Data Processing Method, Apparatus, System, Device and Storage Medium of Database

By configuring the software development toolkit for the database connection pool, loading integrity protection rules and signing data, the problem of high cost of database integrity protection transformation and stability risks is solved, and low-invasion data integrity protection is achieved.

CN115329395BActive Publication Date: 2025-07-08DIGITAL GUANGDONG NETWORK CONSTR CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210950281.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-09
Publication Date
2025-07-08
Estimated Expiration
2042-08-09

AI Technical Summary

Technical Problem

When protecting the integrity of the database, the transformation cost is high and it is risky to the stability of the business system, especially when the business system has been operating stably for a long time.

Method used

By configuring a software development toolkit for the database connection pool, loading integrity protection rules, extracting the original data to be protected for signature, and writing authentication information into a structured query statement to achieve data integrity protection and avoiding transformation of the business layer.

Benefits of technology

It realizes data integrity protection without affecting the stability of the business system, reducing the difficulty and cost of transformation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115329395B_ABST
    Figure CN115329395B_ABST
Patent Text Reader

Abstract

The present invention discloses a data processing method, apparatus, system, device and storage medium for a database. The method includes: loading an integrity protection rule set for the database; obtaining a structured query statement received by the database connection pool; extracting original data to be integrity protected from the structured query statement according to the integrity protection rule as target data; signing the target data according to the integrity protection rule to obtain authentication information; writing the authentication information into the structured query statement; and transmitting the structured query statement to the database connection pool for execution to write the original data and the authentication information into the database. The software development kit is independent of the business layer, maintaining the stability of the business layer. Moreover, when the database connection pool accesses the software development tool, the intrusion is low and the modification is small, greatly reducing the difficulty of transformation and the cost of transformation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security, and particularly to a data processing method, device, system, equipment and storage medium for a database. Background Art

[0002] With the gradual maturity of the specifications for information system passwords, it is currently required to use cryptographic techniques to ensure data integrity protection for sensitive data stored in the database.

[0003] Many business systems did not adopt relevant cryptographic techniques at the initial stage of construction, and there is a risk that a third party maliciously tampers with the database. The tampering is difficult to detect and has an impact on the business.

[0004] Considering that the business system has been able to run stably online for a long time, if the integrity protection transformation is directly carried out on the business system through the business logic layer, it will not only pose a certain risk to the stability of the business system, but also involve many modules of the business system and database tables in the transformation, with a large transformation difficulty and high transformation cost. Summary of the Invention

[0005] The present invention provides a data processing method, device, system, equipment and storage medium for a database to solve the problem of carrying out integrity protection transformation on a business system while taking into account the stability of the business system and the transformation cost.

[0006] According to one aspect of the present invention, there is provided a data processing method for a database, which is applied to a software development kit configured for a database connection pool. The method includes:

[0007] Loading the integrity protection rules set for the database, where the database connection pool is connected to the database;

[0008] Obtaining the structured query statement received by the database connection pool, where the structured query statement is used to write raw data to the database;

[0009] Extracting the raw data to be integrity protected from the structured query statement according to the integrity protection rules as target data;

[0010] Signing the target data according to the integrity protection rules to obtain authentication information;

[0011] Writing the authentication information into the structured query statement;

[0012] Transmitting the structured query statement to the database connection pool for execution to write the raw data and the authentication information into the database.

[0013] According to another aspect of the present invention, there is provided a data processing apparatus for a database, which is applied to a software development kit configured for a database connection pool. The apparatus includes:

[0014] A rule loading module, configured to load integrity protection rules set for the database, where the database connection pool is connected to the database;

[0015] A statement acquisition module, configured to acquire a structured query statement received by the database connection pool, where the structured query statement is used to write original data to the database;

[0016] A data extraction module, configured to extract the original data to be integrity protected from the structured query statement according to the integrity protection rules, as target data;

[0017] A signature module, configured to sign the target data according to the integrity protection rules to obtain authentication information;

[0018] A statement rewriting module, configured to write the authentication information into the structured query statement;

[0019] A data protection module, configured to transmit the structured query statement to the database connection pool for execution, so as to write the original data and the authentication information into the database.

[0020] According to another aspect of the present invention, there is provided a data processing system for a database. The system includes a database and a database connection pool connected to each other, and the database connection pool is configured with a software development kit;

[0021] The database connection pool includes:

[0022] A statement receiving module, configured to receive a structured query statement, where the structured query statement is used to write original data to the database;

[0023] A statement transmission module, configured to transmit the structured query statement to the software development kit;

[0024] The software development kit includes:

[0025] A rule loading module, configured to load integrity protection rules set for the database;

[0026] A statement acquisition module, configured to acquire the structured query statement received by the database connection pool;

[0027] A data extraction module, configured to extract the original data to be integrity protected from the structured query statement according to the integrity protection rules, as target data;

[0028] A signature module, configured to sign the target data according to the integrity protection rule to obtain authentication information;

[0029] A statement rewriting module, configured to write the authentication information into the structured query statement;

[0030] A data protection module, configured to transmit the structured query statement to the database connection pool;

[0031] The database connection pool further includes:

[0032] A statement execution module, configured to execute the structured query statement to write the original data and the authentication information into the database.

[0033] According to another aspect of the present invention, there is provided an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the data processing method of the database according to any embodiment of the present invention.

[0034] According to another aspect of the present invention, there is provided a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it implements the data processing method of the database according to any embodiment of the present invention.

[0035] This embodiment is applied to a software development kit configured for a database connection pool, which loads the integrity protection rule set for the database, and the database connection pool is connected to the database; obtains the structured query statement received by the database connection pool, and the structured query statement is used to write the original data into the database; extracts the original data to be integrity protected from the structured query statement according to the integrity protection rule as the target data; signs the target data according to the integrity protection rule to obtain authentication information; writes the authentication information into the structured query statement; transmits the structured query statement to the database connection pool for execution to write the original data and the authentication information into the database. The software development kit is independent of the business layer, and integrity protection can be achieved through one-time integration and one-time configuration, without modification or intrusion into the business layer, thus maintaining the stability of the business layer. Moreover, based on the operation mode of the software development tool, when the database connection pool accesses the software development tool, the intrusion is low and the modification is small, and it does not involve the modules of the business layer and the tables of the database, greatly reducing the difficulty of modification and the cost of modification.

[0036] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily apparent from the following description. Description of the Drawings

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.

[0038] Figure 1 is a flowchart of a data processing method for a database provided in Embodiment 1 of the present invention;

[0039] Figure 2 is a schematic structural diagram of a service system provided in Embodiment 1 of the present invention;

[0040] Figure 3 is an example diagram of a rule tree provided in Embodiment 1 of the present invention;

[0041] Figure 4 is an example diagram of a syntax tree provided in Embodiment 1 of the present invention;

[0042] Figure 5 is an example diagram of a rewritten syntax tree provided in Embodiment 1 of the present invention;

[0043] Figure 6 is a flowchart of a data processing method for a database provided in Embodiment 2 of the present invention;

[0044] Figure 7 is a flowchart of a data processing method for a database provided in Embodiment 3 of the present invention;

[0045] Figure 8 is a schematic structural diagram of a data processing device for a database provided in Embodiment 4 of the present invention;

[0046] Figure 9 is a schematic structural diagram of a data processing system for a database provided in Embodiment 5 of the present invention;

[0047] Figure 10 is a schematic structural diagram of an electronic device for implementing the data processing method of the database in the embodiments of the present invention. Detailed Embodiments

[0048] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0049] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0050] Embodiment 1

[0051] Figure 1 It is a flowchart of a data processing method for a database provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation where a software development kit (SDK) for database connection pool configuration is used, and the SDK protects the integrity of the data to be written into the database. This method can be executed by a data processing device of the database, especially an SDK configured for the database connection pool. The data processing device of the database can be implemented in the form of hardware and / or software, and the data processing device of the database can be configured in an electronic device.

[0052] As Figure 1 shown, the method includes:

[0053] Step 101, load the integrity protection rules set for the database.

[0054] A database is configured in the business system, and the data generated by the business system is stored in a structured data table, so as to effectively manage various information resources.

[0055] The type of this database can be set according to the storage requirements of the business system, and specifically can include relational databases (such as SQLite, Oracle, MySQL, etc.), non-relational databases (such as MongoDB, Redis, Hbase, etc.), key-value databases (such as Dynamo, LevelDB, etc.), and so on.

[0056] In JDBC (Java Database Connectivity) programming, when a connection is established between a Java program and a database, the database side verifies the username and password and allocates resources for this connection. The Java program needs to load connection objects such as java.sql.connection representing the connection into memory. Therefore, each time a connection object connection is created and disconnected, it will consume a certain amount of time and I / O (input / output) resources, especially when there are a large number of concurrent accesses, the overhead is very large.

[0057] Such as Figure 2 As shown, in order to avoid frequently creating database connections, a database connection pool is provided. The database connection pool is responsible for allocating, managing, and releasing database connections connection. It allows the client used by the user to reuse the existing database connections connection.

[0058] When the database connection pool is initialized, it connects to the database and creates a certain number of database connections connection and puts them into the database connection pool. When the client of the user accesses the database, it applies for a database connection connection from the database connection pool. The client uses the database connection in the database connection pool to communicate with the database. After use, the database connection pool reclaims the database connection connection and delivers it for other threads to use, so as to reduce the number of times of creating and disconnecting the database connection connection and improve the access efficiency of the database.

[0059] According to different requirements of the business system, the types of database connection pools are also different. To enable those skilled in the art to better understand this embodiment, Druid is taken as an example of a database connection pool for illustration.

[0060] Druid is an open-source big data system designed for OLAP (Online Analytical Processing) query requirements. Druid provides low-latency data insertion and real-time data query.

[0061] Druid is developed in Java and provides Rest services based on Jetty for HTTP (Hyper Text Transfer Protocol), and also provides toolkits for languages such as Java / Python.

[0062] Druid is a cluster system that uses zookeeper for node management and event monitoring.

[0063] Based on the database and database connection pool already provided in the business system, this embodiment conducts secondary development through the scalability of the database connection pool to develop and implement an SDK for integrity protection. The SDK can be a collection of functional modules used to perform integrity protection operations on the data in the database. The SDK provides multiple interfaces that can be called by the database connection pool.

[0064] In specific implementation, developers can preset the integrity protection method for the data to be integrity protected in the database according to the business situation, record it in the form of a configuration file, etc., and denote it as an integrity protection rule. The integrity protection rule will be identified by a prefix, such as sign.rules.

[0065] Furthermore, integrity protection is a technical means to protect the integrity of data, which is to ensure that data is not tampered with without authorization or can be quickly detected after being tampered with. When the database connection pool starts, it will load the software development kit SDK. When the software development kit SDK starts, it can load the integrity protection rules.

[0066] Step 102: Obtain the structured query statement received by the database connection pool.

[0067] When a client or a back-end person in the business system performs a business operation and waits to write data to the database, for the sake of distinction, this data is denoted as the original data. At this time, an SQL (Structured Query Language) may be received by the database connection pool, that is, this structured query statement SQL can be used to write the original data to the database. Therefore, this structured query statement SQL is a DML (Data Manipulation Language).

[0068] Writing the original data to the database will cause data changes, and at this time, integrity protection can be triggered.

[0069] Furthermore, writing the original data to the database can be classified into inserting the original data into the database or updating the original data in the database. Therefore, the Structured Query Language (SQL) can be used to insert the original data into the database, or the SQL can be used to update the original data in the database.

[0070] In a specific implementation, an extended interface provided by the database connection pool is determined. This extended interface is a custom interface reserved for the database connection pool, such as the FilterEventAdapter (event filtering adapter) interface of Druid. When the database connection pool receives the SQL of the structured query statement for the changed data, it will traverse and call the methods of the implementation classes of the extended interface.

[0071] When the database connection pool calls the extended interface, the Software Development Kit (SDK) can obtain the SQL of the structured query statement received by the database connection pool through the extended interface.

[0072] Step 103: Extract the original data to be integrity-protected from the structured query statement according to the integrity protection rule as the target data.

[0073] The Software Development Kit (SDK) executes the integrity protection rule, parses the SQL of the structured query statement, and identifies the original data to be integrity-protected from all the original data in the SQL of the structured query statement, which is denoted as the target data.

[0074] Exemplarily, the integrity protection rule includes the tables to be integrity-protected (represented by names, etc.) and the fields (represented by names, etc.). These tables and fields to be integrity-protected can be set by developers according to business requirements.

[0075] Furthermore, the information representing the table can be not only the name of the table itself but also a name with a specific meaning (such as all tables, tables in a certain set). This embodiment does not limit this.

[0076] The information representing the field can be not only the name of the field itself but also a name with a specific meaning (such as all fields, fields in a certain set). This embodiment does not limit this.

[0077] Generally, in the integrity protection rule, the table can be identified by an independent label, which can be the name of the table, and the field can also be identified by an independent label, such as sign_column.

[0078] Furthermore, the tables and fields in the integrity protection rule can be represented in the form of a tree, denoted as the rule tree.

[0079] For example, such asFigure 3 As shown, the tables to be integrity-protected in the integrity protection rules include address_book_person and tb_user. The fields to be integrity-protected in the table address_book_person include account, mobile, and certificate_number. The fields to be integrity-protected in the table tb_user include all, that is, all fields are integrity-protected.

[0080] In this example, based on the Abstract Syntax Tree (AST), semantic and syntactic parsing is performed on the Structured Query Language (SQL) statement, so as to convert the SQL statement into a syntax tree, which includes the name of the table, a list of field names to be written (such as insert, update, etc.), and a list of values of the fields to be written (such as insert, update, etc.).

[0081] For example, as Figure 4 shown, a certain SQL statement is converted into a syntax tree. Among them, the table to be operated on is tb_user, which contains four fields. The field names are id, mobile, password, and certificate_number respectively, and the field values are 1, 12345678912, 123456, and 987654321 respectively.

[0082] Search for the table in the syntax tree, that is, search in the syntax tree to see if there is a table with the same name as the table in the integrity protection rules.

[0083] If the table is found, it means that the table is the table to be integrity-protected. At this time, fields can be further searched in the table of the syntax tree, that is, search in the fields associated with the table in the syntax tree to see if there are fields with the same name as the fields in the integrity protection rules.

[0084] If the field is found, it means that the field is the field to be integrity-protected. At this time, the original data located in the field can be extracted as the target data.

[0085] In this embodiment, the tables and fields to be integrity-protected can be configured according to business requirements, with high flexibility. The integrity protection of some tables and some fields can be achieved, reducing the occupancy of storage space by subsequent signature information.

[0086] Since the businesses of the business systems are different, the types of target data are also different. This embodiment does not limit this.

[0087] Exemplarily, the target data includes at least one of the following:

[0088] Audit data, log data.

[0089] In this example, the tables and fields for persisting audit data and log data are different, and the structures and fields of the tables are fixed. The tables and fields for integrity protection can be identified in advance and added to the integrity protection rules, so as to achieve the positioning of audit data and log data.

[0090] Step 104: Sign the target data according to the integrity protection rules to obtain authentication information.

[0091] The software development kit (SDK) executes the integrity protection rules to sign the target data and obtain authentication information.

[0092] In a specific implementation, the integrity protection rules include sorting methods (represented by names, IDs, etc.) and signature methods (represented by names, IDs, etc.). Among them, the signature method can include one-way encryption algorithms, such as SHA (Secure Hash Algorithm), HMAC (Hash-based Message Authentication Code), etc. The so-called one-way encryption can refer to being only used for data decryption and cannot be decrypted.

[0093] Then, sort the target data according to the sorting method (such as ascending or descending order by the first letter or the last letter) and splice the sorted target data to obtain a data sequence. Perform a one-way encryption operation on the data sequence according to the signature method to obtain authentication information.

[0094] In the integrity protection rules, the sorting method and the signature method can be identified by independent tags or the same tag, such as "order". This embodiment does not limit this.

[0095] For example, match the rule tree of Figure 3 with the syntax tree of Figure 4 The matching result indicates that all fields of the table tb_user are protected for integrity. Then, sort the fields id, mobile, password, and certificate_number of the tb_user table in ascending order by the first letter to obtain the data sequence certificate_number = 987654321id = 1mobile = 12345678912password = 123456, and use HMAC to perform an encryption operation on this data sequence to obtain the authentication information 90ijf20fje90f23jf09j234rf0.

[0096] Step 105: Write the authentication information into the structured query statement.

[0097] If the software development kit (SDK) completes the signature of the target data, the authentication information obtained by signing can be written into the structured query language (SQL) according to the specification of the SQL, that is, the SQL is rewritten according to the SQL specification, and the syntax tree corresponding to the rewritten SQL will also change.

[0098] For example, as Figure 5 shown, a node sign_text representing the field name of the authentication information can be added to the syntax tree, and a node 90ijf20fje90f23jf09j234rf0 representing the field value of the authentication information can be added.

[0099] In a specific implementation, the type of the SQL can be queried. Since the operation methods of different types of SQL are different, the authentication information can be written into the SQL according to the operation method corresponding to the type to obtain the rewritten SQL.

[0100] In an example, if the type of the SQL is to insert original data into a database, the key area and the value area are queried in the SQL. Among them, the key area is the area for recording field names, and the value area is the area for recording field values.

[0101] The field name of the authentication information is added to the key area, and the field value of the authentication information is added to the value area. Among them, the position of the field name of the authentication information in the key area corresponds to the position of the field value of the authentication information in the value area.

[0102] For example, the SQL before rewriting is as follows:

[0103] insert into tb_user(id,mobile,password,certificate_number)value(1,12345678912,123456,987654321)

[0104] The SQL after rewriting is as follows:

[0105] insert into tb_user(id,mobile,password,certificate_number,sign_text)value(1,12345678912,123456,987654321,90ijf20fje90f23jf09j234rf0)

[0106] In another example, if the type of the Structured Query Language (SQL) statement is to update the original data in the database, then query the key-value area in the SQL statement, where the key-value area is the area for recording key-value pairs.

[0107] Generate key-value pairs (key / value) with the field name of the authentication information as the key and the field value of the authentication information as the value, and insert the key-value pairs into the key-value area.

[0108] For example, the SQL statement before rewriting is as follows:

[0109] UPDATE tb_user SET id=2,mobile=‘12345678913’,password=‘1234567’,certificate_number=‘76543211’WHERE id=1

[0110] The SQL statement after rewriting is as follows:

[0111] UPDATE tb_user SET id=2,mobile=‘12345678913’,password=‘1234567’,certificate_number=‘76543211’,sign_text=‘90ijf20fje90f23jf09j234rf0’WHEREid=1

[0112] Step 106: Transmit the SQL statement to the database connection pool for execution to write the original data and authentication information into the database.

[0113] If the Software Development Kit (SDK) completes writing the authentication information in the SQL statement, the SQL statement can be transmitted to the data connection pool. The database connection pool executes the SQL statement to write the original data and authentication information into the database.

[0114] Generally, the database connection pool writes the original data and authentication information into the same row of data in the database.

[0115] If the SDK communicates with the database connection pool through an extended interface (such as Druid's FilterEventAdapter), then the SDK can transmit the SQL statement to the database connection pool through the extended interface (such as Druid's FilterEventAdapter) for execution to write the original data and authentication information into the database.

[0116] This embodiment is applied to a software development kit configured for a database connection pool, which loads the integrity protection rules set for the database. The database connection pool is connected to the database. Obtain the structured query statements received by the database connection pool, where the structured query statements are used to write raw data to the database. Extract the raw data to be integrity-protected from the structured query statements according to the integrity protection rules as the target data. Sign the target data according to the integrity protection rules to obtain authentication information. Write the authentication information into the structured query statements. Transmit the structured query statements to the database connection pool for execution to write the raw data and the authentication information into the database. The software development kit is independent of the business layer, and integrity protection can be achieved through one-time integration and one-time configuration, without modification or intrusion into the business layer, thus maintaining the stability of the business layer. Moreover, based on the operating mode of the software development tool, when the database connection pool accesses the software development tool, the intrusion is low and the modification is small, and it does not involve the modules of the business layer and the tables of the database, greatly reducing the difficulty of modification and the cost of modification.

[0117] Embodiment 2

[0118] Figure 6 The flowchart of a data processing method for a database provided in Embodiment 2 of the present invention. In this embodiment, an operation of configuring a switch is added on the basis of the above embodiment. As Figure 6 shown, the method includes:

[0119] Step 601: Load the integrity protection rules set for the database.

[0120] In this embodiment, the software development kit SDK can implement a plugin that supports hot plugging, denoted as the connection pool plugin engine PluginDruidEngine. The connection pool plugin engine can implement the integrity protection function, thus ensuring the stability of the software development kit SDK when it goes online.

[0121] When loading the software development kit SDK, the connection pool plugin engine PluginDruidEngine can be created, and the integrity protection rules are loaded in the connection pool plugin engine PluginDruidEngine.

[0122] Step 602: Obtain the structured query statements received by the database connection pool.

[0123] In the software development kit SDK, the connection pool plugin engine PluginDruidEngine can receive the structured query statements SQL provided by the database connection pool.

[0124] Step 603: Check the configuration options of the software development kit.

[0125] In this embodiment, configuration options can be set for the software development kit (SDK) to enable and disable the integrity protection function, thereby ensuring the compatibility of the SDK when it is launched.

[0126] Furthermore, the connection pool plugin engine PluginDruidEngine can implement the configuration options. When the configuration option is enabled, the integrity protection function is enabled; when the configuration option is disabled, the integrity protection function is disabled.

[0127] Step 604: If the configuration option is to enable the integrity protection function, extract the original data to be integrity protected from the structured query statement according to the integrity protection rule as the target data.

[0128] If the configuration option is to enable the integrity protection function, then the connection pool plugin engine PluginDruidEngine extracts the original data to be integrity protected from the structured query statement according to the integrity protection rule as the target data.

[0129] Step 605: Sign the target data according to the integrity protection rule to obtain the authentication information.

[0130] The connection pool plugin engine PluginDruidEngine signs the target data according to the integrity protection rule to obtain the authentication information.

[0131] Step 606: Write the authentication information into the structured query statement.

[0132] In the connection pool plugin engine PluginDruidEngine, multiple syntax parsing methods for the structured query language (SQL) are customized. By calling the corresponding syntax parsing method according to the type of the SQL statement, the authentication information can be written into the SQL statement, thereby rewriting the SQL statement.

[0133] In one example, the syntax parsing method includes an insert parsing method InsertVisitor. When the type of the SQL statement is to insert original data into the database, the insert parsing method InsertVisitor is called to write the authentication information into the SQL statement.

[0134] In another example, the syntax parsing method includes an update parsing method UpdateVisitor. When the type of the SQL statement is to update original data in the database, the update parsing method UpdateVisitor is called to write the authentication information into the SQL statement.

[0135] Step 607: Transmit the structured query statement to the database connection pool for execution to write the original data and authentication information into the database.

[0136] The connection pool plugin engine PluginDruidEngine calls the extension interface provided by the database connection pool, transmits the rewritten structured query statement SQL to the database connection pool, and the database connection pool executes the rewritten structured query statement SQL to write the original data and authentication information into the database.

[0137] Step 608: If the configuration option is to turn off the integrity protection function, then transmit the structured query statement to the database connection pool for execution to write the original data into the database.

[0138] If the configuration option is to turn off the integrity protection function, then process the structured query statement SQL according to the original logic, that is, the software development kit SDK can transmit the structured query statement SQL to the database connection pool through the extension interface, and the database connection pool executes the structured query statement SQL to write the original data into the database.

[0139] Furthermore, if the configuration option is to turn off the integrity protection function, the connection pool plugin engine PluginDruidEngine does not perform the above steps 604 - 607, but directly transmits the structured query statement SQL to the database connection pool through the extension interface, and the database connection pool executes the structured query statement SQL to write the original data into the database.

[0140] In addition, considering that the software development kit SDK may malfunction, the database connection pool performs a timing operation when transmitting the structured query statement SQL to the software development kit SDK through the extension interface, and times a preset time period.

[0141] During the timing operation, if the database connection pool receives the structured query statement SQL fed back by the software development kit SDK, then the database connection pool directly executes the structured query statement SQL fed back by the software development kit SDK, where the structured query statement SQL can be the structured query statement SQL for writing authentication information or the structured query statement SQL without writing authentication information.

[0142] At the end of the timing operation (i.e., timeout), if the database connection pool does not receive the structured query statement SQL fed back by the software development kit SDK, then execute the structured query statement SQL received by the database connection pool to ensure the normal execution of the business.

[0143] Embodiment III

[0144] Figure 7The flowchart of a data processing method for a database provided in Embodiment 3 of the present invention. In this embodiment, an operation for verifying data integrity is added based on the above embodiments. As Figure 7 shown, the method includes:

[0145] Step 701: Invoke the database connection pool to traverse the original data stored in the database.

[0146] In this embodiment, the software development kit (SDK) can trigger the verification operation of data integrity through daily audits (regularly) or spot checks. At this time, the database connection pool is invoked to traverse the original data stored in the database.

[0147] If the polling reaches the original data of a certain row associated with authentication information (identified by field names, etc.), indicating that the target data with integrity protection exists in the original data of this row, then the verification operation of data integrity can be performed on it.

[0148] Step 702: Query the integrity protection rules configured for the original data.

[0149] In this embodiment, the integrity protection rules have been loaded in the connection pool plugin engine (PluginDruidEngine) of the software development kit (SDK). Then, when performing the verification operation of data integrity, the connection pool plugin engine (PluginDruidEngine) of the software development kit (SDK) can read the integrity protection rules.

[0150] Step 703: Extract the target data to be integrity-protected from the original data according to the integrity protection rules.

[0151] In a specific implementation, the integrity protection rules include the table and fields to be integrity-protected. Then, the connection pool plugin engine (PluginDruidEngine) of the software development kit (SDK) can convert the original data into a syntax tree; search for the table in the syntax tree; if the table is found, search for the fields in the table of the syntax tree; if the fields are found, extract the original data located in the fields as the target data.

[0152] In this embodiment, since the method of extracting the target data is basically similar to the applications in Embodiments 1 and 2, the description is relatively simple. For related parts, refer to the partial descriptions of Embodiments 1 and 2. This embodiment will not be elaborated here.

[0153] Step 704: Sign the target data according to the integrity protection rules to obtain reference information.

[0154] In a specific implementation, the integrity protection rules include a sorting method and a signature method. Then, the connection pool plugin engine PluginDruidEngine of the software development kit (SDK) can sort the target data according to the sorting method and splice the sorted target data to obtain a data sequence, and perform a one-way encryption operation on the data sequence according to the signature method to obtain reference information.

[0155] In this embodiment, since the signature method is basically similar to the applications in Embodiments 1 and 2, the description is relatively simple. For related parts, refer to the partial descriptions in Embodiments 1 and 2, and this embodiment will not be elaborated herein.

[0156] Step 705: Compare the reference information with the authentication information to determine the integrity of the target data.

[0157] In this embodiment, the connection pool plugin engine PluginDruidEngine of the software development kit (SDK) compares the reference information with the authentication information and determines the integrity of the target data according to the comparison result.

[0158] If the reference information is the same as the authentication information, it is determined that the target data has not been tampered with.

[0159] If the reference information is different from the authentication information, it is determined that the target data has been tampered with.

[0160] Step 706: If the target data has been tampered with, write the target data into a preset abnormal data table.

[0161] In this embodiment, a table can be preset, denoted as the abnormal data table, which is used to record the tampered target data.

[0162] If it is confirmed that the target data has been tampered with, the target data can be extracted, written into the abnormal data table, an alarm message can be generated to notify the management that there is an abnormality in the target data in this row, and wait for the management to call the target data in the abnormal data table for verification.

[0163] Step 707: Roll back the original data to the state of the previous backup.

[0164] The database will be backed up at a certain frequency. If it is confirmed that the target data has been tampered with, a data rollback operation can be performed to roll back the original data to the state of the previous backup, and continue to perform the data integrity verification operation until the target data is restored to the state of not being tampered with.

[0165] Embodiment 4

[0166] Figure 8 This is a schematic structural diagram of a data processing device for a database provided in Embodiment 4 of the present invention. AsFigure 8 As shown, the device is applied to a software development kit configured for a database connection pool, especially for a connection pool plug-in engine of the software development kit. The device includes:

[0167] A rule loading module 801, configured to load integrity protection rules set for the database, where the database connection pool is connected to the database;

[0168] A statement obtaining module 802, configured to obtain a structured query statement received by the database connection pool, where the structured query statement is used to write original data to the database;

[0169] A data extraction module 803, configured to extract the original data to be integrity protected from the structured query statement according to the integrity protection rules, as target data;

[0170] A signature module 804, configured to sign the target data according to the integrity protection rules to obtain authentication information;

[0171] A statement rewriting module 805, configured to write the authentication information into the structured query statement;

[0172] A data protection module 806, configured to transmit the structured query statement to the database connection pool for execution, so as to write the original data and the authentication information into the database.

[0173] In an embodiment of the present invention, the statement obtaining module 802 is further configured to:

[0174] Determine an extended interface provided by the database connection pool;

[0175] When the database connection pool calls the extended interface, obtain the structured query statement received by the database connection pool through the extended interface.

[0176] In an embodiment of the present invention, the data protection module 806 is further configured to:

[0177] Transmit the structured query statement to the database connection pool for execution through the extended interface, so as to write the original data and the authentication information into the database.

[0178] In an embodiment of the present invention, the integrity protection rules include tables and fields to be integrity protected;

[0179] The data extraction module 803 is further configured to:

[0180] Convert the structured query statement into a syntax tree;

[0181] Search for the table in the syntax tree;

[0182] If the table is found, search for the field in the table of the syntax tree;

[0183] If the field is found, extract the original data located in the field as the target data.

[0184] In an embodiment of the present invention, the integrity protection rules include a sorting method and a signature method;

[0185] The signature module 804 is further configured to:

[0186] Sort the target data according to the sorting method and splice the sorted target data to obtain a data sequence;

[0187] Perform a one-way encryption operation on the data sequence according to the signature method to obtain authentication information.

[0188] In an embodiment of the present invention, the statement rewriting module 805 is further configured to:

[0189] Query the type of the structured query statement;

[0190] Write the authentication information into the structured query statement according to the type to obtain a target structured query statement.

[0191] In an embodiment of the present invention, the statement rewriting module 805 is further configured to:

[0192] If the type of the structured query statement is to insert original data into the database, query the key area and the value area in the structured query statement;

[0193] Add the field name of the authentication information to the key area and add the field value of the authentication information to the value area;

[0194] Or

[0195] If the type of the structured query statement is to update original data in the database, query the key-value area in the structured query statement;

[0196] Generate a key-value pair with the field name of the authentication information as the key and the field value of the authentication information as the value;

[0197] Insert the key-value pair into the key-value area.

[0198] In a specific implementation, the target data includes at least one of the following:

[0199] Audit data, log data.

[0200] In an embodiment of the present invention, the device further includes:

[0201] A configuration option check module, configured to check the configuration options of the software development kit; if the configuration option is to enable the integrity protection function, then call the data extraction module 803, and if the configuration option is to disable the integrity protection function, then call the original processing module;

[0202] The original processing module is configured to transmit the structured query statement to the database connection pool for execution to write the original data into the database.

[0203] In an embodiment of the present invention, the device further includes:

[0204] A database traversal module, configured to call the database connection pool to traverse the original data stored in the database, where the original data is associated with authentication information;

[0205] A rule query module, configured to query the integrity protection rules configured for the original data;

[0206] A data verification module, configured to extract target data to be integrity protected from the original data according to the integrity protection rules;

[0207] A reference signature module, configured to sign the target data according to the integrity protection rules to obtain reference information;

[0208] An integrity determination module, configured to compare the reference information with the authentication information to determine the integrity of the target data.

[0209] In an embodiment of the present invention, the integrity protection rules include tables and fields to be integrity protected;

[0210] The data verification module is further configured to:

[0211] Convert the original data into a syntax tree;

[0212] Search for the table in the syntax tree;

[0213] If the table is found, search for the field in the table in the syntax tree;

[0214] If the field is found, extract the original data located in the field as the target data.

[0215] In an embodiment of the present invention, the integrity protection rules include a sorting method and a signature method;

[0216] The reference signature module is further configured to:

[0217] Sort the target data according to the sorting method and splice the sorted target data to obtain a data sequence;

[0218] Perform a one-way encryption operation on the data sequence according to the signature method to obtain a reference information.

[0219] In an embodiment of the present invention, the integrity determination module is further configured to:

[0220] If the reference information is the same as the authentication information, determine that the target data has not been tampered with;

[0221] If the reference information is different from the authentication information, determine that the target data has been tampered with.

[0222] In an embodiment of the present invention, the strong man further includes:

[0223] An abnormal data recording module, configured to write the target data into a preset abnormal data table if the target data is tampered with;

[0224] A raw data rollback module, configured to roll back the raw data to the state of the previous backup.

[0225] The data processing device of the database provided by the embodiment of the present invention can execute the data processing method of the database provided by any embodiment of the present invention, and has the corresponding function modules and beneficial effects for executing the data processing method of the database.

[0226] Embodiment Five

[0227] Figure 9 It is a schematic structural diagram of a data processing system of a database provided for Embodiment Five of the present invention. As Figure 9 shown, the system includes a database 901 and a database connection pool 902 that are connected to each other, and the database connection pool 902 is configured with a software development kit 903;

[0228] The database connection pool 902 includes:

[0229] A statement receiving module, configured to receive a structured query statement for writing raw data to the database 901;

[0230] A statement transmission module, configured to transmit the structured query statement to the software development kit 903;

[0231] The software development kit 903 includes:

[0232] A rule loading module, configured to load the integrity protection rules set for the database 901;

[0233] A statement acquisition module, configured to acquire the structured query statements received by the database connection pool;

[0234] A data extraction module, configured to extract the original data to be integrity-protected from the structured query statements according to the integrity protection rules, as target data;

[0235] A signature module, configured to sign the target data according to the integrity protection rules to obtain authentication information;

[0236] A statement rewriting module, configured to write the authentication information into the structured query statements;

[0237] A data protection module, configured to transmit the structured query statements to the database connection pool;

[0238] The database connection pool 902 further includes:

[0239] A statement execution module, configured to execute the structured query statements to write the original data and the authentication information into the database.

[0240] In an embodiment of the present invention, the database connection pool 902 further includes:

[0241] A timing module, configured to perform a timing operation when transmitting the structured query statements to the software development kit 903;

[0242] The statement execution module is further configured to execute the local structured query statements to write the original data into the database when the timing operation ends and no structured query statements feedback by the software development kit 903 are received.

[0243] The data processing system of the database provided by the embodiments of the present invention can execute the data processing method of the database provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the data processing method of the database.

[0244] Embodiment Six

[0245] Figure 10FIG. 0 shows a schematic structural diagram of an electronic device 10 that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0246] As Figure 10 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0247] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0248] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data processing method of the database.

[0249] In some embodiments, the data processing method of the database can be implemented as a computer program which is tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data processing method of the database described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data processing method of the database by any other suitable means (e.g., by means of firmware).

[0250] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0251] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0252] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0253] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0254] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0255] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0256] It should be understood that various forms of processes shown above can be used, with steps reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0257] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A data processing method for a database, characterized in that, Applied to a software development kit configured for a database connection pool, the software development kit provides multiple interfaces for the database connection pool to call, and the method includes: Loading the integrity protection rules set for the database, where the database connection pool is connected to the database; Obtaining the structured query statement received by the database connection pool, where the structured query statement is used to write raw data to the database; Extracting the raw data to be integrity protected from the structured query statement according to the integrity protection rules as target data; Signing the target data according to the integrity protection rules to obtain authentication information; Querying the type of the structured query statement; Writing the authentication information into the structured query statement according to the type to obtain a target structured query statement; Transmitting the structured query statement to the database connection pool for execution to write the raw data and the authentication information into the database; Among them, the writing the authentication information into the structured query statement according to the type to obtain a target structured query statement includes: If the type of the structured query statement is to insert raw data into the database, query the key area and the value area in the structured query statement; Adding the field name of the authentication information to the key area and adding the field value of the authentication information to the value area; Or If the type of the structured query statement is to update raw data in the database, query the key-value area in the structured query statement; Generating a key-value pair with the field name of the authentication information as the key and the field value of the authentication information as the value; Inserting the key-value pair into the key-value area.

2. The method according to claim 1, wherein The obtaining the structured query statement received by the database connection pool includes: Determining the extended interface provided by the database connection pool; When the database connection pool calls the extended interface, obtaining the structured query statement received by the database connection pool through the extended interface; The transmitting the structured query statement to the database connection pool for execution to write the raw data and the authentication information into the database includes: Transmitting the structured query statement to the database connection pool for execution through the extended interface to write the raw data and the authentication information into the database.

3. The method according to claim 1, characterized in that, The integrity protection rules include the tables and fields to be integrity protected; The extracting the raw data to be integrity protected from the structured query statement according to the integrity protection rules as target data includes: Converting the structured query statement into a syntax tree; Searching for the table in the syntax tree; If the table is found, searching for the field in the table of the syntax tree; If the field is found, extracting the raw data located in the field as target data.

4. The method according to claim 1, characterized in that, The integrity protection rules include a sorting method and a signature method; The signing the target data according to the integrity protection rules to obtain authentication information includes: Sort the target data according to the sorting method and splice the sorted target data to obtain a data sequence; Perform a one-way encryption operation on the data sequence according to the signature method to obtain authentication information.

5. The method according to claim 1, wherein The target data includes at least one of the following: Audit data, log data.

6. The method according to claim 1, characterized in that After extracting the original data to be integrity-protected from the structured query statement according to the integrity protection rule as the target data, the method further includes: Check the configuration options of the software development kit; If the configuration option is to enable the integrity protection function, then extract the original data to be integrity-protected from the structured query statement according to the integrity protection rule as the target data; If the configuration option is to disable the integrity protection function, then transmit the structured query statement to the database connection pool for execution to write the original data into the database.

7. The method according to any one of claims 1-6, characterized in that It further includes: Call the database connection pool to traverse the original data stored in the database, and the original data is associated with authentication information; Query the integrity protection rule configured for the original data; Extract the target data to be integrity-protected from the original data according to the integrity protection rule; Sign the target data according to the integrity protection rule to obtain reference information; Compare the reference information with the authentication information to determine the integrity of the target data.

8. The method according to claim 7, wherein The comparing the reference information with the authentication information to determine the integrity of the target data includes: If the reference information is the same as the authentication information, it is determined that the target data has not been tampered with; If the reference information is different from the authentication information, it is determined that the target data has been tampered with.

9. The method according to claim 7, wherein It further includes: If the target data has been tampered with, write the target data into a preset exception data table; Roll back the original data to the state of the previous backup.

10. A data processing device for a database, characterized in that, Applied to a software development kit configured for a database connection pool, the software development kit provides multiple interfaces for the database connection pool to call. The device includes: A rule loading module, configured to load the integrity protection rule set for the database, and the database connection pool is connected to the database; A statement obtaining module, configured to obtain the structured query statement received by the database connection pool, and the structured query statement is used to write the original data into the database; A data extraction module, configured to extract the original data to be integrity-protected from the structured query statement according to the integrity protection rule as the target data; A signature module, configured to sign the target data according to the integrity protection rule to obtain authentication information; A statement rewriting module, configured to query the type of the structured query statement; write the authentication information into the structured query statement according to the type to obtain a target structured query statement; A data protection module, configured to transmit the structured query statement to the database connection pool for execution to write the original data and the authentication information into the database; Wherein, the statement rewriting module is further configured to: If the type of the structured query statement is to insert raw data into the database, query the key area and value area in the structured query statement; Add the field name of the authentication information to the key area and add the field value of the authentication information to the value area; Or If the type of the structured query statement is to update raw data in the database, query the key-value area in the structured query statement; Generate a key-value pair with the field name of the authentication information as the key and the field value of the authentication information as the value; Insert the key-value pair into the key-value area.

11. A data processing system for a database, characterized in that, The system includes a database and a database connection pool connected to each other. The database connection pool is configured with a software development kit; the software development kit provides multiple interfaces for the database connection pool to call; The database connection pool includes: A statement receiving module, configured to receive a structured query statement for writing raw data to the database; A statement transmission module, configured to transmit the structured query statement to the software development kit; The software development kit includes: A rule loading module, configured to load the integrity protection rules set for the database; A statement obtaining module, configured to obtain the structured query statement received by the database connection pool; A data extraction module, configured to extract the raw data to be integrity-protected from the structured query statement according to the integrity protection rules as target data; A signature module, configured to sign the target data according to the integrity protection rules to obtain authentication information; A statement rewriting module, configured to query the type of the structured query statement; write the authentication information into the structured query statement according to the type to obtain a target structured query statement; A data protection module, configured to transmit the structured query statement to the database connection pool; The database connection pool further includes: A statement execution module, configured to execute the structured query statement to write the raw data and the authentication information into the database; Wherein, the statement rewriting module is further configured to: If the type of the structured query statement is to insert raw data into the database, query the key area and value area in the structured query statement; Add the field name of the authentication information to the key area and add the field value of the authentication information to the value area; Or If the type of the structured query statement is to update raw data in the database, query the key-value area in the structured query statement; Generate a key-value pair with the field name of the authentication information as the key and the field value of the authentication information as the value; Insert the key-value pair into the key-value area.

12. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data processing method of the database according to any one of claims 1-9.

13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program is used to implement the data processing method of the database described in any one of claims 1-9 when executed by a processor.

Citation Information

Patent Citations

  • Data encryption processing method and device

    CN111884986A

  • Database table-dividing query method and equipment

    CN114281842A