Data management method, device, equipment and storage medium for semi-transparent encrypted columns

By using ciphertext data to update and rollback during the data update process of translucent encrypted columns, the problem of data loss is solved, data integrity and security are ensured, and the leakage of plaintext data is avoided.

CN114996734BActive Publication Date: 2025-07-22SHANGHAI DAMENG DATABASE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210637322.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-07
Publication Date
2025-07-22
Estimated Expiration
2042-06-07

AI Technical Summary

Technical Problem

During the data update process of translucent encrypted columns, the prior art leads to the problem of plaintext data loss, especially when updating variable length columns, the translucent encrypted column data of non-updated columns cannot be properly restored, resulting in all users querying NULL data.

Method used

By obtaining the table and column information to be updated in the update operation, it is determined that the old data of each row to be processed is ciphertext data, and a first target record and rollback record are constructed to avoid decrypting the plaintext data during the update process, and directly use ciphertext data for update and rollback, ensuring the integrity of the data.

Benefits of technology

It effectively avoids data loss during the data update process of translucent encrypted column data, ensures that the correct ciphertext data can be obtained under different user identification situations, prevents plaintext data leakage, and improves the security and integrity of data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114996734B_ABST
    Figure CN114996734B_ABST
Patent Text Reader

Abstract

The present invention discloses a data management method, device, equipment and storage medium for semi-transparent encrypted columns. The method includes: obtaining an update operation; determining the old data of each to-be-updated column corresponding to each to-be-processed row according to the to-be-updated table information and the to-be-updated column information, wherein the old data of the to-be-updated column with a semi-transparent encryption identifier is ciphertext data; constructing a first target record according to the semi-transparent encryption identifier of each column in the to-be-updated table, the data of non-updated columns in the to-be-updated table, and the new data of the to-be-updated columns, wherein the data of non-updated columns with a semi-transparent encryption identifier is ciphertext data; constructing a rollback record according to the old data of the to-be-updated columns; and performing data update on the to-be-updated table and the to-be-updated columns according to the first target record, solving the problem of data loss during the data update of semi-transparent encrypted columns, and without considering whether the current operating user is the same as the user identifier of the to-be-updated column when obtaining the old data of the to-be-updated column, avoiding the situation where the old data is empty.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of databases, and in particular, to a data management method, device, equipment and storage medium for semi-transparent encrypted columns. Background Art

[0002] Semi-transparent encrypted column: A column that encrypts data using the storage key of the operating user. The ciphertext data of the semi-transparent encrypted column is appended with the identification information UID of the operating user. Multiple semi-transparent encrypted columns can be included in a table, and the UIDs appended to the ciphertext data of each semi-transparent encrypted column in each row record can be different (or a mapping relationship between the row number, column number, and UID can be stored using additional information). When querying and obtaining data from a semi-transparent encrypted column, if the UID of the current session user is the same as the UID appended to the ciphertext data of the semi-transparent encrypted column, the plaintext data is decrypted and returned; otherwise, NULL is directly returned without decryption (or the ciphertext data can be returned, but the client may not be able to display the complete ciphertext data because the ciphertext data may contain invisible characters or incomplete characters).

[0003] When a table contains semi-transparent encrypted columns, UPDATE updates may cause the plaintext data of the semi-transparent encrypted columns to be lost. During an update, if the UID of the current session user is different from the UID appended to the ciphertext data of the semi-transparent encrypted column, the old data of the semi-transparent encrypted column obtained by the update operation through querying is NULL. Therefore, when rolling back the record during data update, the stored old data in the rollback record is NULL. When the transaction is rolled back, the old data NULL is re-encrypted and written into the record, resulting in the loss of the corresponding plaintext data of the old data in the record, and any user querying and obtaining data will get NULL.

[0004] When updating a variable-length column using UPDATE, the data of the semi-transparent encrypted column in the non-updated column is lost. Because when updating a variable-length column, the record needs to be reconstructed (only when updating a fixed-length column, the record can be updated directly at the corresponding offset position in the original record without reconstructing; when updating a variable-length column, if the record becomes longer, the old record is deleted and the new record is stored at other positions. If the record does not become longer, the new record can be stored at the position where the original record is located, but the offset of the data of each variable-length column in the record may change). The new record includes the new data of the updated column and the old data of the non-updated column. When querying and obtaining the old data of the semi-transparent encrypted column in the non-updated column, if the UID of the current session user is different from the UID appended to the ciphertext data of the semi-transparent encrypted column, the obtained old data is NULL, and the old data NULL is re-encrypted and written into the new record, resulting in the loss of the plaintext data of the non-updated semi-transparent encrypted column in the new record (any user querying and obtaining data will get NULL). Summary of the Invention

[0005] The present invention provides a data management method for semi-transparent encrypted columns to solve the problem of data loss during the data update process of semi-transparent encrypted columns.

[0006] According to one aspect of the present invention, there is provided a data management method for semi-transparent encrypted columns, the method comprising:

[0007] Obtaining an update operation, the update operation including information of a table to be updated and information of columns to be updated, the information of the table to be updated including semi-transparent encryption identifiers of each column in the table to be updated, and the information of the columns to be updated including new data of the columns to be updated;

[0008] Determining old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the columns to be updated, wherein the old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data;

[0009] Constructing a first target record according to the semi-transparent encryption identifiers of each column in the table to be updated, data of non-updated columns in the table to be updated, and new data of the columns to be updated, wherein the data of non-updated columns with semi-transparent encryption identifiers is ciphertext data;

[0010] Constructing a rollback record according to the old data of the column to be updated;

[0011] Updating data of the table to be updated and the columns to be updated according to the first target record.

[0012] According to another aspect of the present invention, there is provided a data management device for semi-transparent encrypted columns, the device comprising:

[0013] An obtaining module, configured to obtain an update operation, the update operation including information of a table to be updated and information of columns to be updated, the information of the table to be updated including semi-transparent encryption identifiers of each column in the table to be updated, and the information of the columns to be updated including new data of the columns to be updated;

[0014] A data determination module, configured to determine old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the columns to be updated, wherein the old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data;

[0015] A first record construction module, configured to construct a first target record according to the semi-transparent encryption identifiers of each column in the table to be updated, data of non-updated columns in the table to be updated, and new data of the columns to be updated, wherein the data of non-updated columns with semi-transparent encryption identifiers is ciphertext data;

[0016] A rollback record construction module, configured to construct a rollback record according to the old data of the column to be updated;

[0017] An update module, configured to update data of the table to be updated and the columns to be updated according to the first target record.

[0018] According to another aspect of the present invention, there is provided an electronic device, including:

[0019] At least one processor; and

[0020] A memory communicatively connected to the at least one processor; wherein,

[0021] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the data management method for semi-transparent encrypted columns according to any embodiment of the present invention.

[0022] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for implementing the data management method for semi-transparent encrypted columns according to any embodiment of the present invention when executed by a processor.

[0023] The technical solution of the embodiment of the present invention obtains an update operation, where the update operation includes information of the table to be updated and information of the columns to be updated. The information of the table to be updated includes the semi-transparent encryption identifier of each column in the table to be updated, and the information of the columns to be updated includes the new data of the columns to be updated. The old data of each column to be updated corresponding to each row to be processed is determined according to the information of the table to be updated and the information of the columns to be updated. Among them, the old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data. A first target record is constructed according to the semi-transparent encryption identifier of each column in the table to be updated, the data of the non-updated columns in the table to be updated, and the new data of the columns to be updated. Among them, the data of the non-updated columns with a semi-transparent encryption identifier is ciphertext data. A rollback record is constructed according to the old data of the columns to be updated. The data of the table to be updated and the columns to be updated is updated according to the first target record. The problem of data loss during the data update process of semi-transparent encrypted columns is solved. By the update operation, the new data of the columns to be updated, the table to be updated, and the semi-transparent encryption identifier of each column in the table to be updated are determined. The old data of each column to be updated corresponding to each row to be processed is determined according to the information of the table to be updated and the information of the columns to be updated. The old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data. When obtaining the old data of the column to be updated, it is not necessary to consider whether the current operating user has the same user identifier as the column to be updated, avoiding the situation where the old data obtained is empty due to different user identifiers. Even if the user identifiers corresponding to the columns to be updated are different, ciphertext data can be obtained for update, thereby avoiding data loss.

[0024] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood from the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0026] Figure 1 is a flowchart of a data management method for semi-transparent encrypted columns provided in Embodiment 1 of the present invention;

[0027] Figure 2 is a flowchart of a data management method for semi-transparent encrypted columns provided in Embodiment 2 of the present invention;

[0028] Figure 3 is a schematic structural diagram of a data management device for semi-transparent encrypted columns provided in Embodiment 3 of the present invention;

[0029] Figure 4 is a schematic structural diagram of an electronic device for implementing the data management method of semi-transparent encrypted columns in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0031] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0032] Embodiment 1

[0033] Figure 1 FIG. is a flowchart of a data management method for semi-transparent encrypted columns provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of managing data of semi-transparent encrypted columns. This method can be executed by a data management device for semi-transparent encrypted columns. The data management device for semi-transparent encrypted columns can be implemented in the form of hardware and / or software, and the data management device for semi-transparent encrypted columns can be configured in electronic devices such as desktop computers, notebooks, and tablets. As Figure 1 shown, the method includes:

[0034] S101. Obtain an update operation, where the update operation includes information of the table to be updated and information of the column to be updated. The information of the table to be updated includes the semi-transparent encryption identifier of each column in the table to be updated, and the information of the column to be updated includes the new data of the column to be updated.

[0035] In this embodiment, the update operation is an operation to update the database; the table to be updated can be specifically understood as a data table with update requirements, and the information of the table to be updated can be specifically understood as the data table information of the table to be updated. For example, the table name of the data table and the semi-transparent encryption identifier of each column in the data table; the semi-transparent encryption identifier can be specifically understood as identification information used to identify whether the data column in the data table is a semi-transparent encrypted column. The column to be updated can be specifically understood as the data column in the data table that needs to be updated, and the information of the column to be updated can be specifically understood as the information of the column to be updated. For example, the column number of the column to be updated; the new data is the data used to replace the original data of the column to be updated in the data table.

[0036] Users operate the database through Structured Query Language (SQL). For example, they perform operations such as INSERT, DELETE, UPDATE, and SELECT on the database by writing corresponding SQL statements. When a user performs an update operation on the columns of a certain table in the database, the database server parses the UPDATE statement received from the client user input to determine the table information to be updated and the column information to be updated. The table information to be updated includes the semi-transparent encryption identifier of each column in the table to be updated, and the column information to be updated includes the new data of the column to be updated.

[0037] Among them, the semi-transparent encryption column identifier in this application can be represented in ways such as 0 / 1, true / false, etc. 0 / false / false means not having a semi-transparent encryption identifier, and 1 / true / true means having a semi-transparent encryption identifier.

[0038] S102. Determine the old data of each column to be updated corresponding to each row to be processed according to the table information to be updated and the column information to be updated. Among them, the old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data.

[0039] In this embodiment, the row to be processed can be specifically understood as the data row in the table to be updated with an update requirement.

[0040] Specifically, a data table usually contains data in multiple rows and columns. When performing an update, it can be an update to all rows or a partial update to some rows. When there is a filtering condition in the table information to be updated, each row to be processed is obtained by filtering each data row through the filtering condition; when there is no filtering condition in the table information to be updated, there is no need for filtering, and all data rows are directly used as the rows to be processed. Determine the table to be updated according to the table information to be updated, determine the column to be updated according to the column information to be updated, determine the specific position of the data that needs to be updated in the table to be updated according to the column to be updated and the row to be processed, and obtain the corresponding old data from the table to be updated according to the specific position of each data. Among them, when obtaining the old data, for each column to be updated, directly obtain the old data. If it has a semi-transparent encryption identifier, this old data is ciphertext data and does not need to be decrypted; if it does not have a semi-transparent encryption identifier, this old data is processed according to the original processing logic.

[0041] When the column to be updated has a semi-transparent encryption identifier, directly obtain the ciphertext data of the old data. This ciphertext data is used to store the old data of the updated column in the rollback record during the update operation in S104, rather than for querying or filtering, and plaintext data is not required. Therefore, there is no need to decrypt the ciphertext data. When the column to be updated is a semi-transparent encryption identifier column, it avoids the situation where the ciphertext data of the old data is decrypted and then encrypted and written into the rollback record when the user identifiers are the same (the ciphertext data is recorded in the rollback log to avoid the leakage of plaintext data); keeping the old data as ciphertext data also avoids the situation where when the user identifiers are different, the data cannot be decrypted and a NULL error occurs, and NULL is written into the rollback record, resulting in the loss of data in the updated column with a semi-transparent encryption identifier during transaction rollback (the data in the updated column seen by all users is NULL).

[0042] S103. Construct a first target record according to the semi-transparent encryption identifier of each column in the table to be updated, the data of the non-updated columns in the table to be updated, and the new data of the column to be updated, where the data of the non-updated columns with semi-transparent encryption identifiers is ciphertext data.

[0043] In this embodiment, the first target record can be specifically understood as the record formed according to the new data during the data table update process, and the first target record is the record in the cache. The non-updated column can be specifically understood as the column of the data in the table to be updated that is not updated. When the column to be updated is a variable-length column, since the length of the updated data may be inconsistent with the length of the data before the update, writing the updated data will cause the record position to change. Therefore, when the column to be updated is a variable-length column, create a new record to store the data. After creating the new record, copy the data of the non-updated columns; when the column to be updated is a fixed-length column, directly update in the original record, write the new data of the column to be updated, and keep the data of the non-updated columns unchanged.

[0044] Specifically, the semi-transparent encryption identifier for each column in the data table is determined in advance when creating the table or modifying the column definition of the table. Based on the semi-transparent encryption identifier on the column, it is determined whether each column to be updated is a semi-transparent encryption column. For semi-transparent encryption columns, corresponding encryption processing is performed on the new data during the update. For non-semi-transparent encryption columns, the new data is processed according to the original processing logic during the update. When updating each column to be updated, it is also necessary to consider whether the column to be updated is a variable-length column or a fixed-length column. When the column to be updated is a fixed-length column, the column to be updated in the original record is directly modified and updated to form the first target record with the data of the non-updated columns. When the column to be updated is a variable-length column, a new record is reconstructed, the new data of the column to be updated is written into the new record, and the data of the non-updated columns in the table to be updated is copied into the new record. When copying the data, for non-updated columns with a semi-transparent encryption identifier, the ciphertext data is directly copied to form the first target record. When the non-updated column is a semi-transparent encryption identifier column, the new record directly copies the ciphertext data, which avoids decrypting and then encrypting the data of the non-updated column and writing it into the new record when the user identifiers are the same, affecting the execution efficiency; the data of the non-updated column remains in ciphertext data, which also avoids the situation where the user of the current update operation is different from the user identifier corresponding to the ciphertext data of the non-updated column, resulting in the data of the non-updated column with a semi-transparent encryption identifier being lost when querying the new record or rolling back the transaction (all users see the data of the non-updated column as NULL). For the update operation, the ciphertext data of the non-updated column with a semi-transparent encryption identifier should remain unchanged. At the same time, the user identifier corresponding to the ciphertext data should also remain unchanged.

[0045] S104. Construct a rollback record based on the old data of the column to be updated.

[0046] Specifically, after constructing the first target record, the old data of the column to be updated is recorded in the rollback record for transaction rollback.

[0047] Among them, when the column to be updated has a semi-transparent identifier, the old data of the column to be updated in the rollback record is ciphertext data. The rollback record also records information about the table to be updated corresponding to the update operation, the column number of the column to be updated, the row information to be updated, the transaction information of the update operation, etc. All column data with a semi-transparent encryption identifier in the rollback record is ciphertext data to avoid the leakage of plaintext data.

[0048] S105. Update the data of the table to be updated and the column to be updated according to the first target record.

[0049] Locate the root address of the data stored in the B-tree of the table index according to the information of the table to be updated, and then determine the physical page to be modified (the index data is in order) and the offset within the page where it is stored according to the data in the first target record, and write the first target record to the specified offset position of the physical page to complete the data update.

[0050] Among them, the first target record includes the data of non-updated columns and the new data of updated columns, and all column data with semi-transparent encryption identifiers are ciphertext data.

[0051] An embodiment of the present invention provides a method for managing data of semi-transparent encrypted columns. By obtaining an update operation, the update operation includes information of a table to be updated and information of columns to be updated. The information of the table to be updated includes semi-transparent encryption identifiers of each column in the table to be updated, and the information of the columns to be updated includes new data of the columns to be updated; determining the old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the columns to be updated, where the old data of the columns to be updated with semi-transparent encryption identifiers is ciphertext data; constructing a first target record according to the semi-transparent encryption identifiers of each column in the table to be updated, the data of non-updated columns in the table to be updated, and the new data of the columns to be updated, where the data of non-updated columns with semi-transparent encryption identifiers is ciphertext data; constructing a rollback record according to the old data of the columns to be updated; and performing data update on the table to be updated and the columns to be updated according to the first target record. The problem of data loss during the data update process of semi-transparent encrypted columns is solved. The old data of the columns to be updated with semi-transparent encryption identifiers written into the rollback record is ciphertext data. When constructing a new first target record, the old data of non-updated columns with semi-transparent encryption identifiers written into the new record is ciphertext data, and there is no need for decryption processing. Therefore, it is not necessary to consider whether the user of the current operation is the same as the user identifier corresponding to the ciphertext data of the semi-transparent encrypted column, avoiding the situation of data loss caused by different user identifiers being unable to decrypt and returning NULL.

[0052] Embodiment 2

[0053] Figure 2 The flowchart of a method for managing data of semi-transparent encrypted columns provided by Embodiment 2 of the present invention is refined on the basis of the above embodiment. As Figure 2 shown, the method includes:

[0054] S201. Obtain an update operation, where the update operation includes information of a table to be updated and information of columns to be updated. The information of the table to be updated includes semi-transparent encryption identifiers of each column in the table to be updated, and the information of the columns to be updated includes new data of the columns to be updated.

[0055] Optionally, the information of the table to be updated includes semi-transparent encryption identifiers of each column in the table to be updated, as well as encryption information, data types, etc. of each column; the information of the columns to be updated includes semi-transparent encryption identifiers, column numbers of the columns to be updated, and new data of the columns to be updated.

[0056] Among them, the data type can be integer INT, string VARCHAR, etc. The data type can be used to determine whether the current column is a fixed-length column or a variable-length column, and the storage format.

[0057] Optionally, the table information to be updated further includes: a filtering condition.

[0058] The filtering condition is used to perform row selection on the data rows in the table to be updated and determine the rows to be processed.

[0059] In this embodiment, the filtering condition can be specifically understood as a condition for screening the rows to be updated in the table to be updated. By parsing the UPDATE statement, the filtering condition is determined. Exemplarily, CREATE TABLE T(C1 INT ENCRYPT MANUAL);

[0060] INSERT INTO T VALUES(2);

[0061] INSERT INTO T VALUES(3);

[0062] COMMIT;

[0063] UPDATE T SET C1 = 1 WHERE C1 = 2;

[0064] Where MANUAL represents a semi-transparent encrypted column, and other representations can also be used, which are not limited in this patent. The execution plan of the above UPDATE statement is as follows, for exemplary display only, and the execution plans of different databases are different:

[0065]

[0066] The execution order is as follows: UPDATE => PRJT => SLCT => CSCN. The upper-level operator obtains the data of the rows to be processed from the lower-level operator. When the number of rows to be processed is 0, the processing is completed. Exemplarily, the update operator UPDATE obtains the information of the rows to be updated from the lower-level projection operator PRJT. The row information is uniquely confirmed by the ROWID or the primary key of the index. The filtering operator SLCT filters the data returned by the scan operator CSCN (the scan operator also includes: CSEK, and the secondary index scan SSCN, SSEK). If the filtering condition is met, the filtering operator passes the data to the upper-level operator until it is uploaded to the update operator for update processing. Otherwise, if the filtering condition is not met, the filtering operator discards the data corresponding to the current row to be processed, that is, does not pass the row data that does not meet the filtering condition to the upper-level operator.

[0067] Exemplarily, the filtering condition can also include other tables other than the table T to be updated.

[0068] For example: CREATE TABLE T2(D1 INT ENCRYPT MANUAL);

[0069] INSERT INTO T VALUES(1);

[0070] UPDATE T SET C1 = 2 FROM T2 WHERE C1 = D1;

[0071] S202. Determine the columns to be filtered and the table information to which the columns to be filtered belong according to the filtering conditions.

[0072] In this embodiment, the columns to be filtered can be specifically understood as the data columns used to screen the data rows in the data table. The number of columns to be filtered can be one or more. By analyzing the filtering conditions, determine the columns to be filtered and the table information to which the columns to be filtered belong. For example, in the above example, the columns to be filtered are columns C1 and D1. Among them, C1 is the first column of the data table T, the data type of column C1 is integer INT and it has a semi-transparent encryption flag; among them, D1 is the first column of the data table T2, the data type of column D1 is integer INT and it has a semi-transparent encryption flag.

[0073] S203. Read the data of the columns to be filtered in each row record from the table to which the columns to be filtered belong.

[0074] When the columns to be filtered have a semi-transparent encryption flag, the data of the columns to be filtered refers to the plaintext data. Among them, if the user identifier of the current operation is the same as the user identifier corresponding to the column ciphertext data, decrypt to obtain the plaintext data to participate in the comparison of the filtering conditions, otherwise directly return NULL without decryption to participate in the comparison (unless the filtering condition is IS NULL, otherwise when the user identifiers are different, the filtering conditions will not be met).

[0075] S204. If the physical record of the row to be filtered in the table to which the columns to be filtered belong is visible, construct a data row according to the physical record and use it as the first target data row, and determine the plaintext data of the columns to be filtered according to the first target data row.

[0076] In this embodiment, the row to be filtered can be specifically understood as the data row in the data table. Each row record in the data table is used as a row to be filtered. By filtering the row to be filtered, the row to be processed that meets the filtering conditions is obtained. The first target data row can be specifically understood as the visible data row formed according to the old data in the physical record, and the data of each column in the data row is plaintext data.

[0077] When performing an update operation on a data table, there may be concurrent transactions modifying the data in the table that the current update operation depends on. After concurrent sessions execute UPDATE / DELETE / INSERT statements, if they do not execute COMMIT or ROLLBACK to end the concurrent transaction, the modified physical records will not be visible to other sessions. For example, when user A modifies the data in the i-th row and j-th column of data table T using UPDATE, and user B queries the data in the i-th row and j-th column of data table T using SELECT, the modification made by user A to the current record has not been committed or rolled back. For user B, the data in the i-th row and j-th column of the physical record of table T is not visible, and user B can only obtain the visible old data before the modification by user A through the first rollback record.

[0078] Determine the data table to which the column to be filtered belongs, and read the data of the column to be filtered in each row record from this data table. First, it is necessary to determine whether it is visible according to the transaction information stored in the physical record corresponding to the current row. If the record is visible, directly construct a data row based on the data in the physical record. The constructed data row is used as the first target data row, and the first target data row is the row to be filtered. The first target data row includes specific data, that is, the data obtained from the physical record. Determine the plaintext data corresponding to the column to be filtered by querying the first target data row. When constructing the data row, if the column to be filtered has a semi-transparent encryption flag, determine the plaintext data of the column to be filtered according to the user identifier of the ciphertext data. The plaintext data is the real plaintext data or NULL; if the column to be filtered does not have a semi-transparent encryption flag, the plaintext data of the column to be filtered is the data originally stored in the physical record.

[0079] S205: If the physical record of the row to be filtered in the table to which the column to be filtered belongs is not visible, construct a data row according to the physical record, determine the visible first rollback record, and adjust the data row according to the first rollback record to obtain the second target data row. Determine the plaintext data of the column to be filtered according to the second target data row.

[0080] In this embodiment, the first rollback record can be specifically understood as the first visible rollback record found according to the rollback record address stored in the physical record (the rollback record address includes: file number, page number, and in-page offset information, which are used to locate the rollback record. A physical record can contain 0, 1, or multiple rollback records, and each new rollback record points to the previous old rollback record). If the rollback record located by the rollback record address is not visible, recursively search for the rollback record forward until it is visible, and use the first visible rollback record as the first rollback record. Among them, whether the rollback record is visible is judged according to the transaction information in the rollback record. The second target data row can be specifically understood as a visible data row formed according to the current physical record and the old data in the first rollback record. The data in each column of the data row is visible data and is plaintext data.

[0081] When the physical record is invisible, the database server first reads the data of each column from the physical record to construct the data row used in memory. At this time, it is not known what causes the record to be invisible. According to the updated column information and the old data in the first rollback record, the column data in the data row is modified, and the columns in the data row are adjusted to the second target data row that is finally visible to the current user. The second target data row is the row to be filtered. The second target data row includes specific data, that is, the data obtained from the physical record and the first rollback record. At this time, the data of each column in the second target data row is visible plaintext data. According to the second target data row, the plaintext data corresponding to the column to be filtered is determined. The plaintext data is the real plaintext data or NULL.

[0082] When the physical record of the current row is invisible and there is no visible first rollback record, the current physical record is skipped and the next physical record is processed. Exemplarily: for concurrent insert INSERT, the rollback record address stored in the physical record is empty.

[0083] S206. Determine whether each row to be filtered in the table to be updated meets the filtering condition according to the plaintext data of the column to be filtered in each row to be filtered. If it meets the filtering condition, it is determined as the row to be processed.

[0084] Construct the first target data row and the second target data row through the physical record and / or the first rollback record, determine the plaintext data of each column to be filtered in the row to be filtered, judge whether each row to be filtered in the table to be updated meets the filtering condition according to the plaintext data of the column to be filtered, and use the data row that meets the filtering condition as the row to be processed.

[0085] Exemplarily, the UPDATE statement corresponding to the update operation is UPDATE T SET C1 = 1 WHERE C1 = 2. Among them, the filtering condition is C1 = 2, the data type of the C1 column is integer INT and has a semi-transparent encryption identifier. First, determine the plaintext data (real plaintext data or NULL) of the row to be filtered corresponding to the column to be filtered C1, and then compare the C1 data of the current row with 2. If the boolean expression corresponding to the filtering condition returns true, this row to be filtered is determined as the row to be processed, otherwise it is discarded and the next row to be filtered is continued to be processed until all rows to be filtered are compared.

[0086] When there is no filtering condition, a full data table scan is performed at this time. For example, the statement corresponding to the query operation is UPDATE T SET C1 = 1. At this time, there is no filtering condition, and all data rows in the table to be updated T are rows to be processed.

[0087] As an optional embodiment of this embodiment, this optional embodiment further specifies the step of constructing the data row according to the physical record as:

[0088] B1. If the column to be filtered has a semi-transparent encryption flag, determine the ciphertext data of the column to be filtered based on the user ID according to the physical record.

[0089] When determining the plaintext data of the column to be filtered, if the column to be filtered has a semi-transparent encryption flag, then the data of the column to be filtered stored in the physical record is all ciphertext data based on the user ID. When constructing the data row, it is necessary to decrypt according to the user ID to obtain the plaintext data (return NULL if the user IDs are different), and S206 uses the plaintext data to participate in the Boolean expression comparison of the filtering conditions.

[0090] B2. Determine whether the ID of the current operating user is the same as the user ID corresponding to the ciphertext data of the column to be filtered in the current row to be filtered. If so, decrypt the ciphertext data of the column to be filtered to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL.

[0091] In this embodiment, the current operating user can be understood as the logged-in user of the current connection session created by the client connecting to the database. Determine whether the ID of the current operating user is the same as the user ID corresponding to the ciphertext data of the column to be filtered in the current row to be filtered. If the same, obtain the user storage encryption key of the specified user according to the user ID, and decrypt the ciphertext data of the column to be filtered according to the user storage encryption key to determine the plaintext data. If not, at this time, there is no need to decrypt, determine that the plaintext data is NULL, and the visible plaintext data obtained by the current operating user is NULL.

[0092] B3. Construct a data row according to the plaintext data.

[0093] Fill the obtained plaintext data into the corresponding data columns in the data row to complete the construction of the data row.

[0094] S207. Determine the old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the column to be updated, where the old data of the column to be updated with a semi-transparent encryption flag is ciphertext data.

[0095] S208. Determine whether the column to be updated has a semi-transparent encryption flag. If so, execute S209; otherwise, execute S210.

[0096] Determine whether the column to be updated has a semi-transparent encryption flag according to the semi-transparent encryption flag of each column in the table to be updated. If the column to be updated has a semi-transparent encryption flag, execute S209 to construct the first target record; if the column to be updated does not have a semi-transparent encryption flag, execute S210 to construct the first target record.

[0097] S209. Encrypt the new data of the column to be updated using the user storage encryption key of the current operating user to obtain target ciphertext data, and construct a first target record based on the target ciphertext data and the data of the non-updated columns.

[0098] In this embodiment, the target ciphertext data can be specifically understood as the ciphertext data obtained after encryption processing. Among them, when the non-updated column has a semi-transparent encryption identifier, the data of the non-updated column is the ciphertext data of the non-updated column.

[0099] When the column to be updated has a semi-transparent encryption identifier, an encryption operation needs to be performed on the new data of the column to be updated to determine the user storage encryption key of the current operating user. The user storage encryption key is preset when creating a user using the CREATE USER statement and corresponds to the user one by one. Under the condition of determining the current operating user, the specified user storage encryption key is found according to the user identifier of the current operating user. Encrypt the new data of the column to be updated using the user storage encryption key of the current operating user to obtain target ciphertext data. The target ciphertext data is associated with the user identifier. The ciphertext data of each column with a semi-transparent encryption identifier in each row of record data can correspond to different user identifiers. Only when the user identifiers are the same can the plaintext data be decrypted and obtained according to the user identifier by finding the user storage encryption key of the specified user. When constructing the first target record based on the target ciphertext data and the data of the non-updated columns, if the column to be updated is a fixed-length column, directly replace the corresponding old data in the original record with the target ciphertext data. By writing the target ciphertext data into the original record, an updated first target record is formed with the data of the non-updated columns in the original record. If the column to be updated is a variable-length column, a new record needs to be created, copy the data of the non-updated columns, and construct the first target record in combination with the target ciphertext data. When copying the data of the non-updated columns, if the non-updated column has a semi-transparent encryption identifier, directly copy the ciphertext data of the non-updated column. This avoids the data of the non-updated columns being decrypted and then encrypted and written into the new record when the user identifiers are the same, which affects the execution efficiency; the data of the non-updated columns remains as ciphertext data, and it also avoids the situation where the user of the current update operation is different from the user identifier corresponding to the ciphertext data of the non-updated column, resulting in the data being unable to be decrypted and returning NULL, and wrongly writing NULL into the new record, thereby causing the data of the non-updated column with a semi-transparent encryption identifier to be lost when querying the new record or rolling back the transaction (the data of the non-updated column seen by all users is NULL).

[0100] It should be noted that after S209 is executed, S211 is executed.

[0101] S210. Process the new data of the column to be updated according to the original processing logic to obtain target data, and construct a first target record based on the target data and the data of the non-updated columns.

[0102] In this embodiment, the original processing logic can be specifically understood as the original data processing logic in the database. For example, data is processed according to a pre-determined algorithm; the target data can be specifically understood as the data obtained after processing the new data of the column to be updated. Among them, when the non-updated column has a semi-transparent encryption identifier, the data of the non-updated column is the ciphertext data of the non-updated column.

[0103] It should be noted that when determining the data of the non-updated column, it is also necessary to judge the visibility of the record. If the physical record is invisible, the first rollback record is queried to determine the visible data.

[0104] In the prior art, when updating a variable-length column, the data of the semi-transparent encrypted column in the non-updated column is lost. Because when updating a variable-length column, the record needs to be reconstructed (only when updating a fixed-length column, the record does not need to be reconstructed, and the value of the fixed-length column can be directly updated at the corresponding offset position in the original record; when updating a variable-length column, if the record becomes longer, the old record is deleted, and the new record will be stored at other positions. If the record does not become longer, the new record can be stored at the position where the original record is located, but the offset of the data of each variable-length column in the record may change). The new record includes the new data of the updated column and the old data of the non-updated column. When querying and obtaining the old data of the semi-transparent encrypted column in the non-updated column, if the user identifier of the current session user is different from the user identifier corresponding to the ciphertext data of the semi-transparent encrypted column, the obtained old data is NULL, and the old data NULL is re-encrypted and written into the new record, resulting in the loss of the plaintext data of the non-updated semi-transparent encrypted column in the new record, and the data obtained by any user query is NULL. In the present application, when updating a variable-length column, the corresponding data of the non-updated column is directly copied and written into the target record without decrypting the data. When any user queries, the data can be obtained. If the data is ciphertext data, it is automatically decrypted according to the user identifier, so there will be no data loss.

[0105] S211. If the column to be updated has a semi-transparent encryption identifier, write the ciphertext old data of the column to be updated into the rollback record.

[0106] Among them, all column data with semi-transparent encryption identifiers in the rollback record are ciphertext data.

[0107] In this embodiment, if the column to be updated has a semi-transparent encryption identifier, the old data of the column to be updated is ciphertext data at this time, and the ciphertext old data of the column to be updated is written into the rollback record. If the column to be updated has a semi-transparent encryption identifier, the column to be updated is a semi-transparent encryption column at this time, and the ciphertext old data of the column to be updated is written into the rollback record, avoiding the situation where the ciphertext data of the old data is decrypted and then encrypted and written into the rollback record when the user identifiers are the same (the ciphertext data is recorded in the rollback log to avoid the leakage of plaintext data); the old data remains ciphertext data, which also avoids the situation where when the user identifiers are different, the data cannot be decrypted and returns a NULL error and the NULL is written into the rollback record, resulting in the loss of data in the updated column with a semi-transparent encryption identifier during transaction rollback (the data in the updated column seen by all users is NULL).

[0108] If the column to be updated does not have a semi-transparent encryption identifier, the original processing logic remains unchanged, and the old data of the column to be updated is written into the rollback record.

[0109] S212. Write the rollback record into the rollback data page.

[0110] The rollback record is written into the rollback data page, and this step is completed before the new data (or the first target record containing the new data) is inserted into the physical page.

[0111] S213. Update the data of the table to be updated and the column to be updated according to the first target record.

[0112] In the prior art, when updating a semi-transparent encryption column, if a transaction rollback is performed, after the transaction rollback, the semi-transparent encryption column cannot be rolled back to the old data. Because if the user identifier of the current session user is different from the user identifier corresponding to the ciphertext data of the semi-transparent encryption column, the old data of the semi-transparent encryption column obtained by the update operation through query is NULL, rather than the corresponding plaintext data of the old data. Therefore, the old data stored in the rollback record is NULL. During transaction rollback, the old data NULL is re-encrypted and written into the record, resulting in the loss of the corresponding plaintext of the old data in the record, and the data obtained by any user query is NULL. In the data update process of the present application, if the column to be updated has a semi-transparent encryption identifier, the old data written into the rollback record is ciphertext. Therefore, the old data obtained during data rollback is ciphertext data, and the corresponding plaintext data is determined according to the ciphertext data, and no data loss will occur.

[0113] The update operation provided by the present application does not use the visible data plaintext of the semi-transparent encryption column, but only uses the ciphertext data of the corresponding column. Therefore, even if the user identifiers of the operating users are the same during the update operation, the ciphertext data does not need to be decrypted, and the visible data plaintext can be directly kept as the initial value NULL.

[0114] Optionally, the rollback record further includes updated table information, the column numbers of the updated columns, the row information of the updated rows, and transaction information.

[0115] In this embodiment, the updated table information can be specifically understood as the information of the data table updated in the rollback record. For example, the table ID of the updated table, the column numbers of the updated columns, etc. The row information of the updated rows can be specifically understood as the information of the updated data rows, and the row information is uniquely confirmed by the ROWID or the primary key of the index. The transaction information can be used to determine whether the rollback record is visible.

[0116] It can be known that when performing an update operation, data is updated for the columns to be updated in the table to be updated. After the update is completed, the table to be updated becomes the updated table. That is, for the same data table, during the update process, it can be the table to be updated, and after the update is completed, this data table in the rollback record is the updated table. Similarly, for the same data column, during the update process, it is the column to be updated, and after the update is completed, it is the updated column.

[0117] As an optional embodiment of this embodiment, the further processing method of this optional embodiment includes A1 - A6:

[0118] A1. Receive the rollback operation of the current transaction of the current session.

[0119] In this embodiment, the rollback operation is a rollback operation on the uncommitted data of the current transaction operation of the current session. After the user modifies the database by inserting, deleting, updating, etc., if it is necessary to revoke the modification, a rollback operation is performed on the current transaction, and a rollback operation is initiated to the database by executing the SQL statement ROLLBACK.

[0120] A2. When the current transaction to be rolled back includes an update operation, for the rollback record of the update operation, locate the current physical record in the physical page that needs to be updated and rolled back according to the updated table information and the row information of the updated rows in the rollback record.

[0121] In this embodiment, the current physical record can be specifically understood as the physical record of the current updated table that has the need for update and rollback located according to the row information of the updated rows in the rollback record. If the current transaction to be rolled back includes an update operation, that is, an update operation is performed in the current transaction, the current physical record that needs to be updated and rolled back is determined from the physical page according to the updated table information and the row information of the updated rows in the rollback record.

[0122] A3. Obtain the corresponding column information from the updated table information according to the column numbers of the updated columns in the rollback record, and determine the old data of the updated columns according to the rollback record.

[0123] Determine the column numbers of the updated columns recorded in the rollback record, and obtain the corresponding column information from the updated data table information according to the column numbers of the updated columns. For example, whether the updated column has a semi-transparent encryption flag, the data type of the updated column, etc. At the same time, determine the old data of each updated column by analyzing the rollback record. If the updated column has a semi-transparent encryption flag, the old data is ciphertext data based on the user ID.

[0124] A4. Determine whether the updated column has a semi-transparent encryption flag according to the corresponding column information of the updated column.

[0125] The corresponding column information of the updated column includes whether the updated column has a semi-transparent encryption flag. Therefore, after determining the corresponding column information of the updated column, it is possible to directly determine whether the updated column has a semi-transparent encryption flag.

[0126] A5. If the updated column has a semi-transparent encryption flag, the old data of the updated column is ciphertext data based on the user ID. Construct a second target record according to the ciphertext old data of the updated column and the current physical record, where the current physical record includes the updated column and non-updated columns, and all columns with a semi-transparent encryption flag are stored as ciphertext data in the second target record.

[0127] For the second target record after the update operation is rolled back, the ciphertext data of the non-updated columns with a semi-transparent encryption flag remains unchanged, and of course the user ID based on which also remains unchanged; the ciphertext data of the updated columns with a semi-transparent encryption flag is restored to the ciphertext data before the update, that is, the ciphertext data of the old data of the updated column in the rollback record based on the original user ID.

[0128] In this embodiment, the second target record can be specifically understood as the record obtained by restoring the old data before the current transaction is rolled back. If the updated column has a semi-transparent encryption flag, it can be determined that the old data of the updated column is ciphertext data. Calculate the offset position of the old data of the updated column in the second target record according to the updated table information, write the ciphertext data of the updated column to the corresponding offset position in the second target record, and jointly construct the second target record with the data of the non-updated columns in the current physical record.

[0129] When rolling back the update operation to construct the second target record, consider the semi-transparent encryption identifier of the updated column, and determine whether it is a variable-length column or a fixed-length column according to the data type of the updated column. When the updated column is a variable-length column, determine whether the updated column has a semi-transparent encryption identifier. When it has a semi-transparent encryption identifier, directly copy the ciphertext old data of the updated column in the rollback record to the reconstructed record structure to obtain the second target record. When the updated column does not have a semi-transparent encryption identifier, process the old data of the updated column according to the original processing logic and write it into the reconstructed record structure to obtain a new second target record. When reconstructing the record, if the non-updated column has a semi-transparent encryption column identifier, copy the ciphertext data of the non-updated column from the current physical record to the reconstructed record structure; if the non-updated column does not have a semi-transparent encryption column identifier, process the data according to the original processing logic. If the updated column is a fixed-length column, write the ciphertext data of the updated column based on the original user identifier in the rollback record into the second target record, and combine the data of the non-updated column in the current physical record to form the second target record.

[0130] When constructing the second target record, for variable-length columns and fixed-length columns, the old record can also be directly deleted and the newly constructed record can be inserted again, and the index data must always be kept ordered according to the primary key.

[0131] A6. If the updated column does not have a semi-transparent encryption identifier, construct the second target record according to the original processing logic.

[0132] When the updated column does not have a semi-transparent encryption identifier, construct the second target record according to the original processing logic in the database.

[0133] Optionally, after the current transaction performs a rollback operation to obtain the second target record, write the second target record into the physical page to complete the rollback operation of the current update rollback record.

[0134] In the method provided in the embodiments of the present application, the rollback operation will not use the visible data plaintext of the semi-transparent encryption column, but only use the ciphertext data of the corresponding column. Therefore, even if the user identifiers of the operating users are the same in the rollback operation, it is not necessary to decrypt the ciphertext data, and the visible data plaintext can be directly filled with NULL.

[0135] As an optional embodiment of this embodiment, this optional embodiment further includes the following steps B1-B3:

[0136] B1. Receive the query operation of other sessions and determine the columns to be queried corresponding to the query operation.

[0137] Each session has its own transaction. Once the current transaction ends (COMMIT or ROLLBACK), a new transaction will be started for the session. Only after the current transaction ends will the modifications made by the current transaction be visible to other sessions. The columns to be queried can be specifically understood as the data columns with query requirements when querying a data table. By parsing the query statement corresponding to the query operation, the columns to be queried are determined. The number of columns to be queried can be one or multiple.

[0138] In this embodiment, when the current session modifies a data table, other sessions can modify or query the same data table. Only when concurrent transactions modify the same row of records will the latter transaction enter the transaction lock waiting state, and the latter transaction can only modify this row of records after the former transaction ends and releases the transaction lock; however, before the former transaction ends, the latter transaction can query the same row of records, and this query operation obtains the data of the current row before the modification by the former transaction through the first rollback record.

[0139] B2. If the current session executes an update operation and the current transaction has ended, determine that the physical record of the updated row is visible to other sessions, construct a data row based on the physical record and use it as the third target data row, and determine the data of the columns to be queried according to the third target data row.

[0140] In this embodiment, the updated row can be specifically understood as the data row updated in the data table when an update operation is executed. If the current session executes an update operation and the current transaction has ended, it can be determined that the physical record of the updated row is visible to other sessions. A data row is directly constructed based on the data in the physical record, and the constructed data row is used as the third target data row. The data corresponding to the columns to be queried is determined by querying the third target data row. When constructing the third target data row, if the column in the query item or the column to be queried in the filter condition has a semi-transparent encryption identifier, compare the operating user of the session with the user identifier based on which the ciphertext data of the column is encrypted. If they are the same, decrypt to obtain the plaintext data, otherwise return NULL.

[0141] The principle of step B2 in this embodiment is the same as that of S204.

[0142] B3. If the current session executes an update operation and the current transaction has not ended, determine that the physical record of the updated row is not visible to other sessions, construct a data row based on the physical record, determine the visible first rollback record, and adjust the data row according to the first rollback record to obtain the fourth target data row, and determine the plaintext data of the columns to be queried according to the fourth target data row.

[0143] Specifically, if an update operation is performed in the current session and the current transaction is not ended, the physical record at this time is not visible to other sessions querying the same row of records. Through recursive search, the first visible rollback record is obtained from the rollback records, a data row is constructed based on the data in the physical record, the column data in the data row is modified according to the updated column information and the old data in the first rollback record, and the columns in the data row are adjusted to the fourth target data row that is finally visible to the current user. At this time, the data in each column of the fourth target data row is visible plaintext data, and the plaintext data corresponding to the column to be queried is determined by querying the fourth target data row.

[0144] When performing a data query, first locate the data row according to the row information, where the row information is uniquely confirmed by the ROWID or the index primary key. Then, obtain the data of the specified column from the data row according to the column information. For example, when querying the 3rd column of the 5th row, first load the physical record of the 5th row from the physical page according to the table and row information. When storing rows, each physical record contains the data of all columns of the current row. Determine whether the physical record is visible according to the current transaction information. If it is not visible, adjust the data row in the memory according to the first rollback record to obtain the target data row. Then, obtain the column information from the table information according to the column number 3, and read the column data from the target data row. For columns with a semi-transparent encryption identifier in the physical record or the first rollback record, the data stored in this column is ciphertext data. The query items and filtering conditions in the query operation use plaintext data. Therefore, it is necessary to determine the user identifier of each column corresponding to each target data row, and judge whether it is the same as the user identifier of the current query user. If it is the same, decrypt the ciphertext data of the specified column of the target data row according to the user identifier to determine the plaintext data and return it. The plaintext data can be used to display to the current query user. If it is different, do not decrypt and return NULL. At this time, the query result of the corresponding column obtained by the current query user is NULL. The user identifier based on which the ciphertext data of each column of the current row is different, and NULL does not necessarily mean that the data is truly NULL, and it may also mean that the user identifiers are different and cannot be decrypted.

[0145] As an optional embodiment of this embodiment, this optional embodiment further refines the construction of the data row according to the physical record into the following steps C1-C4:

[0146] C1. If the column to be queried has a semi-transparent encryption identifier, determine the ciphertext data of the column to be queried based on the user identifier according to the physical record.

[0147] When determining the plaintext data of the column to be queried, if the column to be queried has a semi-transparent encryption identifier, the data of the column to be queried stored in the physical record is all ciphertext data based on the user identifier. When constructing the data row, it is necessary to decrypt according to the user identifier to obtain the plaintext data (return NULL if the user identifiers are different).

[0148] C2. Determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the column to be queried in the row to be updated; if so, decrypt the ciphertext data of the column to be queried to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL.

[0149] Determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the column to be queried in the row to be updated. If they are the same, obtain the user storage encryption key of the specified user according to the user identifier, and decrypt the ciphertext data of the column to be queried according to the user storage encryption key to determine the plaintext data. If they are not the same, there is no need to decrypt at this time, determine that the plaintext data is NULL, and the visible plaintext data obtained by the current operating user is NULL.

[0150] C3. Construct a data row according to the plaintext data.

[0151] Fill the obtained plaintext data into the corresponding data columns in the data row to complete the construction of the data row.

[0152] As an optional embodiment of this embodiment, this optional embodiment further refines the adjustment of the data row according to the first rollback record to obtain the second target data row or the fourth target data row into the following steps D1 - D5:

[0153] D1. Determine the column information and old data of the data column according to the first rollback record.

[0154] Query the first rollback record to determine the column information of each data column and the corresponding old data.

[0155] D2. Determine the data column to be adjusted according to the column information of the data column, and whether the data column to be adjusted has a semi - transparent encryption identifier.

[0156] In this embodiment, the data column to be adjusted can be specifically understood as the data column that needs to be adjusted to visible data according to the first rollback record. Determine whether each column of data needs to be adjusted according to the column information of the data column, and determine whether the data column to be adjusted has a semi - transparent encryption identifier.

[0157] D3. If the data column to be adjusted has a semi - transparent encryption identifier, the old data of the data column to be adjusted is ciphertext data based on the user identifier.

[0158] D4. Determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the data column to be adjusted in the data row. If so, decrypt the ciphertext data of the data column to be adjusted to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL.

[0159] Determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the data column to be adjusted in the data row. If they are the same, obtain the user storage encryption key of the specified user according to the user identifier, decrypt the ciphertext data of the data column to be adjusted according to the user storage encryption key, and determine the plaintext data. If they are not the same, there is no need to decrypt at this time, determine that the plaintext data is NULL, and the visible plaintext data obtained by the current operating user is NULL.

[0160] D5. Replace the old data of the data column to be adjusted according to the plaintext data to form the second target data row or the fourth target data row.

[0161] Replace the old data of the data column to be adjusted with the decrypted plaintext data to form the second target data row or the fourth target data row. The data in the second target data row or the fourth target data row is visible plaintext data.

[0162] If the data column to be adjusted does not have a semi-transparent encryption identifier, the old data of the data column to be adjusted does not need to be decrypted and can be directly used to construct the second target data row and the fourth target data row.

[0163] It should be noted that both the second target data row and the fourth target data row can be determined in the manner of the above steps D1 - D5, and their principles are the same, that is, the second target data row is determined in step S205 and the fourth target data row is determined in step B3, both of which can be determined in the manner of the above steps D1 - D5.

[0164] The embodiment of the present invention provides a method for managing data of semi-transparent encryption columns. The embodiment of the present application refines the construction process of the first target record and the rollback record. When the data update is completed in constructing the first target record, the data update is considered in combination with the identifier of the semi-transparent encryption column, which solves the problem of data loss in the process of updating the data of the semi-transparent encryption column. At the same time, this embodiment provides a rollback process and a query process. When data rollback is performed after receiving a rollback operation, the visible data plaintext of the semi-transparent encryption column will not be used, and only the ciphertext data of the corresponding column will be used. Therefore, the situation of data loss will not occur. In the process of update and rollback, for the data of the semi-transparent encryption column, only the corresponding ciphertext data is used, and there is no need to decrypt the data, and there is no need to consider whether the current operating user has the same user identifier as the original data, avoiding the situation where the data obtained with different user identifiers is empty. For the semi-transparent encryption column, the ciphertext data corresponding to the old data of the semi-transparent encryption column is directly stored in all places where the old data of the semi-transparent encryption column needs to be stored. When performing subsequent other operations, any user can obtain the correct ciphertext data and decrypt it through their own user identifier, ensuring data security and effectively avoiding data loss.

[0165] Embodiment Three

[0166] Figure 3 This is a schematic structural diagram of a data management device for semi - transparent encrypted columns provided in Embodiment 3 of the present invention. As Figure 3 shown, the device includes: an acquisition module 31, a data determination module 32, a first record construction module 33, a rollback record construction module 34, and an update module 35.

[0167] Among them, the acquisition module 31 is used to acquire an update operation, and the update operation includes information of the table to be updated and information of the column to be updated. The information of the table to be updated includes the semi - transparent encryption identifier of each column in the table to be updated, and the information of the column to be updated includes the new data of the column to be updated;

[0168] The data determination module 32 is used to determine the old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the column to be updated. Among them, the old data of the column to be updated with a semi - transparent encryption identifier is ciphertext data;

[0169] The first record construction module 33 is used to construct a first target record according to the semi - transparent encryption identifier of each column in the table to be updated, the data of the non - updated columns in the table to be updated, and the new data of the column to be updated. Among them, the data of the non - updated columns with a semi - transparent encryption identifier is ciphertext data;

[0170] The rollback record construction module 34 is used to construct a rollback record according to the old data of the column to be updated;

[0171] The update module 35 is used to update the data of the table to be updated and the column to be updated according to the first target record.

[0172] Embodiment of the present invention provides a data management device for semi - transparent encrypted columns, which solves the problem of data loss during the data update process of semi - transparent encrypted columns. By the update operation, the new data of the column to be updated, the table to be updated, and the semi - transparent encryption identifier of each column in the table to be updated are determined. According to the information of the table to be updated and the information of the column to be updated, the old data of each column to be updated corresponding to each row to be processed is determined. The old data of the column to be updated with a semi - transparent encryption identifier is ciphertext data, and no decryption process is required. When acquiring the old data of the column to be updated, it is not necessary to consider whether the current operating user has the same user identifier as the column to be updated, avoiding the situation where the acquired old data is empty due to different user identifiers. Even if the user identifiers corresponding to the columns to be updated are different, ciphertext data can be obtained for update, thus avoiding data loss.

[0173] Optionally, the information of the table to be updated further includes: a filtering condition;

[0174] The device further includes:

[0175] A filtering column determination module, configured to determine filtering columns and table information to which the filtering columns belong according to the filtering conditions before determining the old data of each to-be-updated column corresponding to each to-be-processed row according to the to-be-updated table information and the to-be-updated column information.

[0176] A first plaintext determination module, configured to read the data of the filtering columns in each row record from the table to which the filtering columns belong, and determine the plaintext data of the to-be-filtered row corresponding to the to-be-filtered column if the record of the to-be-filtered row in the table to which the to-be-filtered column belongs is visible;

[0177] A second plaintext determination module, configured to, if the physical record of the to-be-filtered row in the table to which the to-be-filtered column belongs is not visible, construct a data row according to the physical record, determine a visible first rollback record, adjust the data row according to the first rollback record to obtain a second target data row, and determine the plaintext data of the to-be-filtered column according to the second target data row;

[0178] A to-be-processed row determination module, configured to determine whether the filtering conditions are met in the to-be-updated table according to the plaintext data of the to-be-filtered row corresponding to each of the to-be-filtered columns, and if the filtering conditions are met, confirm it as a to-be-processed row;

[0179] Optionally, the first plaintext determination module is specifically configured to: if the to-be-filtered column has a semi-transparent encryption identifier, determine the ciphertext data based on the user identifier of the to-be-filtered column according to the physical record; determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the to-be-filtered column of the to-be-filtered row, and if so, decrypt the ciphertext data of the to-be-filtered column to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL.

[0180] Optionally, the first record construction module 33 includes:

[0181] A first construction unit, configured to, if the to-be-updated column has a semi-transparent encryption identifier, encrypt the new data of the to-be-updated column according to the user storage encryption key of the current operating user to obtain target ciphertext data, and construct a first target record according to the target ciphertext data and the data of the non-updated columns;

[0182] A second construction unit, configured to, if the to-be-updated column does not have a semi-transparent encryption identifier, process the new data of the to-be-updated column according to the original processing logic to obtain target data, and construct a first target record according to the target data and the data of the non-updated columns;

[0183] Wherein, when the non-updated column has a semi-transparent encryption identifier, the data of the non-updated column is the ciphertext data of the non-updated column.

[0184] Optionally, the rollback record construction module 34 includes:

[0185] A record writing unit, configured to write the ciphertext old data of the column to be updated into a rollback record if the column to be updated has a semi-transparent encryption identifier;

[0186] A data page writing unit, configured to write the rollback record into a rollback data page;

[0187] Wherein, all column data with semi-transparent encryption identifiers in the rollback record are ciphertext data.

[0188] Optionally, the rollback record further includes information about the table to be updated, the column numbers of the columns to be updated, the row information to be updated, and transaction information;

[0189] The apparatus further includes:

[0190] A rollback operation receiving module, configured to receive a rollback operation for the current transaction of the current session;

[0191] A physical record determining module, configured to, when the current transaction includes an update operation, for the rollback record of the update operation, locate the current physical record to be updated and rolled back in the physical page according to the information about the table to be updated and the row information to be updated in the rollback record;

[0192] An old data determining module, configured to obtain the corresponding column information from the information about the table to be updated according to the column numbers of the columns to be updated in the rollback record, and determine the old data of the columns to be updated according to the rollback record;

[0193] An encryption identifier judging module, configured to judge whether the column to be updated has a semi-transparent encryption identifier according to the corresponding column information of the column to be updated;

[0194] A first constructing module, configured to, if the column to be updated has a semi-transparent encryption identifier and the old data of the column to be updated is ciphertext data based on the user identifier, construct a second target record according to the ciphertext data of the column to be updated and the current physical record, wherein the current physical record includes the column to be updated and non-updated columns, and all columns with semi-transparent encryption identifiers are stored as ciphertext data in the second target record;

[0195] A second constructing module, configured to construct a second target record according to the original processing logic if the column to be updated does not have a semi-transparent encryption identifier.

[0196] Optionally, the apparatus further includes:

[0197] A query operation receiving module, configured to receive a query operation of another session and determine the columns to be queried corresponding to the query operation;

[0198] The first query module is used to determine that the physical record of the updated row is visible to other sessions if the current session performs an update operation and the current transaction has ended, construct a data row based on the physical record and use it as the third target data row, and determine the plaintext data of the column to be queried according to the third target data row.

[0199] The second query module is used to, if the current session performs an update operation and the current transaction has not ended, obtain the visible first rollback record from the rollback record, adjust the data row (the data row loaded from the physical record into the memory) according to the first rollback record to obtain the target data row, and determine the data of the column corresponding to the query operation from the target data row.

[0200] Optionally, the first query module is specifically used to, if the column to be queried has a semi-transparent encryption identifier, determine the ciphertext data of the column to be queried based on the user identifier according to the physical record; determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the column to be queried in the updated row; if so, decrypt the ciphertext data of the column to be queried to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL; construct a data row according to the plaintext data.

[0201] Optionally, the method of adjusting the data row according to the first rollback record to obtain the second target data row or the fourth target data row may be: determining the column information and old data of the data column according to the first rollback record; determining the data column to be adjusted according to the column information of the data column, and whether the data column to be adjusted has a semi-transparent encryption identifier; if the data column to be adjusted has a semi-transparent encryption identifier, the old data of the data column to be adjusted is the ciphertext data based on the user identifier; determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the data column to be adjusted in the data row, if so, decrypt the ciphertext data of the data column to be adjusted to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL; replace the old data of the data column to be adjusted according to the plaintext data to form the second target data row or the fourth target data row.

[0202] The data management device for semi-transparent encrypted columns provided by the embodiments of the present invention can execute the data management method for semi-transparent encrypted columns provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0203] Embodiment 4

[0204] Figure 4The structural schematic diagram of an electronic device 40 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0205] As Figure 4 shown, the electronic device 40 includes at least one processor 41 and a memory communicatively connected to the at least one processor 41, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc. The memory stores a computer program executable by the at least one processor. The processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, the ROM 42, and the RAM 43 are connected to each other via a bus 44. The input / output (I / O) interface 45 is also connected to the bus 44.

[0206] Multiple components in the electronic device 40 are connected to the I / O interface 45, including: an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0207] The processor 41 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 41 executes the various methods and processes described above, such as the data management method for semi-transparent encrypted columns.

[0208] In some embodiments, the data management method for translucent encrypted columns can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the data management method for translucent encrypted columns described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to execute the data management method for translucent encrypted columns by any other suitable means (e.g., by means of firmware).

[0209] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0210] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0211] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0212] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0213] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0214] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs that run on respective computers and have a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0215] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.

[0216] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A data management method for semi-transparent encrypted columns, characterized in that, Including: Obtaining an update operation, where the update operation includes information of a table to be updated and information of columns to be updated. The information of the table to be updated includes a semi-transparent encryption identifier for each column in the table to be updated, and the information of the columns to be updated includes new data for the columns to be updated. Determining old data for each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the columns to be updated, where the old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data. Constructing a first target record according to the semi-transparent encryption identifier for each column in the table to be updated, data of non-updated columns in the table to be updated, and new data of the columns to be updated, where the data of non-updated columns with a semi-transparent encryption identifier is ciphertext data. Constructing a rollback record according to the old data of the columns to be updated. Performing data update on the table to be updated and the columns to be updated according to the first target record. When the information of the table to be updated further includes a filtering condition, before determining the old data for each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the columns to be updated, the method further includes: Determining columns to be filtered and table information to which the columns to be filtered belong according to the filtering condition. Reading data of the columns to be filtered in each row record from the table to which the columns to be filtered belong. If the physical record of the row to be filtered in the table to which the column to be filtered belongs is visible, constructing a data row according to the physical record and using it as the first target data row, and determining the plaintext data of the column to be filtered according to the first target data row. If the physical record of the row to be filtered in the table to which the column to be filtered belongs is not visible, constructing a data row according to the physical record, determining a visible first rollback record, and adjusting the data row according to the first rollback record to obtain a second target data row, and determining the plaintext data of the column to be filtered according to the second target data row. Determining whether each row to be filtered in the table to be updated meets the filtering condition according to the plaintext data of the column to be filtered in each row to be filtered, and if it meets the filtering condition, determining it as a row to be processed.

2. The method according to claim 1, characterized in that, Constructing a data row according to the physical record, including: If the column to be filtered has a semi-transparent encryption identifier, determining ciphertext data based on the user identifier of the column to be filtered according to the physical record. Judging whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the column to be filtered in the row to be filtered. If so, decrypting the ciphertext data of the column to be filtered to determine the plaintext data; otherwise, without decrypting, determining that the plaintext data visible to the current operating user is NULL. Constructing a data row according to the plaintext data.

3. The method according to claim 1, wherein The constructing a first target record according to the semi-transparent encryption identifier for each column in the table to be updated, data of non-updated columns in the table to be updated, and new data of the columns to be updated includes: If the column to be updated has a semi-transparent encryption identifier, encrypting the new data of the column to be updated using the user storage encryption key of the current operating user to obtain target ciphertext data, and constructing a first target record according to the target ciphertext data and the data of non-updated columns. If the column to be updated does not have a semi-transparent encryption identifier, processing the new data of the column to be updated according to the original processing logic to obtain target data, and constructing a first target record according to the target data and the data of non-updated columns. Among them, when the non-updated column has a semi-transparent encryption identifier, the data of the non-updated column is the ciphertext data of the non-updated column.

4. The method according to claim 1, wherein Constructing a rollback record according to the old data of the column to be updated includes: If the column to be updated has a semi-transparent encryption identifier, write the ciphertext old data of the column to be updated into the rollback record; Write the rollback record into the rollback data page; Among them, all column data with semi-transparent encryption identifiers in the rollback record are ciphertext data.

5. The method according to claim 1, characterized in that, The rollback record also includes information about the table to be updated, the column numbers of the columns to be updated, the row information to be updated, and transaction information. The method further includes: Receiving a rollback operation for the current transaction of the current session; When the current transaction includes an update operation, for the rollback record of the update operation, locate the current physical record to be updated in the physical page according to the information about the table to be updated and the row information to be updated in the rollback record; Obtain the corresponding column information from the information about the table to be updated according to the column number of the column to be updated in the rollback record, and determine the old data of the column to be updated according to the rollback record; Judge whether the column to be updated has a semi-transparent encryption identifier according to the corresponding column information of the column to be updated; If the column to be updated has a semi-transparent encryption identifier, the old data of the column to be updated is ciphertext data based on the user identifier. Construct a second target record according to the ciphertext data of the column to be updated and the current physical record, where the current physical record includes the column to be updated and non-updated columns, and all columns with semi-transparent encryption identifiers are stored as ciphertext data in the second target record; If the column to be updated does not have a semi-transparent encryption identifier, construct a second target record according to the original processing logic.

6. The method according to claim 1, wherein It further includes: Receiving a query operation of another session, and determining the column to be queried corresponding to the query operation; If the current session executes an update operation and the current transaction has ended, determine that the physical record of the updated row is visible to other sessions, construct a data row according to the physical record and use it as the third target data row, and determine the plaintext data of the column to be queried according to the third target data row; If the current session executes an update operation and the current transaction has not ended, determine that the physical record of the updated row is not visible to other sessions, construct a data row according to the physical record, determine the visible first rollback record, and adjust the data row according to the first rollback record to obtain a fourth target data row, and determine the plaintext data of the column to be queried according to the fourth target data row.

7. The method according to claim 6, characterized in that Constructing a data row according to the physical record includes: If the column to be queried has a semi-transparent encryption identifier, determine the ciphertext data based on the user identifier of the column to be queried according to the physical record; Judge whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the column to be queried of the updated row; if so, decrypt the ciphertext data of the column to be queried to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL; Construct a data row according to the plaintext data.

8. The method according to claim 1 or 6, characterized in that, Adjusting the data row according to the first rollback record to obtain a second target data row or a fourth target data row includes: Determine the column information and old data of the data column according to the first rollback record; Determine the data column to be adjusted according to the column information of the data column, and whether the data column to be adjusted has a semi-transparent encryption identifier; If the data column to be adjusted has a semi-transparent encryption identifier, the old data of the data column to be adjusted is ciphertext data based on the user identifier; Determine whether the identifier of the current operating user is the same as the user identifier corresponding to the ciphertext data of the data column to be adjusted in the data row. If so, decrypt the ciphertext data of the data column to be adjusted to determine the plaintext data; otherwise, without decrypting, determine that the plaintext data visible to the current operating user is NULL; Replace the old data of the data column to be adjusted according to the plaintext data to form the second target data row or the fourth target data row.

9. A data management device for semi-transparent encrypted columns, characterized in that, Including: An acquisition module for acquiring an update operation, where the update operation includes information of the table to be updated and information of the column to be updated. The information of the table to be updated includes the semi-transparent encryption identifier of each column in the table to be updated, and the information of the column to be updated includes the new data of the column to be updated; A data determination module for determining the old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the column to be updated, where the old data of the column to be updated with a semi-transparent encryption identifier is ciphertext data; A first record construction module for constructing a first target record according to the semi-transparent encryption identifier of each column in the table to be updated, the data of the non-updated columns in the table to be updated, and the new data of the column to be updated, where the data of the non-updated columns with a semi-transparent encryption identifier is ciphertext data; A rollback record construction module for constructing a rollback record according to the old data of the column to be updated; An update module for updating the data of the table to be updated and the column to be updated according to the first target record; When the information of the table to be updated further includes a filtering condition, the device further includes: A filtered column determination module for determining the columns to be filtered and the table information to which the columns to be filtered belong according to the filtering condition before determining the old data of each column to be updated corresponding to each row to be processed according to the information of the table to be updated and the information of the column to be updated; A first plaintext determination module for reading the data of the column to be filtered in each row record from the table to which the column to be filtered belongs, and if the record of the row to be filtered in the table to which the column to be filtered belongs is visible, determining the plaintext data of the row to be filtered corresponding to the column to be filtered; A second plaintext determination module for, if the physical record of the row to be filtered in the table to which the column to be filtered belongs is not visible, constructing a data row according to the physical record, determining the visible first rollback record, and adjusting the data row according to the first rollback record to obtain the second target data row, and determining the plaintext data of the column to be filtered according to the second target data row; A row to be processed determination module for determining whether the table to be updated meets the filtering condition according to the plaintext data of the rows to be filtered corresponding to the columns to be filtered, and if the filtering condition is met, confirming it as a row to be processed.

10. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, enables the at least one processor to execute the data management method for semi-transparent encrypted columns according to any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for implementing the data management method for semi-transparent encrypted columns according to any one of claims 1-8 when the computer instructions are executed by a processor.

Citation Information

Patent Citations

  • Database transparent encryption method and system

    CN111291402A

  • Database starting method and device, equipment and storage medium

    CN111367718A