Access Method for Encrypted Database, Computing Device and Storage Medium

The encrypted database is connected to the preset API interface and the driver interface, and the database operation statements are encrypted, solving the cost and security problems of users when migrating to the encrypted database, realizing the unconscious data encryption and decryption process, reducing the user migration cost and improving security.

CN114036215BActive Publication Date: 2025-07-11ALIBABA CLOUD COMPUTING CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110956070.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-19
Publication Date
2025-07-11
Estimated Expiration
2041-08-19

AI Technical Summary

Technical Problem

In cloud computing scenarios, when users migrate to encrypted databases, they need to customize the existing program logic, which increases costs, and users need to encrypt database operation statements, affecting the user experience.

Method used

Provide a preset API interface to obtain the configuration parameters and encryption parameters of the encrypted database, connect the encrypted database through the driver interface and the connection interface, and use the encryption parameters to encrypt the database operation statements provided by the user, send them to the encrypted database for processing, and then decrypt and display after returning the result.

Benefits of technology

No user is required to encrypt database operation statements, which reduces the development cost of migrating to encrypted databases, improves data security and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114036215B_ABST
    Figure CN114036215B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method for accessing an encrypted database, a computing device, and a storage medium. In the embodiment of the present application, a preset API interface is provided to obtain configuration parameters and encryption parameters of the encrypted database, and a driver interface of the preset API interface is loaded; a connection interface of the preset API interface is created according to the driver interface and the configuration parameters, and the connection interface is used to connect to the encrypted database; the database operation statement provided by the user is encrypted according to the encryption parameters, the driver interface, and the connection interface; the encrypted database operation statement is sent to the encrypted database for processing to obtain a processed result. This enables the user to not need to encrypt the database operation statement. Through the driver interface and the connection interface provided in the preset API interface, and the encryption parameters, the database operation statement can be encrypted, improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technologies, and in particular, to a method for accessing an encrypted database, a computing device, and a storage medium. Background Art

[0002] In the cloud computing scenario, the security of user data is guaranteed by the cloud platform. The distrust of the cloud platform and its staff is one of the main factors hindering users from migrating to the cloud. Among them, an encrypted database uses technologies such as TEE (Trusted Execution Environment) to implement ciphertext queries, enabling users to ensure data security without trusting the cloud platform. However, to implement ciphertext queries with better security, it is necessary to involve users in customizing and modifying the existing program logic, increasing the cost for users to migrate to the encrypted database. Summary of the Invention

[0003] Multiple aspects of this application provide a method for accessing an encrypted database, a computing device, and a storage medium, enabling users to improve data security without encrypting database operation statements by themselves.

[0004] An embodiment of this application provides a method for accessing an encrypted database, including: providing a preset API interface, obtaining configuration parameters and encryption parameters of the encrypted database, and loading a driver interface of the preset API interface; creating a connection interface of the preset API interface according to the driver interface and the configuration parameters, where the connection interface is used to connect to the encrypted database; encrypting a database operation statement provided by a user according to the encryption parameters, the driver interface, and the connection interface; and sending the encrypted database operation statement to the encrypted database for processing to obtain a processed result.

[0005] An embodiment of this application further provides a computing device, including: a memory, a processor, and a communication component; the memory is used to store a computer program; the processor executes the computer program to: provide a preset API interface, obtain configuration parameters and encryption parameters of the encrypted database, and load a driver interface of the preset API interface; create a connection interface of the preset API interface according to the driver interface and the configuration parameters, where the connection interface is used to connect to the encrypted database; encrypt a database operation statement provided by a user according to the encryption parameters, the driver interface, and the connection interface; and the communication component is used to send the encrypted database operation statement to the encrypted database for processing to obtain a processed result.

[0006] An embodiment of this application further provides a computer-readable storage medium storing a computer program, where when the computer program is executed by one or more processors, the one or more processors are caused to implement the steps in the above method.

[0007] The embodiments of the present application further provide a computer program product, including a computer program or instruction. When the computer program is executed by a processor, the processor is caused to implement the steps in the above method.

[0008] In the embodiments of the present application, a preset API interface is provided to obtain configuration parameters and encryption parameters of an encrypted database, and a driver interface of the preset API interface is loaded; a connection interface of the preset API interface is created according to the driver interface and the configuration parameters, and the connection interface is used to connect to the encrypted database; a database operation statement provided by a user is encrypted according to the encryption parameters, the driver interface, and the connection interface; and the encrypted database operation statement is sent to the encrypted database for processing to obtain a processed result.

[0009] Among them, encrypting the database operation statement provided by the user according to the encryption parameters, the driver interface, and the connection interface enables the user not to encrypt the database operation statement. Through the driver interface and the connection interface provided in the preset API interface, and the encryption parameters, the database operation statement can be encrypted, which can improve the security of data. At the same time, there is no need for the user to consume development costs for data encryption, and the user is unaware of the encryption process, improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0011] Figure 1 is a schematic flowchart of a method for accessing an encrypted database according to an exemplary embodiment of the present application;

[0012] Figure 2 is a schematic diagram of accessing an encrypted database according to an exemplary embodiment of the present application;

[0013] Figure 3 is a schematic structural diagram of an access system for an encrypted database according to an exemplary embodiment of the present application;

[0014] Figure 4 is a schematic structural diagram of an access device for an encrypted database provided by an exemplary embodiment of the present application;

[0015] Figure 5 is a schematic structural diagram of a computing device provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments of this application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.

[0017] As can be seen from the foregoing, an encrypted database uses technologies such as TEE (Trusted Execution Environment) to implement ciphertext queries, enabling customers to ensure data security without trusting the cloud platform. In order to ensure the data security of users during the use of the encrypted database, users need to generate encrypted execution statements locally. In addition, when the corresponding return data results are obtained from the encrypted database, users also need to decrypt the data results locally. This requires customizing the logic of existing application programs, thereby increasing the cost for users to migrate to the encrypted database.

[0018] Based on this, the embodiments of this application provide an access method, a computing device, and a storage medium for an encrypted database, enabling users to avoid encrypting database operation statements, realizing that users do not need to modify application programs during the use of the encrypted database, improving data security, and greatly reducing the development cost for users to migrate to the encrypted database.

[0019] The following will elaborate on the access process of the encrypted database in combination with the method embodiments.

[0020] Figure 1 It is a schematic flowchart of an access method for an encrypted database according to an exemplary embodiment of this application. The method 100 provided by the embodiments of this application is executed by a computing device, such as a computer, etc. The method 100 includes the following steps:

[0021] 101: Provide a pre-set API interface, obtain the configuration parameters and encryption parameters of the encrypted database, and load the driver interface of the pre-set API interface.

[0022] 102: Create a connection interface for the pre-set API interface according to the driver interface and the configuration parameters. The connection interface is used to connect to the encrypted database.

[0023] 103: Encrypt the database operation statements provided by the user according to the encryption parameters, the driver interface, and the connection interface.

[0024] 104: Send the encrypted database operation statements to the encrypted database for processing to obtain the processed results.

[0025] It should be noted that a more specific execution entity can be an application program in the computer, and this application program can provide a preset API interface.

[0026] The following elaborates on the above steps in detail:

[0027] 101: Provide a preset API interface, obtain the configuration parameters and encryption parameters of the encrypted database, and load the driver interface of the preset API interface.

[0028] Among them, the preset API (Application Programming Interface) interface can be used to execute database operation statements. Such as the JDBC (Java Database Connectivity) interface. This JDBC interface is an interface rewritten from the standard JDBC interface, but it still complies with the protocol of the standard JDBC interface.

[0029] The encrypted database can refer to a database that uses technologies such as TEE to implement operations such as querying ciphertext to ensure data security.

[0030] The configuration parameters can refer to the parameters used to connect to the encrypted database, such as the database type, host name, port, and database name. The encryption parameters refer to the parameters used to encrypt database operation statements or decrypt data results, such as encryption algorithms, encryption modes, and keys. The encryption algorithms and encryption modes in the encryption parameters can be determined according to requirements, thereby meeting different requirements and flexibly applying different encryption algorithms and modes.

[0031] The driver interface refers to the conversion interface between the preset API interface and the encrypted database, and is the interface that associates and connects the preset API interface with the encrypted database.

[0032] For example, the user can connect to the encrypted database through the encrypted database application program installed on the computer, and thus send database operation statements to the encrypted database. The preset JDBC interface can be called in this application program, that is, this interface can be provided through the application program. This interface is rewritten but still complies with the protocol of the standard JDBC interface. The application program can read the URL (Uniform Resource Locator) of this JDBC interface, which can include configuration parameters and encryption parameters. After the application program reads this URL, it passes the parameters in it to the JDBC driver program manager, and this driver program manager loads the corresponding driver interface EncDriver according to the database identifier in the configuration parameters, such as the database name.

[0033] Among them, obtaining the configuration parameters and encryption parameters of the encrypted database includes: reading the configuration file of the preset API interface to obtain the configuration parameters and encryption parameters in the configuration file.

[0034] For example, as described above, an application program on a computer can read the configuration file of the JDBC interface and read the above URL from the configuration file, which includes the above parameters. Details are not elaborated here.

[0035] Among them, loading the driver interface of the preset API interface includes: obtaining the identifier of the encrypted database according to the configuration parameters; through the driver program manager of the preset API, loading the driver interface corresponding to the identifier according to the identifier of the encrypted database.

[0036] For example, as described above, an application program on a computer obtains the database identifier, such as the database name, from the configuration parameters through the JDBC driver program manager of the preset JDBC interface, and loads the corresponding driver interface EncDriver for the database name. As Figure 2 shown, that is, execute step 211: loading the driver interface.

[0037] In addition, it should be noted that for the requirements of other services, the above services can also be provided by the server. Specifically, the computer can obtain the service interface from the server where the encrypted database is deployed through the web browser, and at the same time load the above preset API interface to the local for corresponding function execution. However, the encryption process is still completed locally, and the encrypted data can only leave the local. At this time, it can also be understood that the above preset API interface is provided locally, but its specific function is loaded from the server to the local for execution.

[0038] 102: Create a connection interface for the preset API interface according to the driver interface and the configuration parameters.

[0039] Among them, the connection interface (EncConnection) is used to connect to the encrypted database.

[0040] Specifically, creating a connection interface for the preset API interface according to the driver interface and the configuration parameters includes: calling the connection method of the driver interface and connecting to the encrypted database according to the configuration parameters, creating a corresponding connection object, and returning the connection object to the connection interface corresponding to the preset API interface.

[0041] For example, as described above, as Figure 2As shown in the figure, the application program on the computer parses the configuration parameters in the URL through the loaded driver interface EncDriver, i.e., the driver interface 202, in the pre-set JDBC interface. Then it calls the connection function or connection method of the driver interface EncDriver, and connects to the database according to the database type, host name, port, and database name in the configuration parameters. Thus, an object of the connection interface 203 is obtained, and the connection interface 203 of this object is returned to the pre-set JDBC interface 201, that is, the connection interface 203 of the pre-set JDBC interface 201 is created, and step 212: create a connection interface is executed.

[0042] It should be noted that the returned connection interface can be the connection interface of the standard JDBC interface.

[0043] 103: Encrypt the database operation statements provided by the user according to the encryption parameters, the driver interface, and the connection interface.

[0044] Among them, the database operation statement refers to an execution statement applicable to the database, such as an SQL (Structured Query Language) statement.

[0045] Specifically, encrypting the database operation statements provided by the user according to the encryption parameters, the driver interface, and the connection interface includes: after creating the connection interface, instantiating the corresponding encryptor through the driver interface and the encryption parameters; creating an execution interface corresponding to the pre-set API interface through the connection interface corresponding to the pre-set API interface for executing the database operation statements; obtaining the database operation statements provided by the user through the pre-set API interface, and calling the corresponding encryptor through the execution interface to encrypt the database operation statements.

[0046] Among them, instantiation means that in object-oriented programming, the process of creating an object using a class is called instantiation. It is the process of concretizing an abstract conceptual class into a physical object of that class.

[0047] For example, according to the foregoing, such as Figure 2As shown, the application on the computer parses the encrypted parameters in the URL through the driver interface EncDriver loaded in the preset JDBC interface 201, that is, the driver interface 202. After creating the connection interface, the driver interface EncDriver instantiates the encryptor (CryptoRewriter, also known as the SQL rewriter) 207 according to the encrypted parameters. The application can return to the connection interface 203 of the preset JDBC interface and call its corresponding creation method to execute step 213: create the execution interface A, such as the EncStatement interface, that is, the execution interface A 204. Or call its corresponding creation method to execute step 214: create the execution interface B, such as the EncPrepared Statement interface, that is, the execution interface B 205. The application can determine which execution interface to create according to the SQL statement input by the user it receives. The created execution interface is returned to the preset JDBC interface 201. The application inputs the SQL statement into the EncStatement interface or the EncPrepared Statement interface in the preset JDBC interface 201, that is, execute step 215: input the database operation statement into the execution interface A 204 (such as the EncStatement interface) or the execution interface B 205 (such as the EncPrepared Statement interface). The execution interface A 204 or the execution interface B 205 will call the instantiated encryptor 207 to encrypt the SQL statement, that is, execute step 220: encrypt the operation statement. The encryptor 207 can encrypt according to the encryption algorithm and the encryption mode, etc.

[0048] It should be noted that users can input database operation statements, such as SQL statements, through the application. The application can then obtain the statements provided by the users. Subsequently, the application can determine whether the statement is a parameterized statement based on its structure. For example, for the SQL statement: SELECT XX FROM XX WHERE XX〉1. Since its parameter is the fixed value "1", it belongs to a non-parameterized statement. If the SQL statement is: SELECT XX FROM XX WHERE XX〉?. Since its parameter is the non-fixed value "?", it belongs to a parameterized statement. For non-parameterized statements, an EncStatement interface needs to be created. For parameterized statements, an EncPrepared Statement interface needs to be created. Additionally, when encrypting database operation statements, such as encrypting SQL statements, it is for their fixed values, such as "1", or non-fixed values, such as "?". The other parts of the statement can be encrypted by the transmission channel during statement transmission. There is no need to elaborate further. Thus, it can support the encryption of both parameterized and non-parameterized SQL statements, with good applicability.

[0049] Among them, instantiating the corresponding encryptor through the driver interface and encryption parameters includes: instantiating the corresponding encryptor through the driver interface and the encryption algorithm and encryption mode in the encryption parameters.

[0050] For example, as described above, the application parses the encryption parameters in the URL, such as the encryption algorithm and encryption mode, through the driver interface EncDriver loaded in the pre-set JDBC interface, that is, the driver interface. After creating the connection interface, the driver interface EncDriver instantiates the encryptor according to the encryption algorithm and encryption mode, such as Figure 2 as shown, the encryptor 207.

[0051] To decrypt the data result subsequently, it is also necessary to instantiate the corresponding decryptor.

[0052] Specifically, the method 100 further includes: after creating the connection interface, instantiating the corresponding decryptor through the driver interface and the key in the encryption parameters; calling the corresponding encryptor through the execution interface to encrypt the database operation statement, including: the encryptor obtaining the key from the decryptor and encrypting the database operation statement according to the encryption algorithm, encryption mode, and key.

[0053] For example, as described above, such as Figure 2As shown in the figure, the application parses the encrypted parameters in the URL, such as the key, through the loaded driver interface EncDriver in the preset JDBC interface 201, that is, the driver interface 202. After creating the connection interface, the driver interface EncDriver instantiates the decryptor (EncDB SDK, also known as the encrypted database software development kit) 208 according to the key and so on. Executing interface A 204 (such as the EncStatement interface) or executing interface B 205 (such as the EncPrepared Statement interface) will call the instantiated encryptor 207 to encrypt the SQL statement. When encrypting, the encryptor 207 can obtain the key from the instantiated decryptor 208, and then the encryptor 207 can perform encryption according to the encryption algorithm, encryption mode, and key, etc. Among them, when encrypting, the encryptor 207 can encrypt the fixed values or non-fixed data data types in the SQL statement. The data types can include int integer type, string string type, etc. According to different types, the values are adjusted to meet the data type requirements of the encryption algorithm, so as to perform subsequent encryption. By determining the data type, it can generally support rewriting the data types in any SQL statement, and support for new operations or data types does not require updates and can be consistent with the data performance in the database.

[0054] Thus, the application can flexibly implement encryption for different encryption algorithms and modes through the encrypted parameters configured in the URL of the JDBC interface, improving the universality of encryption.

[0055] 104: Send the encrypted database operation statement to the encrypted database for processing to obtain the processed result.

[0056] For example, according to the above description, the application on the computer obtains the encrypted SQL statement through the preset JDBC interface. Through the preset JDBC interface, the encrypted SQL statement is sent to the corresponding encrypted database on the cloud server for processing. The encrypted database decrypts the received encrypted SQL statement in the TTE environment, and then executes according to the decrypted statement in the TTE environment, such as querying the corresponding encrypted data or storing data. If data storage is performed, the data can be encrypted and stored in the encrypted database.

[0057] Specifically, sending the encrypted database operation statement to the encrypted database for processing includes: sending the encrypted database operation statement to the encrypted database for processing through the execution interface corresponding to the preset API interface.

[0058] For example, according to the above description, such as Figure 2As shown in the figure, the application program on the computer encrypts the SQL statement through the encryptor 207 in the preset JDBC interface 201, and then returns it to the corresponding execution interface, such as the execution interface A 204 (such as the EncStatement interface). The preset JDBC interface 201 sends the encrypted SQL statement to the corresponding encrypted database on the cloud server for processing through the execution interface A 204 (such as the EncStatement interface). Details are not elaborated here.

[0059] It should be noted that for the encrypted database, the operations it performs need to be carried out in the TTE environment.

[0060] In the embodiment of the present application, since the preset JDBC interface not only follows the standard JDBC protocol, but also can implement the above data encryption, any additional program code changes required for using the encrypted database will be encapsulated in the rewritten preset JDBC interface. This allows the program code to directly use the original plaintext SQL statements without restricting the SQL statements, making it applicable to a wide range of query scenarios. Moreover, during the process of using the encrypted database, no modification by the user is required, greatly reducing the cost for the user to migrate to the encrypted database. In addition, the data in the user's plaintext database operation statements does not leave the local host, ensuring data security.

[0061] In addition, after the database returns data, decryption and display are required. The specific process is as follows:

[0062] Specifically, the method 100 further includes: creating a result set interface corresponding to the preset API interface through the execution interface corresponding to the preset API interface; obtaining the encrypted data result from the encrypted database through the result set interface corresponding to the preset API interface; calling the corresponding decryptor through the result set interface to decrypt the data result by the decryptor; and displaying the decrypted data.

[0063] Among them, the result set interface (EncResultSet) refers to the interface for receiving the data returned by the database.

[0064] For example, as described above, Figure 2As shown in the figure, when the application program on the computer sends the encrypted SQL statement through the execution interface A 204 (such as the EncStatement interface) in the preset JDBC interface 201, it creates a corresponding result set interface 206 (EncResultSet), that is, executes step 216: create a result set interface. When the encrypted SQL statement is sent to the encrypted database through the execution interface A 204 (such as the EncStatement interface) in the preset JDBC interface 201, the encrypted data returned from the encrypted database can be received through the result set interface 206 (EncResultSet), such as the encrypted query data result. Then, the result set interface 206 (EncResultSet) sends the encrypted query data result to the decryptor 208 for decrypting the data result, that is, executes step 217: decrypt the data result. After receiving the encrypted query data result, the decryptor 208 decrypts it according to the key, obtains the decrypted data result, and returns it to the result set interface 206 (EncResultSet), that is, executes step 218: return the decrypted data result to the result set interface 206 (EncResultSet). The application program on the computer can obtain the decrypted data result through the result set interface 206 (EncResultSet) in the preset JDBC interface 201, so that the application program can display the decrypted data result through the result set interface 206 in the preset JDBC interface 201 and display it to the user, that is, executes step 219: display the data result.

[0065] It should be noted that the process of decrypting the returned encrypted data is also imperceptible to the user, and the user does not need to decrypt the encrypted data locally by himself.

[0066] The preset JDBC interface does not require external dependencies and can be integrated into the application code in the form of a library without trusting an intermediate proxy or the user deploying a proxy by himself. And the preset JDBC interface is a JDBC interface based on Java (an object-oriented programming language). Compared with other programming languages, such as C language and C++ language, it will have better performance in terms of ease of use, cross-platformness and performance.

[0067] In addition, it is also worth noting that since the embodiments of the present application can be applied to a variety of SQL statements, and can also be applied to SQL statements of composite query expressions. When the encrypted database receives this type of SQL statement after encryption, it will encrypt and return the finally processed data result to the result set interface in an encrypted manner. There is no need to perform other processing through the preset JDBC interface, that is, there is no need for a large amount of local calculation, and the performance of the encrypted database can be fully utilized.

[0068] Figure 3A schematic structural diagram for accessing an encrypted database provided by an exemplary embodiment of the present application. As Figure 3 shown, the system 300 may include: a first device 301 and a second device 302.

[0069] Among them, the first device 301 may be a device with certain computing capabilities, which can implement the function of sending data to the second device 302 and receiving data sent by the second device 302. The basic structure of the first device 301 may include: at least one processor. The number of processors may depend on the configuration and type of the device with certain computing capabilities. The device with certain computing capabilities may also include a memory, which may be volatile, such as RAM, or non-volatile, such as read-only memory (ROM), flash memory, etc., or may include both types at the same time. Usually, an operating system (OS), one or more application programs, and program data may be stored in the memory. In addition to the processing unit and the memory, the device with certain computing capabilities also includes some basic configurations, such as a network card chip, an IO bus, a display component, and some peripheral devices. Optionally, some peripheral devices may include, for example, a keyboard, a stylus, etc. Other peripheral devices are well known in the art and will not be elaborated here. Optionally, the first device 301 may be a smart terminal, such as a mobile phone, a desktop computer, a notebook, a tablet computer, etc.

[0070] The second device 302 refers to a device that can provide computing and processing services in a network virtual environment, and may refer to a device that uses the network for data processing. Physically, the second device 302 may be any device that can provide computing services, respond to service requests, and perform data processing, such as a cloud server, a cloud host, a virtual center, a conventional server, etc., on which a database is built. The composition of the second device 302 mainly includes a processor, a hard disk, a memory, a system bus, etc., which is similar to a general computer architecture.

[0071] Specifically, the first device 301 provides a preset API interface, obtains the configuration parameters and encryption parameters of the encrypted database, and loads the driver interface of the preset API interface; creates a connection interface of the preset API interface according to the driver interface and the configuration parameters, and the connection interface is used to connect to the encrypted database; encrypts the database operation statements provided by the user according to the encryption parameters, the driver interface, and the connection interface; sends the encrypted database operation statements to the encrypted database for processing to obtain the processed result.

[0072] Specifically, the first device 301 reads the configuration file of the preset API interface to obtain the configuration parameters and encryption parameters in the configuration file.

[0073] Specifically, the first device 301 obtains the identifier of the encrypted database according to the configuration parameters, and loads the corresponding driver interface according to the identifier of the encrypted database through the driver manager of the preset API.

[0074] Specifically, the first device 301 calls the connection method of the driver interface and connects to the encrypted database according to the configuration parameters, creates a corresponding connection object, and returns it to the connection interface corresponding to the preset API interface according to the connection object.

[0075] Specifically, after creating the connection interface, the first device 301 instantiates the corresponding encryptor through the driver interface and the encryption parameters; creates an execution interface corresponding to the preset API interface through the connection interface corresponding to the preset API interface for executing database operation statements; obtains the database operation statements provided by the user through the preset API interface, and calls the corresponding encryptor through the execution interface to encrypt the database operation statements.

[0076] Specifically, the first device 301 instantiates the corresponding encryptor through the encryption algorithm and encryption mode in the driver interface and the encryption parameters.

[0077] In addition, after creating the connection interface, the first device 301 instantiates the corresponding decryptor through the driver interface and the key in the encryption parameters; obtains the key from the decryptor through the encryptor, and encrypts the database operation statements according to the encryption algorithm, encryption mode, and key.

[0078] Specifically, the first device 301 sends the encrypted database operation statements to the encrypted database deployed in the second device 302 for processing through the execution interface corresponding to the preset API interface. The encrypted database deployed in the second device 302 processes the encrypted database operation statements to obtain the encrypted data result and returns it to the first device 301.

[0079] In addition, the first device 301 creates a result set interface corresponding to the preset API interface through the execution interface corresponding to the preset API interface; obtains the encrypted data result from the encrypted database deployed in the second device 302 through the result set interface corresponding to the preset API interface; calls the corresponding decryptor through the result set interface, and decrypts the data result through the decryptor; and displays the decrypted data.

[0080] Among them, the preset API interface includes: JDBC interface.

[0081] It should be noted that for the content not fully described in the system 300, please refer to the content in the foregoing method 100, and the specific implementation manner thereof also refers to the specific implementation manner of the foregoing method 100, which will not be elaborated herein.

[0082] In the scenario of accessing the encrypted database according to the embodiments of the present application, as Figure 3 shown, the user can connect to the encrypted database through the encrypted database application on the first device 301 (such as a computer), so as to send database operation statements to the encrypted database. In this application, a preset JDBC interface can be called, that is, this interface can be provided through the application. This interface is rewritten, but still conforms to the protocol of the standard JDBC interface. The application can read the URL (Uniform Resource Locator) of the JDBC interface, which may include configuration parameters and encryption parameters. After the application reads this URL, it passes the parameters therein to the JDBC driver manager, and the driver manager loads the corresponding driver interface EncDriver according to the database identifier in the configuration parameters, such as the database name.

[0083] The configuration parameters in the URL are parsed through the driver interface EncDriver. Then, the connection function or connection method of the driver interface EncDriver is called, and the database is connected according to the database type, host name, port, and database name in the configuration parameters. Thus, an object of the connection interface is obtained, and the connection interface of this object is returned to the preset JDBC interface, that is, the connection interface of the preset JDBC interface is created. After creating the connection interface, the driver interface EncDriver instantiates an encryptor (CryptoRewriter, also called SQL rewriter) according to the encryption parameters. After creating the connection interface, the driver interface EncDriver instantiates a decryptor (EncDB SDK, also called encrypted database software development kit) according to the secret key, etc. The application can call the corresponding creation method through the connection interface returned to the preset JDBC interface to create an execution interface A, such as the EncStatement interface. Or call the corresponding creation method to create an execution interface B, such as the EncPrepared Statement interface. The application can determine which execution interface to create according to the SQL statement input by the user it receives. The created execution interface is returned to the preset JDBC interface. The application inputs the SQL statement into the EncStatement interface or EncPrepared Statement interface in the preset JDBC interface. The execution interface A or the execution interface B will call the instantiated encryptor to encrypt this SQL statement. When encrypting, the encryptor can obtain the secret key from the instantiated decryptor, and then the encryptor can perform encryption according to the encryption algorithm, encryption mode, and secret key, etc.

[0084] By presetting the JDBC interface, the encrypted SQL statement is sent to the second device 302, such as the encrypted database corresponding to the cloud server, for processing, that is, step 311 is executed: sending the encrypted execution statement. After receiving the encrypted SQL statement, the encrypted database decrypts it in the TTE environment, and then executes according to the decrypted statement in the TTE environment, such as querying the corresponding encrypted data and returning the encrypted data result, that is, step 312 is executed: returning the encrypted data result, or performing data storage. If data storage is performed, the data can be encrypted and stored in the encrypted database. The application program on the computer sends the encrypted SQL statement through the execution interface A in the preset JDBC interface, such as the EncStatement interface, and creates a corresponding result set interface (EncResultSet) at the same time. When the encrypted SQL statement is sent to the encrypted database through the execution interface A in the preset JDBC interface, such as the EncStatement interface, the encrypted data returned from the encrypted database can be received through the result set interface, such as the encrypted query data result. Then, the result set interface sends the encrypted query data result to the decryptor for decrypting the data result. After receiving the encrypted query data result, the decryptor decrypts it according to the key, obtains the decrypted data result, and returns it to the result set interface. The application program on the computer can obtain the decrypted data result through the result set interface in the preset JDBC interface, so that the application program can display the decrypted data result through the result set interface in the preset JDBC interface and display it to the user.

[0085] For the content not described in detail here, reference can be made to the content described above, and it will not be elaborated further.

[0086] In the above-mentioned embodiment of the present application, the first device 301 and the second device 302 are connected to the network. If the first device 301 and the second device 302 are communicatively connected, the network mode of the mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, 5G, etc.

[0087] Figure 4 It is a schematic structural framework diagram of an access device for an encrypted database provided by an exemplary embodiment of the present application. The device 400 can be applied to a terminal device, such as a computer. The device 400 includes: a providing module 401, a creating module 402, an encrypting module 403, and a sending module 404; the functions of each module will be elaborated in detail below:

[0088] A providing module 401 is used to provide a preset API interface, obtain configuration parameters and encryption parameters of an encrypted database, and load a driver interface of the preset API interface.

[0089] A creating module 402 is used to create a connection interface of the preset API interface according to the driver interface and the configuration parameters, and the connection interface is used to connect to the encrypted database.

[0090] An encryption module 403 is used to encrypt database operation statements provided by a user according to the encryption parameters, the driver interface, and the connection interface.

[0091] A sending module 404 is used to send the encrypted database operation statements to the encrypted database for processing to obtain processed results.

[0092] Specifically, the providing module 401 is used to read a configuration file of the preset API interface and obtain the configuration parameters and encryption parameters in the configuration file.

[0093] Specifically, the providing module 401 includes: an obtaining unit, used to obtain an identifier of the encrypted database according to the configuration parameters; a loading unit, used to load a driver interface corresponding to the identifier through a driver program manager of the preset API according to the identifier of the encrypted database.

[0094] Specifically, the creating module 402 is used to call a connection method of the driver interface and connect to the encrypted database according to the configuration parameters, create a corresponding connection object, and return the connection object to the connection interface corresponding to the preset API interface.

[0095] Specifically, the encryption module 403 includes: an instantiation unit, used to instantiate a corresponding encryptor through the driver interface and the encryption parameters after creating the connection interface; a creating unit, used to create an execution interface corresponding to the preset API interface through the connection interface corresponding to the preset API interface for executing database operation statements; an encryption unit, used to obtain database operation statements provided by a user through the preset API interface, call the corresponding encryptor through the execution interface, and encrypt the database operation statements.

[0096] Specifically, the instantiation unit is used to instantiate a corresponding encryptor through an encryption algorithm and an encryption mode in the driver interface and the encryption parameters.

[0097] In addition, the instantiation unit is further used to instantiate a corresponding decryptor through a key in the driver interface and the encryption parameters after creating the connection interface; the encryption unit is used to obtain a key from the decryptor through the encryptor and encrypt the database operation statements according to the encryption algorithm, the encryption mode, and the key.

[0098] Specifically, the sending module 404 is configured to send the encrypted database operation statement to the encrypted database for processing through the execution interface corresponding to the preset API interface.

[0099] In addition, the creating module 402 is configured to create a result set interface corresponding to the preset API interface through the execution interface corresponding to the preset API interface; the apparatus 400 further includes: an obtaining module, configured to obtain the encrypted data result from the encrypted database through the result set interface corresponding to the preset API interface; a decrypting module, configured to call a corresponding decryptor through the result set interface to decrypt the data result through the decryptor; and a displaying module, configured to display the decrypted data.

[0100] Among them, the preset API interface includes: a JDBC interface.

[0101] For the content not detailed in the apparatus 400, please refer to the foregoing description and will not be elaborated here.

[0102] The above describes Figure 4 the internal functions and structures of the apparatus 400 shown. In a possible design, Figure 4 the structure of the apparatus 400 shown can be implemented as a computing device, such as a computer. As Figure 5 shown, the device 500 may include: a memory 501, a processor 502, and a communication component 503;

[0103] The memory 501 is configured to store computer programs.

[0104] The processor 502 is configured to execute the computer program to: provide a preset API interface, obtain configuration parameters and encryption parameters of the encrypted database, and load a driver interface of the preset API interface; create a connection interface of the preset API interface according to the driver interface and the configuration parameters, where the connection interface is used to connect to the encrypted database; encrypt the database operation statement provided by the user according to the encryption parameters, the driver interface, and the connection interface.

[0105] The communication component 503 is configured to send the encrypted database operation statement to the encrypted database for processing to obtain the processed result.

[0106] Specifically, the processor 502 is specifically configured to: read the configuration file of the preset API interface and obtain the configuration parameters and encryption parameters in the configuration file.

[0107] Specifically, the processor 502 is specifically configured to: obtain the identifier of the encrypted database according to the configuration parameters; load the driver interface corresponding to the identifier according to the identifier of the encrypted database through the driver program manager of the preset API.

[0108] Specifically, the processor 502 is specifically configured to: call the connection method of the driver interface, connect to the encrypted database according to the configuration parameters, create a corresponding connection object, and return the connection object to the connection interface corresponding to the preset API interface.

[0109] Specifically, the processor 502 is specifically configured to: after creating the connection interface, instantiate a corresponding encryptor through the driver interface and the encryption parameters; create an execution interface corresponding to the preset API interface through the connection interface corresponding to the preset API interface for executing database operation statements; obtain the database operation statements provided by the user through the preset API interface, and call the corresponding encryptor through the execution interface to encrypt the database operation statements.

[0110] Specifically, the processor 502 is specifically configured to: instantiate a corresponding encryptor through the encryption algorithm and encryption mode in the driver interface and the encryption parameters.

[0111] In addition, the processor 502 is further configured to: after creating the connection interface, instantiate a corresponding decryptor through the driver interface and the encryption key in the encryption parameters; specifically, the processor 502 is configured to obtain the encryption key from the decryptor through the encryptor, and encrypt the database operation statements according to the encryption algorithm, encryption mode, and encryption key.

[0112] Specifically, the communication component 503 is specifically configured to: send the encrypted database operation statements to the encrypted database for processing through the execution interface corresponding to the preset API interface.

[0113] In addition, the processor 502 is further configured to: create a result set interface corresponding to the preset API interface through the execution interface corresponding to the preset API interface; obtain the encrypted data result from the encrypted database through the result set interface corresponding to the preset API interface; call the corresponding decryptor through the result set interface, and decrypt the data result through the decryptor; display the decrypted data.

[0114] Among them, the preset API interface includes: the JDBC interface.

[0115] In addition, an embodiment of the present invention provides a computer program product, including a computer program or instruction, wherein when the computer program is executed by a processor, the processor is caused to implement Figures 1-2 The steps of a method for accessing an encrypted database in the method embodiment are not described in detail here. This program product can be an application installed on a device.

[0116] An embodiment of the present invention provides a computer storage medium, when a computer program is executed by one or more processors, one or more processors are caused to implement Figures 1-2 The steps of a method for accessing an encrypted database in the method embodiment.

[0117] In addition, in some of the processes described in the above embodiments and the accompanying drawings, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations can be executed not in the order in which they appear herein or in parallel. The serial numbers of the operations, such as 101, 102, 103, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations can be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.

[0118] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.

[0119] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of adding a necessary general hardware platform, and of course, it can also be implemented by a combination of hardware and software. Based on such an understanding, the above technical solution essentially or the part that contributes to the prior art can be embodied in the form of a computer product. The present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0120] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable multimedia data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable multimedia data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0121] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable multimedia data processing device to work in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more processes and / or blocks Figure 1 in one or more processes and / or blocks Figure 1 specified in one or more blocks or multiple blocks.

[0122] These computer program instructions can also be loaded onto a computer or other programmable multimedia data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes and / or blocks Figure 1 in one or more processes and / or blocks Figure 1 specified in one or more blocks or multiple blocks.

[0123] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0124] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.

[0125] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0126] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for accessing an encrypted database, which is executed by a computing device on which an application for a user to connect to the encrypted database is installed. The application can call a rewritten set of API interfaces for executing database operation statements. The rewritten set of API interfaces is obtained by rewriting a set of API interfaces that conform to a standard protocol for executing database operation statements, and the rewritten set of API interfaces also conforms to the standard protocol, including: Through the application, obtain the configuration parameters and encryption parameters of the encrypted database configured for the rewritten set of API interfaces to load the driver interface in the rewritten set of API interfaces; Through the driver interface, instantiate the corresponding encryptor according to the encryption parameters, and create a connection interface in the rewritten set of API interfaces for connecting to the encrypted database according to the configuration parameters; Through the connection interface, create an execution interface in the rewritten set of API interfaces; Through the application, obtain the database operation statement input by the user and input the database operation statement into the execution interface; Through the execution interface, call the corresponding encryptor to encrypt the database operation statement and send the encrypted database operation statement to the encrypted database for processing to obtain the processed result.

2. The method according to claim 1, wherein the obtaining the configuration parameters and encryption parameters of the encrypted database configured for the rewritten set of API interfaces includes: Read the configuration file of the rewritten set of API interfaces to obtain the configuration parameters and encryption parameters in the configuration file.

3. The method according to claim 1, wherein the loading the driver interface in the rewritten set of API interfaces includes: Through the application, obtain the identifier of the encrypted database according to the configuration parameters; Pass the identifier of the encrypted database into the driver program manager of the rewritten set of API interfaces through the application; Through the driver program manager, load the driver interface corresponding to the identifier according to the identifier of the encrypted database.

4. The method according to claim 1, wherein creating the connection interface in the rewritten set of API interfaces according to the configuration parameters through the driver interface includes: Call the connection method of the driver interface and connect to the encrypted database according to the configuration parameters, create a corresponding connection object, and return the connection object to the connection interface in the rewritten set of API interfaces.

5. The method according to claim 1, wherein instantiating the corresponding encryptor through the encryption parameters by the driver interface includes: Instantiate the corresponding encryptor through the encryption algorithm and encryption mode in the driver interface and the encryption parameters.

6. The method according to claim 1, the method further includes: After creating the connection interface, instantiate the corresponding decryptor according to the key in the encryption parameters through the driver interface; Invoking the corresponding encryptor through the execution interface to encrypt the database operation statement includes: Obtaining a key from the decryptor by the encryptor, and encrypting the database operation statement according to the encryption algorithm, the encryption mode, and the key.

7. The method according to claim 1, the method further includes: Creating a result set interface in the rewritten set of API interfaces through the execution interface; Obtaining the encrypted data result from the encrypted database through the result set interface; Invoking the corresponding decryptor through the result set interface, and decrypting the data result by the decryptor; Obtaining the decrypted data from the result set interface by the application program, and presenting the decrypted data.

8. The method according to any one of claims 1-7, wherein the preset API interface comprises: JDBC interface.

9. A computing device, on which an application for a user to connect to an encrypted database is installed. The application can call a rewritten set of API interfaces for executing database operation statements. The rewritten set of API interfaces is obtained by rewriting a set of API interfaces that conform to a standard protocol for executing database operation statements, and the rewritten set of API interfaces also conforms to the standard protocol, including: A memory, a processor, and a communication component; The memory is used for storing a computer program; The processor executes the computer program for: Obtaining the configuration parameters and encryption parameters of the encrypted database configured for the rewritten set of API interfaces through the application program to load the driver interface in the rewritten set of API interfaces; Instantiating the corresponding encryptor according to the encryption parameters through the driver interface, and creating a connection interface for connecting to the encrypted database in the rewritten set of API interfaces according to the configuration parameters; Creating an execution interface in the rewritten set of API interfaces through the connection interface; Obtaining the database operation statement input by the user through the application program and inputting the database operation statement into the execution interface; Invoking the corresponding encryptor through the execution interface to encrypt the database operation statement and sending the encrypted database operation statement to the encrypted database for processing to obtain the processed result.

10. A computer-readable storage medium storing a computer program, when the computer program is executed by one or more processors, causing the one or more processors to implement the steps in the method according to any one of claims 1-8.

11. A computer program product comprising a computer program or instructions, wherein, When the computer program is executed by the processor, causing the processor to implement the steps in the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Control method for data security during on-line system and off-line system data interaction

    CN105554038A

  • Data Processing Method Between Encrypted Database and Application Program

    KR1020100135533A