Plug-in database encryption control method and device

By introducing a plug-in-based encryption control method into the distributed database, the problem of strong coupling between the database and cryptographic devices is solved, enabling independent development and maintenance of plug-ins, ensuring high availability and flexibility of the database, supporting dynamic encryption strategy switching, and reducing maintenance costs.

CN121030769APending Publication Date: 2025-11-28上海沄熹科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511121411.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

Existing distributed databases are tightly coupled with cryptographic devices, which means that they cannot provide services normally when nodes fail, affecting high availability. Furthermore, when replacing cryptographic devices, the database needs to be re-adapted, affecting flexibility and scalability.

Method used

The encryption control method adopts a plug-in approach. By deploying encryption plug-ins on the database server, configuring encryption control policies, and having the plug-in management system download, install, and update the plug-ins, encryption, decryption, signing, signature verification, and hash calculation are achieved. Administrators can freely configure policies, the plug-ins are decoupled from the database, and dynamic switching of encryption algorithms is supported.

Benefits of technology

It decouples the database from cryptographic devices, allows for independent development and maintenance of plugins, enables rapid problem fixing, reduces maintenance costs, supports business expansion, and ensures high availability and flexibility of the database.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121030769A_ABST
    Figure CN121030769A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of database security, and particularly provides a plug-in database encryption control method and device, and the method comprises the following steps: S1, deploying an encryption plug-in on a database server; s2, configuring an encryption control strategy on the database server; s3, executing the SQL statement by the user; and S4, in the database system service operation process, the administrator user modifies the encryption control strategy. Compared with the prior art, safer and more reliable database access and operation can be realized, and the integrity and confidentiality of data are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of database security, and specifically provides a plug-in database encryption control method and device. BACKGROUND

[0002] The existing distributed database implements encryption and decryption functions, and needs to be adapted internally to control password cards, password machines and keys to perform encryption and decryption functions. The functions of the database and the encryption and decryption functions of the password device are strongly coupled. When different brands of password devices are replaced, the database needs to be re-adapted. The flexibility of the distributed database is therefore limited.

[0003] The distributed database also has high availability features, and can continue to provide services when a node fails, ensuring high availability of the system. If the password device connected to the node fails, the strong coupling between the password device and the database function will cause the node to fail to provide normal services. The high availability of the distributed database is therefore limited by the reliability of the password device.

[0004] Therefore, it is necessary to control the password device to perform encryption and decryption in the form of a plug-in to achieve decoupling with the database. SUMMARY

[0005] The present application is aimed at the deficiencies of the prior art, and provides a practical plug-in database encryption control method.

[0006] The further technical task of the present application is to provide a plug-in database encryption control device which is reasonable in design and safe and suitable for use.

[0007] The technical solution adopted by the present application to solve the technical problems is as follows:

[0008] A plug-in database encryption control method has the following steps:

[0009] S1, deploying an encryption plug-in on a database server;

[0010] S2, configuring an encryption control strategy on the database server;

[0011] S3, a user executes an SQL statement;

[0012] S4, an administrator user modifies the encryption control strategy during the running process of the database system service.

[0013] Further, in step S1, the administrator uses a database plug-in management system to deploy the encryption plug-in, and downloads, installs and updates the plug-in through the database plug-in management system, or specifies the plug-in to be loaded through a configuration file.

[0014] Further, the database plug-in management system maintains and manages the plug-in, and an administrator manages and controls the running state of the plug-in through the database plug-in management system.

[0015] Further, in step S2, the encryption plug-in loads the database encryption information and takes over encryption, decryption, signature, signature verification and hash calculation, and an administrator user freely configures an encryption control strategy as needed.

[0016] Further, the administrator further refines the encryption control, and after the configuration is completed, the encryption plug-in will start to take over the encryption and decryption algorithm functions of the entire database.

[0017] Further, in step S3, in the process that a user executes an SQL statement, the encryption plug-in reads the encryption information in the database and performs encryption and decryption algorithms according to the pre-configured encryption control strategy; if the encryption and decryption algorithms are successful, the database system continues subsequent operations; if the encryption and decryption algorithms fail, error information is returned to the user.

[0018] Further, in step S4, in the process that the database system provides service running, an administrator user modifies the encryption control strategy, and after the modification is completed, the encryption plug-in will temporarily use the old and new encryption control strategies to perform encryption operations on data; for the operations being executed, the original encryption control strategy is used, and for subsequent operations, the new encryption control strategy is used; after all the operations being executed are completed, the old encryption control strategy is invalidated, and the new encryption control strategy is used.

[0019] A plug-in database encryption control device, comprising at least one memory and at least one processor.

[0020] The at least one memory is used to store a machine readable program.

[0021] The at least one processor is used to call the machine readable program and execute a plug-in database encryption control method.

[0022] Compared with the prior art, the plug-in database encryption control method and device have the following outstanding beneficial effects:

[0023] The database of the application is not directly connected with a password device, but selects different encryption plug-ins according to needs, so that the influence of password device change on the database is avoided.

[0024] The password device is adapted to the plug-in, and the function of each plug-in can be independently developed, maintained, enabled, deployed and run, and the plug-ins are independent of each other and do not affect each other.

[0025] Each plug-in only needs to adapt to the corresponding cryptographic device, the plug-in size is small, and problems can be quickly repaired and new functions can be quickly released, thereby reducing maintenance and repair costs.

[0026] The plug-in can be extended according to business needs to meet the needs of traffic and performance.

[0027] When the cryptographic device has an abnormal state, the corresponding plug-in can be disabled, without affecting the database. BRIEF DESCRIPTION OF DRAWINGS

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings described below are some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.

[0029] Figure 1 It is a flowchart of a plug-in database encryption control method;

[0030] Figure 2 It is an architecture diagram of a plug-in database encryption control method. DETAILED DESCRIPTION

[0031] In order to make the person skilled in the art better understand the scheme of the present application, the present application will be further described in detail below in combination with specific embodiments. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0032] The following is a best embodiment:

[0033] Embodiment 1:

[0034] In the plug-in database encryption control method of the present embodiment, the encryption and decryption functions, signature verification, and hash calculation functions in the database encryption function module are encapsulated as plug-ins providing a unified interface. During the running process of the database, the plug-ins can be installed, configured, run, and unloaded. When the cryptographic device is replaced, the database can disassemble the original plug-in and reinstall the new corresponding plug-in, without the need for re-adaptation. When the cryptographic device has a problem, the database can disable or uninstall the plug-in, without affecting the normal operation of the database.

[0035] The specific implementation includes:

[0036] S1, deploying an encryption plug-in on a database server;

[0037] The administrator uses the database plug-in management system to deploy the encryption plug-in, and downloads, installs and updates the plug-in through the database plug-in management system, or specifies the plug-in to be loaded through a configuration file.

[0038] The database plug-in management system maintains and manages the plug-in, and the administrator manages and controls the running state of the plug-in through the database plug-in management system.

[0039] S2, configuring an encryption control policy on the database server;

[0040] The encryption plug-in loads the database encryption information and takes over the functions of encryption, decryption, signature, signature verification, hash calculation, etc. The administrator user can freely configure the encryption control policy according to needs, including but not limited to whether to specify the use of an externally specified key, whether to specify an encryption algorithm mode, whether to enable a specified encryption algorithm, whether to enable a specified encryption device, etc.

[0041] The administrator further refines the encryption control, and after the configuration is completed, the encryption plug-in will be formally started and take over the encryption and decryption algorithm functions of the entire database.

[0042] S3, the user executes an SQL statement;

[0043] During the execution of the SQL statement by the user, the encryption plug-in reads the encryption information in the database and performs the encryption and decryption algorithm according to the pre-configured encryption control policy. If the encryption and decryption algorithm is successful, the database system continues the subsequent operation. If the encryption and decryption algorithm fails, an error message is returned to the user.

[0044] S4, the administrator user modifies the encryption control policy during the running of the database system service;

[0045] During the running of the database system service, the administrator user modifies the encryption control policy. After the modification is completed, the encryption plug-in will temporarily use the old and new encryption control policies to perform encryption operations on the data. For the operations that are being executed, the original encryption control policy will be used, and for the subsequent operations, the new encryption control policy will be used. After all the operations in execution are completed, the old encryption control policy will be invalidated, and the new encryption control policy will be used.

[0046] Embodiment 2:

[0047] As shown in FIG. 1, Figure 2 there are several parts as follows:

[0048] Cryptographic device: including cryptographic machines, cryptographic cards, ukeys, etc. Different versions of cryptographic devices from different manufacturers have different usage methods. By separately adapting the cryptographic device through the plug-in, the influence of these different devices can be isolated.

[0049] Encryption plug-in: provides a unified encryption algorithm interface, including encryption and decryption, signature verification, hash calculation, etc. Different plug-ins are adapted to different cryptographic devices. By replacing the plug-in, different cryptographic devices can be replaced. Disabling or uninstalling the plug-in can isolate the abnormal cryptographic device. The plug-in can be developed and maintained separately and can be deployed in different database systems.

[0050] Database: The distributed database itself does not need to adapt to the cryptographic machine, and the encryption algorithm can be implemented by calling the plug-in interface. The functions of the database itself and the cryptographic device are decoupled. The version change of the database does not affect the cryptographic device. The database calls the cryptographic device through the plug-in, and the change and replacement of the cryptographic device will not affect the function of the database.

[0051] Embodiment 3:

[0052] As shown in Figure 1 , the specific implementation steps of the method are as follows:

[0053] S1, deploying an encryption plug-in on a database server:

[0054] In this step, the administrator needs to use the database plug-in management system to deploy the encryption plug-in to replace the database encryption function. The administrator can download, install, update, and uninstall the plug-in through the database plug-in management system, or specify the plug-in to be loaded through a configuration file or other means. The database plug-in management system can also maintain and manage the plug-in, including version management, starting and stopping, etc. The administrator can manage and control the running state of the plug-in through the database plug-in management system to ensure the correctness and stability of the plug-in.

[0055] S2, configuring an encryption control strategy on the database server;

[0056] The encryption plug-in will load the database encryption information and take over the encryption function. The administrator user can freely configure the encryption control strategy according to needs, including but not limited to whether to specify the use of an external specified key, whether to specify the encryption algorithm mode, whether to enable the specified encryption algorithm, whether to enable the specified encryption device, etc. In addition, the administrator user can further refine the encryption control, such as whether to enable consistency checking. After setting this option, the data will calculate the hash value before encryption, and after decrypting the encrypted data, the hash value will be recalculated and compared with the initial hash value to check whether the consistency is met. If the consistency is not met, an error of consistency check failure will be reported, and if it is passed, the subsequent operation will be performed. After the administrator user completes the configuration, the encryption plug-in will be officially started and take over the entire database encryption function.

[0057] S3, the user executes an SQL statement;

[0058] During the execution of the SQL statement by the user, the encryption plug-in reads the encryption information in the database and performs encryption algorithm operation according to the pre-configured encryption control policy. If the encryption algorithm passes, the database system continues the subsequent operation; if the encryption algorithm fails, an error message is returned to the user.

[0059] S4、During the running of the database system service, the administrator user modifies the encryption control policy;

[0060] During the running of the database system service, the administrator user modifies the encryption control policy, and after the modification is completed, the encryption plug-in temporarily uses the old and new encryption control policies to perform encryption operation on the data; for the operation being executed, the original encryption control policy is used, and for the subsequent operation, the new encryption control policy is used; after all the operations in execution are completed, the old encryption control policy is invalidated, and the new encryption control policy is used.

[0061] The method of dynamically switching and updating the encryption control policy can guarantee the flexibility and scalability of the database system, and at the same time, ensure the security and integrity of the data.

[0062] Embodiment 4:

[0063] A plug-in database encryption control device, comprising: at least one memory and at least one processor;

[0064] The at least one memory is configured to store a machine readable program.

[0065] The at least one processor is configured to invoke the machine readable program to execute a plug-in database encryption control method.

[0066] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), ready-to-program gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor can be a microprocessor, or can be any conventional processor.

[0067] The memory can be used to store computer programs and / or modules, and the processor realizes various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and calling data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required by a function, etc.; and the data storage area can store data created according to use of the terminal, etc. In addition, the memory can also include a high-speed random access memory, and can also include a non-volatile memory, for example, a hard disk, a memory, a plug-in hard disk, a secure digital (SD) card, a flash card, at least one disk storage period, a flash memory device, or other volatile solid-state memory devices.

[0068] The above specific embodiments are only specific cases of the present application, and the patent protection scope of the present application includes but is not limited to the above specific embodiments. Any technical solution meeting the above specific embodiments of the present application and any appropriate changes or replacements made by those skilled in the art to the technical solution shall fall within the patent protection scope of the present application.

[0069] Although the embodiments of the present application have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to the embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A plug-in database encryption control method, characterized in that, It has the following steps: S1. Deploy the encryption plugin on the database server; S2. Configure encryption control policies on the database server; S3, The user executes an SQL statement; S4. During the operation of the database system service, the administrator user modifies the encryption control policy.

2. The plug-in database encryption control method according to claim 1, characterized in that, In step S1, the administrator uses the database plugin management system to deploy encryption plugins, download, install, and update plugins through the database plugin management system, or specify the plugins to be loaded through configuration files.

3. The plug-in database encryption control method according to claim 2, characterized in that, The database plugin management system maintains and manages the plugins, and the administrator manages and controls the running status of the plugins through the database plugin management system.

4. The plug-in database encryption control method according to claim 3, characterized in that, In step S2, the encryption plugin will load the encrypted information from the database and take over encryption, decryption, signing, signature verification, and hash calculation. Administrators can freely configure encryption control policies as needed.

5. The plug-in database encryption control method according to claim 4, characterized in that, The administrator further refines the encryption control. After the configuration is completed, the encryption plugin will be officially launched and take over the encryption and decryption algorithm functions of the entire database.

6. The plug-in database encryption control method according to claim 5, characterized in that, In step S3, during the execution of the SQL statement by the user, the encryption plugin reads the encryption information in the database and performs encryption and decryption algorithms according to the pre-configured encryption control strategy. If the encryption and decryption algorithm succeeds, the database system continues the subsequent operations; if the encryption and decryption algorithm fails, it returns an error message to the user.

7. The plug-in database encryption control method according to claim 6, characterized in that, In step S4, during the service operation of the database system, the administrator user modifies the encryption control policy. After the modification is completed, the encryption plugin will temporarily use both the old and new encryption control policies to encrypt the data. For operations that are being executed, the original encryption control policy will be used, while subsequent operations will use the new encryption control policy. Once all operations are completed, the old encryption control policy will become invalid, and the new encryption control policy will be used.

8. A plug-in database encryption control device, characterized in that, include: At least one memory and at least one processor; The at least one memory is used to store a machine-readable program; The at least one processor is configured to invoke the machine-readable program to perform the method according to any one of claims 1 to 7.