring the security of database data is a pressing technical issue that needs to be addressed. Summary of the Invention
[0003] To overcome the problems existing in the related art, this specification provides a database encryption and decryption method, apparatus, computing device and storage medium.
[0004] According to a first aspect of an embodiment of this specification, a database encryption and decryption method is provided, the method comprising:
[0005] In response to receiving a data processing request, determining a target data page as an operation object of the transaction engine based on the to-be-processed data targeted by the data processing request;
[0006] generating a target key based on the address information of the target data page, the data located at the target position in the target data page, and an initialization key;
[0007] Through the transaction engine, when the target data page is processed based on the data processing request, the target data page is encrypted and / or decrypted using the target key.
[0008] According to a second aspect of the embodiments of this specification, a database encryption and decryption device is provided, the device comprising:
[0009] a determining unit configured to, in response to receiving a data processing request, determine a target data page as an operation object of the transaction engine based on the to-be-processed data targeted by the data processing request;
[0010] a generating unit, configured to generate a target key based on the address information of the target data page, the data located at a target position in the target data page, and an initialization key;
[0011] An encryption and decryption unit is used to use the target key to perform encryption and / or decryption operations on the target data page when processing the target data page based on the data processing request through the transaction engine.
[0012] According to a third aspect of the embodiments of the present specification, a computing device is provided. The computing device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the operations performed by the above-mentioned database encryption and decryption method are implemented.
[0013] According to a fourth aspect of the embodiments of the present specification, a computer-readable storage medium is provided. A program is stored on the computer-readable storage medium, and when the program is executed by the processor, the operations performed by the above-mentioned database encryption and decryption method are implemented.
[0014] According to a fifth aspect of the embodiments of the present specification, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the operations performed by the above-mentioned database encryption and decryption method are implemented.
[0015] The technical solutions provided by the embodiments of the present specification may include the following beneficial effects:
[0016] When a data processing request is received, based on the data to be processed targeted by the received data processing request, a target data page that is the operation object of the transaction engine is determined. Based on the address information of the target data page, the data at the target position in the target data page, and the initialization key, a target key is generated. So that when the transaction engine processes the target data page based on the data processing request, the target key can be used to perform encryption operations and / or decryption operations on the target data page, so as to automatically implement the encryption and decryption operations of the data page during the operation of the transaction engine, so as to ensure the security of the database.
[0017] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present specification. Description of the Drawings
[0018] The drawings here are incorporated into the specification and constitute a part of the specification, showing the embodiments consistent with the present specification, and are used together with the specification to explain the principles of the present specification.
[0019] Figure 1 It is a schematic diagram of an application scenario of a database encryption and decryption method shown according to an exemplary embodiment of the present specification.
[0020] Figure 2 It is a flowchart of a database encryption and decryption method shown according to an exemplary embodiment of the present specification.
[0021] Figure 3 It is a schematic flowchart of a database encryption process shown according to an exemplary embodiment of the present specification.
[0022] Figure 4 This is a schematic flowchart of a database decryption process shown in accordance with an exemplary embodiment in this specification.
[0023] Figure 5 This is a block diagram of a database encryption / decryption device shown in accordance with an exemplary embodiment in this specification.
[0024] Figure 6 This is an overall architecture diagram of a database encryption / decryption device shown in accordance with an exemplary embodiment in this specification.
[0025] Figure 7 This is a schematic structural diagram of a computing device shown in accordance with an exemplary embodiment in this specification. Detailed implementation manners
[0026] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this specification. On the contrary, they are merely examples of devices and methods consistent with some aspects of this specification as detailed herein.
[0027] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. The singular forms "a", "said", and "the" used in this specification are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0028] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0029] Nowadays, as an important storage and management tool, the database can not only store structured data, such as data in tabular form, but also store semi-structured data (such as JSON, XML format) and unstructured data (such as image, audio, video files). With the continuous development of technology, modern database systems have been able to support a variety of data types, including text data, digital data, geospatial data, big data, and real-time streaming data, etc., enabling the database to meet the diverse storage needs in different application scenarios.
[0030] The data stored in the database plays a crucial role in people's daily lives, which may include sensitive data such as personal information (such as personal identity information), bank accounts, enterprise data, trade secrets, etc. Once this sensitive data is leaked, it may lead to a series of serious problems. However, the open and complex network environment and the continuous escalation of network attack means bring higher risks to the data security of the database, and the data security of the database faces increasing security challenges in the open and complex network environment. Therefore, it is crucial to ensure the data security of the database, and using database encryption technology to ensure the data security of the database has also become a widely adopted solution currently.
[0031] However, in the related technologies, the database encryption technology can only encrypt specific database tables or data table columns, not only the data protection is not comprehensive enough, the decrypted data protection for the cache page is also insufficient, and it has a greater impact on the database transaction processing performance.
[0032] In view of this, this specification provides a database encryption and decryption method, which can minimize the impact on the database transaction processing performance while ensuring the confidentiality of the database data. By enhancing the protection of the decrypted data in the cache, it realizes the security protection of accessing the decrypted data of the cache page during the database transaction processing, and has the ability of automatic and transparent encryption and decryption processing during the transaction processing, which can ensure that the transaction engine remains transparent to the database logical storage structure in the database cache. Moreover, the transparent encryption of the cache page data access can effectively improve the overall security of the database system and the database transaction processing efficiency.
[0033] Optionally, the database encryption and decryption method provided in this specification can be used to implement data encryption and decryption in an embedded database to ensure the security of data in the database. For example, the database encryption and decryption method provided in this specification can be used to implement data encryption and decryption in embedded databases such as SQLite, LevelDB, and Berkeley DB, but not limited to this. The database encryption and decryption method provided in this specification can also be used to implement data encryption and decryption in other embedded databases, or the database encryption and decryption method provided in this specification can also be used to implement data encryption and decryption in other databases other than embedded databases.
[0034] Optionally, the database encryption and decryption method provided in this specification can be used to implement encrypted storage of sensitive data in fields such as finance, healthcare, and government, but not limited to this.
[0035] See Figure 1 , Figure 1 FIG. is a schematic diagram of an application scenario of a database encryption and decryption method shown in this specification according to an exemplary embodiment. As Figure 1 shown, this application scenario can be composed of a terminal device 101 and a computing device 102. Among them, the terminal device 101 can be a desktop computer, a portable computer, a laptop computer, a tablet computer, a smart phone, a smart watch, etc., which can provide database access functions for users; the computing device 102 can be a single server, multiple servers, a server cluster, a cloud computing platform, etc., which can provide background support for the database.
[0036] In some embodiments, a user can trigger a data processing request through the terminal device 101, and the terminal device 101 can send the data processing request to the computing device 102 through the network. The computing device can then process the data in the database in response to the data processing request from the terminal device 101. Moreover, when processing the data in the database in response to the data processing request, the database encryption and decryption method provided in this specification can also be used to ensure the security of the data in the database.
[0037] Optionally, the data processing request can be used to request writing data into the database, or the data processing request can be used to request reading data from the database, etc. This specification does not make any limitations in this regard.
[0038] The above is only an exemplary description of the application scenario of this specification and does not constitute a limitation on the application scenario of this specification. In more possible implementation manners, this specification can be applied to a variety of other processes involving database encryption and decryption processing.
[0039] After introducing the application scenarios of the database encryption and decryption method provided in this specification, the database encryption and decryption method provided in this specification will be described in detail below in combination with the embodiments of this specification.
[0040] See Figure 2 , Figure 2 is a flowchart of a database encryption and decryption method shown in this specification according to an exemplary embodiment. As Figure 2 shown, the method includes the following steps:
[0041] Step 201, in response to receiving a data processing request, based on the data to be processed targeted by the data processing request, determine a target data page that is the operation object of the transaction engine.
[0042] Optionally, the data processing request can be used to request writing data into the database, then the data to be processed targeted by the database processing request is the data to be written into the database; or, the data processing request can be used to request reading data from the database, then the data to be processed targeted by the data processing request is the data to be read from the database.
[0043] It should be noted that in order to make the operations of the database more reliable, especially when dealing with concurrent processing of multiple operations, the consistency and integrity of data can be effectively guaranteed, the concept of transaction is introduced. A transaction is a logical unit that contains multiple database operations. When executing the multiple database operations included in the transaction, these database operations either all succeed or all fail to ensure that the multiple database operations can be executed reliably to ensure the consistency and integrity of data.
[0044] Optionally, for the transaction engine that is the main body of transaction execution in the database, when the transaction engine executes a transaction, it usually operates with data pages as the operation objects, so as to ensure the atomicity, consistency, isolation, and durability of the transaction, enable the transaction engine to effectively manage data updates and ensure the consistency of the database, and at the same time optimize performance and reduce disk input / output (I / O) operations.
[0045] Optionally, the size of the data page can be 4 kilobytes (KB), 8KB, 16KB, etc., but not limited to this. The specific size of the data page can depend on the configuration of the database system, and this specification does not limit this.
[0046] In some embodiments, in response to receiving a data processing request, the data page to which the data to be processed targeted by the data processing request belongs can be determined as the target data page that is the operation object of the transaction engine.
[0047] Step 202: Generate a target key based on the address information of the target data page, the data at the target position in the target data page, and the initialization key.
[0048] Optionally, the address information of the target data page may be the physical address of the target data page, but is not limited thereto. The target position in the target data page may be a specified position in the target data page, which can be set according to the specific requirements of encryption and decryption.
[0049] In some embodiments, a preset key generation algorithm may be used to generate a target key based on the address information of the target data page, the data at the target position in the target data page, and the initialization key.
[0050] Optionally, the preset key generation algorithm may be a specially designed encryption key generation algorithm, or a general symmetric encryption key generation algorithm, an asymmetric encryption key generation algorithm, etc. may be used to implement the generation of the target key.
[0051] Step 203: When processing the target data page based on the data processing request through the transaction engine, use the target key to perform an encryption operation and / or a decryption operation on the target data page.
[0052] In some embodiments, when the transaction engine processes the target data page based on the data processing request, an automated encryption and decryption process may be performed on the target data page using the target key to ensure the data security of the target data page.
[0053] Through the solution provided by the above embodiments, transparent encryption and decryption of all logical storage object pages in the database can be achieved, so as to combine the page access and logical storage management mechanisms in the database transaction processing process to implement encryption and decryption operations on the accessed page data. By embedding an access page encryption and decryption mechanism in the transaction engine to implement an automatic encryption and decryption process during the data page processing, not only the confidentiality of all logical storage objects in the database is ensured, preventing unauthorized access and cache data leakage, but also the problem of the decline in the database transaction processing performance caused by the traditional physical I / O read and write encryption and decryption mechanism is solved. Due to the transparency of the logical storage structure of the cache page read and write, a single transaction read and write does not need to load and decrypt other cache page data, so that the encryption and decryption process based on the data page can reduce the impact on the global database structure, effectively coping with the problem of the overall performance decline of the database caused by the encryption and decryption operations.
[0054] After introducing the basic implementation process of this specification, the following introduces various optional implementation manners of the database encryption and decryption method provided by this specification.
[0055] In some embodiments, the data processing request may carry the logical address of the data to be processed. For step 201, when, in response to receiving the data processing request, determining the target data page that is the operation object of the transaction engine based on the data to be processed targeted by the data processing request, the target data page that is the operation object of the transaction engine may be determined based on the logical address carried by the data processing request.
[0056] In some embodiments, the physical address mapped by the logical address may be determined based on the logical address carried by the data processing request, so as to determine the data page corresponding to the physical address as the target data page that is the operation object of the transaction engine.
[0057] Optionally, the logical address is used to describe the data to be processed that needs to be operated according to the structure of the database (such as table name, row number, index, etc.).
[0058] Optionally, the logical address may be mapped to the corresponding physical address according to the storage structure of the data in the database (such as B+ tree, hash table, etc.). The physical address may be used to indicate the data page where the data to be processed is located. Thus, the data page corresponding to the physical address may be determined as the target data page that is the operation object of the transaction engine, so as to perform corresponding processing on the data to be processed in the target data page.
[0059] It should be noted that the physical address may be the absolute address of the physical storage of the database.
[0060] In some embodiments, after the determination of the target data page is achieved through step 201, then through step 202, based on the address information of the target data page, the data at the target position in the target data page, and the initialization key, a target key may be generated.
[0061] In some embodiments, for step 202, when generating the target key based on the address information of the target data page, the data at the target position in the target data page, and the initialization key, it may be achieved through the following steps:
[0062] Step 2021: Expand the address information of the target data page into the first data of the first specified byte, and combine the first data with the data at the target position in the target data page to obtain the first key.
[0063] Optionally, the address information of the target data page may be the page identifier corresponding to the physical address of the target data page, where the page identifier may be the page number, but is not limited thereto.
[0064] In some embodiments, byte expansion can be performed on the page identifier corresponding to the physical address of the target data page, that is, address expansion of the address information of the target data page is achieved. Optionally, the page identifier corresponding to the physical address of the target data page can be expanded to a first specified byte to obtain first data.
[0065] Optionally, the first specified byte can be 4 bytes, that is, the page identifier corresponding to the physical address of the target data page is expanded to a 4-byte data, and the expanded 4-byte data is used as the first data. However, this is not limited thereto, and the first specified byte can also have other values.
[0066] Optionally, the second specified byte can be 12 bytes, and the data at the target position in the target data page is the data of the second specified byte at the end of the target data page, that is, the data of the 12 bytes at the end of the target data page.
[0067] In some embodiments, the first data obtained by byte expansion of the page identifier corresponding to the physical address of the target data page can be concatenated with the data of the second specified byte at the end of the target data page to obtain a first key.
[0068] Taking the example of expanding the page identifier corresponding to the physical address of the target data page to 4-byte data and combining it with the data of the 12 bytes at the end of the target data page, 16-byte data related to the database storage logic can be obtained by combining the two, as the first key.
[0069] It should be noted that for the case where the data processing request is used to request writing the data to be processed into the database, the data at the target position in the target data page can be plaintext data; for the case where the data processing request is used to request reading the data to be processed from the database, the data at the target position in the target data page can be ciphertext data.
[0070] Step 2022: Generate a key with the same length as the data length of the target data page based on the first key and the initialization key, as the target key.
[0071] Optionally, the initialization key is a high-entropy random number, or the initialization key is a key generated by a security module. However, this is not limited thereto, and other key generation materials related to database applications can also be used as the initialization key.
[0072] It should be noted that by using a high-entropy random number or a key generated by a security module as the initialization key, the unpredictability and security of the initialization key are ensured.
[0073] In some embodiments, multiple rounds of key expansion processing may be performed on the first key and the initialization key until a key with the same data length as the target data page is generated as the target key.
[0074] In some embodiments, when performing multiple rounds of key expansion processing on the first key and the initialization key, for any round of key expansion processing, the key data obtained from this round of key expansion processing may be used as the input for the next round of multiple rounds of key expansion processing.
[0075] Optionally, the first key and the initialization key may be used as the initial key input into a preset key generation algorithm, so as to perform calculations based on the first key and the initialization key through the preset key generation algorithm to obtain the key data obtained after one round of key expansion processing. Thus, the key data obtained after one round of key expansion processing is used as the input for the second round of multiple rounds of key expansion processing, and through the preset key generation algorithm, calculations are performed based on the key data obtained after one round of key expansion processing to obtain the key data obtained after two rounds of key expansion processing, and so on, until a streaming key with the same data length as the target data page is generated. The generated streaming key with the same data length as the target data page can be used as the target key.
[0076] Optionally, the preset key generation algorithm may consist of multiple substitution tables to ensure that the data at the end part of the data page can generate the corresponding target key through the iterative process of multiple rounds of key expansion processing, thereby enhancing the anti-attack ability of the algorithm.
[0077] Through the above embodiments, based on the key generation material one related to the database application (i.e., the initialization key) and the key generation material two related to the database storage logic (i.e., the address information of the target data page and the data at the target position in the target data page), the main key is generated by expanding the key generation material one, and the main key is further combined with the key generation material two related to the database storage logic parameters to generate the target key for page data encryption and decryption, so as to provide a hierarchical key management strategy, in order to enhance the security and unpredictability of the key generation process through key generation materials with diverse sources.
[0078] In some embodiments, the target key can be directly used by the transaction engine to encrypt and decrypt the page data of various logical storage objects when accessing the cache during the transaction processing. That is, after obtaining the target key through step 202, through step 203, when the transaction engine processes the target data page based on the data processing request, the target key is used to encrypt and / or decrypt the target data page.
[0079] In some embodiments, for step 203, when the data processing request is used to request writing the data to be processed into the database, through the transaction engine, when writing the data to be processed into the target data page based on the data processing request, use the target key to perform an encryption operation on the target data page; and / or, when the data processing request is used to request reading the data to be processed from the database, through the transaction engine, when reading the data to be processed from the target data page based on the data processing request, use the target key to perform a decryption operation on the target data page. The encryption process and decryption process based on the target key are introduced below respectively.
[0080] First, the encryption process based on the target key is introduced.
[0081] It should be noted that for the encryption process based on the target key, the target key is generated based on the address information of the target data page, the plaintext data at the target position in the target data page, and the initialization key.
[0082] In some embodiments, for the process of using the target key to perform an encryption operation on the target data page through the transaction engine when writing the data to be processed into the target data page based on the data processing request, it can be implemented in the following manner:
[0083] Through the transaction engine, when writing the data to be processed into the target data page based on the data processing request, perform a byte-by-byte exclusive OR (XOR) operation on the target key and the plaintext data to be processed into the target data page to obtain the ciphertext data of the target data page, so as to implement the encryption operation on the target data page.
[0084] Through the above encryption process, it can be ensured that the encryption of each bit of the page data accessed by the transaction engine depends on a unique streaming key, so as to enhance the encryption strength of the database cache data storage.
[0085] In some embodiments, when the transaction engine writes the data to be processed into the target data page based on the data processing request, it can first store the plaintext data to be processed into the target data page in the database cache, so as to perform an encryption operation based on the plaintext data stored in the database cache and then persist it to the disk to achieve encrypted storage of the data. That is, the transaction engine can store the plaintext data to be processed into the target data page in the database cache, so as to perform a byte-by-byte exclusive OR operation on the plaintext data stored in the database cache and the target key.
[0086] In some embodiments, after performing a byte-by-byte exclusive OR operation on the plaintext data stored in the database cache and the target key, the plaintext data stored in the database cache can also be deleted.
[0087] Optionally, the deletion of the plaintext data stored in the database cache can be achieved by overwriting the data area in the cache multiple times or using a specific algorithm to overwrite the data.
[0088] Through the above embodiments, after each transaction engine finishes writing encrypted data, the plaintext data in the database cache can be immediately cleared to ensure that sensitive plaintext information does not remain in the cache, reducing the risk of cache data being stolen by malware or unauthorized users.
[0089] In some embodiments, when writing data to be processed to a target data page based on a data processing request, after encrypting the target data page using a target key, a target key can also be regenerated based on the data at a target position in the target data page after the encryption operation, the address information of the target data page, and an initialization key.
[0090] That is, after the transaction engine implements the storage update of the target data page, the above-mentioned target key generation method can be reapplied, and the data at the target position in the encrypted data page can be converted into a new decryption key through the above-mentioned key generation process for the generation of subsequent decryption page keys, preventing security risks caused by long transactions accessing a large amount of data using the same key, and further improving data security.
[0091] See Figure 3 , Figure 3 is a schematic flowchart of a database encryption process shown in this specification according to an exemplary embodiment. As Figure 3 shown, the workflow of the encryption part can include the following steps:
[0092] Step 301, page acquisition and initial encryption.
[0093] In some embodiments, the encryption process can be started after obtaining the data to be written to the database data page.
[0094] In some embodiments, a master key can be generated through a key expansion method using key generation material 1 related to the database application (i.e., the initialization key) to ensure the security foundation of the encryption process.
[0095] Step 302, generation of the target key for page encryption.
[0096] In some embodiments, encryption can be performed in units of each logical storage object page data. Optionally, the page number of the absolute address of the physical storage of the database can be extended to 4-byte data, which is combined with the original data of the last 12 bytes at the end of the logical storage object page data to form the second 16-byte key generation material related to the database storage logic. Then, the 16-byte key generation material two and the master key are processed through multiple rounds of iteration by a specially designed encryption algorithm to generate the target key for page encryption.
[0097] Optionally, in each round of iteration, the encrypted data obtained from the previous iteration can be used as the new key generation material for the next round of iteration until the target key with the same size as the database read / write page data length is generated.
[0098] Step 303, data encryption operation.
[0099] In some embodiments, the generated page encryption key and the page data can be subjected to encryption operations such as byte-by-byte exclusive OR to generate the corresponding ciphertext.
[0100] Through the byte-by-byte exclusive OR encryption operation, it can be ensured that the encryption of each bit of data depends on a unique stream key, enhancing the encryption strength and security.
[0101] Step 304, data overwriting and cleaning.
[0102] In some embodiments, through overwriting and clearing operations, it can be ensured that each time the database transaction engine immediately clears the relevant data of the decrypted page in the cache after decrypting and using the page data, so as to prevent the residue of sensitive information in the cache and reduce the risk of leakage of the decrypted page cache data.
[0103] Optionally, the generation method of the key expansion (the first key generation material) related to the database application can adopt an alternative substitution table to enhance the flexibility and security of key generation. Specifically, different key expansion substitution tables can be selected according to actual application requirements, and this specification does not limit this.
[0104] It should be noted that Figure 3 the embodiments shown are only exemplary descriptions of the encryption process and do not constitute a limitation on the implementation manners of this specification. And Figure 3 the embodiments shown only briefly introduce the optional implementation manners of each step. For the detailed introduction of the implementation manners of each step, please refer to the foregoing, and details will not be repeated here.
[0105] Next, the decryption process based on the target key will be introduced.
[0106] It should be noted that for the decryption process based on the target key, the target key is generated based on the address information of the target data page, the ciphertext data located at the target position in the target data page, and the initialization key.
[0107] In some embodiments, for the process of using the target key to decrypt the target data page when the transaction engine reads the data to be processed from the target data page based on the data processing request, it can be implemented in the following manner:
[0108] When the transaction engine reads the data to be processed from the target data page based on the data processing request, perform a byte-by-byte exclusive OR operation on the target key and the ciphertext data in the target data page to recover the plaintext data of the same length as the ciphertext data as the plaintext data of the target data page, so as to implement the decryption operation of the target data page.
[0109] Optionally, during the process of the transaction processing engine decrypting the ciphertext data of the relevant page, according to the query index order of the database logical storage object, skip the decryption of the full table object data page, and only decrypt the logical I / O page that needs to be accessed, thereby reducing the data decryption overhead and improving the database transaction processing performance.
[0110] In some embodiments, when the transaction engine reads the data to be processed from the target data page based on the data processing request, after decrypting to obtain the plaintext data of the target data page, the plaintext data obtained through the byte-by-byte exclusive OR operation can be stored in the database cache, so as to respond to the data processing request based on the plaintext data stored in the database cache.
[0111] In some embodiments, after responding to the data processing request based on the plaintext data in the database cache, the plaintext data stored in the database cache can also be deleted.
[0112] Optionally, the deletion of the plaintext data stored in the database cache can be achieved by overwriting multiple times or using a specific algorithm to overwrite the data area in the cache.
[0113] Through the above embodiments, after each time the transaction engine decrypts and uses the page data, the immediate cleaning of the cached plaintext data can be automatically performed, and the relevant sensitive data in the cache can be overwritten multiple times or overwritten using a specific algorithm to ensure that the cached sensitive information does not remain in the cache and reduce the risk of leakage of the decrypted page cache data.
[0114] See Figure 4 , Figure 4 is a schematic flowchart of a database decryption process shown in this specification according to an exemplary embodiment. As Figure 4 shown, the working process of the decryption part can include the following steps:
[0115] Step 401, Page acquisition and initial encryption.
[0116] In some embodiments, the decryption process can be initiated after the ciphertext data of the corresponding database data page is read from the database.
[0117] In some embodiments, key generation material one related to the database application can be utilized to generate a master key through a key expansion method.
[0118] Step 402, Generation of the target key for page decryption.
[0119] In some embodiments, the index to be queried can be obtained based on the header information and the root page of the first page of the decryption page. The 4-byte data obtained by expanding the page number stored physically in the database and the 12-byte ciphertext at the end of the page form key generation material two of 16 bytes. In combination with the master key, a separate page decryption key for each page is generated and the page data is decrypted.
[0120] In some embodiments, according to the page data of each logical storage object, the 12-byte ciphertext at the end can be extracted and combined with the page number of the absolute address stored physically in the database to be expanded into 16-byte data key generation material two related to the database storage logic. The 16-byte data and the master key are iterated through a specially designed decryption algorithm, with the encrypted data from the previous iteration serving as the key generation material for the next iteration until a page decryption key equal in length to the ciphertext of the logical storage object page data is generated.
[0121] Step 403, Data decryption operation.
[0122] In some embodiments, the page decryption key and the page data can be XORed to generate the plaintext.
[0123] Step 404, Data overwriting and cleaning.
[0124] In some embodiments, after the transaction engine finishes decryption, the decrypted page data is securely stored in the cache and then passed to the application layer for necessary business operations.
[0125] In some embodiments, to ensure that sensitive information in the cache is not misused or leaked, after each decryption operation, cache plaintext data cleaning can be automatically performed. Optionally, the relevant decrypted data in the database cache can be overwritten and deleted to ensure that the traces of the decrypted data in the cache are completely cleared, thereby preventing potential risks of residual information in the cache.
[0126] Through the instant cleaning mechanism of cached plaintext data, it can be ensured that even after the encrypted database is successfully accessed, the key information can be correctly interpreted and used, providing double protection for the security and privacy of users.
[0127] It should be noted that this decryption process particularly emphasizes the uniqueness and diversity of keys. Each database logical I / O page is encrypted and decrypted using a unique page encryption and decryption key. This approach enhances the overall security of database storage encryption. Even if the key of one data block is cracked, the security of other data blocks will not be affected.
[0128] In some embodiments, to maintain the cleanliness of the database management system and avoid potential cache leaks, all temporarily allocated cache spaces are cleaned and released in a timely manner after the data transfer is completed.
[0129] It should be noted that the decryption process aims to provide a secure and efficient data processing environment through strict time monitoring and key management, thereby ensuring the security of sensitive data in the cache and ensuring that information is not exploited by malicious attackers during the transmission process.
[0130] According to the database encryption and decryption method provided in this specification, page transparent encryption can be implemented on database logical storage repository objects using self-developed or commercial encryption algorithms. Encryption and decryption operations are performed in the database cache in units of database transaction engine read and write pages to ensure the confidentiality of all logical storage object data in the database.
[0131] Meanwhile, a hierarchical key management strategy can be adopted to manage two key generation materials, the master key and the page encryption and decryption key, as well as the key generation materials used to generate the master key and the page encryption and decryption key, ensuring the high security of the generation, storage, and management of various keys and preventing key leakage and abuse.
[0132] Moreover, the encryption operation can be automatically executed when the transaction engine writes transaction-related page data to the database cache, and the decryption operation can be automatically executed when reading page data from the database cache to achieve a page data encryption and decryption process that is transparent to the logical storage structure. Users do not need to perceive the specific encryption and decryption operations, ensuring the seamless integration of the database transaction engine and the storage engine.
[0133] In addition, a page encryption and decryption key update mechanism can be adopted. After each modification of page data, through the update mechanism, a key for subsequent decryption of the page can be generated based on the new data stored at the end of the page, preventing security risks caused by using the same key for long transactions and improving the anti-attack ability of the system.
[0134] In addition, a database cache plaintext data immediate cleaning operation can be adopted. After each transaction engine decrypts and uses the page data, the relevant data of the decrypted page in the cache is immediately cleaned to prevent the residue of sensitive information in the cache and reduce the leakage risk of the decrypted page cache data.
[0135] Through the database encryption and decryption method provided in this specification, not only can the encryption operation be automatically executed when the transaction engine writes the page data into the database cache, but also when the transaction engine reads the data, according to the query process of the database logical I / O, the decryption operation can be automatically executed when reading the page data from the database cache. The encryption and decryption process of cache access during the database transaction processing is completely transparent to the user database application, and this encryption and decryption strategy for cache page reading and writing related to transaction processing can minimize the impact of data storage encryption and decryption on the performance of database transaction processing.
[0136] In addition, a page encryption and decryption key update mechanism can also be adopted. When each data write causes a page update, through the key update mechanism, a new target key is regenerated based on the new data stored at the end of the page for subsequent page decryption, preventing security risks caused by the use of the same key in long transactions, such as key leakage or being cracked, and further enhancing the security of the cache page data.
[0137] In addition, after each transaction engine decrypts and uses the page data, the plaintext data in the cache can be immediately cleaned to ensure that the plaintext sensitive information does not remain in the cache and reduce the risk of the cache data being stolen by malware or unauthorized users.
[0138] In summary, through the database encryption and decryption method provided in this specification, the comprehensive transparent encryption and decryption functions of cache page data for the database logical storage structure can be realized. On the premise of ensuring that the user application is unaware of the use of cryptographic technology, the full encryption of database storage objects is realized, ensuring the security of data during storage and processing, effectively preventing illegal access and data leakage of cache data during transaction processing. At the same time, the dynamic key management and cache data cleaning mechanism effectively prevent key leakage and cache attacks to prevent the residue of sensitive information in the cache and reduce the leakage risk of decrypted page cache data. And it can also optimize the execution efficiency of the transaction engine and improve the efficiency of database operations.
[0139] Corresponding to the embodiments of the foregoing method, this specification also provides embodiments of a device and the computing device to which it is applied.
[0140] As Figure 5 shown, Figure 5 is a block diagram of a database encryption and decryption device shown in this specification according to an exemplary embodiment. The device includes:
[0141] A determination unit 501, configured to, in response to receiving a data processing request, determine a target data page that is an operation object of a transaction engine based on the data to be processed targeted by the data processing request;
[0142] A generation unit 502, configured to generate a target key based on the address information of the target data page, the data at a target position in the target data page, and an initialization key;
[0143] An encryption / decryption unit 503, configured to, through the transaction engine, perform an encryption operation and / or a decryption operation on the target data page using the target key when processing the target data page based on the data processing request.
[0144] In some embodiments, when the generation unit 502 is configured to generate a target key based on the address information of the target data page, the data at a target position in the target data page, and an initialization key, it is configured to:
[0145] Expand the address information of the target data page into first data of a first specified byte, and combine the first data with the data at a target position in the target data page to obtain a first key;
[0146] Generate a key having the same data length as that of the target data page based on the first key and the initialization key as the target key.
[0147] In some embodiments, when the generation unit 502 is configured to generate a key having the same data length as that of the target data page based on the first key and the initialization key as the target key, it is configured to:
[0148] Perform multiple rounds of key expansion processing on the first key and the initialization key until a key having the same data length as that of the target data page is generated as the target key.
[0149] In some embodiments, when the generation unit 502 is configured to perform multiple rounds of key expansion processing on the first key and the initialization key, it is configured to:
[0150] For any round of key expansion processing, use the key data obtained in this round of key expansion processing as the input for the next round of multiple rounds of key expansion processing.
[0151] In some embodiments, the address information of the target data page is the page identifier corresponding to the physical address of the target data page; the data at the target position in the target data page is the data of the second specified byte at the end of the target data page; the initialization key is a high-entropy random number, or the initialization key is a key generated by the security unit.
[0152] In some embodiments, when the processing unit 503 is used to perform an encryption operation and / or a decryption operation on the target data page using the target key through the transaction engine when processing the target data page based on the data processing request, it is used for at least one of the following:
[0153] The data processing request is used to request writing the data to be processed into the database. When writing the data to be processed into the target data page based on the data processing request through the transaction engine, an encryption operation is performed on the target data page using the target key;
[0154] The data processing request is used to request reading the data to be processed from the database. When reading the data to be processed from the target data page based on the data processing request through the transaction engine, a decryption operation is performed on the target data page using the target key.
[0155] In some embodiments, when the processing unit 503 is used to perform an encryption operation on the target data page using the target key through the transaction engine when writing the data to be processed into the target data page based on the data processing request, it is used for:
[0156] Through the transaction engine, when writing the data to be processed into the target data page based on the data processing request, a byte-by-byte exclusive OR operation is performed on the target key and the plaintext data to be processed into the target data page to obtain the ciphertext data of the target data page, so as to implement the encryption operation on the target data page.
[0157] In some embodiments, the device further includes:
[0158] A first storage unit, configured to store the plaintext data to be processed into the target data page in the database cache, so as to perform a byte-by-byte exclusive OR operation based on the plaintext data stored in the database cache and the target key.
[0159] In some embodiments, when the processing unit 503 is used to perform a decryption operation on the target data page using the target key through the transaction engine when reading the data to be processed from the target data page based on the data processing request, it is used for:
[0160] Through the transaction engine, when reading the data to be processed from the target data page based on the data processing request, perform a byte-by-byte exclusive OR operation on the target key and the ciphertext data in the target data page to obtain the plaintext data of the target data page, so as to implement the decryption operation of the target data page.
[0161] In some embodiments, the device further includes:
[0162] A second storage unit, configured to store the plaintext data obtained through the byte-by-byte exclusive OR operation into a database cache, so as to respond to the data processing request based on the plaintext data stored in the database cache.
[0163] In some embodiments, the device further includes a deletion unit, and the deletion unit is configured to perform at least one of the following:
[0164] After performing a byte-by-byte exclusive OR operation on the plaintext data stored in the database cache and the target key, delete the plaintext data stored in the database cache;
[0165] After responding to the data processing request based on the plaintext data in the database cache, delete the plaintext data stored in the database cache.
[0166] In some embodiments, the generating unit 502 is further configured to regenerate the target key based on the data at the target position in the target data page after the encryption operation, the address information of the target data page, and the initialization key.
[0167] In some embodiments, the data processing request carries the logical address of the data to be processed;
[0168] When the determining unit 501 is configured to determine the target data page that is the operation object of the transaction engine based on the data to be processed targeted by the data processing request, it is configured to:
[0169] Based on the logical address carried in the data processing request, determine the physical address mapped by the logical address;
[0170] Determine the data page corresponding to the physical address as the target data page that is the operation object of the transaction engine.
[0171] For the specific implementation process of the functions and roles of each unit in the above device, please refer to the implementation process of the corresponding steps in the above method, which will not be elaborated here.
[0172] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions in the method embodiments. The device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution in this specification. A person of ordinary skill in the art can understand and implement it without creative work.
[0173] The above embodiments mainly introduce the division of device modules based on functionality. Refer to Figure 6 , Figure 6 which is the overall architecture diagram of a database encryption and decryption device shown in this specification according to an exemplary embodiment. As Figure 6 shown, the overall architecture of the database encryption and decryption device may include four parts: a main control program module (Main Control Module) 610, an encryption component module (Encryption Component Module) 620, a key management module (Key Management Module) 630, and a database module (Database Module) 640. Each of the above modules can be used as a specific functional entity to cooperate together to ensure the data security and stability of the system and ensure that all operations are carried out smoothly according to the established process.
[0174] Optionally, the main control program module 610 is mainly responsible for calling each functional module, and is also responsible for processing and distributing user requests, and implementing security policies, including but not limited to authentication, authorization, and security auditing. As the scheduling center of the system, this module ensures the correct transfer of information between each module and the orderly execution of tasks.
[0175] Optionally, the encryption component module 620 is responsible for encrypting and decrypting sensitive data to prevent unauthorized access to the data during transmission or storage. This module can use strong encryption algorithms to ensure the confidentiality of the data and can dynamically adjust the encryption policy according to the security policy of the system. It should be noted that the processing unit 503 shown in the device block diagram above Figure 5 can be used as a part of the encryption component module 620.
[0176] Optionally, to achieve efficient encryption operations, the encryption component module 620 can be designed to be extensible and modular, allowing for the selection of appropriate encryption algorithms according to different security requirements. In addition, to address potential future threats and algorithm upgrades, the encryption component module 620 can also support dynamic algorithm replacement.
[0177] Optionally, the key management module 630 is the part of the system responsible for handling all operations related to encryption keys, including key generation, distribution, and storage. It should be noted that the generation unit 502 in the device block diagram shown above can be used as part of the encryption component module 620. Figure 5 As shown in the device block diagram, the generation unit 502 can be used as part of the encryption component module 620.
[0178] It should be noted that the key management module 630 is responsible for generating and distributing the materials used for data encryption. This module ensures that all keys used in encryption operations comply with security policies and are securely managed throughout the key lifecycle.
[0179] Optionally, the database module 640 is responsible for storing the encrypted data and managing the associated encryption metadata. This module ensures the security of the data when stored at the backend, supports efficient data retrieval and maintenance operations, and also provides an audit logs function to record all accesses and changes to the database for future auditing and review. It should be noted that the determination unit 501 in the device block diagram shown above can be used as part of the encryption component module 620. Figure 5 As shown in the device block diagram, the determination unit 501 can be used as part of the encryption component module 620.
[0180] Optionally, the data storage encryption structure can be stored in units of multiple database logical I / O pages. Among them, the database file itself consists of two parts: a header file and data content. The first page does not distinguish between the header file and the data content. The header file and the root page are encrypted together on the first page. Subsequent other cache read / write (logical I / O) pages are stored in a tree structure through indexing. Optionally, the database data content part is encrypted through a page encryption module to ensure data security at the most initial level. Optionally, the page data content can be further divided into two sub-parts: a data index point and user data. Among them, the data index point is mainly responsible for indexing data blocks, while user data carries the user's sensitive data assets. By independently encrypting each data logical I / O page using the above data storage encryption structure with an algorithm, the security of each data page can be effectively guaranteed.
[0181] Optionally, during the process of the transaction engine handling page access, the page data is first encrypted by the encryption component at the application layer to ensure the confidentiality of sensitive information. The encrypted data is then stored back in the corresponding position of the database cache read / write (logical I / O) page.
[0182] Through the design of the overall encrypted data storage structure described above, transparent encryption of all stored object data in the database can be achieved without affecting the performance and availability of the database. In this way, even in the case of data leakage, unauthorized third parties cannot read or understand the encrypted data, thus ensuring the confidentiality and security of the stored information.
[0183] This specification also provides a computing device. See Figure 7 , Figure 7 which is a schematic structural diagram of a computing device shown in this specification according to an exemplary embodiment. As Figure 7 shown, the computing device includes a processor 710, a memory 720, and a network interface 730. The memory 720 is used to store computer instructions that can run on the processor 710. The processor 710 is used to implement the database encryption and decryption method provided by any embodiment of this specification when executing the computer instructions. The network interface 730 is used to implement input and output functions. In more possible implementation manners, the computing device may further include other hardware, which is not limited in this specification.
[0184] This specification also provides a computer-readable storage medium. The computer-readable storage medium can be in various forms. For example, in different examples, the computer-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof. Specifically, the computer-readable medium can also be paper or other suitable media that can print programs. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, it implements the database encryption and decryption method provided by any embodiment of this specification.
[0185] This specification also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the database encryption and decryption method provided by any embodiment of this specification.
[0186] Those skilled in the art should understand that one or more embodiments of this specification can be provided as a method, an apparatus, a computing device, a computer-readable storage medium, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0187] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiment corresponding to the computing device, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment.
[0188] The above describes specific embodiments of this specification. Other embodiments are within the scope of this specification. In some cases, the actions or steps recorded in this specification can be executed in a different order from that in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or consecutive order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0189] The embodiments of the subject matter and functional operations described in this specification can be implemented in the following: digital electronic circuits, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or a combination of one or more of them. The embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible non-transitory program carrier to be executed by a data processing apparatus or to control the operation of a data processing apparatus. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, such as a machine-generated electrical, optical, or electromagnetic signal, which is generated to encode and transmit information to a suitable receiver apparatus for execution by a database encryption / decryption apparatus. A computer storage medium can be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of one or more of them.
[0190] The processes and logical flows described in this specification can be performed by one or more programmable computers executing one or more computer programs to perform the corresponding functions by operating on input data and generating output. The processes and logical flows can also be performed by, for example, FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit) of special logic circuits, and the apparatus can also be implemented as special logic circuits.
[0191] Computers suitable for executing computer programs include, for example, general and / or special microprocessors, or any other type of central processing unit. Generally, the central processing unit will receive instructions and data from a read-only memory and / or a random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, etc., or the computer will be operatively coupled to such mass storage devices to receive data therefrom or transfer data thereto, or both. However, a computer is not necessarily required to have such devices. In addition, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name just a few.
[0192] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as including semiconductor memory devices (such as EPROM, EEPROM, and flash memory devices), magnetic disks (such as internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special logic circuits.
[0193] Although this specification contains many specific implementation details, these should not be construed as limiting the scope of any invention or the scope of what is claimed, but rather are mainly used to describe the features of specific embodiments of a particular invention. Certain features described in multiple embodiments in this specification can also be implemented in combination in a single embodiment. On the other hand, various features described in a single embodiment can also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although features can function in certain combinations as described above and are even initially claimed as such, one or more features from the claimed combination can in some cases be removed from the combination, and the claimed combination can be directed to a sub-combination or a variation of the sub-combination.
[0194] Similarly, although the operations are depicted in the drawings in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or sequentially, or that all illustrated operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Additionally, the separation of various system modules and components in the above-described embodiments should not be construed as required in all embodiments, and it should be understood that the program components and systems described can generally be integrated together in a single software product or packaged into multiple software products.
[0195] Thus, particular embodiments of the subject matter have been described. Other embodiments are within the scope of this specification. In some cases, the acts recited in this specification can be performed in a different order and still achieve the desired result. Additionally, the processes depicted in the drawings are not necessarily in the particular order or sequential order shown to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.
[0196] Those skilled in the art will readily conceive of other embodiments of this specification after considering the specification and practicing the invention herein. This specification is intended to cover any variations, uses, or adaptations of this specification that follow the general principles of this specification and include common general knowledge or conventional technical means in the technical field not claimed in this application. That is, this specification is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope.
[0197] The foregoing are only alternative embodiments of this specification and are not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this specification shall be included within the scope of protection of this specification.
Claims
1. A database encryption and decryption method, characterized in that, The method includes: In response to receiving a data processing request, determining a target data page that is an operation object of a transaction engine based on the data to be processed targeted by the data processing request; Generating a target key based on the address information of the target data page, the data at a target position in the target data page, and an initialization key; When processing the target data page based on the data processing request through the transaction engine, performing an encryption operation and / or a decryption operation on the target data page using the target key.
2. The method according to claim 1, characterized in that, The generating a target key based on the address information of the target data page, the data at a target position in the target data page, and an initialization key includes: Expanding the address information of the target data page into first data of a first specified number of bytes, and combining the first data with the data at a target position in the target data page to obtain a first key; Generating a key having the same data length as that of the target data page based on the first key and the initialization key as the target key.
3. The method according to claim 2, wherein The generating a key having the same data length as that of the target data page based on the first key and the initialization key as the target key includes: Performing multiple rounds of key expansion processing on the first key and the initialization key until a key having the same data length as that of the target data page is generated as the target key.
4. The method according to claim 3, wherein When performing multiple rounds of key expansion processing on the first key and the initialization key, the method includes: For any round of key expansion processing, using the key data obtained in this round of key expansion processing as the input for the next round of multiple rounds of key expansion processing.
5. The method according to claim 2, wherein The address information of the target data page is a page identifier corresponding to the physical address of the target data page; The data at a target position in the target data page is data of a second specified number of bytes at the end of the target data page; The initialization key is a high-entropy random number, or the initialization key is a key generated by a security module.
6. The method according to claim 1, characterized in that The performing an encryption operation and / or a decryption operation on the target data page using the target key when processing the target data page based on the data processing request through the transaction engine includes at least one of the following: The data processing request is used to request writing the data to be processed into a database. When writing the data to be processed into the target data page based on the data processing request through the transaction engine, performing an encryption operation on the target data page using the target key; The data processing request is used to request reading the data to be processed from a database. When reading the data to be processed from the target data page based on the data processing request through the transaction engine, performing a decryption operation on the target data page using the target key.
7. The method according to claim 6, wherein The performing an encryption operation on the target data page using the target key when writing the data to be processed into the target data page based on the data processing request through the transaction engine includes: Through the transaction engine, when writing the data to be processed into the target data page based on the data processing request, a byte-by-byte exclusive OR operation is performed on the target key and the plaintext data to be processed into the target data page to obtain the ciphertext data of the target data page, so as to implement the encryption operation of the target data page.
8. The method according to claim 7, wherein Before performing the byte-by-byte exclusive OR operation on the target key and the plaintext data in the target data page to obtain the ciphertext data of the target data page, the method further includes: Storing the plaintext data to be processed into the target data page in the database cache, so as to perform a byte-by-byte exclusive OR operation based on the plaintext data stored in the database cache and the target key.
9. The method according to claim 6, wherein The step of decrypting the target data page using the target key when reading the data to be processed from the target data page based on the data processing request through the transaction engine includes: Through the transaction engine, when reading the data to be processed from the target data page based on the data processing request, a byte-by-byte exclusive OR operation is performed on the target key and the ciphertext data in the target data page to obtain the plaintext data of the target data page, so as to implement the decryption operation of the target data page.
10. The method according to claim 9, wherein After performing the byte-by-byte exclusive OR operation on the target key and the ciphertext data in the target data page to obtain the plaintext data of the target data page, the method further includes: Storing the plaintext data obtained through the byte-by-byte exclusive OR operation in the database cache, so as to respond to the data processing request based on the plaintext data stored in the database cache.
11. The method according to claim 8 or 10, characterized in that, The method further includes at least one of the following: After performing the byte-by-byte exclusive OR operation based on the plaintext data stored in the database cache and the target key, deleting the plaintext data stored in the database cache; After responding to the data processing request based on the plaintext data in the database cache, deleting the plaintext data stored in the database cache.
12. The method according to claim 1, wherein After encrypting the target data page using the target key when processing the target data page based on the data processing request through the transaction engine, the method further includes: Regenerating the target key based on the data at the target position in the encrypted target data page, the address information of the target data page, and the initialization key.
13. The method according to claim 1, characterized in that, The data processing request carries the logical address of the data to be processed; Determining the target data page that is the operation object of the transaction engine based on the data to be processed targeted by the data processing request includes: Determining the physical address mapped by the logical address based on the logical address carried in the data processing request; Determining the data page corresponding to the physical address as the target data page that is the operation object of the transaction engine.
14. A database encryption and decryption device, characterized in that, The device includes: A determination unit, configured to, in response to receiving a data processing request, determine a target data page that is the operation object of the transaction engine based on the data to be processed targeted by the data processing request; A generating unit, configured to generate a target key based on the address information of the target data page, the data at a target position in the target data page, and an initialization key; An encryption / decryption unit, configured to, through the transaction engine, perform an encryption operation and / or a decryption operation on the target data page using the target key when processing the target data page based on the data processing request.
15. A computing device, characterized in that, The computing device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the operations performed by the database encryption / decryption method according to any one of claims 1 to 13 are implemented.
16. A computer-readable storage medium, characterized in that, A program is stored on the computer-readable storage medium, and when the program is executed by the processor, the operations performed by the database encryption / decryption method according to any one of claims 1 to 13 are implemented.