Operation Method, System, Storage Medium and Computer Terminal of Database

By using the atomic operation module to process database operation requests in the on-chip storage of the processor, the problem of low security in the trusted area of ​​the processor is solved, and high security of database operations is achieved.

CN114637743BActive Publication Date: 2025-05-30ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210148186.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-17
Publication Date
2025-05-30
Estimated Expiration
2042-02-17

AI Technical Summary

Technical Problem

In the prior art, the database runs in a trusted area of ​​the processor, but the security of database operations is not high and there is a lack of effective solutions.

Method used

By transmitting the ciphertext operation requests sent by the database engine to the on-chip storage of the processor, the atomic operation module is used to process the original operation requests in the trusted area, obtain the original operation results, and return the ciphertext operation results to the database engine, realizing the physical and software isolation between the database engine and the operation processing module.

Benefits of technology

It improves the security of database operations, ensures that the database can only access ciphertext data, enhances the security of data processing, and solves the problem of low security of database operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114637743B_ABST
    Figure CN114637743B_ABST
Patent Text Reader

Abstract

The present application discloses an operation method, system, storage medium, and computer terminal for a database. Among them, the method includes: transmitting a ciphertext operation request sent by a database engine to the on-chip storage of a processor, where the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request; processing the original operation request through an atomic operation module in the on-chip storage to obtain an original operation result, where the atomic operation module runs in the trusted area of the processor; returning the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result. The present application solves the technical problem in the related art that when the database runs in the trusted area of the processor, the security of operating on the database is not high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of database operations. Specifically, it relates to a method, system, storage medium, and computer terminal for operating a database. Background Art

[0002] Currently, cloud computing customers have increasingly urgent requirements for the security and reliability of public cloud data. The hardware features such as isolation or encryption provided by a security processor can ensure data security. However, the currently used processors themselves do not provide protection for the confidentiality and integrity of secure memory. Therefore, the security of operating a database running on a processor is not high.

[0003] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of the present application provide a method, system, storage medium, and computer terminal for operating a database, so as to at least solve the technical problem that in related technologies, when a database runs in the trusted area of a processor, the security of operating the database is not high.

[0005] According to one aspect of the embodiments of the present application, a method for operating a database is provided, including: transmitting a ciphertext operation request sent by a database engine to an on-chip storage of a processor, where the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request; processing the original operation request through an atomic operation module in the on-chip storage to obtain an original operation result, where the atomic operation module runs in the trusted area of the processor; and returning the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

[0006] According to another aspect of the embodiments of the present application, an operating system for a database is further provided, including: a database engine for sending a ciphertext operation request, where the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request; a processor connected to the database engine, including: an on-chip storage and a trusted area, where an atomic operation module runs in the trusted area, and the processor is used to transmit the ciphertext operation request to the on-chip storage, process the original operation request through the atomic operation module in the on-chip storage to obtain an original operation result, and return the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result; and the database engine is further used to operate on the data stored in the database based on the ciphertext operation result.

[0007] According to another aspect of the embodiments of the present application, there is also provided a computer-readable storage medium. The computer-readable storage medium includes a stored program. When the program runs, it controls the device where the computer-readable storage medium is located to execute the above-mentioned operation method of the database.

[0008] According to another aspect of the embodiments of the present application, there is also provided a computer terminal, including: a memory and a processor. The processor is used to run the program stored in the memory. When the program runs, it executes the above-mentioned operation method of the database.

[0009] In the embodiments of the present application, first, the ciphertext operation request sent by the database engine can be transmitted to the on-chip storage of the processor, where the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request; the original operation request is processed through the atomic operation module in the on-chip storage to obtain the original operation result, where the atomic operation module runs in the trusted area of the processor; the ciphertext operation result is returned from the on-chip storage to the database engine, where the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result. The database engine is used to operate on the data stored in the database based on the ciphertext operation result, realizing the physical and software isolation between the database engine and the module actually performing the operation processing, improving the security of data processing. The atomic operation module can be placed in the trusted area of the processor, and only ciphertext data can be accessed during the operation of the database engine, thereby improving the security of database operations, and further solving the technical problem of low security in operating the database in the trusted area of the processor in the related art. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0011] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing the operation method of the database according to the embodiments of the present application;

[0012] Figure 2 is a flowchart of an operation method of a database according to the embodiments of the present application;

[0013] Figure 3 is a schematic diagram of an encryption structure according to the embodiments of the present application;

[0014] Figure 4 is a schematic diagram of the overall architecture of a database operating system according to the embodiments of the present application;

[0015] Figure 5 It is a schematic diagram of an operation device of a database according to an embodiment of the present application;

[0016] Figure 6 It is a structural block diagram of a computer terminal according to an embodiment of the present application. Detailed implementation manners

[0017] In order to enable those skilled in the art of the present technology to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0018] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0019] First, some nouns or terms that appear in the process of describing the embodiments of the present application are applicable to the following explanations:

[0020] On-Chip Computing: On-Chip Computing is a trusted computing technology that uses the on-chip storage inside the CPU as the running memory and encrypts it when the memory page is swapped out to ordinary memory. Using the on-chip computing technology can achieve full memory encryption of software and prevent attacks on memory, such as bus sniffing, cold start, etc.

[0021] Trusted Execution Environment TEE (Trusted Execution Environment): The trusted execution environment is a secure area of the processor that ensures the confidentiality and integrity of the code and data loaded inside it. It provides an isolated execution space security area, and the trusted programs running in it can prevent infringement by ordinary application programs, operating systems (OS), or even virtual machine detectors (Hypervisor).

[0022] ARM TrustZone: ARM TrustZone is a secure computing environment unique to ARM processors. They allow users to define trusted regions of memory, the contents of which are protected for integrity and cannot be accessed by any software outside the trusted region.

[0023] Currently, the domestic cloud market's demand for confidential computing and domestic processors is closely related. On the one hand, using domestic processors can meet the security requirements of self-control and autonomy. On the other hand, it can also assign the issues of responsibilities and powers to domestic manufacturers. Against the background of the complex security issues faced by the cloud computing environment, it is necessary to utilize the TrustZone feature of domestic ARM processors to implement an encrypted database solution in the cloud environment scenario.

[0024] Among them, as a security extension of the ARM processor architecture, TrustZone provides isolation capabilities for a variety of physical resources at the hardware level, including memory isolation, interrupt isolation, device isolation, etc. However, ARM TrustZone itself does not provide confidentiality and integrity protection for secure memory. It is necessary to utilize the on-chip memory (OCM) configured on the ARM and introduce memory encryption technology to resist physical attacks.

[0025] The existing work on encrypted databases based on trusted chip technology is mainly divided into solutions based on trusted hardware and those based on homomorphic encryption. Among them, the mainstream solutions based on trusted hardware mainly include EnclaveDB (Enhanced Key Code Database), StealthDB (Hidden Database), Cipherbase (Encrypted Database), and DBStore (Warehouse Management System). EnclaveDB runs a complete in-memory database in SGX (Software Guard Extensions, instruction extensions) and relies on the memory encryption and integrity checks provided by SGX to protect the database data. StealthDB and Cipherbase choose not to modify existing commercial databases but to extend the database through user-defined functions (UDFs). They use the ciphertext calculation module running in SGX to decrypt the ciphertext. Throughout the process, the database never comes into contact with the plaintext data. DBStore is a mobile security database solution based on TrustZone (hardware architecture), using SQLite (embedded database engine) as the database engine, but it does not implement an encryption solution for physical memory and cannot defend against physical attacks.

[0026] Microsoft Azure SQL Database uses SGX as a trusted hardware mechanism. On the database server, the data is always in an encrypted state, and only in the trusted environment enclave is the ciphertext decrypted, computed, and re-encrypted. It also provides functions such as remote authentication for clients.

[0027] DBStore: In academic work, DBStore uses the trusted hardware mechanism TrustZone provided by ARM to protect the database SQLite on mobile devices. This work runs SQLite in Trustzone, isolating it from untrusted software.

[0028] Azure SQL Database (a database in cloud computing) is an encrypted database based on SGX. It can use enclaves (critical code) to protect atomic operations on ciphertext. The database cannot access plaintext data and can only operate on ciphertext data by calling atomic operations. Since the chips cannot be domesticated, it is difficult to achieve the security goal of being self - controllable.

[0029] In addition, due to the technical differences between SGX and ARM TrustZone, the trusted execution environment mechanisms and security guarantees they provide are different. The encrypted database solution based on SGX cannot be directly ported to TrustZone and cannot directly achieve the same security level. The DBStore solution runs SQLite directly in Trustzone, with changes and adaptations to the database. In addition, it relies on isolated memory, but since memory encryption is not performed, it does not defend against physical attacks.

[0030] To solve the above problems, this application provides a database operation method. The database can be set in an untrusted execution environment, and an atomic operation module is set in a trusted execution environment for actual operations, so that the database can only access ciphertext data and is difficult to access plaintext data, thereby improving data security.

[0031] Embodiment 1

[0032] According to the embodiments of this application, an embodiment of a database operation method is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer - executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0033] The method embodiments provided by the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the database operation method is shown. As Figure 1As shown, the computer terminal 10 (or mobile device 10) may include one or more processors 102 (shown as 102a, 102b, ……, 102n in the figure) (the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than those Figure 1 shown in, or have a different configuration from that Figure 1 shown.

[0034] It should be noted that the above one or more processors 102 and / or other data processing circuits may generally be referred to as "data processing circuits" herein. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device). The data processing circuit serves as a processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0035] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the operation method of the database in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned operation method of the database. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0036] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0037] The display can be, for example, a touch-screen Liquid Crystal Display (LCD), which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0038] It should be noted here that, in some alternative embodiments, the above-mentioned Figure 1 illustrated computer device (or mobile device) may include hardware elements (including circuits), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware elements and software elements. It should be pointed out that Figure 1 is only an example of a specific specific instance and is intended to illustrate the types of components that may exist in the above-mentioned computer device (or mobile device).

[0039] Under the above operating environment, the present application provides an operation method for the database as shown in Figure 2 the figure. Figure 2 is a flowchart of an operation method for a database according to an embodiment of the present application.

[0040] Step S202, transmit the ciphertext operation request sent by the database engine to the on-chip storage of the processor.

[0041] Among them, the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request.

[0042] The above-mentioned database engine can be a database query engine. The above-mentioned database engine can be in an untrusted execution environment, which is convenient for users to use flexibly.

[0043] The above-mentioned on-chip storage can store plaintext data. The above-mentioned on-chip storage can be used as the running memory of a trusted program, and can perform AES-GCM encryption on the memory pages leaving the on-chip storage and decrypt the swapped-in memory pages, so that the data stored in the on-chip storage is in plaintext form, while the data stored in other memories is in ciphertext form, which can solve the physical attack threat caused by the lack of memory encryption provided by ARM TrustZone. It can achieve the same, or even stronger, security guarantee as using SGX.

[0044] In an alternative embodiment, to improve the security of data operations, the original operation request can be encrypted to obtain a ciphertext operation request, and then the database engine in an untrusted execution environment is used to receive the ciphertext operation request, making it difficult for the database engine in the untrusted execution environment to directly access the unencrypted data, thereby improving data security. Among them, since the database engine can only access the data after encryption processing such as the ciphertext operation request during the data processing process, therefore, it does not need to be limited to using a specific database engine, making the database engine have strong applicability and compatibility.

[0045] In another alternative embodiment, after obtaining the original operation request, the original operation request can be stored in the on-chip storage of the processor, and the target operation operator in the atomic operation program can read the original operation request stored in the on-chip storage to obtain the original operation result corresponding to the target operation request, and store the original operation result in the on-chip storage.

[0046] In another alternative embodiment, the atomic operation module can decrypt the received ciphertext operation request to obtain the original operation request. After obtaining the original operation request, the original operation request can be first stored in the on-chip storage of the processor. The on-chip storage can store multiple original operation requests, and the on-chip storage can process the original operation requests in the order in which they are stored. The target operation request can be the original operation request currently being processed by the on-chip storage. By processing the target operation request, the current operation result corresponding to the currently processed original operation request can be obtained, and the current operation result is stored in the on-chip storage. When it is necessary to obtain the original operation result corresponding to the original operation request, the original operation result can be obtained from the on-chip storage.

[0047] In another alternative embodiment, to improve the security during the data query process of the client, the client can send the original operation request through an encrypted channel and encrypt the original operation request in the encrypted channel to obtain a ciphertext operation request.

[0048] In yet another alternative embodiment, an encryption type extension module can be set in the database engine to extend the encryption type of the database system, forward the operations of the encryption type to the trusted atomic operation module, and process the returned results. The extended design enables the encryption database solution to have strong applicability and compatibility and does not need to be limited to a specific database.

[0049] Step S204, process the original request through the atomic operation module in the on-chip storage to obtain the original operation result.

[0050] Among them, the atomic operation module runs in the trusted area of the processor.

[0051] The above atomic operation module can be in a trusted execution environment. For example, the atomic operation module can run in the secure world of ARM TrustZone, isolated from untrusted operating systems, etc., to prevent the leakage of confidential information at the software level. Among them, the atomic operation module can be an atomic operation program.

[0052] The above atomic operation module can perform arithmetic logic operations, comparison operations, etc., can receive the ciphertext operands and operators input by the database engine, perform corresponding operations after decrypting the operands, and encrypt and return the results to the database engine.

[0053] The security of the on-chip storage above is relatively high. Therefore, the original operation request can be processed by the atomic operation module in the on-chip storage to obtain the original operation result.

[0054] In an alternative embodiment, to improve the security of data, after obtaining the ciphertext operation request, the original operation request can be processed by the on-chip storage with relatively high security according to the ciphertext operation request to obtain the original operation result. To prevent data leakage, the original operation result can be encrypted by the atomic operation module in the on-chip storage to obtain the above ciphertext operation result.

[0055] Among them, the atomic operation module runs in the trusted area of the processor, and the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result.

[0056] Step S206, return the ciphertext operation result from the on-chip storage to the database engine.

[0057] Among them, the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

[0058] In an alternative embodiment, the ciphertext operation result can be returned to the database engine. The database engine can operate on the data stored in the database according to the ciphertext operation result. Specifically, the database engine can send the ciphertext data stored in the database to the client according to the ciphertext operation result.

[0059] It should be noted that this solution does not make invasive modifications to the database engine, can be compatible with existing mature database systems, is not limited to specific databases, and has stronger flexibility.

[0060] Through the above steps, first, the ciphertext operation request sent by the database engine can be transmitted to the on-chip memory of the processor. The ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request. In the on-chip memory, the original operation request is processed by the atomic operation module to obtain the original operation result. The atomic operation module runs in the trusted area of the processor. The ciphertext operation result is returned from the on-chip memory to the database engine. The ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result. The database engine is used to operate on the data stored in the database based on the ciphertext operation result, which realizes the isolation of the database engine from the module actually performing operation processing at the physical level and software level, improves the security of data processing, and the atomic operation module can be placed in the trusted area of the processor. Moreover, only ciphertext data can be accessed during the operation of the database engine, thereby improving the security of database operations, and further solving the technical problem of low security in operating the database in the trusted area of the processor in the related art.

[0061] In the above embodiment of the present application, processing the original operation request by the atomic operation module to obtain the original operation result includes: decrypting the ciphertext operation request by the decryption operator included in the atomic operation module to obtain the original operation request; processing the original operation request by the target operation operator included in the atomic operation module to obtain the original operation result; encrypting the original operation result by the encryption operator included in the atomic operation module to obtain the ciphertext operation result.

[0062] The above target operation operator can be an operator corresponding to arithmetic logic operations, an operator corresponding to comparison operations, etc.

[0063] In an alternative embodiment, the atomic operation module can decrypt the ciphertext operation request through the decryption operator it includes in a trusted environment to obtain the original operation request. The original operation request can be a request for arithmetic logic operations, comparison operations, etc. The target operation operator corresponding to the original operation request can be obtained. For example, if the original operation request is to perform arithmetic logic operations on the target character, the operation operator corresponding to the arithmetic logic operation can be used to perform operations on the target character to obtain the original operation result. If the original operation request is to perform a comparison operation on any two characters in the target character, the operation operator corresponding to the comparison operation can be used to perform operations on the target character to obtain the original operation result.

[0064] Further, in order to enable the original operation result to be transmitted in the untrusted area, the original operation result can be encrypted to obtain the ciphertext operation result. The database engine can operate on the data in the database according to the ciphertext operation result and send it to the client.

[0065] In the above embodiments of the present application, the original operation request includes: a target operand and at least one target operator. Among them, the original operation request is processed by the target operation operator included in the atomic operation module to obtain an original operation result, including: obtaining the operator corresponding to each target operator from multiple operators included in the atomic operation module; combining the operators corresponding to at least one target operator to obtain a target operation operator; and processing the target operand through the target operation operator to obtain the original operation result.

[0066] The above-mentioned target operand can be a character to be calculated, such as a number or a letter. The above-mentioned target operator can be operators such as addition, subtraction, multiplication, division, greater than, less than, etc.

[0067] The above-mentioned multiple operators can be fine-grained atomic operation operators, and any combination can be made between different operators to form a more complex target operation operator. Since the granularity of the operator is small and stateless, multiple copies of the operator can be run to provide services for the database, and it has good scalability and isolation.

[0068] In an alternative embodiment, the operator corresponding to each target operator can be obtained from multiple operators included in the atomic operation module, and multiple operators can be combined to obtain a more complex target operation operator, so as to process the target operand through the target operation operator to obtain the original operation result.

[0069] In the above embodiments of the present application, when there are multiple target operators, obtaining the operator corresponding to each target operator from multiple operators included in the atomic operation module includes: saving multiple operators as multiple copies; and obtaining the operator corresponding to each target operator from each copy.

[0070] In an alternative embodiment, multiple operators can be saved as multiple copies, and the corresponding operator for each target operator can be provided through multiple copies, which can have better scalability and isolation, and improve the security and flexibility in the data operation process.

[0071] In the above embodiments of the present application, before decrypting the ciphertext operation request through the decryption operator included in the atomic operation module to obtain the original operation request, the method further includes: detecting whether the client sending the ciphertext operation request is successfully authenticated; and when it is detected that the client is successfully authenticated, decrypting the ciphertext operation request through the decryption operator to obtain the original operation request.

[0072] In an alternative embodiment, when the cloud service receives the ciphertext operation request sent by the client, it can first authenticate the client to detect whether the client has the operation permission. Specifically, the client can be authenticated by logging in, and the login authentication of the client can be detected through key management to check whether the client has the operation permission. When it is detected that the client authentication is successful, the ciphertext operation request can be decrypted by the decryption operator in the atomic operation module to obtain the original operation request. By authenticating the client, it is possible to prevent unauthenticated clients from using the database engine, thereby improving the security of the database engine.

[0073] In the above embodiment of the present application, the method further includes: when it is detected that the remaining storage space in the on-chip storage is less than a preset value, encrypting the original data stored in the on-chip storage to obtain ciphertext data; and storing the ciphertext data in the memory.

[0074] The above preset value can be set according to the remaining storage control space reserved by the user.

[0075] In an alternative embodiment, since the storage space of the on-chip storage is limited, when the remaining storage space in the on-chip storage is less than the preset value, that is, when the on-chip storage space is about to be exhausted, the original data stored in the on-chip storage can be moved, and it can be moved to other spaces. To ensure data security, before moving to other spaces, the original data to be moved can be encrypted to obtain ciphertext data, and the ciphertext data can be moved. Specifically, the ciphertext data can be stored in the memory to release the storage space of the on-chip storage, and it is necessary to ensure that only ciphertext data appears in the memory, so that the database query engine and high-privilege users can access the ciphertext data in the memory, but it is difficult to access the plaintext data in the on-chip storage.

[0076] In another alternative embodiment, since there is an untrusted database administrator (DBA) who has the management permission of the database and can access the memory without restriction, it is necessary to encrypt the data in the memory so that only ciphertext data appears in the memory, thereby improving data security. Since the DBA has physical access to the memory device, it may carry out physical attacks such as bus sniffing. Therefore, only ciphertext data can be stored in the memory, and there is no need to store plaintext data in the memory, which can improve the security of the memory. In addition, during the data processing process, there may also be an untrusted operating system of the cloud server, a virtual machine detector, or virtual machines of other tenants, which may be exploited by malicious programs and steal the confidential data in the memory after being attacked. Therefore, it is necessary to save ciphertext data in the memory to avoid being maliciously stolen.

[0077] As Figure 3The figure shows a schematic diagram of an encryption structure, which includes three regions, namely, a trusted region, an untrusted region, and an encryption region. Among them, the trusted region includes an atomic operation program and on-chip storage, the untrusted region includes a database query engine, and the encryption region includes memory. The atomic operation program (the above-mentioned atomic operation module) can read the encrypted data from the memory, decrypt it and perform calculations in the trusted on-chip storage. After the calculation is completed, the result can be re-encrypted and written back to the memory. Since the on-chip storage space is limited, when it is exhausted, a page replacement operation can be performed, that is, the data in the on-chip storage is stored in other memories. When swapping out, the data in the page can be encrypted to ensure that only ciphertext data exists in the memory, so as to improve the security of the data.

[0078] In the above embodiment of the present application, the method further includes: reading ciphertext data from the memory; decrypting the ciphertext data to obtain the original data; storing the original data in the on-chip storage.

[0079] In an alternative embodiment, when it is necessary to process the ciphertext data, the ciphertext data can be read from the memory, decrypted to obtain the original data, and the original data is stored in the on-chip storage for operation to improve the security of the data.

[0080] In the above embodiment of the present application, before transmitting the ciphertext operation request sent by the database engine to the on-chip storage of the processor, the method further includes: obtaining the ciphertext operation request from the database engine through the request forwarding module, where the request forwarding module is installed in the database engine; forwarding the ciphertext operation request to the atomic operation module through the request forwarding module.

[0081] The above request forwarding module can be installed in the database engine.

[0082] In an alternative embodiment, after the database engine receives the ciphertext operation request, the ciphertext operation request can be obtained from the database engine through the request forwarding module and forwarded to the trusted atomic operation module. Specifically, the processing status of multiple atomic operation modules can also be recorded in the request forwarding module, and a suitable atomic operation module can be selected for forwarding according to the processing status of the multiple atomic operation modules. Specifically, a relatively idle atomic operation module can be selected for forwarding to improve the processing efficiency of the atomic operation module.

[0083] In the above embodiment of the present application, returning the ciphertext operation result from the on-chip storage to the database engine includes: receiving the ciphertext operation result sent by the atomic operation module through the request forwarding module; forwarding the ciphertext operation result to the database engine through the request forwarding module.

[0084] In an alternative embodiment, after obtaining the ciphertext operation result, the atomic operation module may send the ciphertext operation result from the on-chip storage to the request forwarding module. The request forwarding module may forward the obtained ciphertext operation result to the database engine. By forwarding the data between the database engine and the atomic operation module through the request forwarding module, the data processing efficiency can be improved without increasing it.

[0085] As Figure 4 Shown is a schematic diagram of the overall architecture of the database operating system, which includes two regions, namely the trusted region and the untrusted region. Among them, the trusted region includes a client, login authentication, key management, and atomic operation program, and the untrusted region includes encryption type extension and database query engine. The specific operation process is as follows: The client can first perform login authentication in the cloud server. Through key management, it can be verified whether the authentication is passed. After the authentication is passed, the client can send the original operation request through the encrypted channel. In the encrypted channel, the original operation request can be encrypted to generate a ciphertext operation request. The database query engine can forward the ciphertext operation request to the atomic operation program for operation. Specifically, the trusted atomic operation program can be determined through the encryption type extension, and the ciphertext operation request can be forwarded to the atomic operation program. After receiving the ciphertext operation request, the atomic operation program can decrypt the ciphertext operation request to obtain the original operation request, execute the corresponding operation according to the original operation request, and obtain the original operation result. The original operation result can be encrypted to obtain the ciphertext operation result, and the ciphertext operation result can be fed back to the database query engine. The database query engine can return the ciphertext operation result to the client through the encrypted channel. In the encrypted channel, the ciphertext operation result can be decrypted to obtain the original operation result, so that the client can obtain the original operation result.

[0086] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0087] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present application.

[0088] Embodiment 2

[0089] According to an embodiment of the present application, there is also provided an operating device for a database for implementing the above-mentioned operating method of the database, as Figure 5 shown. The device includes: a receiving module 502, a processing module 504, and a feedback module 506.

[0090] The receiving module is configured to transmit the ciphertext operation request sent by the database engine to the on-chip storage of the processor, where the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request;

[0091] The processing module is configured to process the original operation request through an atomic operation module in the on-chip storage to obtain an original operation result, where the atomic operation module runs in the trusted area of the processor;

[0092] The feedback module is configured to return the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

[0093] It should be noted here that the above receiving module 502, processing module 504, and feedback module 506 correspond to steps S202 to S206 in Embodiment 1. The three modules and the corresponding steps have the same implemented examples and application scenarios, but are not limited to the content disclosed in the above Embodiment 1. It should be noted that the above modules, as part of the device, can run in the computer terminal 10 provided in Embodiment 1.

[0094] In the above embodiments of the present application, the processing module includes: a decryption unit, a processing unit, and an encryption unit.

[0095] Among them, the decryption unit is used to decrypt the ciphertext operation request through the decryption operator included in the atomic operation module to obtain the original operation request; the processing unit is used to process the original operation request through the target operation operator included in the atomic operation module to obtain the original operation result; the encryption unit is used to encrypt the original operation result through the encryption operator included in the atomic operation module to obtain the ciphertext operation result.

[0096] In the above embodiments of the present application, the original operation request includes: target operands and at least one target operator. The processing unit is further configured to obtain the operator corresponding to each target operator from multiple operators included in the atomic operation module; combine the operators corresponding to at least one target operator to obtain a target operator; and process the target operands through the target operator to obtain the original operation result.

[0097] In the above embodiments of the present application, when there are multiple target operators, the processing unit is further configured to save multiple operators as multiple copies; and obtain the operator corresponding to each target operator from each copy.

[0098] In the above embodiments of the present application, the device includes: a detection module.

[0099] Among them, the detection module is used to detect whether the client sending the ciphertext operation request is successfully authenticated; the decryption module is used to decrypt the ciphertext operation request through the decryption operator to obtain the original operation request when it is detected that the client is successfully authenticated.

[0100] In the above embodiments of the present application, the device includes: an encryption module and a storage module.

[0101] Among them, the encryption module is used to encrypt the original data stored in the on-chip storage to obtain ciphertext data when it is detected that the remaining storage space in the on-chip storage is less than a preset value; the storage module is used to store the ciphertext data in the memory.

[0102] In the above embodiments of the present application, the device includes: a reading module and a decryption module.

[0103] Among them, the reading module is used to read the ciphertext data from the memory; the decryption module is used to decrypt the ciphertext data to obtain the original data; the storage module is further used to store the original data in the on-chip storage.

[0104] In the above embodiments of the present application, the device further includes: an acquisition module and a forwarding module.

[0105] Among them, the obtaining module is used to obtain the ciphertext operation request from the database engine through the request forwarding module, where the request forwarding module is installed in the database engine; the forwarding module is used to forward the ciphertext operation request to the atomic operation module through the request forwarding module.

[0106] In the above embodiments of the present application, the feedback module includes: a receiving unit and a forwarding unit.

[0107] Among them, the receiving unit is used to receive the ciphertext operation result sent by the atomic operation module through the request forwarding module; the second forwarding unit is used to forward the ciphertext operation result to the database engine through the request forwarding module.

[0108] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as the schemes, application scenarios, and implementation processes provided in Embodiment 1, but are not limited to the schemes provided in Embodiment 1.

[0109] Embodiment 3

[0110] An embodiment of the present application may provide an operating system for a database, including:

[0111] A database engine, configured to send a ciphertext operation request, where the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request;

[0112] A processor, connected to the database engine, includes: on-chip storage and a trusted area, and an atomic operation module runs in the trusted area. The processor is configured to transmit the ciphertext operation request to the on-chip storage, process the original operation request through the atomic operation module in the on-chip storage to obtain an original operation result, and return the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result;

[0113] The database engine is further configured to operate on the data stored in the database based on the ciphertext operation result. In the above embodiments of the present application, the atomic operation module includes: a decryption operator, configured to decrypt the ciphertext operation request to obtain the original operation request; a target operation operator, configured to process the original operation request to obtain the original operation result; an encryption operator, configured to encrypt the original operation result to obtain the ciphertext operation result.

[0114] In the above embodiments of the present application, the system further includes: a client, configured to send a ciphertext operation request; an authentication server, communicatively connected to the client, configured to authenticate the client; an atomic operation module, communicatively connected to the authentication server, configured to decrypt the ciphertext operation request through the decryption operator to obtain the original operation request when the authentication server successfully authenticates the client.

[0115] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as those provided in Embodiment 1, including the application scenarios and implementation processes, but are not limited to the solutions provided in Embodiment 1.

[0116] Embodiment 4

[0117] An embodiment of the present application may provide a computer terminal, which may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal may also be replaced with a terminal device such as a mobile terminal.

[0118] Optionally, in this embodiment, the above computer terminal may be located in at least one of multiple network devices in a computer network.

[0119] In this embodiment, the above computer terminal may execute the program code of the following steps in the operation method of the database: transmitting the ciphertext operation request sent by the database engine to the on-chip storage of the processor, where the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request; processing the original operation request through the atomic operation module in the on-chip storage to obtain the original operation result, where the atomic operation module runs in the trusted area of the processor; and returning the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

[0120] Optionally, Figure 6 is a structural block diagram of a computer terminal according to an embodiment of the present application. As Figure 6 shown, the computer terminal may include: one or more (only one is shown in the figure) processors and a memory.

[0121] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the operation method and device of the database in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, to implement the above operation method of the database. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories may be connected to Terminal A through a network. Examples of the above network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and their combinations.

[0122] The processor can call the information and application programs stored in the memory through a transmission device to execute the following steps: transmit the ciphertext operation request sent by the database engine to the on-chip storage of the processor, where the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request; process the original operation request through an atomic operation module in the on-chip storage to obtain the original operation result, where the atomic operation module runs in the trusted area of the processor; return the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

[0123] Optionally, the above-mentioned processor can also execute the program code of the following steps: decrypt the ciphertext operation request through the decryption operator included in the atomic operation module to obtain the original operation request; process the original operation request through the target operation operator included in the atomic operation module to obtain the original operation result; encrypt the original operation result through the encryption operator included in the atomic operation module to obtain the ciphertext operation result.

[0124] Optionally, the above-mentioned processor can also execute the program code of the following steps: obtain the operation operator corresponding to each target operator from multiple operation operators included in the atomic operation module; combine the operation operators corresponding to at least one target operator to obtain the target operation operator; process the target operand through the target operation operator to obtain the original operation result.

[0125] Optionally, the above-mentioned processor can also execute the program code of the following steps: save multiple operation operators as multiple copies; obtain the operation operator corresponding to each target operator from each copy.

[0126] Optionally, the above-mentioned processor can also execute the program code of the following steps: detect whether the client sending the ciphertext operation request is successfully authenticated; in the case of detecting that the client authentication is successful, decrypt the ciphertext operation request through the decryption operator to obtain the original operation request.

[0127] Optionally, the above-mentioned processor can also execute the program code of the following steps: in the case of detecting that the remaining storage space of the on-chip storage is less than a preset value, encrypt the original data stored in the on-chip storage to obtain ciphertext data; store the ciphertext data in the memory.

[0128] Optionally, the above-mentioned processor can also execute the program code of the following steps: read the ciphertext data from the memory; decrypt the ciphertext data to obtain the original data; store the original data in the on-chip storage.

[0129] Optionally, the above-mentioned processor may also execute the program code of the following steps: obtaining a ciphertext operation request from a database engine through a request forwarding module, where the request forwarding module is installed in the database engine; forwarding the ciphertext operation request to an atomic operation module through the request forwarding module.

[0130] Optionally, the above-mentioned processor may also execute the program code of the following steps: receiving a ciphertext operation result sent by the atomic operation module through the request forwarding module; forwarding the ciphertext operation result to the database engine through the request forwarding module.

[0131] By adopting the embodiment of the present application, an operation solution for a database is provided. First, a ciphertext operation request sent by a database engine can be transmitted to the on-chip storage of a processor, where the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request; the original operation request is processed through an atomic operation module in the on-chip storage to obtain an original operation result, where the atomic operation module runs in the trusted area of the processor; the ciphertext operation result is returned from the on-chip storage to the database engine, where the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result, realizing the isolation of the database engine from the module actually performing operation processing at the physical level and software level, improving the security of data processing. The atomic operation module can be placed in the trusted area of the processor, and only ciphertext data can be accessed during the operation of the database engine, thereby improving the security of database operation, and further solving the technical problem of low security in operating the database in the trusted area of the processor in the related art.

[0132] Those of ordinary skill in the art can understand that Figure 6 the structure shown is only schematic, and the computer terminal may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, and a mobile Internet device (Mobile Internet Devices, MID), a PAD and other terminal devices. Figure 6 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal may also include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 6 in the figure, or have a different configuration from that shown Figure 6 in the figure.

[0133] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, and the storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.

[0134] Embodiment 5

[0135] An embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the above storage medium can be used to store the program code executed by the operation method of the database provided in the above embodiment.

[0136] Optionally, in this embodiment, the above storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.

[0137] Optionally, in this embodiment, the storage medium is set to store program code for performing the following steps: transmitting the ciphertext operation request sent by the database engine to the on-chip storage of the processor, where the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request; processing the original operation request through the atomic operation module in the on-chip storage to obtain the original operation result, where the atomic operation module runs in the trusted area of the processor; returning the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

[0138] Optionally, the above storage medium is further set to store program code for performing the following steps: decrypting the ciphertext operation request through the decryption operator included in the atomic operation module to obtain the original operation request; processing the original operation request through the target operation operator included in the atomic operation module to obtain the original operation result; encrypting the original operation result through the encryption operator included in the atomic operation module to obtain the ciphertext operation result.

[0139] Optionally, the above storage medium is further set to store program code for performing the following steps: obtaining the operation operator corresponding to each target operator from the multiple operation operators included in the atomic operation module; combining the operation operators corresponding to at least one target operator to obtain the target operation operator; processing the target operand through the target operation operator to obtain the original operation result.

[0140] Optionally, the above storage medium is further configured to store program code for performing the following steps: saving multiple operation operators as multiple copies; obtaining the operation operator corresponding to each target operator from each copy.

[0141] Optionally, the above storage medium is further configured to store program code for performing the following steps: detecting whether the client sending the ciphertext operation request is successfully authenticated; decrypting the ciphertext operation request by a decryption operator to obtain the original operation request when it is detected that the client is successfully authenticated.

[0142] Optionally, the above storage medium is further configured to store program code for performing the following steps: encrypting the original data stored in the on-chip storage to obtain ciphertext data when it is detected that the remaining storage space in the on-chip storage is less than a preset value; storing the ciphertext data in the memory.

[0143] Optionally, the above storage medium is further configured to store program code for performing the following steps: reading the ciphertext data from the memory; decrypting the ciphertext data to obtain the original data; storing the original data in the on-chip storage.

[0144] Optionally, the above storage medium is further configured to store program code for performing the following steps: obtaining the ciphertext operation request from the database engine through a request forwarding module, where the request forwarding module is installed in the database engine; forwarding the ciphertext operation request to the atomic operation module through the request forwarding module.

[0145] Optionally, the above storage medium is further configured to store program code for performing the following steps: receiving the ciphertext operation result sent by the atomic operation module through the request forwarding module; forwarding the ciphertext operation result to the database engine through the request forwarding module.

[0146] An operation solution for a database is provided by adopting the embodiments of the present application. First, a ciphertext operation request sent by a database engine can be transmitted to the on-chip storage of a processor, where the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request; the original operation request is processed in the on-chip storage through an atomic operation module to obtain an original operation result, where the atomic operation module runs in the trusted area of the processor; the ciphertext operation result is returned from the on-chip storage to the database engine, where the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result, realizing the isolation of the database engine from the module actually performing operation processing at the physical and software levels, improving the security of data processing. The atomic operation module can be placed in the trusted area of the processor, and only ciphertext data can be accessed during the operation of the database engine, thereby improving the security of database operations, and further solving the technical problem that in the related art, the database runs in the trusted area of the processor and the security of operating on the database is not high.

[0147] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.

[0148] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0149] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0150] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0151] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0152] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0153] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for operating a database, characterized in that, it includes: Transmitting the ciphertext operation request sent by the database engine to the on-chip storage of the processor, where the ciphertext operation request is used to represent the operation request obtained by encrypting the original operation request; Processing the original operation request in the on-chip storage through the atomic operation module to obtain the original operation result, where the atomic operation module runs in the trusted area of the processor; Returning the ciphertext operation result from the on-chip storage to the database engine, where the ciphertext operation result is used to represent the operation result obtained by encrypting the original operation result, and the database engine is used to operate on the data stored in the database based on the ciphertext operation result.

2. The method according to claim 1, characterized in that, Processing the original operation request through the atomic operation module to obtain the original operation result includes: Decrypting the ciphertext operation request through the decryption operator included in the atomic operation module to obtain the original operation request; Processing the original operation request through the target operation operator included in the atomic operation module to obtain the original operation result; Encrypting the original operation result through the encryption operator included in the atomic operation module to obtain the ciphertext operation result.

3. The method according to claim 2, characterized in that, The original operation request includes: a target operand and at least one target operator, where processing the original operation request through the target operation operator included in the atomic operation module to obtain the original operation result includes: Obtaining the operation operator corresponding to each target operator from multiple operation operators included in the atomic operation module; Combining the operation operators corresponding to the at least one target operator to obtain the target operation operator; Processing the target operand through the target operation operator to obtain the original operation result.

4. The method according to claim 3, characterized in that, In the case where there are multiple target operators, obtaining the operation operator corresponding to each target operator from multiple operation operators included in the atomic operation module includes: Saving the multiple operation operators as multiple copies; Obtaining the operation operator corresponding to each target operator from each copy.

5. The method according to claim 2, characterized in that, Before decrypting the ciphertext operation request through the decryption operator included in the atomic operation module to obtain the original operation request, the method further includes: Detecting whether the client sending the ciphertext operation request is successfully authenticated; In the case where it is detected that the client is successfully authenticated, decrypting the ciphertext operation request through the decryption operator to obtain the original operation request.

6. The method according to claim 1, characterized in that, The method further includes: In the case where it is detected that the remaining storage space of the on-chip storage is less than a preset value, encrypting the original data stored in the on-chip storage to obtain ciphertext data; Storing the ciphertext data in the memory.

7. The method according to claim 6, wherein, the method further comprises: reading the ciphertext data from the memory; decrypting the ciphertext data to obtain the original data; storing the original data in the on-chip storage.

8. The method according to any one of claims 1 to 7, wherein, before transmitting the ciphertext operation request sent by the database engine to the on-chip storage of the processor, the method further comprises: obtaining the ciphertext operation request from the database engine through a request forwarding module, wherein the request forwarding module is installed in the database engine; forwarding the ciphertext operation request to the atomic operation module through the request forwarding module.

9. The method according to claim 8, wherein, returning the ciphertext operation result from the on-chip storage to the database engine includes: receiving the ciphertext operation result sent by the atomic operation module through the request forwarding module; forwarding the ciphertext operation result to the database engine through the request forwarding module.

10. An operating system of a database, wherein, comprises: a database engine for sending a ciphertext operation request, wherein the ciphertext operation request is used to represent an operation request obtained by encrypting an original operation request; a processor connected to the database engine, comprising: on-chip storage and a trusted area, wherein an atomic operation module runs in the trusted area, and the processor is used to transmit the ciphertext operation request to the on-chip storage, process the original operation request through the atomic operation module in the on-chip storage to obtain an original operation result, and return the ciphertext operation result from the on-chip storage to the database engine, wherein the ciphertext operation result is used to represent an operation result obtained by encrypting the original operation result; the database engine is further used to operate on the data stored in the database based on the ciphertext operation result.

11. The system according to claim 10, wherein, the atomic operation module comprises: a decryption operator for decrypting the ciphertext operation request to obtain the original operation request; a target operation operator for processing the original operation request to obtain the original operation result; an encryption operator for encrypting the original operation result to obtain the ciphertext operation result.

12. The system according to claim 11, wherein, the system further comprises: a client for sending a ciphertext operation request; a verification server communicatively connected to the client for authenticating the client; the atomic operation module communicatively connected to the verification server for decrypting the ciphertext operation request through the decryption operator to obtain the original operation request when the verification server authenticates the client successfully.

13. A computer-readable storage medium, wherein, The computer-readable storage medium includes a stored program, wherein, when the program runs, it controls the device where the computer-readable storage medium is located to execute the operation method of the database according to any one of claims 1 to 9.

14. A computer terminal, characterized in that it includes: a memory and a processor, the processor is used to run the program stored in the memory, wherein, when the program runs, it executes the operation method of the database according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Input / output data encryption

    CN108449172A

  • Database system

    CN111670436A