Database bastion resource management and control method based on HTML5 technology
Through the HTML5-based database bastion resource management method, the compatibility and compatibility problems of bastion machines in the Innovative Innovation operating system are solved, efficient and secure database management without client dependencies is achieved, multiple databases are supported, and fine-grained audits and dynamic strategies are provided, which improves user experience and system stability.
Patent Information
- Application Number
- CN202510645311.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-15
AI Technical Summary
The existing bastion machine has poor compatibility on the Xinchuang operating system, making it difficult to support new domestic databases, and the control strategy is insufficiently compatible with client tools, resulting in poor user experience and security issues.
The database bastion resource management and control method based on HTML5 technology is adopted. By building users, bastion machines and database network segments, dynamic interception of high-risk operations and sensitive data desensitization, combined with the decision analysis system for auditing and resource demand prediction, a loosely coupled network architecture and load balancing is achieved.
No client dependencies are required, which improves security and compatibility, supports multiple databases, provides fine-grained audits and dynamic policies, simplifies firewall deployment, and improves system stability and security.
Smart Images

Figure CN120493285A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of database fortress resource management and control, and specifically to a database fortress resource management and control method based on HTML5 technology. Background Art
[0002] Databases are the core infrastructure of the information age. Powerful data analysis capabilities empower businesses to make precise decisions and are the cornerstone of the digital economy. Bastion hosts are the core hub for database security operations and maintenance. Especially in highly compliant scenarios like government affairs and finance, bastion hosts provide a "least privilege + full traceability" protection system for databases. They are a critical line of defense for meeting security requirements and building a trusted data environment.
[0003] Currently, bastion hosts implement database security management through a built-in database management tool that controls the data flow between the database tool and the database. This architecture has the following insurmountable drawbacks:
[0004] 1. Client tools are difficult to be trusted.
[0005] Mainstream database management tools, including PLSQL, Navicat, and DBeaver, can only run on Windows operating systems running on the X86 architecture. Even with virtualization, they can barely run on some domestic X86 operating systems. However, these tools are very slow, providing a poor user experience and are difficult to run on trusted operating systems such as those from Loongson, Sunway, and ARM architectures.
[0006] 2. Guaranteeing compatibility between management and control policies and customers is difficult. Management tools primarily provide specific database management functions, while bastion hosts are required to provide management and control during the database management process. However, because the tools and bastion hosts are provided by completely different manufacturers and lack a standard compatibility handshake protocol, the primary compatibility work falls to the bastion host manufacturer. As a result, the bastion host is only compatible with some versions of some management tools, and the latest versions may cause management issues.
[0007] 3. New domestic databases are difficult to support. New-generation databases such as DAMO, Jincang, Alibaba OceanBase, and Huawei Gauss are developing rapidly. Many bastion hosts will take a long time to become compatible with these new databases, but this creates a huge conflict with the strong demand for their use. Summary of the Invention
[0008] To solve the above problems, the present invention proposes a database fortress resource management and control method based on HTML5 technology, including:
[0009] Construct user network segments, bastion network segments, and database network segments. The database network segment and user network segment are isolated by the bastion network segment. Users can only access the bastion network segment and access the database network segment through the bastion network segment.
[0010] Set control strategies, dynamically intercept high-risk operations, and dynamically desensitize sensitive data;
[0011] Conduct audit analysis through the decision analysis system to analyze the popularity database and make resource demand forecasts.
[0012] In a preferred embodiment, the bastion host network segment deploys a load balancer and multiple hosts, and the status of each host is automatically synchronized with each other; the user first accesses the load balancer, and the load balancer forwards the request to one of the normally operating hosts.
[0013] In a preferred embodiment, the user network segment, bastion host network segment, and database network segment are loosely coupled; the https protocol is used between the client browser of the user network segment and the load balancer of the bastion host network segment; the http protocol is used between the load balancer and the host; and the JDBC protocol is used between the host and the resources of the database network segment.
[0014] In a preferred embodiment, the popularity database is analyzed, the relationship between the popularity database and the business peak is mined, and the linear correlation value r between the two is measured:
[0015]
[0016] Among them, x i is the amount of database operations on the ith database, y i is the i-th business peak indicator, n is the total number of databases, is the corresponding mean.
[0017] In a preferred embodiment, the specific method for resource demand prediction is as follows:
[0018] Build a time series model and calculate the database resource indicator Y at the current time t t :
[0019]
[0020] Where P is the total time period in the past, ε t is white noise; is the database resource index Y for the Ith time period from time t t-I For the database resource index Y at the current time t t The influence weight of θ I is the moving average coefficient of the Ith time period from time t, ε t-Iis the white noise of the I-th time period from time t;
[0021] The database resource indicators at multiple time points t are constructed into time series data and input into the LSTM network. Its memory characteristics are used to learn long-term dependencies and output future resource demand forecasts.
[0022] In a preferred embodiment, whether the operation volume surges is determined based on the future resource demand forecast value, a threshold is set, and when the number of concurrent operation requests exceeds the threshold, a new database process is triggered.
[0023] In a preferred embodiment, a control strategy is set to dynamically intercept high-risk operations, specifically including:
[0024] High-risk operation control strategies are pre-defined at the platform level, and preset statements are clearly marked as high-risk instructions that are prohibited from execution. When operation and maintenance personnel perform database operations, the platform uses the SQL parsing engine to analyze the statements in real time to determine whether they contain high-risk instructions. Once a high-risk instruction is detected, the platform immediately triggers a dynamic interception mechanism to prevent the high-risk instruction from continuing to be transmitted, ensuring that it cannot reach the database for execution.
[0025] In a preferred embodiment, when operation and maintenance personnel query a table containing sensitive data, the data in the table obtained by them is dynamically desensitized.
[0026] In a preferred embodiment, the use of the database by operators is analyzed to optimize and adjust the database configuration strategy, including: statement dimension, object dimension, and access dimension.
[0027] Compared with the prior art, the present invention has the following beneficial technical effects:
[0028] 1. No client dependency, eliminating the workload of client management and maintenance, and also avoiding Trojans and viruses introduced by the client.
[0029] 2. Access between the client and the bastion host is done through HTTPS, which only requires opening one port. Previously, the bastion host needed to open multiple ports, which greatly simplifies the firewall deployment strategy and improves security.
[0030] 3. Support more personalized and scenario-specific management and control strategies, such as dynamic desensitization, dynamic interception, etc.
[0031] 4. More fine-grained audit analysis can audit the specific statements executed by specific operators. Traditional bastion hosts can only audit the execution statements of database users and cannot locate specific individuals.
[0032] 5. Supports load balancing and fault tolerance, making it easier to scale horizontally in terms of performance and more reliable in terms of stability. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 This is a scenario architecture diagram of the solution of the present invention;
[0034] Figure 2 A schematic diagram of the access entrance provided for operation and maintenance personnel of the present invention;
[0035] Figure 3 A schematic diagram for dynamically intercepting unauthorized behavior of operation and maintenance personnel;
[0036] Figure 4 A schematic diagram for dynamically desensitizing sensitive data;
[0037] Figure 5 This is a schematic diagram of the process work order;
[0038] Figure 6 This is a schematic diagram of the personalized strategy configuration of the present invention;
[0039] Figure 7 Schematic diagram of the decision analysis system of the present invention;
[0040] Figure 8 This is a schematic diagram of the logical architecture of the solution of the present invention;
[0041] Figure 9 This is a schematic diagram of the present invention being compatible with multiple databases through a web page mode;
[0042] Figure 10 FIG. 2 is a schematic diagram of the physical structure of the present invention. DETAILED DESCRIPTION
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0044] Example 1
[0045] Application Scenario
[0046] like Figure 1 The figure shows the scenario architecture diagram of the solution of the present invention.
[0047] Among various heterogeneous databases, including: Redis, Dameng Database, MySQL, SQL Server, PostgreSQL, Hangao Database, Renmin University of China Golden Warehouse, Oracle, DB2, etc., the present invention can connect to databases of various brands and types.
[0048] Before operation: Provides hierarchical permission management to control data definition language (DDL) and data manipulation language (DML); supports backup and recovery operations; has monitoring functions and process management, etc. to ensure preparation and standardization before database operations.
[0049] During operation: data import and export within a limited time and quantity can be realized; data can be filtered and desensitized; operations such as script publishing are supported to ensure data security and standardized execution during the operation.
[0050] Post-operation: Provides auditing functionality for operational analysis and supports operations such as rollback for post-operation tracing and error correction.
[0051] Operational application support: The underlying layer provides data connection services, database log services, heterogeneous migration adapters, audit analysis services, backup / recovery / rollback services, data desensitization services, etc., to support the implementation of upper-layer operational functions.
[0052] Multiple usage scenarios: covering different work scenarios such as development, management, and operation and maintenance, meeting the needs of different personnel in database-related work.
[0053] One access method: Through HTML5 technology, operations can be performed on browsers (such as Google Chrome and Microsoft Edge browsers). It also supports direct access and use by developers, operations and maintenance personnel, and management personnel to achieve convenient database management operations.
[0054] The present invention can be provided to development, operation and maintenance, and management departments for use.
[0055] 1. Development Department (Operation Development Library):
[0056] Provide developers with access to meet daily operation needs.
[0057] Provide services for generating data for import into development libraries and desensitize sensitive data.
[0058] 2. Operation and maintenance department (operation generation library):
[0059] like Figure 2 As shown, it provides an access point for operation and maintenance personnel to meet daily operation needs. Operation and maintenance personnel mainly operate the database object tree and SQL run window to execute SQL statements. Both the object tree and the SQL query window can realize the corresponding functions in the browser through HTML5.
[0060] Dynamically intercept unauthorized actions of operation and maintenance personnel to prevent misoperation or malicious tampering of data. Figure 3As shown, when the operation and maintenance personnel intentionally or unintentionally execute the truncate statement (the truncate statement will instantly clear all data in the table), in the traditional bastion host mode, the truncate statement will cause a data accident. However, in this solution, since the control policy is configured at the platform level, the control policy can dynamically intercept the high-risk operation. The high-risk operation is effectively intercepted at the platform level and cannot reach the database level.
[0061] In a preferred embodiment, the management and control strategy dynamically intercepts the high-risk operation and specifically includes:
[0062] (1) Policy configuration: Predefine high-risk operation control policies at the platform level, and explicitly mark truncate statements as high-risk instructions that must be prohibited from execution. Through a visual interface, operations and maintenance personnel can flexibly set policy parameters, such as the scope of effectiveness (specific databases, tables, or users), interception methods (real-time blocking or early warning), etc., to form targeted protection rules.
[0063] (2) Real-time SQL statement analysis: When operations personnel perform database operations, the platform uses the SQL parsing engine to analyze the statements in real time. Using lexical analysis and syntax analysis techniques, it accurately identifies the statement type and operation object, and determines whether it contains high-risk instructions such as truncate.
[0064] (3) Dynamically intercept high-risk operations: Once a truncate statement is detected, the platform immediately triggers a dynamic interception mechanism. Through intervention at the network layer or protocol layer, the statement is prevented from continuing to be transmitted, ensuring that it cannot reach the database for execution. At the same time, the reason for the interception (such as "the operation violates the high-risk instruction control policy") is fed back to the operation and maintenance personnel to guide compliance operations.
[0065] (4) Audit and Record: Detailed log records are kept for intercepted truncate operations, including operation time, executing user, statement content, interception strategy, and other information. This supports post-audit tracing, facilitating analysis of operation intent and troubleshooting of potential risks, while also providing data basis for optimizing management and control strategies.
[0066] Dynamically desensitize sensitive data to prevent leakage of sensitive data information.
[0067] like Figure 4 As shown, when operations personnel query a table containing sensitive data, the data they obtain is not the actual data in the database, but rather a data that has been dynamically desensitized. This data, which has been dynamically desensitized, has no commercial value, thus preventing operations personnel from obtaining sensitive data through their work.
[0068] Support process work orders and dynamically increase the rights of operation and maintenance personnel in special scenarios, such as Figure 5As shown, if operations personnel truly need to run SQL to modify data and obtain sensitive information, they should apply for and obtain approval, and the platform should be able to support their various unauthorized needs. The unauthorized process can be audited by management.
[0069] 3. Management department (monitoring and auditing database usage):
[0070] Personalized strategy settings are provided for development and operation personnel before, during, and after operations. Figure 6 As shown, the administrator can configure personalized policies for a database operated by a certain person, including statement dimension, object dimension, and access dimension.
[0071] Audit the behavior of development and operation and maintenance personnel, such as Figure 6 As shown, managers can audit a maintenance person to conduct a comprehensive audit:
[0072] a. Which specific person? (e.g. Figure 6 db_user user)
[0073] b. When was the operation performed?
[0074] c. What statement was executed?
[0075] d. Is the statement executed successfully?
[0076] e. How much time did the statement take?
[0077] Analyze database usage and optimize database configuration strategies, such as Figure 7 Audit data can be sent to decision analysis systems for more complex analysis.
[0078] Preferably, you can analyze the heat database to see whether the response speed is normal, whether the hardware needs to be upgraded if the performance is too low, etc. The specific method is as follows:
[0079] A. Analyze database usage
[0080] Use the database's built-in tools (such as MySQL's slow query log and performance mode) to collect real-time indicators such as response time, throughput, and number of concurrent connections to locate SQL statements that execute slowly or are frequently accessed, thereby determining "hot databases" (frequently accessed database tables).
[0081] Monitor CPU, memory, disk I / O, and network usage, analyze resource bottlenecks through Performance Schema, and assess whether response speed is normal. For example, set a query time threshold, and if it exceeds the threshold, it will be considered an abnormality.
[0082] B. Optimize and adjust database configuration strategy
[0083] Adjust configurations based on resource analysis results. For example, in MySQL, increase buffer_pool_size to improve memory cache efficiency and optimize innodb_flush_log_at_trx_commit to reduce disk write pressure.
[0084] Add joint indexes to high-frequency query statements to avoid full table scans; optimize inefficient SQL and replace subqueries with JOINs to reduce database computing overhead.
[0085] If high CPU usage and disk I / O bottlenecks persist, evaluate hardware upgrades, including replacing SSDs, increasing memory, or upgrading the CPU to improve database processing performance.
[0086] C. Audit data
[0087] Enable the database audit function to record all operations (user, time, SQL statement), especially monitoring high-risk operations (such as truncate and drop).
[0088] Regularly review operation logs to check for unauthorized access, unauthorized changes, and other behaviors to ensure that operations comply with security policies (such as intercepting unapproved truncate statements).
[0089] Summarize operational records and compliance results into reports to facilitate problem tracing and optimize audit strategies.
[0090] D. Data transmission and complex analysis
[0091] Collected performance data and audit logs are organized into a structured format and transmitted to the decision-making analysis system via APIs or data pipelines. Leveraging the system's machine learning and correlation analysis capabilities, we deeply explore the relationship between popular databases and business peaks, predict resource requirements, and assist in developing more precise optimization strategies. We dynamically adjust the read-write split architecture and predict hardware upgrade opportunities, achieving continuous database performance optimization and risk management.
[0092] In a preferred embodiment, indicators such as the number of queries, response time, and number of concurrent connections of the popularity database are collected, and business peak identification data such as the number of visits to the business system and the number of transactions are obtained at the same time, and aligned by time granularity (such as hours).
[0093] Specifically, normalization is used to eliminate the dimensionality effect and obtain normalized data; the relationship between the popularity database and business peak is explored to measure the linear correlation value r between the two:
[0094]
[0095] Among them, x i is the amount of database operations on the ith database, y iis the i-th business peak indicator, n is the total number of databases, The closer the absolute value of r is to 1, the stronger the correlation is.
[0096] The specific method of resource demand forecasting is as follows:
[0097] Build a time series model, train the model through historical data, and calculate the database resource indicator Y at the current time t t :
[0098]
[0099] Where P is the total time period in the past, ε t is white noise; is the database resource index Y for the Ith time period from time t t-I For the database resource index Y at the current time t t The influence weight of θ I is the moving average coefficient of the Ith time period from time t, ε t-I is the white noise of the Ith time period from time t. Database resource indicators include CPU usage and memory usage.
[0100] The database resource indicators at multiple moments t are constructed into time series data and input into the LSTM network. Its memory characteristics are used to learn long-term dependencies, output future resource demand forecasts, and guide dynamic adjustments.
[0101] According to the predicted value of future resource demand, it is determined whether the operation volume has increased sharply, and a threshold is set. When the number of concurrent operation requests exceeds the threshold, a new database process is triggered.
[0102] Example 2
[0103] Solution logical architecture
[0104] like Figure 8 FIG. 1 is a schematic diagram of the logical architecture of the solution of the present invention, which includes: a system layer, a platform layer and a resource layer.
[0105] System layer: Provides a unified entrance for outsourced personnel, application operation and maintenance personnel, developers, DBAs, etc., including: Web client, Web terminal, authentication center, management and control center, process center, and log center to achieve centralized access and management.
[0106] Platform layer:
[0107] Security module: Through hierarchical permissions, intelligent desensitization, command control, mode authorization, anti-leakage, watermark, audit and other functions, it ensures the security of data interaction and prevents unauthorized access and data leakage.
[0108] Efficiency module: provides functions such as script submission, scheduled tasks, script sharing, command history, etc., optimizes operation processes, and improves database management efficiency.
[0109] Resource layer: The data access layer integrates various heterogeneous database resources such as transactions, customers, finance, production, and testing to achieve unified management and access.
[0110] Platform goal: From an organizational perspective, comprehensively manage the interactions between internal and external personnel and the database to reduce risks and improve efficiency.
[0111] Core Competencies:
[0112] End-to-end control: Achieve complete end-to-end control and eliminate management blind spots.
[0113] Pure B / S architecture: covers multiple databases through a single interface, with functions comparable to C / S clients, and is easy to use across platforms.
[0114] Independent permissions: Set permissions independently from the database, support mode selection, and provide full coverage with one authorization, which is highly flexible.
[0115] Script management: supports script review and sharing, standardizes script operations, and improves collaboration efficiency.
[0116] Fine-grained security policy: Accurately parses SQL syntax and manages SQL and scripts, rather than simply identifying keywords, to enhance security.
[0117] Intelligent desensitization: No need to create database copies or triggers, etc., supports custom desensitization rules, and effectively protects sensitive data.
[0118] The logical architecture has three major characteristics.
[0119] 1. No dependence on the client.
[0120] The solution has a unified entry method, which only requires the use of a browser, which is a component of any operating system.
[0121] Compared with the traditional bastion host solution, it greatly reduces the difficulty of client deployment and eliminates stubborn problems such as database client piracy and built-in Trojans.
[0122] 2. Efficiency and safety coexist.
[0123] The built-in database operation functions can meet the daily needs of the using departments.
[0124] The built-in security policy can effectively prevent accidental deletion of the database, malicious tampering of data, and leakage of data information.
[0125] 3. Compatible with heterogeneous databases.
[0126] The difference from network access to database access is completed through the http+jdbc standard, such as Figure 9 As shown in the figure, through practice, through the browser HTTP + JDBC standard, it has been able to be compatible with more than 20 databases through web mode, including all mainstream databases at home and abroad such as: DAMO, Jincang, Oracle, MySQL, DB2, etc.
[0127] The HTTP standard is used to unify the access protocol from users to the database bastion host. As shown in the platform screenshot, all database office staff (including those working from home) do not need to install any additional programs on their computers. They only need to open the browser and enter the address in the browser to successfully access the server.
[0128] Example 3
[0129] Solution physical architecture
[0130] like Figure 10 FIG. 1 is a schematic diagram of the physical structure of the present invention.
[0131] The user and database network segments are physically isolated, ensuring security. The user network segment is the same as the browser's network segment, and the database and user network segments are separated by the bastion host network segment. Therefore, users can only access the bastion host network segment, and then access the database network segment through the bastion host network segment. It is absolutely impossible to directly access the database network segment from the user network segment because the two network segments are physically isolated.
[0132] The bastion host network segment supports multi-active nodes, which can improve the performance and overall stability of the solution. The present invention deploys a load balancer + multi-host architecture in the bastion host network segment, and the status of each host is automatically synchronized with each other. User access first accesses the load balancer, which forwards the request to one of the normally operating hosts. Even if a host fails, it will not affect customer use. This multi-active architecture has higher performance and no single point of failure of the running host.
[0133] The user network segment, bastion host network segment, and database network segment are loosely coupled, eliminating the need for any one network segment to perform customized configuration for the others (unimpeded network connectivity between the three networks satisfies deployment requirements). HTTPS is used between the client browser and the load balancer. This secure HTTP protocol prevents hackers from eavesdropping on the connection between the client and the load balancer. HTTP is used between the load balancer and the host because the bastion host network segment is a strictly controlled production network segment, making it difficult for external hackers to eavesdrop, making HTTP more efficient. The JDBC protocol is used between the platform host and database resources, offering optimal compatibility with various databases. According to the JDBC standard, the network layer uses the TCP / IP communication protocol.
[0134] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. The embodiments should therefore be considered illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be encompassed therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.
Claims
1. A database fortress resource management and control method based on HTML5 technology, characterized in that: include: Construct user network segments, bastion network segments, and database network segments. The database network segment and user network segment are isolated by the bastion network segment. Users can only access the bastion network segment and access the database network segment through the bastion network segment. Set control strategies, dynamically intercept high-risk operations, and dynamically desensitize sensitive data; Conduct audit analysis through the decision analysis system to analyze the popularity database and make resource demand forecasts.
2. The database fortress resource management and control method based on HTML5 technology according to claim 1 is characterized in that: The bastion host network segment deploys a load balancer and multiple hosts, and the status of each host is automatically synchronized with each other; the user first accesses the load balancer, and the load balancer forwards the request to one of the normally operating hosts.
3. The database fortress resource management and control method based on HTML5 technology according to claim 2 is characterized in that: The user network segment, bastion network segment, and database network segment are loosely coupled; the https protocol is used between the client browser of the user network segment and the load balancer of the bastion network segment; the http protocol is used between the load balancer and the host; and the JDBC protocol is used between the host and the resources of the database network segment.
4. The database fortress resource management and control method based on HTML5 technology according to claim 1 is characterized in that: Analyze the popularity database, explore the relationship between the popularity database and business peaks, and measure the linear correlation value r between the two: Among them, x i is the amount of database operations on the ith database, y i is the i-th business peak indicator, n is the total number of databases, is the corresponding mean.
5. The database fortress resource management and control method based on HTML5 technology according to claim 1 is characterized in that: The specific method of resource demand forecasting is as follows: Build a time series model and calculate the database resource indicator Y at the current time t t : Where P is the total time period in the past, ε t is white noise; is the database resource index Y for the Ith time period from time t t-I For the database resource index Y at the current time t t The influence weight of θ I is the moving average coefficient of the Ith time period from time t, ε t-I is the white noise of the I-th time period from time t; The database resource indicators at multiple time points t are constructed into time series data and input into the LSTM network. Its memory characteristics are used to learn long-term dependencies and output future resource demand forecasts.
6. The database fortress resource management and control method based on HTML5 technology according to claim 5 is characterized in that: According to the predicted value of future resource demand, it is determined whether the operation volume has increased sharply, and a threshold is set. When the number of concurrent operation requests exceeds the threshold, a new database process is triggered.
7. The database fortress resource management and control method based on HTML5 technology according to claim 1 is characterized in that: Set control strategies to dynamically intercept high-risk operations, including: High-risk operation control strategies are pre-defined at the platform level, and preset statements are clearly marked as high-risk instructions that are prohibited from execution. When operation and maintenance personnel perform database operations, the platform uses the SQL parsing engine to analyze the statements in real time to determine whether they contain high-risk instructions. Once a high-risk instruction is detected, the platform immediately triggers a dynamic interception mechanism to prevent the high-risk instruction from continuing to be transmitted, ensuring that it cannot reach the database for execution.
8. The database fortress resource management and control method based on HTML5 technology according to claim 1 is characterized in that: When operation and maintenance personnel query tables containing sensitive data, the data in the tables they obtain are dynamically desensitized.
9. The database fortress resource management and control method based on HTML5 technology according to claim 1 is characterized in that: Analyze operators' use of the database and optimize and adjust database configuration strategies, including statement dimension, object dimension, and access dimension.
Citation Information
Patent Citations
Database auditing method based on bridged mode
CN103475727A
A system and a method for remote access consolidation and centralize monitoring of a dispatch data network
CN108984379A
Method for implementing automatic password change having fault tolerance mechanism for cloud host and cloud bastion host
WO2023050110A1
Method and system for access management
WO2024198734A1