A database access method, related devices, storage medium, and program product
Through the collaboration between computer equipment, permission management equipment and signature data management equipment, database account information is determined, database security and stability issues are solved, and database access is rigorous and secure.
Patent Information
- Application Number
- CN202210335745.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-03-31
AI Technical Summary
How to ensure the security of the database in Internet products, prevent security risks caused by concentrated permissions, and improve the stability and security of the database.
The computer device obtains the access permission information and signature data of the target object from the permission management device and the signature data management device, and determines the target database account information based on the identity information of the target object, performs access permission control and data encryption and decryption to ensure the security of the database.
It effectively reduces the interference rate of the database, improves the stability and security of the database, prevents security risks caused by data leakage of a single device, and realizes the rigor and security of database access.
Smart Images

Figure CN114707128B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a database access method, related devices, storage media, and program products. Background Art
[0002] In the process of the development and application of Internet technology, the relevant data of various Internet products are usually stored in corresponding databases for the use of Internet product users or for database administrators to manage and analyze. In actual applications, a database usually stores a large amount of data, which contains great value and plays a crucial role in the normal operation of Internet products. Therefore, how to ensure the security of databases and related data has become a hot topic of current research. Summary of the Invention
[0003] Embodiments of this application provide a database access method, related devices, storage media, and program products, which can ensure the security of the accessed database.
[0004] On the one hand, embodiments of this application provide a database access method, including:
[0005] Receiving an access request initiated by a target object for a target database, where the access request carries the identity information of the target object;
[0006] In response to the access request, sending a permission acquisition request for the target object to a permission management device, where the permission management device stores access permission information of at least one object;
[0007] Receiving the access permission information of the target object sent by the permission management device, where the access permission information is used to indicate whether the target object is allowed to access the target database;
[0008] If the access permission information indicates that the target object is allowed to access the target database, requesting the signature data management device to obtain the signature data of the target database, where the signature data management device stores the signature data of at least one database;
[0009] Based on the obtained signature data and the identity information of the target object, determining the target database account information required for the target object to access the target database, and accessing the target database through the determined target database account information.
[0010] On the other hand, embodiments of this application provide a database access device, including:
[0011] A receiving unit, configured to receive an access request initiated by a target object for a target database, where the access request carries the identity information of the target object;
[0012] A sending unit, configured to, in response to the access request, send a permission acquisition request for the target object to a permission management device, where the permission management device stores access permission information of at least one object;
[0013] The receiving unit is further configured to receive the access permission information of the target object sent by the permission management device, where the access permission information is used to indicate whether the target object is allowed to access the target database;
[0014] An acquisition unit, configured to, if the access permission information indicates that the target object is allowed to access the target database, request the signature data management device to acquire the signature data of the target database, where the signature data management device stores the signature data of at least one database;
[0015] A processing unit, configured to determine the target database account information required when the target object accesses the target database based on the acquired signature data and the identity information of the target object, and access the target database through the determined target database account information.
[0016] On the one hand, an embodiment of the present application provides a computer device, including:
[0017] A processor, where the processor is configured to implement one or more computer programs;
[0018] A computer storage medium, where the computer storage medium stores one or more computer programs, and the one or more computer programs are adapted to be loaded and executed by the processor to perform the database access method as described in the first aspect.
[0019] On the one hand, an embodiment of the present application further provides a computer storage medium, where the computer storage medium stores one or more computer programs, and the one or more computer programs are adapted to be loaded and executed by the processor to perform the database access method as described in the first aspect.
[0020] On the one hand, an embodiment of the present application provides a computer product, where the computer product includes a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the database access method as described in the first aspect.
[0021] In the embodiments of the present application, when a computer device responds to an access request initiated by a target object for a target database of an agent, it can obtain the access permission information of the target object from a permission management device, and when the obtained access permission information indicates that the target object can access the target database, it further obtains the signature data of the target database from a signature management device, so as to select corresponding database account information for the target object based on the signature data of the target database and the identity information of the target object, so that the computer device can access the target database through the selected database account information. It can be seen that when the computer device responds to an access request for the target database, it needs to obtain the approval of the permission management device and the signature data management device. If either device refuses to provide data to the computer device or provides incorrect data to the computer device, it will cause the computer device to be unable to successfully respond to the access request, so that the target database cannot be accessed. Therefore, before the computer device, the permission management device, and the signature data management device cooperate to determine the database account information required by the target object, the target database will not be affected by any operations related to the target object, so that the interference rate of the target database during the entire agent process is reduced, effectively improving the stability of the target database. In addition, since accessing the target database requires using corresponding database account information, and the database account information needs to be confirmed through the cooperation of the computer device, the permission management device, and the signature data management device, it is not difficult to understand that the database access method provided by the embodiments of the present application can avoid the over-concentration of permissions for responding to access requests, and thus can avoid the security of the database being affected due to a security risk in a certain device, thereby ensuring the security of the database being agented. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0023] Figure 1a is a schematic structural diagram of a database access system provided by an embodiment of the present application;
[0024] Figure 1b is another schematic structural diagram of a database access system provided by an embodiment of the present application;
[0025] Figure 2 is a schematic flowchart of a database access method provided by an embodiment of the present application;
[0026] Figure 3It is a timing schematic diagram of a database access process provided by an embodiment of the present application;
[0027] Figure 4 It is a schematic flowchart of another database access method provided by an embodiment of the present application;
[0028] Figure 5a It is a schematic flowchart of a process for creating a database account provided by an embodiment of the present application;
[0029] Figure 5b It is a timing diagram for accessing and proxying a database in a database server provided by an embodiment of the present application;
[0030] Figure 5c It is a schematic flowchart of a process for hosting a database server provided by an embodiment of the present application;
[0031] Figure 5d It is a schematic flowchart of a process for encrypting and storing database management account information provided by an embodiment of the present application;
[0032] Figure 5e It is a schematic flowchart of a process for decrypting database management account information provided by an embodiment of the present application;
[0033] Figure 6a It is a schematic flowchart of a process for a computer device to respond to an access request provided by an embodiment of the present application;
[0034] Figure 6b It is a schematic flowchart of a process for a computer device to execute an access statement during the process of responding to an access request provided by an embodiment of the present application;
[0035] Figure 7 It is a schematic structural diagram of a database access device provided by an embodiment of the present application;
[0036] Figure 8 It is a schematic structural diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0037] In order to enable those skilled in the art to better understand the method provided by the embodiments of the present application, the following will clearly and completely describe the technical methods in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. It should be noted that each specific embodiment described in the embodiments of the present application is only a part of the embodiments of the present application, rather than all of the embodiments. Based on each embodiment in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the scope of protection of the present application.
[0038] In order to ensure the security of the database when accessing it, an embodiment of the present application proposes a database access method. When accessing the database using this database access method, relevant authentication data for identity authentication needs to be obtained from different devices, and these different devices are managed by different management parties respectively, which can avoid potential security risks to the database security caused by data leakage of a certain party. Then, since the database access method provided by the embodiment of the present application can ensure that the database has high security, therefore, the database access method provided by the embodiment of the present application can be applied in a variety of application scenarios, and these various application scenarios can include, but are not limited to, any one or more of the following: cloud technology, artificial intelligence, intelligent transportation, etc. And in specific applications, the embodiment of the present application can be used to build a data operation platform, so that the data operation platform can use the data access method provided by the embodiment of the present application to perform access proxy for multiple databases to ensure the security of the databases being proxied. Among them, the databases being proxied can be relational databases (i.e., SQL databases) or non-relational databases (i.e., Not Only SQL, NoSQL databases). Exemplarily, the data operation platform can be an SQLink (Safe Query Link) platform.
[0039] In the specific implementation of the embodiments of the present application, a computer device can be used to execute the database access method provided by the embodiments of the present application. Among them, the computer device can include, but is not limited to, a terminal device and a server. That is to say, the computer device can be a terminal device, a server, or of course a computing system composed of a terminal device and a server. The embodiments of the present application do not limit this. Specifically, in the embodiments of the present application, the terminal device can include, but is not limited to: smart phones, tablet computers, laptop computers, desktop computers, vehicle-mounted terminals, intelligent voice interaction devices, smart home appliances, aircraft, etc. In a specific embodiment, various application programs (Applications, APPs) and / or clients can also run in the terminal device, such as: multimedia playback clients, social clients, browser clients, information flow clients, education clients, and image processing clients, and so on. The above-mentioned server can include, but is not limited to: an independent physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network, content distribution network), and big data and artificial intelligence platforms. It can be understood that the embodiments of the present application do not specifically limit the computer device used when executing the database access method. In specific applications, the above-mentioned related devices can be flexibly combined and used according to the actual application scenario.
[0040] The principle of the database access method provided by the embodiments of the present application will be generally described based on the above description, so that relevant personnel can more clearly understand the related implementation manners of the embodiments of the present application.
[0041] In an embodiment of the present application, after receiving an access request from a target object for a target database, a computer device may determine the identity information of the target object, so that the computer device can obtain the access permission information of the target object from a permission management device according to the obtained identity information. Further, the computer device may determine the database that the target object is permitted to access. Among them, the main purpose of the computer device to obtain the access permission information is to determine whether the target object can access the target database. If the determined access permission information indicates that the target object cannot access the target database, then the computer device may reject the access of the target object to the target database. Correspondingly, if the determined access permission information indicates that the target object can access the target database, then the computer device may obtain the signature data of the target database from a signature data management device, so that the computer device can jointly determine the target database account information required when the target object accesses the target database based on the obtained signature data and the identity information of the target object. After the computer device determines the target database account information, the computer device may access the target database through the determined target database account information, thereby realizing the access of the target object to the target database. Exemplarily, after the computer device determines the target database account information, the computer device may log in to the database account indicated by the target database account information for the target object, so as to realize the access of the target object to the target database through the database account.
[0042] Among them, the computer device, the permission management device, and the signature data management device in the embodiments of the present application are respectively managed by different management parties. Specifically, the computer device can be managed by a database proxy party, which is mainly used to create a proxy instance in the computer device so that the computer device can access the database through the proxy instance. Essentially, the proxy instance can be understood as program code, which is mainly used to respond to the access requests of the database being proxied according to the execution logic set by the program code to establish a data connection between the device initiating the request and the database requested to be accessed. That is to say, when the computer device responds to the access request of the target object, it can establish a data connection between the terminal device where the target object is located and the target database through the corresponding proxy instance, so as to realize the access of the target object to the target database. The permission management device can be managed by a permission management party, and the permission management party can configure access permission information for any object so that the computer device can request the permission management device to obtain the access permission information related to the target object. In practical applications, when the permission management device configures relevant access permission information for any object, it can first seek the consent of the database management party. The database management party can be understood as the management party that creates the database or actually manages the database. That is to say, the access permission information of the object in the permission management device can be granted by the database management party. Exemplarily, the access permission information can include, but is not limited to, any one or more of the following: the database allowed to be accessed, the time period allowed to initiate access to the database, etc. The signature data management device is mainly managed by the signature data management party, and the signature data management party can store the signature data of the database in the signature data management device. In a specific implementation, the signature data of the database can be the signature data associated with the proxy instance used to proxy the database. The signature data is mainly used to encrypt and / or decrypt the relevant data of the corresponding database, thus ensuring the basic security of the database. Based on the above description, it can be seen that the computer device, the permission management device, and the signature data management device are respectively controlled by different management parties. When the computer device responds to an access request initiated to the database proxied by the computer device, the computer device needs to request and obtain the corresponding authentication data from different management parties before allowing the target object to access the corresponding database. Then, it is not difficult to see that the leakage of data of any party cannot cause the database to be accessed through non-secure channels. Therefore, when proxying the access to the database, adopting the database access method provided by the embodiments of the present application can effectively ensure the security of the database being accessed.
[0043] In one embodiment, the above database access method can be applied to a database access system as shown in Figure 1a the following. As shown in Figure 1aAs shown, the system may include an access proxy device 101 (i.e., the computer device mentioned above for executing the database access method), a signature data management device 102, a permission management device 103, and a database management device 104. Among them, the database management device 104 and the permission management device 103 can establish a communication connection so that database administrators can configure relevant access permission information for an object in the permission management device 103 through the database management device 104. The database management device 104 can also establish a communication connection with the access proxy device 101 so that the database management device 104 can entrust the access proxy device 101 to perform access proxy for the relevant databases managed by the database management device 104, so that the relevant databases can be accessed through the database access method provided by the embodiments of the present application to ensure the security of the relevant databases. The database management device 104 can also establish a communication connection with the signature data management device 102 so that database administrators can configure the signature data of the database in the signature data management device 102 through the database management device 104, so that the database-related information of the database (such as important data in the database and / or the database management account information mentioned later, etc.) can be encrypted and stored, further ensuring the security of the database. In addition, based on Figure 1a It is not difficult to see that a communication connection can also be established between the access proxy device 101 and the permission management device 103, so that the access proxy device 101 can request and obtain the access permission information of the relevant object from the permission management device 103. Similarly, a communication connection can also be established between the access proxy device 101 and the signature data management device 102, so that the access proxy device 101 can request and obtain the signature data of the corresponding database from the signature data management device 102.
[0044] In another embodiment, in the specific application of the embodiments of the present application, the computer device can also monitor and record the operation information generated by the access operation of the target object to the target database during the access process of the target object to the target database, so that each access to the target database is traceable, facilitating subsequent execution of relevant audit work for the target database. Exemplarily, the operation information generated by the access operation of the target object can be recorded in a log recording device. Then, in this case, the embodiments of the present application can also be applied to a Figure 1b database access system as shown. As Figure 1b shown, in addition to including Figure 1aIn addition to the permission management device, signature data management device, access proxy device, and database management device in the system shown, it may further include: a logging device, an identity firewall, and a terminal device. Among them, the target object may initiate an access request for the target database using the terminal device; the identity firewall may be used to authenticate and / or authorize the identity information of each object in the terminal device. Exemplarily, the technologies for implementing the identity firewall may include, but are not limited to: proxy, virtual private network (VPN), Active Directory, OAuth (an open protocol), and OpenID (a digital identity recognition framework), etc. The terminal device may establish a communication connection with the identity firewall, so that the identity firewall can, based on the access request sent by the terminal device, authenticate the identity of the target object initiating the access request to determine the identity information of the target object. The logging device may be used to record all modification information and access information related to the database during the process of the access proxy device proxying the database. Then, the logging device may establish a communication connection with the access proxy device so that the logging device can receive and record relevant modification information or monitor and record relevant access operations. Of course, the logging device may also establish a communication connection with the signature data management device and the permission management device, and the embodiments of the present application do not limit this.
[0045] It should be noted that, in actual applications, the terminal device and the database management device may be the same device, that is, the device for managing the database and the device for initiating the access request may be the same; the logging device and the access proxy device may also be the same device. In this case, a device can integrate multiple functions, thereby streamlining the structure of the entire system and, to a certain extent, increasing the difficulty and cost for relevant operation and maintenance personnel to maintain the database access system. In addition, it should also be noted that, in the database access system of the embodiments of the present application, the data formats used for data transmission between various devices may include, but are not limited to, any one or more of the following: JSON, XML, MessagePack, Protobuf, etc.
[0046] Based on the above principles of the database access method, the embodiments of the present application propose a database access method, which can be executed by a computer device (or: access proxy device). Specifically, the execution process of the database access method can be referred to Figure 2 , as Figure 2 shown, the method may include steps S201 - S205:
[0047] S201, receive an access request initiated by a target object for a target database, where the access request carries the identity information of the target object.
[0048] In a specific implementation, the target object can be any object that is allowed to initiate an access request to the target database. Specifically, the target object can be the service object of the business service where the database is located (e.g., the user of the music playback service), or the management object of the business service (e.g., the development object or the operation and maintenance object of the music playback service, etc.). The target database can be any database that can be accessed and proxied by a computer device. The access proxy can be understood as: using a computer device to respond to the access operation for the corresponding database, so as to establish a communication connection between the terminal device where the target object initiating the access request is located and the corresponding database through the computer device, thereby realizing the access of the corresponding object to the database. Among them, the access request can be initiated by the target object using a terminal device, and the terminal device has a communication connection with the computer device, so that the computer device can receive the access request initiated by the target object for the target database. In a specific application, relevant clients or web pages can also run on the terminal device. Therefore, the target object can specifically initiate an access request to the computer device through the client or web page in the terminal device. The access request can carry the identity information of the target object, and the identity information can be used to indicate whether the target object is a management object for managing the target database, or to indicate whether the target object has the permission to manage the target database, etc. Then, it can be understood that the identity information in actual applications can specifically include, but is not limited to, one or more of the following information: the object identifier of the target object and whether the target object is a management object, etc.
[0049] Among them, the object identifier corresponds one-to-one with the target object. That is to say, an object identifier can uniquely identify an object, and an object can also have only one object identifier. This can enable the computer device to accurately obtain the object information related to the target object based on the object identifier. The object information can be, for example, access permission information. The management object refers to the object that manages the target database in the database management device to which the target database belongs. Correspondingly, an object that can access the target database but does not have the permission to manage the target database can be called a non-management object. It can be understood that the access permission indicated by the access permission information of the management object is usually greater than the access permission indicated by the access permission information of the non-management object. Based on this, it can be understood that including whether the target object is a management object in the identity information can help the computer device quickly determine the response priority of the corresponding access request. The higher the response priority of the access request, the earlier the computer device responds. Then, it can be understood that in order to timely stop and block the access request with potential safety hazards initiated by a certain object to the target database, usually, the response priority of the access request of the management object can be greater than the response priority of the access request of the non-management object.
[0050] The following is a detailed description of the significance of identity information used to indicate whether the target object is a management object in conjunction with a specific example. In this example, it is assumed that object A (non-management object or other type of object) initiates an access request to the target database, and the access request carries malicious program instructions, which can be used to damage the storage format of data in the database. Then, after the management object of the target database detects this risky behavior, the management object can initiate an access request to the computer device, and the access request can carry a program instruction for blocking the response. The program instruction for blocking the response can be used to instruct the computer device to refuse to respond to the access request initiated by object A, or to instruct the computer device to temporarily change the address information of the target database to block the access path of object A to the target database, thereby maintaining the security of the target database. Then, in this case, if the computer device receives the access request of object A and the access request of the management object at the same time, or if the access request of object A and the access request of the management object are waiting to be responded to in the computer device at the same time, the computer device can give priority to responding to the access request of the management object, thereby avoiding the execution of malicious program instructions on the target database and ensuring the security of the target database.
[0051] S202: In response to the access request, a permission acquisition request for the target object is sent to a permission management device.
[0052] After the computer device receives the access request, it can parse the access request to obtain the identity information of the target object carried in the access request. Since the identity information can include the object identifier of the target object, and the object identifier and the target object are in a one-to-one correspondence, the computer device can also obtain the object identifier of the target object after parsing the access request, and then the computer device can generate a corresponding permission acquisition request based on the obtained object identifier. In other words, the permission acquisition request can carry the object identifier and / or identity information of the target object, so the permission management device can also query the access permission information of the target object from the corresponding storage space (such as: cloud space, local storage space) according to the object identifier of the target object, thereby responding to the permission acquisition request of the target object.
[0053] Among them, the access permission information of at least one object is stored in the permission management device. The at least one object may include one or more of the service object and the management object of the business service where the target database is located. Of course, the target object may exist among the at least one object. In addition, it can be understood that in other implementation manners or other application scenarios, the at least one object may also include the service object and / or management object of other business services where databases that can be accessed by the computer device are located, etc. In this case, it can be understood that the computer device in the embodiment of the present application can perform access proxy for multiple databases, and the target database may be included in the multiple databases. Then, it can be further understood that the access permission information of the service object and / or management object of the business server where other databases are located can of course also be stored in the permission management device. The other databases mentioned here may specifically include: databases other than the target database among the multiple databases. That is to say, the access permission information of one or more objects can be stored in the permission management device.
[0054] In a specific application, any access permission information may be stored in association with a certain object. Exemplarily, the permission management device may store the object identifier of the target object in association with the access permission information of the target object, so that the permission management device can obtain the corresponding access permission information according to the object identifier of any object. The access permission information of any object can be used to indicate the databases that the object can access, and can also be used to indicate whether the object is allowed to access the target database. Optionally, when the access permission information is used to indicate the databases that the corresponding object can access, the access permission information may include the database identifiers of one or more databases, or may include the access paths of one or more databases. Of course, the access permission information of any object may also be empty, which means that the object does not have the permission to access any database. The embodiment of the present application does not specifically limit the specific content and specific storage form of the access permission information. It should be noted that in actual applications, the access permission information stored in the permission management device may be configured after the permission management device receives an access permission application request of a relevant object.
[0055] To facilitate a clear understanding of the relevant implementation manners of the embodiments of the present application, the following will briefly describe the specific manner in which a target object applies to a permission management device for configuring access permission information related to a target database with specific examples. Specifically, the target object may apply to the permission management device for corresponding access permissions through a terminal device that has a communication connection with the permission management device. Exemplarily, the target object may send an access permission application request to the permission management device through the terminal device, and the request carries the access permission information to be configured and the identity information of the target object. After the permission management device receives the access permission application request, it may predict the permission information of the target object based on the identity information of the target object, and then determine whether it is necessary to configure the corresponding access permission information to be configured for the target object based on the predicted permission information.
[0056] Optionally, in other implementation manners, the computer device may also send a permission granting request to the database management device of the target database after receiving the access permission application request, so that the database management device can determine whether to grant the access permission applied for by the target object after receiving the permission granting request, and feedback the granting result to the permission management device, and further enable the permission management device to configure reasonable access permission information for the target object according to the granting result. The access permission information configured by the permission management device for the target object is the granted access permission information included in the granting result. In practical applications, the permission management device has functions such as permission application, permission approval, permission auditing, and permission cleaning. Since the access permission information of the target object stored in the permission management device has been recognized by the database management party, that is to say, the access permission information of each object can be essentially understood to be in the hands of the database management party, it is not difficult to understand that storing the access permission information in the permission management device is safe and reliable. In other embodiments, the access permission information stored in the permission management device may also be configured in other ways, such as: the database management device configures default access permission information for each object associated with the target database, and the embodiments of the present application do not limit this.
[0057] Based on the above description, it can be seen that different levels of permission information can be allocated to different objects in the embodiments of the present application. For example, different levels of permission information are allocated to various types of objects such as database administrators, proxy platform R & D personnel, and data operation personnel. This can effectively prevent malicious access to the database being proxied, thereby ensuring the security of the database before it is officially accessed.
[0058] S203. Receive the access permission information of the target object sent by the permission management device, where the access permission information is used to indicate whether the target object is allowed to access the target database.
[0059] The access permission information received by the computer device may be sent by the permission management device to the computer device after responding to the permission acquisition request. Exemplarily, the permission management device may respond to the permission acquisition request sent by the computer device, generate a response result including the access permission information of the target object, and send the response result to the computer device. In a specific implementation, the manner in which the permission management device responds to the permission acquisition request may be: after receiving the permission acquisition request, the permission management device parses the object identifier of the target object from the permission acquisition request, and then, the permission management device may query the access permission information associated with the object identifier based on the object identifier. After the permission management device queries the access permission information, it may generate a corresponding response result and send it to the computer device, so that the computer device can obtain the access permission information of the target object included in the response result after receiving the response result, thereby enabling the computer device to determine whether the target object is allowed to access the target database.
[0060] S204, if the access permission information indicates that the target object is allowed to access the target database, request the signature data management device to obtain the signature data of the target database.
[0061] In one embodiment, if the access permission received by the computer device indicates that the target object can access the target database, the computer device may request the signature data management device to obtain the signature data of the target database, and further enable the computer device to parse the database account information related to the target database based on the signature data. Among them, the signature data can be understood as a key, which is mainly used to encrypt and decrypt information related to the target database (such as: database account information, data in the database). Then, in this case, the signature data management device may be a key management device (KMS, Key Management System), and the key stored in the key management device may also be referred to as KMS key data. The key management device is a dedicated infrastructure suitable for storing confidential content. In the embodiments of the present application, the management party of the key management device and the management party of the computer device (such as: the access proxy device) are not the same, which reflects the idea of permission separation applied when accessing the database in the embodiments of the present application. It can be understood that permission separation can prevent a certain party from having too much permission or too much important data. Therefore, it is also possible to avoid the problem that the security of the database is hidden due to the data leakage of a certain party, thereby improving the security of the database.
[0062] In this case, it should be noted that, in one implementation, the signature data in the signature data management device can be stored in association with the proxy instance (for example, an instance identifier of a proxy instance is associated with storing a signature data). That is to say, the signature data of the target database can be the signature data associated with the proxy instance for proxying the target database. In this case, when the computer device requests the signature data management device to obtain the signature data of the target database, the computer device can, after determining the proxy instance for proxying the target database, request the signature data management device to obtain the signature data associated with the proxy instance, so as to obtain the signature data of the target database. Of course, it can also be that the signature data management device, when responding to the request of the computer device, determines the proxy instance for proxying the target database, and further obtains the signature data associated with the determined proxy instance as the signature data of the target database and sends it to the computer device, so that the computer device can successfully obtain the signature data of the target database. In yet another implementation, the signature data of the target database in the signature data management device can also be stored in association with the database identifier of the target database, and in a specific implementation, one signature data can be associated with one database or can be associated with multiple databases. That is to say, in the embodiments of the present application, there may be a situation where the signature data of multiple databases is the same, and the embodiments of the present application do not specifically limit whether the relationship between the signature data and the database is a one-to-one relationship or a one-to-many relationship.
[0063] Unless otherwise specified, for the sake of convenience of description, in the following embodiments, the signature data is associated with the proxy instance for storage as an example to elaborate on other steps of the embodiments of the present application. Also, for the sake of clearly understanding the related implementation manners of the embodiments of the present application, the relationship among the proxy instance, the target database, and the computer device in the embodiments of the present application is described as follows: The computer device can construct one or more proxy instances, and each proxy instance can be used to perform access proxy for at least one database. Of course, the at least one database can include the target database. Based on the foregoing, it can be seen that the proxy instance can essentially be regarded as program code. Then, for different proxy instances among the one or more proxy instances constructed by the computer device, the response manner or response logic adopted by them can be different. Therefore, when the signature data is associated with the proxy instance for storage, the signature data corresponding to different proxy instances can be different, and the signature data of the databases proxied by different proxy instances can also be different. Correspondingly, it is not difficult to understand that for each database proxied by the same proxy instance, its signature data can be the same, that is, the signature data of different databases can be the same. For example, it is assumed that the computer device creates proxy instance A and proxy instance B, and the signature data associated with proxy instance A in the signature data management device is signature data 1, and the signature data associated with proxy instance B is signature data 2. On this basis, this example further assumes that proxy instance A is used to proxy database a and database b, and proxy instance B is used to proxy database c. Then, in this case, if the target database is database a or database b, the signature data of the target database obtained by the computer device can be signature data 1; if the target database is database c, the signature data obtained by the computer device can be signature data 2.
[0064] S205. Based on the obtained signature data and the identity information of the target object, determine the target database account information required for the target object to access the target database, and access the target database through the determined target database account information.
[0065] In an embodiment of the present application, the target database account information may include a database account identifier and a database account password. Then, the way for the computer device to access the target database through the determined target database account information may be that the computer device logs in to the database account indicated by the target database account information for the target object, so as to establish a communication connection with the target database through this database account, thereby realizing the access of the target object to the target database. It should be noted that different objects with different identity information use different database accounts. Specifically, when the identity information indicates that the target object is a management object, the database account used by the target object may be a database management account for managing the target database; when the identity information indicates that the target object is a non-management object, the database account used by the target object may be a general database account constructed by the computer device. In practical applications, the computer device may construct a general database account for one computer device. That is to say, when the object initiating the access request to the target database is a non-management object, the database account it uses may be a fixed general database account and will not change due to different objects. For example, the objects that can access the target database are object A and object B, and both object A and object B are non-management objects. Then, when the computer device responds to the access request initiated by object A for the target database, it can realize the access of object A to the target database by logging in to the general database account of the target database; similarly, for object B, the computer device can also realize the access of object B to the target database by logging in to the general database account of the target database. It can be seen that as long as it is a non-management object, the database account it uses when accessing the target database can be the same. Of course, in other embodiments, the computer device may also create multiple general database accounts for the target database, so that any object can access the target database through any general database account. However, it should be noted that in the embodiment of the present application, in order to facilitate system maintenance and data security management, the method of creating one general database account for one database is preferably considered.
[0066] Based on this, it is not difficult to understand that during the computer device's access proxy to the target database, the computer device can ensure successful response to access requests initiated by any object to the target database by maintaining two database accounts (a general database account and a database management account). This approach can reduce the number of database accounts that the computer device needs to maintain, thereby enabling the computer device to allocate more resources when maintaining a single database account, and to a certain extent enhancing the security of the computer device when maintaining relevant information of the database account. Also, since the computer device needs to obtain signature data first when determining either of the two database accounts, and then can determine the corresponding database account based on the signature data, this avoids directly storing the account information of the database account, thus reducing the probability of the target database being accessed abnormally due to the leakage of the database account, and further ensuring the security of the target database.
[0067] In a specific embodiment of the present application, the computer device can also monitor and record all access operations performed by the target object on the target database during the process of the target object accessing the target database. Exemplarily, the computer device can use a logging device to store relevant access records, which can enable the access records of the target database to be traced back, so that all access operations of the target database can be audited, further ensuring the security of the target database. The logging device can be constructed based on simple disk log files and / or complex analytical data warehouses, etc., or can also be constructed based on a combination of multiple logging systems. For example, the logging device in the embodiment of the present application can use Kafka (a distributed messaging system) to collect query summaries, and use ClickHouse (a columnar database management system for online analysis) to complete data storage, aggregation, and query; of course, in specific applications, the computer device can also discard the logging component when there is no logging requirement, or streamline the structure of the logging device according to the actual situation by using the database account created on the database side by the relevant data operation platform for database account auditing within the database (such as SQLink) when the number of objects that need to access the database is small or the objects are fixed. The embodiment of the present application does not make specific limitations on this.
[0068] To facilitate a clearer understanding by relevant personnel of the specific execution process of the above-mentioned Figure 2 shown database access method, the following combines the Figure 3 shown sequence diagram and specific examples to more comprehensively and detailedly elaborate on the Figure 2 shown execution process of the database access method. However, it should be noted that Figure 3The timing diagram and related description shown are only an exemplary description of the execution process of the embodiment of the present application and cannot be used as a limitation of the embodiment of the present application. In this example, it is assumed that the access permission information of the target object includes the database identifiers of all databases that the target object can access; the signature data is KMS key data; the target object can execute related scripts when accessing the target database. The script can refer to an executable file written in a certain format using a specific descriptive language, which can also be understood as an access statement in the embodiment of the present application.
[0069] Based on this, see Figure 3 , Figure 3 The terminal device is a communication device for the target object to initiate an access request to the target database; the access proxy device is a device that performs access proxying on the target database and responds to the access request initiated by the target object to the target database. Exemplarily, it can be the computer device for executing the above-mentioned embodiment of the present application; the authority management device is a device that stores the access permission information of the target object; the key management device is the signature data management device mentioned above, and the KMS key data in the key management device is the signature data in the embodiment of the present application; the database server is the server where the target database is located, and the log recording device is used to record relevant information about the access operation performed by the target object on the target database. Based on Figure 3 It can be seen that the complete process of the target object accessing the target database can exemplarily include the following 14 steps:
[0070] 1. The target object applies for database permissions from the permission management device through the terminal device. That is, before the target object initiates an access request to the target database, the target object can first apply to the permission management device for granting relevant database permissions. Database permissions can include access permissions and execution permissions of the target object. Access permissions can be used to indicate one or more databases that the target object is allowed to access, and execution permissions can be used to indicate the specific access operations that the target object is allowed to perform on each database, such as: access time, type of access statement, amount of data modified by the access statement on the target database, etc.
[0071] 2. The target object applies to the access proxy device for a database list through the terminal device. The database list may include at least one database identifier, and the database corresponding to the database identifier is the database that the target object can access.
[0072] 3. The access proxy device queries the access permission information of the target object from the permission management device. When the access proxy device detects that the target object applies to obtain the database list, the access proxy device can query the access permission information of the target object from the permission management device. Specifically, the access permission information may include the database list. It should be noted that when the access proxy device queries the access permission information of the target object (such as obtaining the database list) from the permission management device, the permission management device can first authenticate the access proxy device and allow the access proxy device to query the access permission information of the target object after the authentication passes, so as to ensure that the access proxy device querying the access permission information is secure, and thus the security of the target database can be ensured before the target object officially accesses the target database.
[0073] 4. The permission management device returns the access permission information of the target object to the access proxy device. After the access proxy device passes the authentication process of the permission management device, the permission management device can allow the access proxy device to obtain the access permission information of the target object, or the permission management device can return the queried access permission information to the access proxy device after querying the access permission information of the target object.
[0074] 5. The access proxy device returns the database list to the terminal device. After the access proxy device queries the database list of the target object, the access proxy device can return the database list to the terminal device so that the target object can view the databases to which it has access permissions, thereby enabling the target object to initiate a request to execute scripts for the databases.
[0075] 6. The target object initiates a request to execute scripts to the access proxy device through the terminal device. After the target object determines the target database to be accessed, it can generate corresponding execution scripts through the terminal device and request the access proxy device to execute these execution scripts to complete the specific access operations that the target object wants to perform.
[0076] 7. The access proxy device queries the execution permission of the target object from the permission management device. Based on the foregoing, the execution permission of the target object is also stored in the permission management device, and the execution permission is used to indicate the specific access operations that the target object can perform on the target database. Therefore, when the access proxy device receives a request to execute a script, the access proxy device can first query the corresponding execution permission from the permission management device to determine whether to allow the target object to execute the relevant execution script.
[0077] 8. The permission management device returns the execution permission of the target object to the access proxy device.
[0078] 9. The access proxy device requests the key management device to obtain KMS key data. When the target object has the execution permission to execute the relevant script, the access proxy device can obtain the KMS key data from the key management device, so that the access proxy device can determine the database account information required for the target object to access the target database based on the KMS key data.
[0079] 10. The permission management device returns the KMS key data to the access proxy device.
[0080] 11. The access proxy device executes the script on the database server using the database account.
[0081] After the access proxy device determines the database account information required for the target object, the access proxy device can log in to the relevant database account for the target object, so that the access proxy device can execute the script on the database server in the name of the relevant database account.
[0082] 12. The database server reports the access summary to the log recording device. The access summary can be used to indicate the execution script information executed by the target object for the target database this time, and the execution information of the execution script during the execution. Exemplarily, the content of the access summary can include any one or more of the following: access initiation time, access end time, object identifier of the target object, total access duration, and script execution result, etc. During the execution of the script, the database server can continuously report the execution information of the execution script to the log recording device, so that the log recording device can record the relevant access records in time, which helps the subsequent audit work of the target database.
[0083] 13. The database server returns the script execution result to the access proxy device.
[0084] 14. The access proxy device returns the script execution result to the terminal device. After the execution of the script is completed, the database server can return the script execution result to the access proxy device, and then the access proxy device can feedback the script execution result to the target object.
[0085] In an embodiment of the present application, when a computer device responds to an access request initiated by a target object for a target database, it needs to obtain the access permission information of the target object from a permission management device to determine whether the target object has the access permission to the target database. Further, only after the computer device determines that the target object can access the target database, will the computer device attempt to obtain the database account information required when the target object accesses the target database, so that the target object can access the target database by logging in to the database account indicated by the database account information. During the process of the computer device determining the database account information, the computer device needs to first request the signature data management device to obtain the signature data of the target database. If the acquisition fails, the computer device cannot determine the database account information, thus preventing the target object from accessing the target database. Then, it can be seen that to achieve the access of the target object to the target database, the computer device needs to obtain the access permission information that the target object is allowed to access the target database from the permission management device, and the computer device needs to obtain the signature data of the target database from the signature data management device. The access permission information and the signature data are both indispensable. Therefore, the idea of separating permissions is applied in the database access method proposed in the embodiment of the present application, making the database access process more rigorous and reducing the problem that the database security cannot be guaranteed due to data leakage. In other words, adopting the database access method provided in the embodiment of the present application can effectively ensure the security of the database.
[0086] Based on the above database access method, an embodiment of the present application provides another database access method, which can also be executed by a computer device. Please refer to Figure 4 , such as Figure 4 shown, this method may include steps S401 - S406:
[0087] S401, receive an access request initiated by a target object for a target database, where the access request carries the identity information of the target object.
[0088] In a specific embodiment, the database management device to which the target database belongs needs to first host the target database to a computer device (i.e., first let the computer device allocate an agent instance for proxying the target database to the target database), so that the computer device can respond on behalf of the target object to the access request initiated for the target database, so as to realize the access of the target object to the target database. Among them, hosting the target database to the computer device can be understood as managing the target database on behalf of it. In the embodiments of the present application, it mainly refers to the computer device processing the access request for the target database on behalf of it. The sign of successfully hosting the target database to the computer device is that the computer device successfully creates a database account that can be used to access the target database. Among them, the database account can be created by the computer device according to the signature data of the target database, the database identifier of the target database, and the instance identifier of the agent instance that proxies the target database.
[0089] To facilitate a clear understanding of the embodiments of the present application, the following provides a detailed description of the method for a computer device to host a target database. In one embodiment, after receiving a proxy request sent by the database management device to which the target database belongs, the computer device can, in response to the proxy request, obtain the database identifier of the target database. Among them, the proxy request may carry the database identifier of the target database. Then, the computer device can obtain the database identifier of the target database by parsing the proxy request. Of course, the proxy request may also carry the server address information of the database server to which the target database belongs and the server management account information of the server. In this case, the computer device can establish a communication connection with the database server indicated by the server address information by logging in to the server management account indicated by the server management account information, so that the computer device can obtain the database identifier of the target database from the database server to which the target database belongs. When the computer device responds to the proxy request, the computer device can also determine a proxy instance for proxying the target database to obtain the instance identifier of the proxy instance. It should be noted that the computer device determining the proxy instance of the target database here can be understood as: the computer device allocates a proxy instance for the target database. Exemplarily, the computer device can randomly allocate a proxy instance for the target database, or allocate a suitable proxy instance for it after analyzing the target database, or allocate a proxy instance for the target database according to the proxy instance specified by the database management device. If the proxy instance allocated by the computer device is the proxy instance specified by the database management device, the proxy request may also carry the instance identifier of the proxy instance, so that the computer device can allocate the proxy instance indicated by the instance identifier for the target database. Based on the foregoing, in order to successfully host the target database, the computer device also needs to obtain the signature data of the target database. In the embodiments of the present application, the signature data is stored in association with the proxy instance, and the proxy instance can be used to proxy the database. Therefore, when the computer device determines the signature data of the target database, it can first request the signature data management device to obtain the signature data associated with the proxy instance, and use the obtained signature data as the signature data of the target database. After the computer device determines the database identifier of the target database, the instance identifier of the proxy instance for proxying the target database, and the signature data of the target database, the computer device can create a database account for the target database. If the creation of the database account is successful, the computer device can access the target database through the database account, which means that the computer device has successfully hosted the target database; correspondingly, if the creation of the database account fails, the computer device cannot access the target database through the database account, which means that the computer device has failed to host the target database.
[0090] Among them, the method for the computer device to create a database account can be referred to Figure 5aand the following description: When a computer device generates a database account, it needs to first generate a database account identifier and a database account password corresponding to the database account. Specifically, the computer device can first generate a database account identifier by using the obtained instance identifier and database identifier. Further, after the computer device generates the database account identifier, the computer device can perform SM3 signature on the database account identifier and the signature data of the target database to generate a database account password. Among them, SM3 is a domestic cryptographic algorithm, which is applicable to the generation and verification of digital signatures and verification message authentication codes, as well as the generation of random numbers, and can meet the security requirements of various cryptographic applications. The embodiments of this application do not explain SM3 in detail. Of course, the computer device can also use other cryptographic algorithms to generate the corresponding database account password based on the signature data, and the embodiments of this application do not limit this. After the computer device generates the database account identifier and the database account password, the computer device can create a database account based on the database account identifier and the database account password. In this case, the database account information of the target database can include the above-mentioned database account identifier and the database account password.
[0091] It should be noted that in practical applications, the computer device can also generate the corresponding database account information while obtaining the data required to create the database account, and it is not necessary to create the database account only after the database identifier, signature data, and instance identifier are all obtained. Specifically, you can continue to refer to Figure 5a , such as Figure 5a shown, the step of the computer device obtaining the signature data of the target database can be executed after the computer device generates the database account identifier. That is, in a feasible implementation manner, the computer device can generate a database account identifier after obtaining the database identifier and the instance identifier, and only after the database account identifier is generated, obtain the signature data of the target database from the signature data management device to further generate the database account password of the database account based on the signature data and the database account identifier. In the embodiments of this application, the computer device may fail to generate the database account identifier. Therefore, the signature data obtained by the computer device can only play a role after the database account identifier is successfully generated. Then, the computer device can obtain the signature data after the database account identifier is successfully generated, and when the database account identifier generation fails, the computer device does not need to obtain the corresponding signature data from the signature data management device. Since the computer device also needs to perform a series of identity authentication processes when obtaining the signature data from the signature data management device, which takes a certain amount of processing time, obtaining the signature data after the database account identifier is successfully generated can, to a certain extent, avoid wasting the computing resources of the computer device.
[0092] In another embodiment, since the target database in the embodiments of the present application can exist in a database server, the database server may include one or more databases. In this case, the manner in which the database management device hosts the target database to the computer device may also refer to Figure 5b . To closely combine with Figure 5b , the computer device is hereinafter referred to as an access proxy device to elaborate in detail on the Figure 5b -shown hosting process. As Figure 5b shown, when the database management device to which the target database belongs needs to host the target database to the access proxy device, the database management device may first request the access proxy device to allocate proxy instances for each database in the proxy database server. After the access proxy device allocates proxy instances for the database server, it may feedback the instance identifier of the proxy instance to the database management device. Among them, if the proxy instance allocated by the access proxy device is a brand-new proxy instance (i.e., a proxy instance that does not proxy any database), the database management device may request the signature data management device to initialize the signature data associated with the proxy instance after receiving the instance identifier. Exemplarily, the initialization method of the signature data may be that the signature data management device randomly initializes it, or the database management device specifies specific signature data to the signature data management device to complete the initialization of the specified content. Correspondingly, if the proxy instance allocated by the access proxy device is a proxy instance that has been put into use, this means that there is already associated signature data for the proxy instance, so the database management device does not need to request the signature data management device to initialize the signature data associated with the proxy instance again.
[0093] Continue to refer to Figure 5b, it can be seen that after the database management device detects that the access proxy device has successfully allocated a proxy instance for the database server, the database management device can initiate a proxy request to the access proxy device to request the access proxy device to host the database server, so as to realize the hosting of the relevant databases (such as: the target database) in the database server by the access proxy device. In this case, the proxy request can carry the server address information of the database server and the account information of the server management account. Then, after receiving the corresponding proxy request, the access proxy device can log in to the server management account based on the account information of the server management account to obtain a database list from the database server. The database list can include the database identifiers of the databases that are not hosted among all the databases included in the database server (such as: the database identifier of the target database). Further, the computer device can obtain the signature data associated with the proxy instance used to proxy the database server, and then the computer device can create database accounts for the corresponding databases respectively based on the signature data and each database identifier existing in the database list, and generate a creation result. The creation result can include the database identifier corresponding to the database for which the computer device has successfully created a database account. Then, the computer device can also transmit the creation result to the database server in a broadcast manner, so that when the database server interacts with other external systems, the external systems can also access the hosted databases (such as: the target database) through the embodiments of the present application.
[0094] After the computer device successfully creates the database accounts of the relevant databases in the database server, the computer device can also encrypt and store the account information of the server management account of the database server, so that when the target object has the management permission for the target database, it can access the target database based on the account information of the server management account. Then, in this case, for the specific process of the database management device hosting the database server to the access proxy device, reference can also be made to Figure 5c as shown, where Figure 5c the database management account can be the server management account of the database server. Since Figure 5c the process of Figure 5b has been described in the above relevant description for Figure 5c therefore, the embodiments of the present application will not elaborate on the process shown in
[0095] S402, in response to the access request, send a permission acquisition request for the target object to the permission management device.
[0096] S403, receive the access permission information of the target object sent by the permission management device, and the access permission information is used to indicate whether the target object is allowed to access the target database.
[0097] S404. If the access permission information indicates that the target object is permitted to access the target database, request the signature data management device to obtain the signature data of the target database.
[0098] In one embodiment, the specific manner in which the computer device executes steps S402 to S404 may refer to the relevant embodiments in steps S202 and S204, and will not be elaborated herein in the embodiments of the present application.
[0099] S405. In the case where the identity information indicates that the target object is a non - management object, obtain the database identifier of the target database.
[0100] Based on the foregoing, in the embodiments of the present application, the identity information may indicate that the target object is a non - management object or a management object. Moreover, for objects with different identity information, the target database account information used when accessing the target database is different. Specifically, when the identity information indicates that the target object is a non - management object, the target database account information adopted by the target object may be the account information corresponding to the database account created by the computer device for the target database. In the embodiments of the present application, in order to ensure the security of the database account, when the computer device determines the target database account information adopted by the non - management object, it needs to calculate the corresponding database account information according to the manner in which the computer device creates the database account (such as: Figure 5a the manner shown). That is to say, when the target object is a non - management object, the computer device needs to determine the database identifier of the target database and the instance identifier of the proxy instance for proxying the target database. In addition, the computer device also needs to request the signature data management device to obtain the signature data of the target database, so that the computer device can calculate the corresponding database account information based on the database identifier, instance identifier, and signature data.
[0101] When the identity information indicates that the target object is a managed object, the computer device can determine the database management account information of the target database as the target database account information required to be adopted by the target object. The database management account information can be sent by the database management device to the computer device when requesting the computer device to host the target database. And to ensure the storage security of the database management account information, the computer device can encrypt and store the database management account information of the target database. The specific time for encryption storage can be after the computer device successfully creates the database account of the target database. The specific storage location can be in the computer device or in the signature data management device. In this embodiment of the present application, the example of storing the encrypted database management account information in the computer device is used for illustration. In this embodiment of the present application, the method for the computer device to encrypt and store the database management account information and the method for the computer device to decrypt the encrypted database management account information to obtain the target database account information required by the target object will be elaborated in detail in step S406, and will not be elaborated here.
[0102] S406. Generate the target database account information required for the target object to access the target database according to the database identifier and the signature data, and access the target database through the determined target database account information.
[0103] In one embodiment, when the identity information indicates that the target object is a non-managed object, the computer device needs to calculate the database account information created for the target database as the target database account information adopted by the target object. Among them, the database account information can include a database account identifier and a database account password. Then, exemplarily, when calculating the database account information, the computer device can first obtain the instance identifier of the proxy instance for proxying the target database; further, the computer device can generate a database account identifier based on the instance identifier and the database identifier. Then, the computer device can further generate a database account password according to the database account identifier and the signature data. Based on this, the computer device can also generate the database account information including the database account identifier and the database account password as the target database account information.
[0104] In another embodiment, when the identity information indicates that the target object is a managed object, the target database account information adopted by the target object can be the database management account information. Among them, the database management account information can be the same as the account information of the server management account. That is to say, the computer device can use the account information of the server management account as the database management account information of the target database, such as: such as Figure 5b or Figure 5cThe database management account information corresponding to the managed process shown can be the server management account information. In a specific implementation, the computer device can encrypt and store the database management account information as follows: The computer device receives the database management account information of the target database sent by the database management device of the target database and generates a key for the target database. Exemplarily, the key can be randomly generated by the computer device. The computer device can also request the signature data management device to obtain the signature data of the target database, and use the generated key and the obtained signature data to generate encryption processing parameters, so as to encrypt the database management account information using the encryption processing parameters and the key to obtain the encrypted account information.
[0105] Then, based on the above method of encrypting and storing the database management account by the computer device, it is not difficult to understand that when the computer device determines the database management account used by the management object, it can use the corresponding decryption method to decrypt the database management account from the encrypted data. Specifically, when the identity information indicates that the target object is a management object, when the computer device determines the target database account information used by the target object, it can first obtain the encrypted data of the target database, and the encrypted data at least includes the encrypted database management account information. Then the computer device can decrypt the encrypted account information according to the obtained signature data to decrypt the corresponding database management account information, so that the computer device can use the decrypted database management account information as the target database account information required by the target object.
[0106] In another embodiment, for the specific process of the computer device encrypting and storing the database management account information, reference can also be made to Figure 5d . Such as Figure 5dAs shown, when it is necessary to encrypt the database management account information, the computer device can obtain the signature data of the target database from the signature data management device after generating a key for the target database. If the computer device successfully obtains the signature data, the computer device can perform SM3 signing of the key and the signature data to generate encryption processing parameters (the encryption processing parameters can essentially be a vector). Further, the computer device can use the key and the encryption processing parameters to perform SM4 peer encryption (a domestic cryptographic algorithm) on the database management account information to obtain a ciphertext. The ciphertext is the encrypted account information mentioned above. Further, in order to ensure that the computer device can decrypt the ciphertext to obtain the database management account information, the computer device can combine and package the key and the ciphertext to obtain the encrypted data. That is to say, the encrypted data in the embodiment of the present application may include the encrypted account information and the key. In order to facilitate the verification of the security of the encrypted data (such as: verifying whether the encrypted data has been tampered with or intercepted and destroyed, etc.), the computer device can also calculate the cyclic redundancy check code (i.e., the cyclic redundancy check code) of the encrypted data after obtaining the encrypted data. Figure 5d The CRC in the encryption is used to calculate the cyclic redundancy check (CRC), and the calculated check code is added to the end of the encrypted data to further generate a data block including the encrypted data and the check code. After the computer device generates the data block, the computer device can store the data block. At this point, the computer device can be regarded as realizing the entire process of encrypting and storing the database management account information.
[0107] Then, correspondingly, when the computer equipment adopts Figure 5d When the encrypted storage method shown is used, the method for the computer device to determine the database management account information can be found in Figure 5e .like Figure 5e As shown, the computer device can first obtain the corresponding data block, and then verify the integrity of the data block after obtaining the data block, so as to achieve preliminary security authentication of the database management account information. If the data block is complete, the computer device can split the encrypted data in the data block to obtain the key and ciphertext. In order to decrypt the ciphertext, the computer device needs to obtain the signature data of the target object from the signature data management device. If the signature data of the target database has been obtained before, there is no need to obtain it again. Then it can be understood that Figure 5eThe step of obtaining the signature data is to facilitate a complete understanding of how the computer device decrypts the database management account information by relevant readers based on the flowchart, and does not strictly limit the execution steps of the computer device and the execution flow between steps. After the computer device obtains the signature data, the computer device can perform SM3 signature on the signature data and the key to generate decryption processing parameters. It can be understood that the decryption processing parameters here and the above encryption processing parameters match each other. Then, that is to say, the computer device can perform SM4 peer decryption on the ciphertext using the key and the decryption processing parameters to determine the target database account information required by the database management account information as the target object.
[0108] The following details the implementation method for the computer device to access the target database through the determined target database account information in step S406. Among them, during the access process of the target object to the target database, the computer device can execute an access statement, and the executed access statement can be carried in the access request received by the computer device. Specifically, the access request received by the computer device can carry at least one access statement. Also, when the computer device realizes the access of the target object to the target database, it also needs to refer to the identity information of the target object. The access logics (such as: the process of executing at least one access statement carried in the access request) corresponding to objects with different identity information may be different.
[0109] In one embodiment, when the identity information of the target object indicates that the target object is a management object, after decrypting to obtain the database management account information of the target database, the computer device can log in to the database management account indicated by the database management account information for the target object, so that the target object can be allowed to directly execute this at least one access statement when accessing the target database. Of course, in order to further enhance the security of relevant data in the target database, the computer device can also obtain the execution permission information of the management object from the permission management device, and then determine the target access statement allowed to be executed from at least one access statement and then execute the target access statement. The embodiments of the present application do not make specific limitations on this.
[0110] In yet another embodiment, when the identity information of the target object indicates that the target object is a non - management object, the computer device can obtain the execution permission information of the non - management object from the permission management device. Among them, the execution permission information can at least include a data volume threshold, which is used to indicate the maximum data volume of the data that the target object is allowed to modify in the target database. Of course, the execution permission information can also include any one or more of the following information: the statement type of the access statement allowed for the target object (such as: query statement type, delete statement type, create index statement type, etc.), the total access duration allowed for the target object to access the target database (such as: 30 minutes), and the access time period allowed for the target object to access the target database (such as: from 8:00 to 10:00 every morning), etc. It can be seen that by allocating such execution permission information to each object, the access behaviors such as viewing, modifying, adding, and deleting operations on the data in the database by different objects can be precisely managed at the smallest granularity.
[0111] After the computer device obtains the execution permission information, the computer device can execute this at least one access statement in sequence. During the execution process, the computer device can also determine the impact brought by the execution of each access statement to the target database, such as: the data volume of the data modified in the target database. Exemplarily, the modified data can include, but is not limited to, any one or more of the following: the deleted data, the updated data (such as: updating the original data A to data B), and the added data. Then, if the data volume of the data modified in the target database is greater than the data volume threshold indicated by the execution permission information of the target object, the computer device can instead determine whether the target database supports the transaction mechanism. The transaction mechanism is a unique term in the database, which mainly refers to a series of operations executed by a single logical unit of work. When data updates occur synchronously in the database, the transaction mechanism can prevent data inconsistency. Among them, when the target database supports the transaction mechanism, the computer device can revoke the modifications caused by all the executed access statements in at least one statement to the target database (which can be understood as rolling back the transaction); when the target database does not support the transaction mechanism, the computer device can revoke the modifications caused by the currently executed access statement to the target database (that is: revoke the modifications caused by the access statement executed when the data volume is greater than the data volume threshold), and refuse to execute the remaining access statements in at least one access statement.
[0112] It should also be noted that in the embodiments of the present application, the execution result corresponding to the executed access statement will not take effect immediately in the target database. The computer device can send the execution result to the database management device, and only after obtaining the execution approval of the database management device, will it perform the corresponding change operation on the target database. This processing method can effectively prevent the impact on the data in the target database caused by misoperations and ensure the security of the data in the target database.
[0113] Based on the above descriptions regarding Figure 2 and Figure 4 a complete exemplary process for the computer device to access the target database through the determined target database account information in the embodiments of the present application can be seen in Figure 6a . As Figure 6a shown, when the computer device detects an access request initiated by the target object, the computer device can first determine the identity information of the target object, that is, determine whether the target object is a management object. When the target object is a management object, the computer device can decrypt the encrypted database management account information of the target database to access the target database using the database management account. When the target object is a non-management object, the computer device can obtain the access permission information of the target object from the permission management device to determine whether the target object has the permission to access the target database. If the target object has the permission to access the target database, the computer device queries the driver of the target database, and when the queried driver is a secure driver, calculates the database account information of the target database so that the computer device can implement the access of the target object to the target database based on the database account information. Among them, the driver can be understood as a special program that enables the computer device and the database server where the target database is located to communicate with each other. Exemplarily, a secure driver can be understood as a driver that enables the communication between the computer device and the database server where the target database is located to proceed normally. Then, correspondingly, when the queried driver is a non-secure driver, the computer device needs to determine the database management account information of the target database as the target database access information required by the non-management object, and further use the database management account indicated by the database management account information to implement the access to the target database.
[0114] Among them, the specific process for the target object (non-management object or management object) to access the target database can be seen in Figure 6b . It should be noted that in Figure 6bBefore starting to execute the access, if the target object is a non - managed object, the computer device needs to first determine the execution permission information of the target object, so that the computer device can execute the access statement that the target object wants to execute on the target database based on the execution permission information. The access execution process after starting to execute the access can be as Figure 6b shown. If the target object is a managed object, the computer device can sequentially execute multiple access statements that need to be executed until the execution of the last access statement ends. If the target object is a non - managed object, the computer device can determine whether the target database supports transactions. If the target database supports transactions, the computer device can construct a transaction based on at least one access statement carried in the access request and start executing the transaction after the transaction is constructed. During the execution of the transaction, it is necessary to determine whether the execution result meets the execution permission indicated by the execution permission information of the target object, and determine whether there is an access statement in the transaction that matches the disabling operation of the target object. Exemplarily, the disabling operation can include an access statement that prohibits the target object from executing, such as: a statement to delete the database. Only when the access statements are all non - disabling operations, the computer device will call the corresponding driver to execute the at least one access statement in the target database in the form of a transaction. And, after the execution of the transaction, the computer device can also abandon and roll back the transaction when the execution result does not meet the execution permission, that is: revoke the impact on the target database caused by the execution of the at least one access statement. Optionally, if the target database does not support transactions, the computer device can also perform a security assessment on the access statements carried in the access request in combination with the identity information of the target object (that is: Figure 6b determining whether the access statement is a compliant statement in
[0115] ), and execute the corresponding access statement when the computer device determines that the impact on the target database after the execution of the access statement is within the safe range.In the embodiments of the present application, when a computer device responds to an access request initiated by a target object for a target database, it needs to obtain the access permission information of the target object from a permission management device to determine whether the target object has the access permission to the target database. Further, after the computer device determines that the target object can access the target database, the computer device will attempt to request the signature data of the target database from a signature data management device, so that the computer device can determine the database account information required when the target object accesses the target database, so as to enable the target object to access the target database by logging in to the database account indicated by the database account information. It can be seen that to achieve access to the target database, it is necessary for the computer device, the permission management device, and the signature data management device to cooperate to complete, and different devices are respectively managed by different management parties, which reflects the idea of separation of powers and can effectively prevent the security of the proxy database from being affected due to data leakage of a certain device, so as to ensure the security of the proxy database before being accessed. In addition, when the target object accesses the target database, the computer device will also determine the execution permission information of the target object to avoid adverse effects on the security of the target database caused by the access statements executed by the target object, thus ensuring the security of the proxy database during the access process. In addition, since a log recording device can also be used in the embodiments of the present application to record the access operations of the target object for the target database, subsequent updates of any data in the target database can be traced, which is convenient for performing audit work related to the target database, and can ensure the security of the target database even after the access occurs. Based on the above description, it is not difficult to see that the embodiments of the present application can achieve prevention before the event, control during the event, and audit after the event, and thus can provide all-round protection for the security of the proxy database.
[0116] Based on the description of the related embodiments of the above database access method, the embodiments of the present application also disclose a database access device, and the database access device may be a computer program (including program code) running in the above-mentioned computer device. In a specific embodiment, the database access device may be used to execute as Figure 2 or Figure 4 shown database access method. Please refer to Figure 7 , the database access device may include a receiving unit 701, a sending unit 702, an obtaining unit 703, and a processing unit 704.
[0117] The receiving unit 701 is configured to receive an access request initiated by a target object for a target database, and the access request carries the identity information of the target object;
[0118] A sending unit 702, configured to send a permission acquisition request for the target object to a permission management device in response to the access request, where the permission management device stores access permission information of at least one object;
[0119] The receiving unit 701 is further configured to receive the access permission information of the target object sent by the permission management device, where the access permission information is used to indicate whether the target object is allowed to access the target database;
[0120] An acquisition unit 703, configured to, if the access permission information indicates that the target object is allowed to access the target database, request the signature data management device to acquire the signature data of the target database, where the signature data management device stores the signature data of at least one database;
[0121] A processing unit 704, configured to determine the target database account information required when the target object accesses the target database based on the acquired signature data and the identity information of the target object, and access the target database through the determined target database account information.
[0122] In one implementation manner, the processing unit 704 may specifically be configured to execute:
[0123] When the identity information indicates that the target object is a management object, acquire the encrypted data of the target database, where the encrypted data includes the encrypted account information, and the encrypted account information is obtained by encrypting the database management account information of the target database;
[0124] Perform a decryption process on the encrypted account information according to the signature data to obtain the database management account information;
[0125] Determine the database management account information as the target database account information required when the target object accesses the target database.
[0126] In another implementation manner, the encrypted data further includes a key, and the encrypted account information is obtained by encrypting the database management account information according to the key and the signature data; the processing unit 704 may further be configured to execute:
[0127] Generate decryption process parameters according to the key and the signature data;
[0128] Perform a decryption process on the encrypted account information by using the decryption process parameters and the key to obtain the database management account information.
[0129] In yet another embodiment, the database access device may further include an encryption processing unit 705, and the encryption processing unit 705 may be configured to perform:
[0130] Receive the database management account information of the target database sent by the database management device to which the target database belongs, and generate a key for the target database;
[0131] Request the signature data management device to obtain the signature data of the target database, and generate encryption processing parameters using the generated key and the signature data, where the encryption processing parameters match the decryption processing parameters;
[0132] Encrypt the database management account information using the encryption processing parameters and the key to obtain the encrypted account information.
[0133] In yet another embodiment, the processing unit 704 may further be configured to perform:
[0134] When the identity information indicates that the target object is a non - management object, obtain the database identifier of the target database;
[0135] Generate the target database account information required for the target object to access the target database according to the database identifier and the signature data.
[0136] In yet another embodiment, the processing unit 704 may further be configured to perform:
[0137] Obtain the instance identifier of the proxy instance for proxying the target database;
[0138] Generate a database account identifier based on the instance identifier and the database identifier;
[0139] Generate a database account password according to the database account identifier and the signature data;
[0140] Generate the target database account information including the database account identifier and the database account password.
[0141] In yet another embodiment, the database access device may further include an account creation unit 706, and the account creation unit 706 may be configured to perform:
[0142] Receive the proxy request sent by the database management device to which the target database belongs;
[0143] In response to the proxy request, obtain the database identifier of the target database, determine the proxy instance for proxying the target database, and obtain the instance identifier of the proxy instance;
[0144] Request the signature data management device to obtain the signature data associated with the proxy instance as the signature data of the target database, where one signature data in the signature data management device corresponds to one proxy instance;
[0145] Create a database account for the target database according to the database identifier, the instance identifier, and the signature data of the target database, so as to allow access to the target database through the database account information of the database account.
[0146] In another embodiment, the access request carries at least one access statement, and the processing unit 704 can be used to execute:
[0147] If the identity information of the target object indicates that the target object is a non - management object, obtain the execution permission information of the target object from the permission management device, where the execution permission information includes a data volume threshold, and the data volume threshold is used to indicate the data volume of data allowed to be modified by the target object in the target database;
[0148] Execute the at least one access statement in sequence, and determine the maximum data volume of the data modified in the target database during the execution process;
[0149] When the determined data volume is greater than the data volume threshold and the target database supports the transaction mechanism, revoke the modifications to the target database caused by all the executed access statements in the at least one access statement;
[0150] When the determined data volume is greater than the data volume threshold and the target database does not support the transaction mechanism, revoke the modifications to the target database caused by the access statements executed when the data volume is greater than the data volume threshold.
[0151] According to an embodiment of the present application, Figure 2 and Figure 4 Each step involved in the method shown can be executed by Figure 7 Each unit in the database access device shown. For example, Figure 2 In the database access method shown, step S201 can be executed by the receiving unit 701 in the database access device shown, step S202 can be executed by the sending unit 702 in the database access device shown, step S203 can be executed by the receiving unit 701 in the database access device shown, step S204 can be executed by the obtaining unit 703 in the database access device shown, step S205 can be executed by Figure 7 In the database access device shown, step S202 can be executed by the sending unit 702 in the database access device shown, step S203 can be executed by the receiving unit 701 in the database access device shown, step S204 can be executed by the obtaining unit 703 in the database access device shown, step S205 can be executed by Figure 7 In the database access device shown, step S203 can be executed by the receiving unit 701 in the database access device shown, step S204 can be executed by the obtaining unit 703 in the database access device shown, step S205 can be executed by Figure 7 In the database access device shown, step S204 can be executed by the obtaining unit 703 in the database access device shown, step S205 can be executed by Figure 7 In the database access device shown, step S204 can be executed by the obtaining unit 703 in the database access device shown, step S205 can be executed by Figure 7It is executed by the processing unit 704 in the database access device shown. Again, Figure 4 Step S401 in the database access method shown can be executed by Figure 7 the receiving unit 701 in the database access device shown, step S402 can be executed by Figure 7 the sending unit 702 in the database access device shown, step S403 can be executed by Figure 7 the receiving unit 701 in the database access device shown, step S404 can be executed by Figure 7 the obtaining unit 703 in the database access device shown, and steps S405 to S406 can both be executed by Figure 7 the processing unit 704 in the database access device shown.
[0152] According to another embodiment of the present application, Figure 7 Each unit in the database access device shown is divided based on logical functions. The above-mentioned each unit can be separately or all combined into one or several other units to form, or, some (certain) of the units can be further split into multiple smaller units in terms of function to form, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. In other embodiments of the present application, the above-mentioned database access device may also include other units. In actual applications, these functions can also be assisted by other units, and can be assisted by multiple units.
[0153] According to another embodiment of the present application, it can be achieved by running a computer program (including program code) capable of executing the steps involved in the methods shown in Figure 2 and Figure 4 on a general computing device such as a domain name management device including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM), to construct a database access device as shown in Figure 7 and to implement the database access method of the embodiments of the present application. The computer program can be recorded on, for example, a computer storage medium, and be loaded into the above-mentioned computing device through the computer storage medium and run therein.
[0154] In the embodiment of the present application, when the database access device responds to an access request initiated by a target object for a target database of an agent, it can obtain the access permission information of the target object from the permission management device, and when the obtained access permission information indicates that the target object can access the target database, it further obtains the signature data of the target database from the signature management device, so as to select corresponding database account information for the target object based on the signature data of the target database and the identity information of the target object, so that the database access device can access the target database through the selected database account information. It can be seen that when the database access device responds to an access request for a target database, it needs to obtain the approval of the permission management device and the signature data management device. If any device refuses to provide data to the database access device or provides incorrect data to the database access device, it will cause the database access device to be unable to successfully respond to the access request, so that the target database cannot be accessed. Therefore, before the database access device, the permission management device, and the signature data management device cooperate to determine the database account information required by the target object, the target database will not be affected by any operations related to the target object, so that the interference rate of the target database during the entire agent process is reduced, effectively improving the stability of the target database. In addition, since accessing the target database requires using corresponding database account information, and the database account information needs to be confirmed through the cooperation of the database access device, the permission management device, and the signature data management device, it is not difficult to understand that the database access method provided by the embodiment of the present application can avoid the over-concentration of permissions for responding to access requests, and thus can avoid the security of the database being affected due to a security risk in a certain device, thereby ensuring the security of the database being agented.
[0155] Based on the relevant descriptions of the above method embodiments and apparatus embodiments, the embodiment of the present application also provides a computer device (or access proxy device), please refer to Figure 8 . The computer device at least includes an input unit 801, an output unit 802, a processor 803, and a computer storage medium 804, and the input unit 801, the output unit 802, the processor 803, and the computer storage medium 804 of the computer device can be connected through a bus or other means.
[0156] Among them, the above-mentioned computer storage medium 804 is a memory device in the computer device, which is used to store programs and data. It can be understood that the computer storage medium 804 here can include both the built-in storage medium in the computer device and, of course, the extended storage medium supported by the computer device. The computer storage medium 804 provides a storage space, and the operating system of the computer device is stored in this storage space. Moreover, one or more computer programs suitable for being loaded and executed by the processor 803 are stored in this storage space, and these computer programs can be one or more program codes. It should be noted that the computer storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory; optionally, it can also be at least one storage medium located far from the aforementioned processor. The processor 803 (or CPU (Central Processing Unit, central processor)) is the computing core and control core of the computer device, which is suitable for implementing one or more computer programs, specifically suitable for loading and executing one or more computer programs to implement the corresponding method flow or corresponding function.
[0157] In one embodiment, Figure 8 the computer device shown can execute the steps executed by the computer device in the above embodiment, that is: one or more computer programs stored in the computer storage medium 804 can be loaded and executed by the processor 803 to implement the above-mentioned related Figure 2 and Figure 4 steps shown. In a specific implementation, one or more computer programs stored in the computer storage medium 804 are loaded and executed by the processor 803:
[0158] Receive an access request initiated by a target object for a target database, and the access request carries the identity information of the target object;
[0159] In response to the access request, send a permission acquisition request for the target object to a permission management device, and the permission management device stores access permission information of at least one object;
[0160] Receive the access permission information of the target object sent by the permission management device, and the access permission information is used to indicate whether the target object is allowed to access the target database;
[0161] If the access permission information indicates that the target object is allowed to access the target database, then request the signature data management device to obtain the signature data of the target database, and the signature data management device stores the signature data of at least one database;
[0162] Based on the obtained signature data and the identity information of the target object, determine the target database account information required for the target object to access the target database, and access the target database using the determined target database account information.
[0163] In one implementation, the processor 803 may be specifically configured to load and execute:
[0164] When the identity information indicates that the target object is a management object, obtain the encrypted data of the target database, where the encrypted data includes the encrypted account information, and the encrypted account information is obtained by encrypting the database management account information of the target database;
[0165] Perform decryption processing on the encrypted account information according to the signature data to obtain the database management account information;
[0166] Determine the database management account information as the target database account information required for the target object to access the target database.
[0167] In another implementation, the encrypted data further includes a key, and the encrypted account information is obtained by encrypting the database management account information according to the key and the signature data; the processor 803 may be specifically configured to load and execute:
[0168] Generate decryption processing parameters according to the key and the signature data;
[0169] Perform decryption processing on the encrypted account information using the decryption processing parameters and the key to obtain the database management account information.
[0170] In another implementation, the processor 803 may also be specifically configured to load and execute:
[0171] Receive the database management account information of the target database sent by the database management device to which the target database belongs, and generate a key for the target database;
[0172] Request the signature data management device to obtain the signature data of the target database, and generate encryption processing parameters using the generated key and the signature data, where the encryption processing parameters match the decryption processing parameters;
[0173] Perform encryption processing on the database management account information using the encryption processing parameters and the key to obtain the encrypted account information.
[0174] In another implementation, the processor 803 may also be specifically configured to load and execute:
[0175] When the identity information indicates that the target object is a non - management object, obtain the database identifier of the target database;
[0176] Generate the target database account information required for the target object to access the target database according to the database identifier and the signature data.
[0177] In another embodiment, the processor 803 may further be specifically configured to load and execute:
[0178] Obtain the instance identifier of the proxy instance for proxying the target database;
[0179] Generate a database account identifier based on the instance identifier and the database identifier;
[0180] Generate a database account password according to the database account identifier and the signature data;
[0181] Generate the target database account information including the database account identifier and the database account password.
[0182] In another embodiment, the processor 803 may further be specifically configured to load and execute:
[0183] Receive a proxy request sent by the database management device to which the target database belongs;
[0184] In response to the proxy request, obtain the database identifier of the target database, determine the proxy instance for proxying the target database, and obtain the instance identifier of the proxy instance;
[0185] Request the signature data management device to obtain the signature data associated with the proxy instance as the signature data of the target database, where one signature data in the signature data management device corresponds to one proxy instance;
[0186] Create a database account for the target database according to the database identifier, the instance identifier, and the signature data of the target database, so as to allow access to the target database through the database account information of the database account.
[0187] In another embodiment, the access request carries at least one access statement, and the processor 803 may further be specifically configured to load and execute:
[0188] If the identity information of the target object indicates that the target object is a non - management object, obtain the execution permission information of the target object from the permission management device. The execution permission information includes a data volume threshold, and the data volume threshold is used to indicate the data volume of the data allowed to be modified by the target object in the target database;
[0189] Execute the at least one access statement in sequence, and determine the maximum data volume of the data modified in the target database during the execution process;
[0190] When the determined data volume is greater than the data volume threshold and the target database supports the transaction mechanism, revoke the modifications to the target database caused by all the executed access statements in the at least one access statement;
[0191] When the determined data volume is greater than the data volume threshold and the target database does not support the transaction mechanism, revoke the modifications to the target database caused by the access statements executed when the data volume is greater than the data volume threshold.
[0192] In the embodiments of the present application, when a computer device responds to an access request initiated by a target object for a proxy target database, it can obtain the access permission information of the target object from the permission management device. When the obtained access permission information indicates that the target object can access the target database, it further obtains the signature data of the target database from the signature management device, so as to select the corresponding database account information for the target object based on the signature data of the target database and the identity information of the target object. Thus, the computer device can access the target database through the selected database account information. It can be seen that when the computer device responds to an access request for the target database, it needs to obtain the recognition of the permission management device and the signature data management device. If either device refuses to provide data to the computer device or provides incorrect data to the computer device, it will cause the computer device to be unable to successfully respond to the access request, resulting in the target database being unable to be accessed. Therefore, before the computer device, the permission management device, and the signature data management device cooperate to complete the determination of the database account information required by the target object, the target database will not be affected by any operations related to the target object, thereby reducing the interference rate of the target database during the entire proxy process and effectively improving the stability of the target database. In addition, since accessing the target database requires using the corresponding database account information, and the database account information needs to be confirmed through the cooperation of the computer device, the permission management device, and the signature data management device, it is not difficult to understand that the database access method provided by the embodiments of the present application can avoid the over - concentration of permissions for responding to access requests, and thus can avoid the security of the database being affected due to potential security risks in a certain device, thereby ensuring the security of the database being proxied.
[0193] The embodiments of the present application also provide a computer storage medium, in which one or more computer programs corresponding to the above database access method are stored. When one or more processors load and execute the one or more computer programs, the description of the database access method in the above embodiments can be implemented. The embodiments of the present application will not be elaborated herein. The description of the beneficial effects of using the same method will not be elaborated herein. It can be understood that the computer program can be deployed on one or more devices capable of communicating with each other for execution.
[0194] It should be noted that, according to one aspect of the present application, a computer product or a computer program is also provided. The computer product includes a computer program, and the computer program is stored in a computer storage medium. The processor in the computer device reads the computer program from the computer storage medium and then executes the computer program, so that the computer device can execute the above Figure 2 and Figure 4 methods provided in various alternative ways in the database access method embodiments shown.
[0195] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer storage medium. When the computer program is executed, it can include the processes of the embodiments of the above database access method. Among them, the computer storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0196] It should be particularly noted that when the above embodiments are applied to specific products or technologies, if it involves the act of obtaining data related to the target object, the relevant products or technologies need to obtain the permission or consent of the target object, and the data obtained by the relevant products or technologies needs to comply with the laws, regulations and standards of the relevant countries and regions.
[0197] It can be understood that the above-disclosed is only partial embodiments of the present application. Of course, the scope of rights of the present application cannot be limited thereby. Those of ordinary skill in the art can understand all or part of the processes of the above embodiments and the equivalent changes made according to the claims of the present application still fall within the scope covered by the invention.
Claims
1. A database access method, characterized in that, including: receiving a proxy request sent by a database management device to which a target database belongs; in response to the proxy request, obtaining a database identifier of the target database, determining a proxy instance for proxying the target database, and obtaining an instance identifier of the proxy instance; requesting a signature data management device to obtain signature data associated with the proxy instance as the signature data of the target database, wherein one signature data in the signature data management device corresponds to one proxy instance; creating a database account for the target database according to the database identifier, the instance identifier, and the signature data of the target database, so as to allow access to the target database through database account information of the database account; receiving an access request initiated by a target object for the target database, where the access request carries identity information of the target object; in response to the access request, sending a permission acquisition request for the target object to a permission management device, where the permission management device stores access permission information of at least one object; receiving the access permission information of the target object sent by the permission management device, where the access permission information is used to indicate whether the target object is allowed to access the target database; if the access permission information indicates that the target object is allowed to access the target database, requesting the signature data management device to obtain the signature data of the target database, where the signature data management device stores signature data of at least one database; determining target database account information required when the target object accesses the target database based on the obtained signature data and the identity information of the target object, and accessing the target database through the determined target database account information.
2. The method according to claim 1, wherein The determining the target database account information required when the target object accesses the target database based on the obtained signature data and the identity information of the target object includes: when the identity information indicates that the target object is a management object, obtaining encrypted data of the target database, where the encrypted data includes encrypted account information, and the encrypted account information is obtained by encrypting database management account information of the target database; performing a decryption process on the encrypted account information according to the signature data to obtain the database management account information; determining the database management account information as the target database account information required when the target object accesses the target database.
3. The method according to claim 2, characterized in that, The encrypted data further includes a key, and the encrypted account information is obtained by encrypting the database management account information according to the key and the signature data; The performing a decryption process on the encrypted account information according to the signature data to obtain the database management account information includes: generating decryption process parameters according to the key and the signature data; performing a decryption process on the encrypted account information by using the decryption process parameters and the key to obtain the database management account information.
4. The method according to claim 3, wherein The method further includes: Receive the database management account information of the target database sent by the database management device to which the target database belongs, and generate a key for the target database; Request the signature data management device to obtain the signature data of the target database, and generate encryption processing parameters using the generated key and the signature data, where the encryption processing parameters match the decryption processing parameters; Perform encryption processing on the database management account information using the encryption processing parameters and the key to obtain the encrypted account information.
5. The method according to claim 1, wherein The determining the target database account information required for the target object to access the target database based on the obtained signature data and the identity information of the target object includes: When the identity information indicates that the target object is a non-management object, obtain the database identifier of the target database; Generate the target database account information required for the target object to access the target database according to the database identifier and the signature data.
6. The method according to claim 5, wherein The generating the target database account information required for the target object to access the target database according to the database identifier and the signature data includes: Obtain the instance identifier of the proxy instance for proxying the target database; Generate a database account identifier based on the instance identifier and the database identifier; Generate a database account password according to the database account identifier and the signature data; Generate the target database account information including the database account identifier and the database account password.
7. The method according to claim 1, characterized in that, The access request carries at least one access statement, and accessing the target database using the determined target database account information includes: If the identity information of the target object indicates that the target object is a non-management object, obtain the execution permission information of the target object from the permission management device, where the execution permission information includes a data volume threshold for indicating the data volume of data allowed to be modified by the target object in the target database; Execute the at least one access statement in sequence, and determine the maximum data volume of the data modified in the target database during the execution process; When the determined data volume is greater than the data volume threshold and the target database supports the transaction mechanism, revoke the modifications to the target database caused by all the executed access statements in the at least one access statement; When the determined data volume is greater than the data volume threshold and the target database does not support the transaction mechanism, revoke the modifications to the target database caused by the access statements executed when the data volume is greater than the data volume threshold.
8. A database access device, characterized in that, Includes: An account creation unit for receiving a proxy request sent by the database management device to which the target database belongs; In response to the proxy request, obtain the database identifier of the target database, determine a proxy instance for proxying the target database, and obtain the instance identifier of the proxy instance; request the signature data management device to obtain the signature data associated with the proxy instance as the signature data of the target database, where one signature data in the signature data management device corresponds to one proxy instance; create a database account for the target database according to the database identifier, the instance identifier, and the signature data of the target database, so as to allow access to the target database through the database account information of the database account. A receiving unit, configured to receive an access request initiated by a target object for a target database, where the access request carries the identity information of the target object. A sending unit, configured to, in response to the access request, send a permission acquisition request for the target object to a permission management device, where the permission management device stores access permission information of at least one object. The receiving unit is further configured to receive the access permission information of the target object sent by the permission management device, where the access permission information is used to indicate whether the target object is allowed to access the target database. An obtaining unit, configured to, if the access permission information indicates that the target object is allowed to access the target database, request the signature data management device to obtain the signature data of the target database, where the signature data management device stores the signature data of at least one database. A processing unit, configured to determine the target database account information required when the target object accesses the target database based on the obtained signature data and the identity information of the target object, and access the target database through the determined target database account information.
9. A computer device, characterized in that, Comprising: A processor, where the processor is configured to implement one or more computer programs. A computer storage medium, where the computer storage medium stores one or more computer programs, and the one or more computer programs are suitable for being loaded and executed by the processor to perform the database access method according to any one of claims 1-7.
10. A computer storage medium, characterized in that, The computer storage medium stores one or more computer programs, and the one or more computer programs are suitable for being loaded and executed by the processor to perform the database access method according to any one of claims 1-7.
11. A computer product, characterized in that, The computer product includes a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the database access method according to any one of claims 1-7.
Citation Information
Patent Citations
Access control method and device, gateway, client and security token service
CN112187724A