Encryption Method, Device, Equipment and Storage Medium for Time-Series Database Storage Layer
By compensating and encrypting the data in the timing database storage layer, the problem of lack of encryption function in the timing database storage layer in the prior art is solved, and efficient data security protection is achieved.
Patent Information
- Application Number
- CN202111025554.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-02
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-09-02
AI Technical Summary
The existing timing database storage layer lacks encryption functions and cannot effectively protect the sensitive data stored in it.
A time-series database storage layer encryption method is proposed. By compiling the encrypted data, compiling the data to be encrypted, compiling the data, and encrypting the compiling data using the encryption device to obtain the encrypted data, and finally replacing the encrypted data with the encrypted data.
Encrypting the data in the storage layer of the timing database is realized, improving data security and preventing data leakage and unauthorized access.
Smart Images

Figure CN113722737B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of database technology. Specifically, it relates to an encryption method, device, equipment, and storage medium for the storage layer of a time series database. Background Art
[0002] A database is "a warehouse for organizing, storing, and managing data according to a data structure". It is a collection of a large amount of data that is long-term stored in a computer, organized, shareable, and uniformly managed. The storage space of a database is very large and can store millions, tens of millions, or even hundreds of millions of pieces of data. However, the database does not store data randomly but has certain rules, otherwise the query efficiency will be very low when querying data.
[0003] Common databases include relational databases, such as Mysql and SqlServer, and time series databases, also known as time series sequence databases. Time series databases are used to store data with time tags. For example, data in the power industry usually has a very high generation frequency. For example, multiple pieces of data can be obtained in one second.
[0004] The data in the storage layer of existing relational databases has an encryption function. However, currently, the data in the storage layer of time series databases has not been seen to have an encryption function. Summary of the Invention
[0005] Based on this, an encryption method, device, equipment, and storage medium for the storage layer of a time series database are proposed to encrypt the data in the storage layer of the time series database.
[0006] In a first aspect, an encryption method for the storage layer of a time series database is provided, including:
[0007] Performing padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database;
[0008] Encrypting the padded data to obtain the encrypted data corresponding to the data to be encrypted;
[0009] Replacing the data to be encrypted with the encrypted data corresponding to the data to be encrypted.
[0010] The above encryption method for the time series database storage layer performs padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database; encrypts the padded data to obtain the encrypted data corresponding to the data to be encrypted; and replaces the data to be encrypted with the encrypted data corresponding to the data to be encrypted. Since in the time series database, the payload data is stored in the Payload in the WAL log, or in the Data in the Block in the TSM file, therefore, encrypting the time series database storage layer means encrypting the payload data in the Payload or Data, thereby achieving the encryption of the time series database storage layer.
[0011] In one embodiment, the encrypting the padded data to obtain the encrypted data corresponding to the data to be encrypted includes:
[0012] The encryption interface sends the padded data to the encryption device according to the call process and data format of the encryption device;
[0013] Obtain the encrypted data corresponding to the data to be encrypted returned by the encryption device according to the padded data.
[0014] In one embodiment, the encrypting the padded data to obtain the encrypted data corresponding to the data to be encrypted includes:
[0015] Send the current public key corresponding to the time series database to the encryption device through the encryption interface;
[0016] Obtain the matching result of the current public key by the encryption device, where the matching result is the matching result of the current public key and the current private key in the encryption device;
[0017] If the matching result is a successful match, send the padded data and the ciphertext sub-key of the storage area where the padded data is located to the encryption device through the encryption interface;
[0018] Obtain the encrypted data corresponding to the data to be encrypted obtained by the encryption device encrypting the padded data according to the ciphertext sub-key.
[0019] In one embodiment, the encryption method for the time series database storage layer further includes:
[0020] When creating the storage area where the encrypted data is located, send a generation instruction to the encryption device. The generation instruction carries the current public key corresponding to the time series database, so that the encryption device uses the current public key corresponding to the time series database to encrypt the randomly generated sub-key to obtain the ciphertext sub-key of the storage area where the encrypted data is located;
[0021] Obtain the ciphertext sub-key of the storage area where the encrypted data is located returned by the encryption device.
[0022] In one embodiment, the encryption method of the time series database storage layer further includes:
[0023] Obtain the replacement public key corresponding to the time series database;
[0024] Send the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device;
[0025] Obtain the replacement sub-key returned by the encryption device according to the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located;
[0026] Use the replacement sub-key to replace the ciphertext sub-key of the storage area where the encrypted data is located.
[0027] In one embodiment, the encryption method of the time series database storage layer further includes:
[0028] Obtain the backup library public key;
[0029] Send the backup library public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device;
[0030] Obtain the backup library encrypted sub-key returned by the encryption device according to the backup library public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located;
[0031] Copy the backup library encrypted sub-key, the backup library public key, and the encrypted data to a backup directory for storage.
[0032] In one embodiment, after copying the backup library encrypted sub-key, the backup library public key, and the encrypted data to a backup directory for storage, it further includes:
[0033] Compare the backup library public key with the public key of the restore database;
[0034] If the public key of the backup database is the same as the public key of the restore database, the restore database obtains the encrypted data and the backup database encryption sub-key.
[0035] In a second aspect, an encryption device for a time series database storage layer is provided, including:
[0036] A padding module, configured to perform padding processing on the data to be encrypted to obtain padded data corresponding to the data to be encrypted, where the data to be encrypted is payload data stored in a WAL log or a TSM file in the time series database;
[0037] An encryption module, configured to encrypt the padded data to obtain encrypted data corresponding to the data to be encrypted;
[0038] A storage module, configured to replace the data to be encrypted with the encrypted data corresponding to the data to be encrypted.
[0039] In a third aspect, a computer device is provided, characterized by including a memory, a processor, and a computer program stored in the memory and executable on the processor, where when the processor executes the computer program, the steps of the encryption method for the time series database storage layer as described above are implemented.
[0040] In a fourth aspect, a computer-readable storage medium is provided, where computer program instructions are stored in the computer-readable storage medium, and when the computer program instructions are read and executed by a processor, the steps of the encryption method for the time series database storage layer as described above are executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0042] Figure 1 It is a schematic flowchart of the implementation process of the encryption method for the time series database storage layer in the embodiments of the present application;
[0043] Figure 2 It is a schematic structural diagram of log messages and Blocks in the time series database in the embodiments of the present application;
[0044] Figure 3 It is a schematic diagram of block encryption in the embodiments of the present application;
[0045] Figure 4It is a schematic diagram of the composition structure of the encryption device in the time series database storage layer of the present application embodiment;
[0046] Figure 5 It is an internal structure block diagram of a computer device in the present application embodiment. Detailed implementation manners
[0047] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0048] In one embodiment, an encryption method for the time series database storage layer is provided. The execution subject of the encryption method for the time series database storage layer described in the embodiments of the present invention is a computer device capable of implementing the encryption method for the time series database storage layer described in the embodiments of the present invention. The computer device may include, but is not limited to, a terminal and a server. Among them, the terminal includes a desktop terminal and a mobile terminal. The desktop terminal includes, but is not limited to, a desktop computer; the mobile terminal includes, but is not limited to, a mobile phone, a tablet, and a laptop computer. The server includes a high-performance computer and a high-performance computer cluster.
[0049] In one embodiment, as Figure 1 shown, an encryption method for the time series database storage layer is provided, including:
[0050] Step 100: Perform padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted. The data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database.
[0051] The time series database manages data in partitions according to time periods, that is, there are multiple storage areas in the time series database. The storage area can be called a shard. For example, taking 7 days as a time period, the data generated in 7 days is stored in one storage area. Each storage area corresponds to a underlying TSM storage engine. The TSM storage engine includes a WAL log and a TSM file. Among them, the WAL log is used for time series database failure recovery and master-slave synchronization. User requests are always first written into the WAL log and then submitted to the TSM file.
[0052] The data to be encrypted is payload data. For example, the data to be encrypted is 01010111111001. Specifically, the data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database. Among them, the payload data in the WAL log specifically refers to the data stored in the Payload in the log message, and the payload data in the TSM file specifically refers to the data stored in the Data in the Block. Since in the time series database, the payload data is stored in the Payload in the WAL log or in the Data in the Block in the TSM file, therefore, encrypting the storage layer of the time series database means encrypting the payload data in the Payload or Data.
[0053] The composition structures of the log messages in the WAL log and the Blocks in the TSM file can be as Figure 2 shown. For the log messages in the WAL log, Payload is used to store the payload data of the log message, CRC is used to store the check code of the payload data, and Size is used to store the data length of the payload data; for the TSM file, the TSM file consists of Blocks, and Blocks are composed of multiple Blocks. A Block is a block for storing data. A Block is composed of a CRC and a Data. Among them, Data is used to store the payload data, and CRC is used to store the check code of the payload data.
[0054] Padding processing is to ensure that the length of the padded data is an integer multiple of N, where N is the block length of the block cipher algorithm, usually 16 bytes.
[0055] Performing padding processing on the data to be encrypted includes: using a preset padding method to perform padding processing on the data to be encrypted to obtain padded data, where the data length of the padded data is equal to an integer multiple of N. For example, N is 8 bytes, and the length of the data to be encrypted is 26 bytes. Then, perform padding processing on the data to be encrypted. For example, the data length of the padded data after padding is 32 bytes. Among them, the preset padding method can be PKCS#7, that is, perform padding processing on the data to be encrypted according to PKCS#7.
[0056] Step 200, encrypt the padded data to obtain the encrypted data corresponding to the data to be encrypted.
[0057] Since the length of the padded data has reached K times of N, where K is a positive integer greater than or equal to 1, then send the padded data to the encryption program. The encryption program uses the encryption algorithm to encrypt each of the K pieces of data that make up the padded data to obtain the encrypted data. As Figure 3 shown.
[0058] Step 300, replace the data to be encrypted with the encrypted data corresponding to the data to be encrypted.
[0059] If the data to be encrypted is the data in the Payload stored in the log message, then delete the data to be encrypted in the Payload, and then store the encrypted data corresponding to the data to be encrypted in the Payload; if the data to be encrypted is the data in the Data stored in the Block, then delete the data to be encrypted in the Data, and then store the encrypted data corresponding to the data to be encrypted in the Data.
[0060] Since the data length of the encrypted data obtained after encryption will be greater than the data length of the data to be encrypted before encryption, therefore, if the data to be encrypted is the payload data in the Payload, the value stored in the Size also needs to be modified after encryption, that is, the value stored in the Size is set to the length of the encrypted data.
[0061] The above encryption method for the storage layer of the time series database performs padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database; encrypt the padded data to obtain the encrypted data corresponding to the data to be encrypted; replace the data to be encrypted with the encrypted data corresponding to the data to be encrypted. Since in the time series database, the payload data is stored in the Payload in the WAL log, or stored in the Data in the Block in the TSM file, therefore, encrypting the storage layer of the time series database is to encrypt the payload data in the Payload or Data, thus realizing the encryption of the storage layer of the time series database.
[0062] In one embodiment, before step 100 performs padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, it further includes: calculating the checksum of the data to be encrypted; if the data to be encrypted is the payload data in the Payload, then store the calculated checksum in the CRC in the log message of the WAL log; if the data to be encrypted is the payload data in the Data, then store the calculated checksum in the CRC in the Block in the TSM file.
[0063] The checksum is used to determine whether the decrypted data after decryption is accurate.
[0064] In the above embodiments, a checksum of the data to be encrypted is calculated before encryption. In this way, after the encrypted data is decrypted subsequently, the checksum can be used to verify the decrypted data, thereby ensuring that the decrypted data is the same as the data to be encrypted before encryption. Without a checksum, it would be very difficult to detect errors in any of the links of data encryption, data decryption, data transmission, and data storage.
[0065] In one embodiment, the step of encrypting the padded data in step 200 to obtain the encrypted data corresponding to the data to be encrypted includes: step 201 and step 202.
[0066] In step 201, the encryption interface sends the padded data to the encryption device according to the call process and data format of the encryption device.
[0067] The encryption interface is an interface for sending and receiving data between encryption devices; the encryption device is a device capable of encrypting the data to be encrypted (padded data) in the time series database. For example, the encryption device is a device corresponding to an encryption algorithm provider.
[0068] For example, the call process of a certain encryption device is as follows: first send the public key to the encryption device for the encryption device to confirm the public key; then send the ciphertext sub-key to the encryption device for the encryption device to decrypt the ciphertext sub-key using the private key; finally send the data to be encrypted to the encryption device for the encryption device to encrypt the data to be encrypted using the decrypted ciphertext sub-key. After the encryption device finishes encryption, it releases the decrypted ciphertext sub-key.
[0069] When the encryption interface receives the data to be encrypted, it converts the format of the data to be encrypted according to the data format corresponding to the encryption device to obtain the data format required by the encryption device, and then sends the data to be encrypted with the converted format to the encryption device.
[0070] The encryption interface and the encryption device can be in a one-to-many relationship, that is, one encryption interface is set, and through this one encryption interface, the data to be encrypted can be sent to any one of multiple encryption devices, thereby enabling the data to be encrypted to support multiple encryption algorithms for encryption. However, it should be noted that when the time series database is running, it can only be encrypted by the same type of encryption device.
[0071] First, obtain the data format corresponding to each encryption device among multiple encryption devices; then design the encryption interface according to the data format corresponding to each encryption device. For example, there are multiple segments of code designed in the code corresponding to the encryption interface, and each segment of code is obtained according to the data format corresponding to one encryption device, and each segment of code realizes the conversion of the data format of the time series database to the data format required by the encryption device.
[0072] Step 202, obtain the encrypted data corresponding to the data to be encrypted returned by the encryption device according to the padding data.
[0073] After receiving the padding data, the encryption device encrypts the padding data using an encryption algorithm to obtain the encrypted data corresponding to the data to be encrypted.
[0074] In the above embodiment, the padding data to be encrypted is sent to the encryption device for encryption through the encryption interface. That is, as long as the call process and data format of the encryption device are known, the data to be encrypted can be encrypted by the devices corresponding to different encryption algorithm providers, so as to support encrypting the data in the time series database storage layer with different encryption algorithms.
[0075] In one embodiment, encrypting the padding data in step 200 to obtain the encrypted data corresponding to the data to be encrypted includes:
[0076] Step 200A, send the current public key corresponding to the time series database to the encryption device through the encryption interface.
[0077] The current public key corresponding to the time series database is the public key of the time series database at the current moment. A public key is set for the time series database, and through this public key, the sub-keys of each storage area under the time series database are encrypted. Send the current public key corresponding to the time series database to the encryption device so that the encryption device can match the current public key sent by the time series database with the current private key stored in itself.
[0078] Step 200B, obtain the matching result of the current public key by the encryption device, where the matching result is the matching result of the current public key and the current private key in the encryption device.
[0079] The matching result is either a successful match or a failed match. If the encryption device finds that the current public key sent by the time series database and the current private key stored in itself are a pair, the matching result of the current public key is a successful match. If the encryption device finds that the current public key sent by the time series database and the current private key stored in itself are not a pair, the matching result of the current public key is a failed match. If the match fails, a failure feedback message is generated to remind the staff to handle it through this failure feedback message.
[0080] Step 200C, if the matching result is a successful match, send the padding data and the encrypted sub-key of the storage area where the padding data is located to the encryption device through the encryption interface.
[0081] If the match is successful, send the padding data and the encrypted sub-key of the storage area (shard) where the padding data is located to the encryption device through the encryption interface so that the encryption device can encrypt the data to be encrypted.
[0082] Step 200D, obtain the encrypted data corresponding to the data to be encrypted obtained by the encryption device encrypting the padded data according to the ciphertext sub-key.
[0083] After receiving the ciphertext sub-key and the padded data in the storage area, the encryption device first decrypts the ciphertext sub-key using the current private key stored in itself to obtain the decrypted ciphertext sub-key; then uses the decrypted ciphertext sub-key to encrypt the padded data to obtain the encrypted data; and returns the encrypted data.
[0084] In the above embodiment, an encryption method is provided. First, the current public key corresponding to the time series database is sent to the encryption device. If the matching result of the current public key is successful, the padded data and the ciphertext sub-key of the storage area where the padded data is located are sent to the encryption device through the encryption interface; finally, obtain the encrypted data obtained by the encryption device encrypting the padded data according to the ciphertext sub-key. It can be seen that since the sub-key is used to encrypt the data, and the sub-key is also encrypted by the public key. Further, the decrypted ciphertext sub-key only appears in the encryption device and will not appear outside the encryption device, which can effectively ensure that the sub-key is not leaked, thereby ensuring data security.
[0085] In one embodiment, the encryption method for the storage layer of the time series database further includes: Step 400 and Step 500.
[0086] Step 400, when creating the storage area where the encrypted data is located, send a generation instruction to the encryption device, and the generation instruction carries the current public key corresponding to the time series database, so that the encryption device uses the current public key corresponding to the time series database to encrypt the randomly generated sub-key to obtain the ciphertext sub-key of the storage area where the encrypted data is located.
[0087] The storage area of the time series database is divided according to time. For example, create storage area 1, store the data generated from January 1, 2050 to January 7, 2050 in storage area 1, create storage area 2, store the data generated from January 8, 2050 to January 14, 2050 in storage area 2, create storage area 3, store the data generated from January 14, 2050 to January 20, 2050 in storage area 3. Therefore, when more data needs to be stored, more storage areas need to be created adaptively.
[0088] When creating a storage area where encrypted data is located, a generation instruction is sent to the encryption device. The generation instruction is used to instruct the encryption device to generate a ciphertext sub-key. Specifically, the current public key corresponding to the time-series database is also carried in the generation instruction. After receiving the generation instruction, the encryption device first randomly generates a string of binary numbers, which is the sub-key of the storage area. Then, the randomly generated binary numbers are encrypted using the current public key corresponding to the time-series database to obtain the ciphertext sub-key.
[0089] Step 500: Obtain the ciphertext sub-key of the storage area where the encrypted data is located returned by the encryption device.
[0090] After obtaining the ciphertext sub-key returned by the encryption device, store the ciphertext sub-key in the meta file and associate the ciphertext sub-key with the number of the storage area.
[0091] The above embodiment provides a method for generating the ciphertext sub-key of a storage area, that is, when creating a storage area, the current public key is sent to the encryption device, and then the encryption device encrypts the randomly generated sub-key using the public key to obtain the ciphertext sub-key and returns it.
[0092] In one embodiment, the encryption method of the time-series database storage layer further includes: Step 600, Step 700, and Step 800.
[0093] Step 600: Obtain the replacement public key corresponding to the time-series database.
[0094] The replacement public key is the public key used to replace the current public key corresponding to the time-series database.
[0095] Step 700: Send the replacement public key corresponding to the time-series database, the current public key corresponding to the time-series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device.
[0096] The encryption device needs to use the replacement public key, the current public key, and the ciphertext sub-key to generate the replacement sub-key. Therefore, in order to replace the public key, it is necessary to send the replacement public key corresponding to the time-series database, the current public key corresponding to the time-series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device.
[0097] Step 800: Obtain the replacement sub-key returned by the encryption device according to the replacement public key corresponding to the time-series database, the current public key corresponding to the time-series database, and the ciphertext sub-key of the storage area where the encrypted data is located.
[0098] After receiving the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located, the encryption device first matches the current public key corresponding to the time series database with its own current private key. If the match passes, it uses the current private key to decrypt the ciphertext sub-key of the storage area where the encrypted data is located to obtain the decrypted ciphertext sub-key, and then uses the replacement public key to encrypt the decrypted ciphertext sub-key to obtain the replacement sub-key.
[0099] Step 900, use the replacement sub-key to replace the ciphertext sub-key of the storage area where the encrypted data is located.
[0100] After obtaining the replacement sub-key returned by the encryption device, replace the ciphertext sub-key of the storage area where the encrypted data is located with the replacement sub-key.
[0101] The above embodiments provide a scheme for replacing the public key. It can be understood that sometimes the public key may be leaked, resulting in the insecurity of the data in the entire time series database. At this time, the above scheme is adopted to replace the public key, effectively ensuring the security of the database data.
[0102] In one embodiment, the encryption method for the storage layer of the time series database further includes:
[0103] Step 1000, obtain the backup library public key.
[0104] The backup library public key is the public key of the database to be backed up.
[0105] Step 1100, send the backup library public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device.
[0106] Step 1200, obtain the backup library encryption sub-key returned by the encryption device according to the backup library public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located.
[0107] The backup library encryption sub-key is obtained by encrypting the decrypted sub-key (where the decrypted sub-key is the decrypted sub-key corresponding to the ciphertext sub-key of the storage area where the encrypted data is located) with the backup library public key. After receiving the backup library public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located, the encryption device first matches the current public key corresponding to the time series database with its own private key. After the match passes, it uses its own private key to decrypt the ciphertext sub-key of the storage area where the encrypted data is located to obtain the decrypted sub-key, and then encrypts the decrypted sub-key with the backup library public key to obtain the backup library encryption sub-key.
[0108] Step 1300, copy the backup library encryption sub-key, the backup library public key, and the encrypted data to a backup directory for storage.
[0109] Among them, the backup directory is a storage area for data backup. For example, the backup directory is the system backup directory, that is, the backup directory.
[0110] The purpose of copying the backup library encryption sub-key, the backup library public key, and the encrypted device to the backup directory for storage is to facilitate subsequent data restoration. The following explains why these data need to be stored in the backup directory to achieve data restoration.
[0111] Suppose there are two time-series databases, namely dbA and dbB. The public keys of dbA and dbB are public key 1 and public key 2 respectively. The storage areas of dbA are storage areas A1, A2... An respectively, and the sub-keys are k1, k2... kn respectively. The sub-keys k1, k2... kn are encrypted using public key 1. The storage areas of dbB are storage areas B1, B2... Bn respectively, and the sub-keys are h1, h2... hn respectively. The sub-keys h1, h2... hn are encrypted using public key 2. At this time, it is necessary to back up the data in the time-series database dbA, and hope that when restoring the data later, the data in dbA can be restored to dbB. If the data in dbA is directly copied to the backup directory, then dbB will not be able to decrypt the data from dbA because dbB cannot decrypt the encrypted sub-keys from dbA. Therefore, when backing up the data in dbA, not only the data in dbA needs to be copied to the backup directory, but also the sub-keys k1, k2... kn from dbA need to be decrypted using the private key of dbA, and finally the sub-keys k1, k2... kn from dbA are encrypted using the public key of dbB to obtain the backup library encryption sub-key, and then the backup library encryption sub-key, the backup library public key, and the encrypted data are stored in the backup directory.
[0112] The above embodiment provides a data backup solution to implement data backup so that data can be restored when data is lost or damaged.
[0113] In one embodiment, for the encryption method of the time-series database storage layer, after the step 1300 of copying the backup library encryption sub-key, the backup library public key, and the encrypted data to the backup directory for storage, it further includes:
[0114] Compare the backup library public key with the public key of the restoration database;
[0115] If the backup library public key is the same as the public key of the restoration database, the restoration database obtains the encrypted data and the backup library encryption sub-key.
[0116] Restore the database, which is the database to which the backed-up data needs to be restored. For example, when restoring the database, the public key of the backup library in the backup directory is compared with its own public key. If the comparison result is the same, the encrypted data and the backup library encryption sub-key are obtained from the backup directory, thus realizing data restoration.
[0117] Then, after the restore database obtains the encrypted data, how to decrypt the encrypted data? First, the restore database sends its own public key to the encryption device corresponding to the restore database; the encryption device matches the public key sent by the restore database with its own private key. If the matching result is successful, it sends a matching success to the restore data; according to the matching success, the restore database sends the encrypted data from the backup directory and the backup library encryption sub-key to the encryption device; the encryption device decrypts the backup library encryption sub-key according to the stored private key corresponding to the restore database to obtain the decrypted sub-key, and then uses the decrypted sub-key to decrypt the encrypted data from the backup directory to obtain the decrypted data.
[0118] The above embodiments provide a data restoration solution. It can be understood that when there is a need for data restoration, for example, when the data in the time series database is damaged, data restoration can be performed.
[0119] In one embodiment, the encryption method for the storage layer of the time series database further includes:
[0120] Obtain the encryption setting information of the time series database;
[0121] If the encryption setting information of the time series database is encryption, encrypt the payload data in the WAL log or TSM file stored in the time series database.
[0122] The encryption setting information is information indicating whether to encrypt or not encrypt the payload data in the time series database, and the encryption setting information is stored in the meta file.
[0123] In the above embodiments, some time series databases may need to be encrypted, and some time series databases may not need to be encrypted. Therefore, for each time series database, obtain the encryption setting information of the time series database. Only when the encryption setting information is encryption, encrypt the payload data stored in the time series database. If the encryption setting information is not encryption, there is no need to encrypt the payload data stored in the time series database.
[0124] In one embodiment, after step 300 of the encryption method for the storage layer of the time series database uses the encrypted data corresponding to the data to be encrypted to replace the data to be encrypted, it further includes:
[0125] Send the current public key corresponding to the time series database to the encryption device through the encryption interface;
[0126] Obtain the matching result of the current public key by the encryption device, where the matching result is the matching result of the current public key and the current private key in the encryption device;
[0127] If the matching result is successful, send the encrypted data and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device through the encryption interface;
[0128] Obtain the decrypted data returned by the encryption device according to the encrypted data and the ciphertext sub-key of the storage area where the encrypted data is located.
[0129] After receiving the ciphertext sub-key of the storage area where the encrypted data is located and the encrypted data, the encryption device first decrypts the ciphertext sub-key using the current private key to obtain the decrypted ciphertext sub-key, then decrypts the encrypted data using the decrypted ciphertext sub-key to obtain the decrypted data, and finally returns the decrypted data.
[0130] In the above embodiment, when there is a decryption requirement, the encrypted data can also be decrypted.
[0131] In one embodiment, as Figure 4 shown, an encryption device 400 for the storage layer of a time series database is provided, including:
[0132] A padding module 401 for performing padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database;
[0133] An encryption module 402 for encrypting the padded data to obtain the encrypted data corresponding to the data to be encrypted;
[0134] A storage module 403 for replacing the data to be encrypted with the encrypted data corresponding to the data to be encrypted.
[0135] In one embodiment, the padding module 401 is specifically configured to:
[0136] The encryption interface sends the padded data to the encryption device according to the call process and data format of the encryption device;
[0137] Obtain the encrypted data corresponding to the data to be encrypted returned by the encryption device according to the padded data.
[0138] In one embodiment, the padding module 401 is specifically configured to:
[0139] Send the current public key corresponding to the time series database to the encryption device through the encryption interface;
[0140] Obtain the matching result of the current public key by the encryption device, where the matching result is the matching result of the current public key and the current private key in the encryption device;
[0141] If the matching result is successful, send the filled data and the ciphertext sub-key of the storage area where the filled data is located to the encryption device through the encryption interface;
[0142] Obtain the encrypted data corresponding to the data to be encrypted obtained by the encryption device encrypting the filled data according to the ciphertext sub-key.
[0143] In one embodiment, the encryption device 400 of the time series database storage layer further includes: a creation module, configured to:
[0144] When creating the storage area where the encrypted data is located, send a generation instruction to the encryption device, where the generation instruction carries the current public key corresponding to the time series database, so that the encryption device uses the current public key corresponding to the time series database to encrypt the randomly generated sub-key to obtain the ciphertext sub-key of the storage area where the encrypted data is located;
[0145] Obtain the ciphertext sub-key of the storage area where the encrypted data is located returned by the encryption device.
[0146] In one embodiment, the encryption device 400 of the time series database storage layer further includes: a replacement module, configured to:
[0147] Obtain the replacement public key corresponding to the time series database;
[0148] Send the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device;
[0149] Obtain the replacement sub-key returned by the encryption device according to the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located;
[0150] Use the replacement sub-key to replace the ciphertext sub-key of the storage area where the encrypted data is located.
[0151] In one embodiment, the encryption device 400 of the time series database storage layer further includes: a backup module, configured to:
[0152] Obtain the backup library public key;
[0153] Send the public key of the backup library corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device;
[0154] Obtain the encrypted sub-key of the backup library returned by the encryption device according to the public key of the backup library corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located;
[0155] Copy the encrypted sub-key of the backup library, the public key of the backup library, and the encrypted data to the backup directory for storage.
[0156] In one embodiment, the encryption device 400 of the time series database storage layer further includes: a restoration module, configured to:
[0157] Compare the public key of the backup library with the public key of the restoration database;
[0158] If the public key of the backup library is the same as the public key of the restoration database, the restoration database obtains the encrypted data and the encrypted sub-key of the backup library.
[0159] In one embodiment, as Figure 5 shown, a computer device is provided. The computer device may specifically be a terminal or a server. The computer device includes a processor, a memory, and a network interface connected through a system bus. The memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the computer device stores an operating system and may also store a computer program. When the computer program is executed by the processor, the processor may implement the encryption method of the time series database storage layer. The non-volatile memory may include a read-only memory (ROM), a programmable ROM (PROM), an electrically programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM) or an external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc. The internal memory may also store a computer program. When the computer program is executed by the processor, the processor may execute the encryption method of the time series database storage layer. Those skilled in the art can understand, Figure 5The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0160] The encryption method for the time series database storage layer provided by this application can be implemented in the form of a computer program, and the computer program can run on a computer device as shown in Figure 5 the figure. Each program template of the encryption device that makes up the time series database storage layer can be stored in the memory of the computer device. For example, the padding module 401, the encryption module 402, and the storage module 403.
[0161] A computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor performs the following steps:
[0162] Perform padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data in the WAL log or TSM file stored in the time series database;
[0163] Encrypt the padded data to obtain the encrypted data corresponding to the data to be encrypted;
[0164] Replace the data to be encrypted with the encrypted data corresponding to the data to be encrypted.
[0165] In one embodiment, a computer-readable storage medium is provided, storing a computer program. When the computer program is executed by a processor, the processor performs the following steps:
[0166] Perform padding processing on the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data in the WAL log or TSM file stored in the time series database;
[0167] Encrypt the padded data to obtain the encrypted data corresponding to the data to be encrypted;
[0168] Replace the data to be encrypted with the encrypted data corresponding to the data to be encrypted.
[0169] It should be noted that the above-mentioned encryption method for the time series database storage layer, the encryption device for the time series database storage layer, the computer device, and the computer-readable storage medium belong to a general inventive concept, and the content in the embodiments of the encryption method for the time series database storage layer, the encryption device for the time series database storage layer, the computer device, and the computer-readable storage medium can be mutually applicable.
[0170] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical or other forms.
[0171] In addition, the units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0172] Furthermore, in each embodiment of this application, the various functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0173] In this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0174] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, this application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included in the protection scope of this application.
Claims
1. An encryption method for the storage layer of a time series database, characterized in that, Including: Performing padding processing on the data to be encrypted to obtain padded data corresponding to the data to be encrypted, where the data to be encrypted is payload data stored in the WAL log or TSM file in the time series database; Encrypting the padded data to obtain encrypted data corresponding to the data to be encrypted; Replacing the data to be encrypted with the encrypted data corresponding to the data to be encrypted; Obtaining the public key of the backup library; Sending the public key of the backup library corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device; Obtaining the encrypted sub-key of the backup library returned by the encryption device according to the public key of the backup library corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located; Copying the encrypted sub-key of the backup library, the public key of the backup library, and the encrypted data to the backup directory for storage.
2. The encryption method according to claim 1, characterized in that, The encrypting the padded data to obtain encrypted data corresponding to the data to be encrypted includes: The encryption interface sending the padded data to the encryption device according to the call process and data format of the encryption device; Obtaining the encrypted data corresponding to the data to be encrypted returned by the encryption device according to the padded data.
3. The encryption method according to claim 1, characterized in that, The encrypting the padded data to obtain encrypted data corresponding to the data to be encrypted includes: Sending the current public key corresponding to the time series database to the encryption device through the encryption interface; Obtaining the matching result of the current public key by the encryption device, where the matching result is the matching result of the current public key and the current private key in the encryption device; If the matching result is successful, sending the padded data and the ciphertext sub-key of the storage area where the padded data is located to the encryption device through the encryption interface; Obtaining the encrypted data corresponding to the data to be encrypted obtained by the encryption device encrypting the padded data according to the ciphertext sub-key.
4. The encryption method according to claim 3, characterized in that, It further includes: When creating the storage area where the encrypted data is located, sending a generation instruction to the encryption device, where the generation instruction carries the current public key corresponding to the time series database, so that the encryption device encrypts the randomly generated sub-key using the current public key corresponding to the time series database to obtain the ciphertext sub-key of the storage area where the encrypted data is located; Obtaining the ciphertext sub-key of the storage area where the encrypted data is located returned by the encryption device.
5. The encryption method according to claim 1, characterized in that, It further includes: Obtaining the replacement public key corresponding to the time series database; Sending the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device; Obtaining the replacement sub-key returned by the encryption device according to the replacement public key corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located; Using the replacement sub-key to replace the ciphertext sub-key of the storage area where the encrypted data is located.
6. The encryption method according to claim 1, characterized in that, After the copying the encrypted sub-key of the backup library, the public key of the backup library, and the encrypted data to the backup directory for storage, it further includes: Compare the public key of the backup library with the public key of the restored database; If the public key of the backup library is the same as the public key of the restored database, the restored database obtains the encrypted data and the backup library encryption sub-key.
7. An encryption device for the storage layer of a time series database, characterized in that, Includes: A padding module for padding the data to be encrypted to obtain the padded data corresponding to the data to be encrypted, where the data to be encrypted is the payload data stored in the WAL log or TSM file in the time series database; An encryption module for encrypting the padded data to obtain the encrypted data corresponding to the data to be encrypted; A storage module for replacing the data to be encrypted with the encrypted data corresponding to the data to be encrypted; A backup module for: Obtain the public key of the backup library; Send the public key of the backup library corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located to the encryption device; Obtain the backup library encryption sub-key returned by the encryption device according to the public key of the backup library corresponding to the time series database, the current public key corresponding to the time series database, and the ciphertext sub-key of the storage area where the encrypted data is located; Copy the backup library encryption sub-key, the public key of the backup library, and the encrypted data to the backup directory for storage.
8. A computer device, characterized in that, Includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the encryption method of the time series database storage layer according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions. When the computer program instructions are read and executed by the processor, the steps of the encryption method of the time series database storage layer according to any one of claims 1 to 6 are executed.