Table field level encryption and security access control method and system
By building a transparent gateway in SQL Server, unified management of column master keys, and using virtual login passwords and multi-factor authentication, the problem of column master key leakage and insufficient access control in SQL Server is solved, achieving higher security and identity reliability.
Patent Information
- Application Number
- CN202111658174.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-30
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-12-30
AI Technical Summary
In the prior art, SQL Server has the risk of widespread spread of column master keys in table field-level encryption operations, and does not support multi-factor authentication and flexible access rules, so it cannot effectively resist high-risk SQL operations.
By building a transparent gateway between the first server and the second server, the column master key is uniformly managed, and its centralized storage, rotation and status update are realized to avoid key propagation. At the same time, a virtual login password is used to connect to the gateway to reduce the spread of real database usernames and passwords, and multi-factor authentication is used and flexible access rules are set.
It effectively avoids the risk of column master key leakage, reduces the risk of spreading database username and password, enhances identity reliability, and can flexibly resist high-risk SQL operations.
Smart Images

Figure CN114462059B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and in particular to a table field level encryption and security access control method and system. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] The relational database (SQL Server) supports encryption operations (Always Encrypted) at the table field level, which can protect data from rogue administrators, backup thieves, and man-in-the-middle attacks. Supported encryption methods include deterministic encryption (Deterministic) and non-deterministic encryption (Randomized). The column master key (Master Key) is provided to the client in the form of an x.509 certificate to decrypt the column encryption key (Encryption Key), thereby encrypting query parameters and decrypting query results.
[0004] Since the column master key needs to be provided to the client, it will be widely disseminated and there is a risk of leakage. Although SQL Server supports Azure cloud key warehouse service, which can centrally store column master keys, not all systems support Azure cloud services. Some medical and financial institutions cannot use Azure cloud services due to security review and other factors, which may lead to the risk of column master key leakage.
[0005] Furthermore, SQL Server does not support comprehensive multi-factor authentication (MFA). It uses account and password authentication, which requires providing the database account and password to the client, thus causing the spread of database account and password, which poses a risk of leakage. In addition, SQL Server cannot flexibly set access rules, thus failing to effectively defend against high-risk SQL operations. Summary of the invention
[0006] In order to solve the above problems, the present invention proposes a table field level encryption and security access control method and system. When forwarding messages between a first server and a second server, a transparent gateway uniformly manages the column master key to realize encryption and decryption of the message. In addition, through centralized storage, rotation, status update, etc. of the column master key, the propagation of the column master key is avoided and the risk of leakage is solved.
[0007] In order to achieve the above object, the present invention adopts the following technical solution:
[0008] In a first aspect, the present invention provides a table field level encryption and security access control method, comprising:
[0009] Connecting to the first server through the virtual login password and receiving an access request message from the first server;
[0010] Parse the access request message to obtain the query parameter to be encrypted and its value, and decrypt the ciphertext of the column encryption key according to the encryption type, the ciphertext of the column encryption key and the column master key determined by the encryption field, encrypt the value of the query parameter according to the encryption type and the decrypted column encryption key, encapsulate the encrypted query parameter into the access request message, and forward it to the second server;
[0011] A response message from the second server is received, the response message is parsed and decrypted, and the decrypted response message is sent to the first server.
[0012] As an optional implementation, after connecting to the first server, an encrypted channel is established with the first server to receive an access request message, and the connection method with the first server includes a virtual login password, IP address verification, login time verification, login machine name verification or login program verification.
[0013] As an optional implementation, the column master key is managed in a unified manner, including centralized storage, rotation and status update of the column master key, determining the column master key fingerprint based on the analysis of the access request message to obtain the corresponding column master key, and decrypting the ciphertext of the column encryption key.
[0014] As an optional implementation, during the process of parsing and decrypting the response message, the encryption metadata of the column is obtained, including the encrypted field, encryption type, ciphertext of the column encryption key, and column master key fingerprint, and the corresponding column master key is retrieved according to the column master key fingerprint to decrypt the ciphertext of the column encryption key, and the response message is decrypted according to the encryption type and the decrypted column encryption key.
[0015] As an optional implementation, the encrypted query parameters are encapsulated into the access request message, and the query parameter metadata type is modified at the same time, so as to encapsulate the encrypted query parameters into the SQL statement in the access request message, thereby completing the modification of the message body;
[0016] When the plain text of the decrypted response message is encapsulated into the response message, the encryption metadata is deleted and the field type is restored.
[0017] As an optional implementation, the control method further includes decrypting an OUT parameter of the stored procedure, parsing a response message of the stored procedure to obtain an encryption type, and decrypting the OUT parameter using a pre-cached column encryption key.
[0018] As an optional implementation, the control method further includes dangerous behavior interception, and the dangerous behavior interception includes DDL statement interception, DML statement interception, query result row number control, and login failure number control.
[0019] In a second aspect, the present invention provides a table field level encryption and security access control system, comprising:
[0020] A communication module, configured to connect to the first server through a virtual login password and receive an access request message from the first server;
[0021] an encryption module configured to parse the access request message, obtain the query parameter to be encrypted and its value, and decrypt the ciphertext of the column encryption key according to the encryption type, the ciphertext of the column encryption key and the column master key determined by the encryption field, encrypt the value of the query parameter according to the encryption type and the decrypted column encryption key, encapsulate the encrypted query parameter into the access request message, and forward it to the second server;
[0022] The decryption module is configured to receive a response message from the second server, parse and decrypt the response message, and send the decrypted response message to the first server.
[0023] In a third aspect, the present invention provides an electronic device comprising a memory and a processor, and computer instructions stored in the memory and executed on the processor, wherein when the computer instructions are executed by the processor, the method described in the first aspect is performed.
[0024] In a fourth aspect, the present invention provides a computer-readable storage medium for storing computer instructions, wherein when the computer instructions are executed by a processor, the method described in the first aspect is performed.
[0025] Compared with the prior art, the present invention has the following beneficial effects:
[0026] The present invention provides a table field level encryption and security access control method and system. When a first server and a second server access data, a transparent gateway is constructed between the two servers. During the message forwarding process, the transparent gateway uniformly manages the column master key, realizes the centralized storage, rotation, status update, etc. of the column master key, avoids the propagation of the column master key, and solves the risk of leakage.
[0027] The present invention provides a table field level encryption and security access control method and system, which provides a virtual username and password connection gateway without leaking the real database username and password, thereby reducing the risk of spreading the real username and password; and proposes a multi-factor based identity authentication method, sets flexible access rules, ensures the reliability of identity, and effectively resists high-risk SQL operations.
[0028] Advantages of additional aspects of the present invention will be given in part in the following description, and in part will become obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0030] Figure 1 A schematic diagram of a table field level encryption and secure access control method provided in Example 1 of the present invention;
[0031] Figure 2 This is a log audit processing network topology diagram provided in Example 1 of the present invention. DETAILED DESCRIPTION
[0032] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0033] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0034] It should be noted that the terms used herein are only for describing specific embodiments, and are not intended to limit exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that the terms "include" and "have" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0035] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other.
[0036] Example 1
[0037] like Figure 1 As shown, this embodiment provides a table field level encryption and security access control method, which is applied on the gateway side, including:
[0038] Connecting to the first server through the virtual login password and receiving an access request message from the first server;
[0039] Parse the access request message to obtain the query parameter to be encrypted and its value, and decrypt the ciphertext of the column encryption key according to the encryption type, the ciphertext of the column encryption key and the column master key determined by the encryption field, encrypt the value of the query parameter according to the encryption type and the decrypted column encryption key, encapsulate the encrypted query parameter into the access request message, and forward it to the second server;
[0040] A response message from the second server is received, the response message is parsed and decrypted, and the decrypted response message is sent to the first server.
[0041] In this embodiment, taking the data access between the client and the SQL database server as an example, a transparent gateway is built between the client and the SQL database server to realize the data access request and response between the application server and the database server. The gateway can monitor the TCP traffic of multiple network cards and ports on the client, or monitor a single network card and forward the traffic to different SQL Server servers.
[0042] As an optional implementation, the gateway can share the same server with SQL Server, so the gateway listens to port 2433 by default, and the administrator can manually configure the listening network card and port information.
[0043] In this embodiment, a virtual login password is used to connect to the client, an encrypted channel is established with the client, and an access request message from the client is received; by providing a virtual login password without exposing the real database username and password, the risk of spreading the real username and password is reduced.
[0044] As an optional implementation, password verification is achieved by mapping a virtual login password with a real database user name password.
[0045] As an optional implementation method, the virtual username and password are centrally managed by the gateway, and the mapping relationship can be modified at any time.
[0046] In this embodiment, in addition to the virtual username and password verification, a multi-factor authentication method based on IP address verification, login time verification, login machine name verification and login program verification is also used to establish a connection with the client;
[0047] Specifically: IP address verification: set access rules (black and white lists) based on the source IP address of the TCP protocol in the access request message; such as setting rules for a single IP address, IP address range or CIDR block.
[0048] Login time verification: Set access rules based on the client's login time, such as allowing access only during working hours.
[0049] Login machine name verification: Parse the Login7 message of the TDS protocol, obtain the login machine name, and decide whether to deny access based on the pre-configured machine name verification rules.
[0050] Login program verification: Parse the Login7 message of the TDS protocol, obtain the login program name, and decide whether to deny access based on the pre-configured program name verification rules.
[0051] In this embodiment, since there is a security risk when the client transmits plain text to the gateway, an encrypted channel is enabled between the client and the gateway; the System.Net.Security.SslStream type of the .NET Framework is used to establish a TLS encrypted channel between the client and the gateway.
[0052] As an optional implementation, if performance is a priority, the non-secure connection option can be enabled, and the TLS channel will no longer be used to transmit messages between the client and the gateway; however, it should be noted that even if the non-secure connection option is enabled, considering security issues, the TDSLogin7 message of the client login process will also use the TLS channel to transmit the username, password, etc.
[0053] In this embodiment, after receiving the access request message from the client, the upper layer TDS protocol is parsed, and the processed TDS message is forwarded to the designated SQL Server server according to the pre-configured access policy and encrypted query parameters;
[0054] The encryption process of query parameters includes: since TDS messages that can execute SQL statements include Rpc messages and SQLBatch messages, the gateway program needs to be able to parse Rpc messages and SQLBatch messages and determine the message formats of the two messages; among them, Rpc messages can execute SQL statements and stored procedures; SQLBatch can only execute SQL statements without query parameters.
[0055] Use the Microsoft.SqlServer.TransactSql.ScriptDom library to parse the syntax tree of the SQL statement to obtain the field name and value of the query parameter. Then use the sp_describe_parameter_encryption system stored procedure of SQL Server to determine whether the query parameter field is an encrypted field, as well as the encryption type of the encrypted field (Deterministic, Randomized), the ciphertext of the column encryption key, the fingerprint information of the column master key, and other metadata information.
[0056] If the query parameter belongs to an encrypted field, its value needs to be encrypted. Specifically, the column master key is obtained from the local MySQL database or certificate repository according to the fingerprint of the column master key, the ciphertext of the column encryption key is decrypted according to the column master key, and then according to the encryption type (Deterministic, Randomized) of the encrypted field, a random vector or a deterministic vector is selected. Finally, the AES (256-bit) encryption algorithm and the decrypted column encryption key are used to encrypt the value of the query parameter.
[0057] Encapsulate the encrypted query parameter ciphertext into the access request message, serialize the modified TDS message into the System.IO.MemoryStream stream, and complete the modification of the TDS message body.
[0058] It should be noted that the ciphertext of the query parameter value cannot be directly written into the SQL statement. The query parameter metadata information needs to be modified. For example, the parameter type needs to be changed from the original VARCHAR, NUMBER, etc. to the VARBINARY type, and the query parameter value needs to be changed to the PLP encoding format (only one PLP Chunk is required).
[0059] In this embodiment, since the SQL database stores ciphertext, constant queries of encrypted fields (for example: FieldA=123AND FiledB=”Value”) cannot be executed correctly, and the constant query needs to be converted into a parameter query with encrypted metadata; and if it is a SQLBatch message, the message type also needs to be converted into an Rpc message.
[0060] Specifically, after parsing the SQL text and obtaining the query field, table, mode and other information, an SQL text for querying field metadata is issued to SQL Server to obtain the field's Type, MaxLength, Precision, Scale, EncryptionType and other metadata, and to construct query parameters, thereby encrypting the query parameters using the above steps.
[0061] In this embodiment, the encrypted query parameters are encapsulated into an access request message and forwarded to the SQL database server, so that the SQL database server responds to the access request message, and receives a response message from the SQL database server, and transmits the response message back to the client according to the preconfigured policy and the decrypted query result.
[0062] The decryption process of the query result includes: parsing the TabularResult message of the TDS response message to obtain the encryption metadata of the column, including whether the field is an encrypted field, the encryption type of the field (Deterministic, Randomized), the ciphertext of the column encryption key, and the fingerprint information of the column master key;
[0063] According to the fingerprint information of the column master key, the column master key is obtained from the local MySQL database or certificate warehouse, and the ciphertext of the column encryption key is decrypted according to the column master key. Then, according to the encryption type (Deterministic, Randomized) of the encrypted field, a random vector or a deterministic vector is selected. Finally, the AES (256-bit) encryption algorithm and the decrypted column encryption key are used to decrypt the query result and obtain the execution result of the SQL statement.
[0064] After obtaining the plain text of the query result, write the plain text into the TDS message body, serialize the modified TDS message into the System.IO.MemoryStream stream, and complete the modification of the TDS message body.
[0065] Since the query result has been decrypted, the corresponding encrypted metadata in ColMetaData of the TabularResult message is deleted, and the query result type is restored from the VARBINARY type to the actual type of the field (such as VARCHAR, NUMBER, etc.).
[0066] In the TDS protocol, although the stored procedure's return message ReturnValue contains the encryption type (Deterministic, Randomized) of the OUT parameter, it does not contain the ciphertext of the column encryption key and the fingerprint information of the column master key. Therefore, if you use the ADO.NET client to directly access SQL Server, you cannot decrypt the stored procedure's OUT parameter.
[0067] Then, in this embodiment, the process of implementing the stored procedure OUT parameter decryption through the transparent gateway is to pre-cache the query result of sp_describe_parameter_encryption before calling the stored procedure, and when the response result ReturnValue message is obtained, directly use the previously cached column encryption key, thereby implementing the decryption processing of the OUT parameter.
[0068] In this embodiment, unified management of column master keys is implemented through a transparent gateway, specifically including: centralized storage of column master keys, rotation of column master keys, and update of column master key status;
[0069] Among them, the column master key is stored centrally; the column master key is centrally stored on the transparent gateway side, supporting MySQL relational database storage. At the same time, if the gateway program runs on the Windows Server server, it also supports Windows certificate store storage.
[0070] The database security administrator needs to export the column master key from SQL Server in TripleDES-SHA1 encrypted format and then import it into the transparent gateway.
[0071] After the gateway program parses the TDS protocol to obtain the column encryption metadata, it locates the specific location of the certificate based on the certificate fingerprint (Thumprint) of the obtained metadata.
[0072] Column master key rotation: A batch program executed once a day performs the column master key rotation task some time before the column master key expiration date.
[0073] Master key rotation uses PowerShell's Sql Server module, New-SqlColumnMasterKey, Invoke-SqlColumnMasterKeyRotation, Complete-SqlColumnMasterKeyRotation, Remove-SqlColumnMasterKey and other commands to complete the column master key rotation task.
[0074] If the key rotation fails, the next time the batch program is started, it will try to rotate again. If the rotation still cannot be completed before the expiration date, the system log will be recorded to remind the administrator to manually rotate the column master key.
[0075] The status of the old column master key is updated; after the column master key expires, the batch program executed once a day updates the certificate status to invalid; and the invalidated column master key cannot be used.
[0076] In this embodiment, the method also includes dangerous behavior interception, including: DDL statement interception, DML statement interception, query result row number control, user login failure number control, etc.;
[0077] Among them, DDL statement interception; using Microsoft's Microsoft.SqlServer.TransactSql.ScriptDom library, parse the SQL text, obtain the statement type of the SQL text (DDL statement), DDL operation objects database, table, view, trigger, schema, etc., DDL operation types alter, create, drop, etc., according to the pre-set rules of the logged-in user, decide whether to deny access and issue an alarm.
[0078] DML statement interception: use Microsoft's Microsoft.SqlServer.TransactSql.ScriptDom library to parse SQL text, obtain the statement type (DML statement), operation object table name, operation type CRUD, and decide whether to deny access and issue an alarm based on the pre-set rules of the logged-in user.
[0079] Control the number of query result rows; parse the TabularResult message of TDS, obtain the number of query results in the Done Token, and decide whether to intercept the number of query results and issue an alarm based on pre-set rules.
[0080] Control the number of user login failures: Set the maximum number of user login failures. If the number of login failures exceeds the set threshold, the client will be prohibited from connecting again within a certain period of time.
[0081] Other interception rules; such as intercepting Update statements and Delete statements without query conditions.
[0082] In this embodiment, all access behaviors to the transparent gateway are recorded, and the access records (such as SQL text, binding parameters, query results, etc.) are viewed in a graphical interface; Figure 2 The network topology diagram of log audit processing shown in the figure shows that in order not to affect the performance of the gateway, TDS messages are sent to the kafka cluster, and the batch program records the SQL text and restores the binding parameters, etc., for easy viewing. The contents of the log audit include: execution time, global session ID, client IP address, service name, client machine name, called stored procedure name, ID, transaction, SQL execution result, number of SQL returned records, SQL feature Hash, SQL execution time, SQL statement type, SQL statement (including binding parameters), data flow size, etc.
[0083] Example 2
[0084] This embodiment provides a table field level encryption and security access control system, including:
[0085] A communication module, configured to connect to the first server through a virtual login password and receive an access request message from the first server;
[0086] an encryption module configured to parse the access request message, obtain the query parameter to be encrypted and its value, and decrypt the ciphertext of the column encryption key according to the encryption type, the ciphertext of the column encryption key and the column master key determined by the encryption field, encrypt the value of the query parameter according to the encryption type and the decrypted column encryption key, encapsulate the encrypted query parameter into the access request message, and forward it to the second server;
[0087] The decryption module is configured to receive a response message from the second server, parse and decrypt the response message, and send the decrypted response message to the first server.
[0088] It should be noted that the above modules correspond to the steps described in Example 1, and the examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the contents disclosed in the above Example 1. It should be noted that the above modules, as part of the system, can be executed in a computer system such as a set of computer executable instructions.
[0089] In further embodiments, there is also provided:
[0090] An electronic device includes a memory and a processor, and computer instructions stored in the memory and executed on the processor, wherein when the computer instructions are executed by the processor, the method described in Embodiment 1 is performed. For the sake of brevity, it will not be described in detail here.
[0091] It should be understood that in this embodiment, the processor may be a central processing unit CPU, and the processor may also be other general-purpose processors, digital signal processors DSP, application-specific integrated circuits ASIC, off-the-shelf programmable gate arrays FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0092] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A portion of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.
[0093] A computer-readable storage medium is used to store computer instructions, and when the computer instructions are executed by a processor, the method described in Example 1 is completed.
[0094] The method in Example 1 can be directly embodied as a hardware processor, or a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it is not described in detail here.
[0095] Those skilled in the art will appreciate that the units, i.e., algorithm steps, of the various examples described in conjunction with this embodiment can be implemented in electronic hardware or in a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0096] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A table field level encryption and security access control method, characterized in that: include: Connecting to the first server through the virtual login password and receiving an access request message from the first server; Parse the access request message to obtain the query parameter to be encrypted and its value, and decrypt the ciphertext of the column encryption key according to the encryption type, the ciphertext of the column encryption key and the column master key determined by the encryption field, encrypt the value of the query parameter according to the encryption type and the decrypted column encryption key, encapsulate the encrypted query parameter into the access request message, and forward it to the second server; Encapsulate the encrypted query parameters into the access request message, and modify the query parameter metadata type to encapsulate the encrypted query parameters into the SQL statement in the access request message, thereby completing the modification of the message body; When encapsulating the plaintext of the decrypted response message into the response message, the encryption metadata is deleted and the field type is restored; receiving a response message from the second server, parsing and decrypting the response message, and sending the decrypted response message to the first server; When the first server and the second server access data, a transparent gateway is built between the two servers. During the message forwarding process, the transparent gateway uniformly manages the column master key. Column master keys are managed in a unified manner, including centralized storage, rotation, and status update of column master keys. The column master key fingerprint is determined based on the analysis of the access request message to obtain the corresponding column master key and decrypt the ciphertext of the column encryption key. The database security administrator exports the column master key from SQL Server in TripleDES-SHA1 encrypted format and then imports it into the transparent gateway; Propose a multi-factor authentication method, set flexible access rules, ensure the reliability of identity, and effectively resist high-risk SQL operations.
2. A table field level encryption and security access control method as claimed in claim 1, characterized in that: After connecting to the first server, an encrypted channel is established with the first server to receive an access request message. The connection method with the first server includes a virtual login password, IP address verification, login time verification, login machine name verification or login program verification.
3. A table field level encryption and security access control method as claimed in claim 1, characterized in that: In the process of parsing and decrypting the response message, the encryption metadata of the column is obtained, including the encrypted field, encryption type, ciphertext of the column encryption key, and column master key fingerprint. The corresponding column master key is retrieved according to the column master key fingerprint to decrypt the ciphertext of the column encryption key. The response message is decrypted according to the encryption type and the decrypted column encryption key.
4. A table field level encryption and security access control method as claimed in claim 1, characterized in that: The control method further includes decrypting an OUT parameter of the stored procedure, parsing a response message of the stored procedure to obtain an encryption type, and decrypting the OUT parameter using a pre-cached column encryption key.
5. A table field level encryption and security access control method as claimed in claim 1, characterized in that: The control method also includes dangerous behavior interception, which includes DDL statement interception, DML statement interception, query result row number control, and login failure number control.
6. A table field level encryption and security access control system, using a table field level encryption and security access control method as claimed in claim 1, characterized in that: include: A communication module, configured to connect to the first server through a virtual login password and receive an access request message from the first server; an encryption module configured to parse the access request message, obtain the query parameter to be encrypted and its value, and decrypt the ciphertext of the column encryption key according to the encryption type, the ciphertext of the column encryption key and the column master key determined by the encryption field, encrypt the value of the query parameter according to the encryption type and the decrypted column encryption key, encapsulate the encrypted query parameter into the access request message, and forward it to the second server; The decryption module is configured to receive a response message from the second server, parse and decrypt the response message, and send the decrypted response message to the first server.
7. An electronic device, characterized in that: The method comprises a memory and a processor, and computer instructions stored in the memory and executed on the processor, wherein when the computer instructions are executed by the processor, the method according to any one of claims 1 to 5 is completed.
8. A computer-readable storage medium, characterized in that: Used to store computer instructions, which, when executed by a processor, complete the method described in any one of claims 1 to 5.
Citation Information
Patent Citations
Method and system for access of universal encrypted database in cloud environment
CN107370725A
Data access control method and device and computer readable storage medium
CN113010911A