A data fusion method and apparatus, a storage medium, and an electronic device

By allocating new key identification information to the fusion key information to be fused in a fully encrypted database, the problem of data being unavailable due to key conflict is solved, and high-security data fusion is achieved.

CN115473681BActive Publication Date: 2025-05-27ALIBABA CLOUD COMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210957772.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-10
Publication Date
2025-05-27
Estimated Expiration
2042-08-10

AI Technical Summary

Technical Problem

In the data fusion scenario of a fully encrypted database, the problem of data being unable to be obtained due to key conflicts.

Method used

By obtaining the fusion key information in the database to be fused, it is determined whether its key identification information matches. If it matches, new key identification information will be allocated, and the key information and mapping relationship will be updated in the target database.

Benefits of technology

It realizes that there is no need to decrypt cipher text data during data fusion, avoids the risk of data leakage, and improves the security of data fusion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115473681B_ABST
    Figure CN115473681B_ABST
Patent Text Reader

Abstract

The present application discloses a data fusion method and apparatus, a storage medium, and an electronic device. Among them, the data fusion method includes: obtaining the fusion key information to be fused in the database to be fused; determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database; if so, assigning a new key identification information to the fusion key identification information; replacing the fusion key identification information in the fusion key information with the target key information of the new key identification information, and recording it in the target database; recording the mapping relationship between the fusion key identification information and the new key identification information in the target database; thereby effectively improving the security of data fusion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer application technologies, and particularly relates to a data fusion method and apparatus. This application also relates to a computer storage medium and an electronic device. Background Art

[0002] A fully encrypted database aims to eliminate the potential data leakage risks existing at any moment during the operation of the database, ensuring that data exists in ciphertext form throughout the processes of transmission, use, and storage. Meanwhile, it still has complete database query capabilities, eliminating the possibility for the cloud platform and operation and maintenance personnel to access plaintext data, ensuring that customers have full ownership of the data stored on the cloud server, and ensuring that the database on the cloud server side cannot obtain the plaintext data of users throughout the process of providing data services; authorized users can read and write data in the cloud server side database through existing protocols normally; unauthorized users cannot obtain the plaintext data of protected users. Thus, full encryption of the database is achieved, thereby improving data security. Summary of the Invention

[0003] This application provides a data fusion method to solve the technical problem in the prior art that data cannot be obtained due to data conflicts in the data fusion scenario of a fully encrypted database.

[0004] This application provides a data fusion method, including:

[0005] Obtain the fusion key information to be fused in the database to be fused;

[0006] Determine whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database;

[0007] If so, assign new key identification information to the fusion key identification information;

[0008] Replace the fusion key identification information in the fusion key information with the target key information of the new key identification information, and record it in the target database;

[0009] Record the mapping relationship between the fusion key identification information and the new key identification information in the target database.

[0010] In some embodiments, it further includes:

[0011] Determine whether the database to be fused and the target database are homologous databases of the same user;

[0012] If not, assign a globally unique identifier to the fusion key attribute information of the fusion key information; determine whether the globally unique identifier is recorded in the key attribute fusion mapping table of the target database;

[0013] If not, perform the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database.

[0014] In some embodiments, determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database includes:

[0015] Determine whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information;

[0016] If so, the new key identification information assigned to the fusion key identification information includes:

[0017] If so, assign a new key attribute identification information to the fusion key attribute identification information;

[0018] Recording the target key information with the fusion key identification information in the fusion key information replaced by the new key identification information into the target database includes:

[0019] Record the target key information with the fusion key identification information in the fusion key information replaced by the new key attribute identification information into the target database;

[0020] Recording the mapping relationship between the fusion key identification information and the new key identification information into the target database includes:

[0021] Record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information into the target database.

[0022] In some embodiments, recording the mapping relationship between the new key attribute identification information and the fusion key attribute identification information into the target database includes:

[0023] Record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information into the key attribute fusion mapping table of the target database.

[0024] In some embodiments, determining whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information includes:

[0025] Determine whether the fusion key attribute identification information matches the key attribute identification information in the key attribute fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between key attribute identification information and the globally unique identifier.

[0026] In some embodiments, it further includes:

[0027] Determine whether the database to be fused and the target database are homologous databases of the same user;

[0028] If so, assign a first globally unique identifier to the fusion key attribute information of the fusion key information;

[0029] Assign a second globally unique identifier to the fusion data key information of the fusion key information; determine whether the first globally unique identifier is recorded in the key attribute fusion mapping table of the target database, and whether the second globally unique identifier is recorded in the data key fusion mapping table of the target database;

[0030] If not, perform the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database.

[0031] In some embodiments, the determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database includes:

[0032] Determine whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information, and determine whether the fusion data key identification information corresponding to the fusion data key information matches the data key identification information corresponding to the data key information;

[0033] If so, the new key identification information assigned to the fusion key identification information includes:

[0034] Assign a new key attribute identification information to the fusion key attribute identification information, and assign a new data key identification information to the fusion data key identification information;

[0035] Re-encrypt the new data key identification information and the fusion data key information corresponding to the new data key identification information;

[0036] Recording the target key information with the fusion key identification information in the fusion key information replaced by the new key identification information into the target database includes:

[0037] Replace the fusion key identification information in the fusion key information with the target key attribute information of the new key attribute identification information, record it in the target database, and replace the fusion data key identification information with the new data key identification information, and the master key identification information corresponding to the fusion data key identification information as the target data key information, and record it in the target database; wherein, the master key identification information is the identification information of the master key information for encrypting the fusion data key identification information.

[0038] Recording the mapping relationship between the fusion key identification information and the new key identification information in the target database includes:

[0039] Record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the target database, and record the mapping relationship between the new data key identification information and the fusion data key identification information in the target database.

[0040] In some embodiments, determining whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information, and determining whether the fusion data key identification information corresponding to the fusion data key information matches the data key identification information corresponding to the data key information includes:

[0041] Determine whether the fusion key attribute identification information matches the key attribute identification information in the key attribute fusion mapping table of the target database; and determine whether the fusion data key identification information matches the data key identification information in the data key fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between the fusion key attribute identification information and the key attribute identification information, and the first globally unique identifier; the data key fusion mapping table is used to record the mapping relationship between the fusion data key identification information and the data key identification information, and the second globally unique identifier.

[0042] In some embodiments, recording the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the target database includes:

[0043] Record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the key attribute fusion mapping table of the target database;

[0044] Recording the mapping relationship between the new data key identification information and the fused data key identification information into the target database includes:

[0045] Recording the mapping relationship between the new data key identification information and the fused data key identification information into the data key fusion mapping table of the target database.

[0046] In some embodiments, it further includes:

[0047] Determining whether the ciphertext data to be fused corresponding to the fused key information in the database to be fused is empty;

[0048] If not, determining the ciphertext data to be fused fused into the target database as the target ciphertext data;

[0049] Obtaining the fused key identification information in the target ciphertext data;

[0050] Determining the new key identification information having the mapping relationship with the obtained fused key identification information;

[0051] Updating the fused key identification information in the target ciphertext data to the new key identification information.

[0052] This application also provides a data fusion device, including:

[0053] An obtaining unit, configured to obtain the fused key attribute information to be fused in the database to be fused;

[0054] A determining unit, configured to determine whether the fused key identification information in the fused key information matches the key identification information of the key information in the target database;

[0055] An allocation unit, configured to allocate new key identification information for the fused key identification information when the determination result of the determining unit is yes;

[0056] A first recording unit, configured to record the target key information obtained by replacing the fused key identification information in the fused key information with the new key identification information into the target database;

[0057] A second recording unit, configured to record the mapping relationship between the fused key identification information and the new key identification information into the target database.

[0058] This application also provides a computer storage medium, configured to store data generated by a network platform and a program for processing the data generated by the network platform;

[0059] When the program is read and executed by a processor, it executes the data fusion method as described above.

[0060] This application also provides an electronic device, including:

[0061] A processor;

[0062] A memory for storing a program for processing data generated by a network platform. When the program is read and executed by the processor, it executes the data fusion method as described above.

[0063] Compared with the prior art, this application has the following advantages:

[0064] A data fusion method provided by this application reassigns a key ID to conflicting key IDs, and updates the meta-information of the fused ciphertext data based on this, so that the ciphertext data does not need to be decrypted during the fusion process, and at the same time, the ownership of the data is not changed, that is, only ciphertext metadata is involved in the fusion process, and data decryption is not involved. Therefore, there is no risk of data leakage. Further, since data decryption is not involved, the fusion process is not restricted by the environment. In the case of unauthorized access, only data decryption errors occur, and the data content of the encrypted data still cannot be obtained. Therefore, the security of data fusion or migration can be effectively improved. Furthermore, by assigning a globally unique identifier to the fusion key attribute information in the fusion key information to be fused, or by assigning globally unique identifiers to the fusion key attribute information and the fusion data key information respectively, duplicate fusion of the fusion key information can be avoided, that is, it can be determined whether a globally unique identifier is recorded in the target database. If not, it means that the fusion key information has not been fused, and vice versa. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 is a flowchart of a data fusion method provided by this application according to one or more embodiments;

[0066] Figure 2 is a flowchart of the first embodiment of a data fusion method provided by this application;

[0067] Figure 3 is a flowchart of the second embodiment of a data fusion method provided by this application;

[0068] Figure 4 is a timing diagram of a data fusion method provided by this application;

[0069] Figure 5 is a schematic structural diagram of a data fusion device provided by this application;

[0070] Figure 6 is a schematic structural diagram of an embodiment of an electronic device provided by this application. Detailed Implementation Manner

[0071] Numerous specific details are set forth in the following description in order to provide a thorough understanding of the present application. However, the present application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the connotation of the present application. Therefore, the present application is not limited by the specific implementations disclosed below.

[0072] The terms used in the present application are merely for the purpose of describing specific embodiments and are not intended to limit the present application. The descriptive methods used in the present application and the appended claims, such as "a", "first", and "second", etc., are not intended to limit the quantity or the order of precedence, but are used to distinguish information of the same type from each other.

[0073] Combined with the background art, it can be seen that a fully encrypted database can ensure that data exists in ciphertext form throughout the processes of transmission, use, and storage, thereby improving data security. However, in the face of data analysis scenarios, in order to mine data value, it is inevitable to combine third-party data to achieve data analysis and data mining. Therefore, it is necessary to physically and / or logically fuse the data of two or more databases so that the fused data can be intuitively analyzed on the data fusion library to mine the data value.

[0074] In a fully encrypted database, the data stored in the database is all ciphertext data encrypted and protected by a user data key (DEK: Data Encryption Key), and the user key information (CC: Cipher Context) used during encryption associated therewith. Therefore, the fusion of two or more fully encrypted databases not only requires fusing the ciphertext data but also requires fusing the key information. Usually, the relevant information of the key is stored in a key store (KeyStore). Therefore, when fusing the ciphertext data, it is also necessary to fuse the key store together to ensure that the fused ciphertext data can still be correctly decrypted. Since the key information in the key store of a fully encrypted database has locality, for example, the DEKID (Data Encryption Key ID) and CtxID (Key Information Index ID, that is: Key Attribute ID) are unique within the scope of their respective key stores, but there will be conflict problems during the data fusion process of a fully encrypted database, resulting in the situation where the ciphertext data cannot be normally decrypted when read in the fusion database after fusion. For example: In the data fusion scenario, when the sources of the fused data are a homologous database and different databases, and when fusing data for different users and the same user, the conflict situations can be as shown in the following table:

[0075]

[0076] Based on the above table, it can be seen that regardless of whether the data fusion scenario is in a homogeneous database or different databases, and whether it is for the same user or different users, there is a problem of CtxID conflict during data fusion. Since CtxID is monotonically increasing within each database, it will inevitably lead to CtxID conflicts when two or more databases are fused.

[0077] Furthermore, for the case of homogeneous databases under the same user, there is a problem of <MEKID, DEKID> conflict. For example, in the synchronization-derived library: User 1 has a table t1 in database A and synchronizes it to database B. Then User 1 creates table t2a in database A and table t2b in database B respectively. At this time, A and B will independently update the key-related metadata in their respective key repositories for t2a and t2b. The independent t2a and t2b will have the same DEKID and CtxID. Because database B is initialized and synchronized from database A under the same user, the MEKID is the same. When fusing databases A and B, both <MEKID, DEKID> and CtxID will conflict. Based on the above, in the data fusion scenario, CtxID may conflict, or <MEKID, DEKID> may conflict. That is, regardless of whether it is for the same user or different users, and regardless of whether it is in a homogeneous database or different databases, any conflict in the data fusion scenario may cause the ciphertext data to be unable to be decrypted normally, and thus the data cannot be obtained.

[0078] It can be understood that the above examples are based on the data fusion scenario of fully encrypted databases, and there will also be cases of key identification information conflicts in other application scenarios.

[0079] In view of this, the present application provides a data fusion method based on a fully encrypted database, as Figure 1 shown, Figure 1 is a flowchart of an embodiment of the data fusion method provided by the present application; before describing the method embodiment in detail, the technical terms involved in this embodiment will be explained first.

[0080] Key Store: It is used to store and manage the user's key data.

[0081] Globally unique: It is not repeated in all database instances; a globally unique identifier refers to an identifier used to identify information that is not repeated in the database.

[0082] Master Encryption Key / Master Encryption Key ID (MEK / MEKID: Master Encryption Key / Master Encryption Key ID, which is also the OwnerID): The Master Encryption Key (MEK) is the main encryption key, and the Master Encryption Key ID (MEKID) is the user's main key ID identity in the database system. It is allocated at the key repository granularity and can globally and uniquely identify the user's identity. In implementation, it can be generated randomly. For the same entity user, the MEKID is different on different encrypted database system instances.

[0083] Data Encryption Key / Data Encryption Key ID (DEK / DEKID): The DEK is the key used by the user to encrypt data. The DEKID is the unique identifier of the DEK and is unique within the key repository scope. A DEK can be globally and uniquely determined by <MEKID, DEKID>. The relationship between the MEK and the DEK can be understood as follows: the DEK is used to encrypt and protect the user data, and the MEK is used to encrypt and protect the DEK.

[0084] CC / CtxID: CC (Cipher Context) contains the meta-information required to decrypt the ciphertext data, including the encryption algorithm, encryption mode, DEKID, etc. The CtxID is the unique identifier of the CC and is unique within the key repository scope. That is, CC can be understood as the attribute information about the key, and the CtxID is the identification information of the key attribute information, that is, the key attribute identification information.

[0085] The above is an explanation of the technical terms involved in a data fusion method based on a fully encrypted database provided by this application. In view of the above introduction to the prior art, to overcome the defects existing in the prior art, this application provides a data fusion method based on a fully encrypted database, and the specific content is as follows:

[0086] As Figure 1 shown, Figure 1 is a flowchart of a data fusion method provided by this application according to one or more embodiments. The method may include:

[0087] Step S101: Obtain the fusion key information to be fused in the database to be fused; where the database to be fused can also be regarded as the source database;

[0088] Step S102: Determine whether the fusion key identification information in the fusion key information matches the key identification information in the target database;

[0089] Step S103: If so, allocate new key identification information for the fusion key identification information;

[0090] Step S104: Replace the fusion key identification information in the fusion key information with the target key information of the new key identification information, and record it in the target database;

[0091] Step S105: Record the mapping relationship between the fusion key identification information and the new key identification information in the target database.

[0092] First Embodiment:

[0093] In this embodiment, the database involved can be a fully encrypted database or other databases with key information conflicts. Therefore, in this embodiment, only the fully encrypted database is taken as an example, which does not limit the scope of solving the key information conflict problem.

[0094] The key information in the key warehouse of the fully encrypted database has locality. For example, both DEKID and CtxID are unique within the scope of the key warehouse. When performing data fusion or data migration on two or more databases, these local information may conflict. Therefore, in order to avoid the repetition of fusion, before or after the specific implementation of step S102, the specific execution order is not limited, and it can be as Figure 2 shown, and specifically may further include:

[0095] Step S201-11: Determine whether the database to be fused and the target database are homologous databases of the same user;

[0096] The homologous database can be understood as the same database or a synchronously derived library, which can be for different users or the same user. The purpose of step S201-11 is to determine whether at least two databases that need to perform data fusion are homologous databases of the same user. For example: User 1 has a table t1 in database A, and then User 1 synchronizes t1 to database B, then database B is a synchronously derived library of database A.

[0097] Step S201-12: If not, assign a globally unique identifier to the fusion key attribute information of the fusion key information;

[0098] The purpose of step S201-12 is to assign a globally unique identifier. When the determination result of step S201-11 is negative, that is, when the database to be fused and the target database are not homologous databases of the same user, assign the globally unique identifier to the fusion key attribute information (Ctx) of the fusion key information. Specifically, it can be assigned based on the key attribute table (CC Table) stored in the key warehouse of the database to be fused, as shown in Table 1 below:

[0099] Table 1 (Table 1 stores the fusion key attribute information of the fusion key attribute table of the database to be fused):

[0100]

[0101] That is, a corresponding globally unique identifier can be assigned to each record in the key attribute table. In this embodiment, the globally unique identifier can be in the form of a UUID. The so-called UUID is the Universally Unique Identifier, which is a 128-bit value that can be calculated through a certain algorithm. UUID is used to identify the attribute type and is regarded as a unique identifier in all spaces and times. Since UUID belongs to the prior art, the specific content of UUID will not be elaborated here. The above takes two pieces of fusion key information in the fusion database as an example. In fact, it can also be one or more. The number of specific fusion key information is not limited. The fusion migration process can be migrated and fused one by one or in batches. The specific method is not limited. This is only an example here.

[0102] It should be noted that in the fusion key attribute table, each record is associated with MEKID, DEKID, UUID, and specific attributes, namely information such as CtxID, MEKID, DEKID, UUID. Therefore, MEKID and DEKID can be obtained through CtxID.

[0103] It can be understood that in the key repository of the database to be fused, not only the fusion key attribute table can be stored, but also the fusion data key table can be stored, as shown in Table 2 below (Table 2 stores the fusion data key information of the fusion data key table of the database to be fused):

[0104]

[0105] It can be understood that in this embodiment, a corresponding globally unique identifier needs to be assigned to each piece of fusion key attribute information in the fusion key attribute table of the database to be fused; a corresponding globally unique identifier can also be assigned to each piece of key attribute information in the key attribute table of the target database. As shown in Table 3 below:

[0106] Table 3 (Table 3 stores the key attribute information of the key attribute table of the target database):

[0107] CtxID MEKID ... UUID ** **** ... "********_****_****_****_************"

[0108] Similarly, in the key attribute table in the target database, each record is also associated with MEKID, DEKID, UUID, and specific attributes, namely information such as CtxID, MEKID, DEKID, UUID. Therefore, MEKID and DEKID can be obtained through CtxID. There is also a data key table in the target database, as shown in Table 4 below (Table 4 stores the data key information of the data key table in the target database):

[0109]

[0110] It should be noted that the above Table 3 and Table 4 are only for explanatory purposes, using * to represent the corresponding information, and the specific information content can be determined according to the actual application scenario. In this embodiment, a globally unique identifier can be assigned to the key attribute information and data key information in the target database, or it can be assigned when the target database is used as a fusion database. Therefore, whether to assign a globally unique identifier to the target database can be determined according to requirements or specific application scenarios.

[0111] The assignment of the globally unique identifier can be pre-assigned or real-time assigned. The specific assignment time is not restricted, as long as it can meet the requirements of the matching operation.

[0112] Step S201-13: Determine whether the globally unique identifier is recorded in the key attribute fusion mapping table of the target database. The purpose of step S201-13 is to determine whether the globally unique identifier (UUID) corresponding to the fusion key attribute information in the database to be fused is the same as the globally unique identifier (UUID) corresponding to the key attribute information in the target database. Specifically, it can be determined whether they are the same by comparing the fields of the two.

[0113] To avoid repeated fusion and / or avoid problems such as wasted storage space and maintenance costs caused by additional redundancy, the specific implementation process of step S201-13 in this embodiment may include:

[0114] Determine whether the globally unique identifier of the fusion key attribute information in the fusion key information matches the globally unique identifier of the key attribute information in the key attribute fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between key attribute identification information and the globally unique identifier corresponding to the key attribute identification information, as shown in Table 5 below (Table 5 is the key attribute fusion mapping table in the target database, that is: CC Fusion Mapping Table):

[0115]

[0116] Among them, the UUID field in Table 5 is the primary key. The CtxID_SRC and CtxID have a unique constraint. For each conflicting <MEKID_SRC, CtxID_SRC> record, a new CtxID is assigned to it in the table, otherwise CtxID_SRC is continued to be used as CtxID. Use * to represent the corresponding information, and the specific information content can be determined according to the actual application scenario.

[0117] Based on the examples of Table 1 to Table 5 provided above, it can be seen that by comparing the UUID = 86ae913e-166a-431a-a392-18fcfab606dc in Table 1 with the UUIDs in Table 5, no UUID matching the UUID = 86ae913e-166a-431a-a392-18fcfab606dc in Table 1 is found in Table 5. Therefore, the determination result is no.

[0118] When the determination result of step S201-13 is no, then step S102 is executed; when the determination result of step S201-13 is yes, then the fusion is exited or a prompt message indicating duplicate fusion is output, which is not specifically limited.

[0119] The specific implementation process of step S102 may include:

[0120] Step S102-11: Determine whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information;

[0121] The fusion key attribute identification information corresponding to the fusion key attribute information is CtxID. The purpose of step S102-11 is to determine whether the fusion key attribute identification information in the database to be fused and the key attribute identification information in the target database match. In other words, it is to determine whether the fusion key attribute identification information recorded in the fusion key attribute table of the database to be fused is recorded in the key attribute table of the target database. The specific implementation method can be to compare the fusion key attribute identification information with the key attribute table of the target database, and if they are the same, it is considered a match. Continuing with the examples of Table 1 to Table 5 above, for example: compare the CtxID = 17 recorded in the fusion key attribute table of the database to be fused with the CtxID recorded in the key attribute table of the target database, and find that the CtxID of the first record in the key attribute table of the target database is also equal to 17. Therefore, the two CtxIDs are the same, and then it is determined that there is a matching CtxID in the key attribute table of the target database, and then step S103 is entered: If so, a new key identification information is assigned to the fusion key identification information.

[0122] It can be understood that when the determination result of step S102-11 is negative, the fusion key attribute information can be recorded in the key attribute table of the target database, and there is no need to allocate new key attribute identification information, that is, step S103 does not need to be executed.

[0123] The specific implementation process of step S103 may include:

[0124] Step S103-11: If so, allocate new key attribute identification information for the fusion key attribute identification information;

[0125] Continuing with the above example, the purpose of step S103-11 is to re-allocate a new identification information for the fusion key attribute identification information with CtxID = 17. For example: CtxID = 33.

[0126] Step S104: Replace the fusion key identification information in the fusion key information with the target key information of the new key identification information and record it in the target database. The specific implementation process may include:

[0127] Step S104-11: Replace the fusion key identification information in the fusion key information with the target key information of the new key attribute identification information and record it in the target database. That is: after replacing the fusion key identification information with the new key attribute identification information, the key information is determined as the target key information and recorded in the key attribute table of the target database, as shown in Table 6:

[0128] CtxID MEKID ... UUID ** **** ... "********_****_****_****_************" * **** ... "********_****_****_****_************" 33 2335 ... "86ae913e-166a-431a-a392-18fcfab606dc"

[0129] The data key table in the target database is shown in Table 7, for example:

[0130]

[0131] Step S105: Record the mapping relationship between the fusion key identification information and the new key identification information in the target database. The specific implementation process may include:

[0132] Step S105-11: Record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the target database.

[0133] Similarly, in order to avoid duplicate fusion and / or avoid problems of storage space waste and maintenance cost caused by additional redundancy, the mapping relationship between the new key attribute identification information and the fusion key attribute identification information can be recorded in the key attribute fusion mapping table of the target database. As shown in Table 8 below:

[0134]

[0135]

[0136] It is understandable that the target key information can also be recorded in the key attribute table in the target database. In this embodiment, taking the record in the key attribute fusion mapping table as an example for description, there is no limitation on the specific location in the target database where the mapping relationship is recorded, as long as the key attribute information can be fused through the new key attribute identification information.

[0137] Based on the above content, when obtaining relevant key information, the new key attribute identification information 33 corresponding to the fusion key attribute identification information 17 can be found through the key attribute fusion mapping table, and then in the key attribute table in the target database, according to CtxID = 33, the corresponding <MEKID, DEKID>, that is, <2335, 1>, and other key attribute information, such as encryption algorithm, encryption mode, etc., can be found. Through <MEKID, DEKID>, the corresponding key ciphertext information, that is, DEK information, can be found in the data key table in the target database.

[0138] First of all, it is determined that the to-be-fused database and the target database in step S201-11 are not homologous databases of the same user; furthermore, it is determined that there is no matching relationship between the global unique identifier of the fusion key information in step S201-13 and the global unique identifier of the key information in the target database. Therefore, it is necessary to enter the relevant steps of step S102 for execution. On the contrary, when the global unique identifier of the fusion key information in step S201-13 matches the global unique identifier of the key information in the target database, it indicates that the relevant information of the fusion key attribute information has been recorded in the key attribute fusion mapping table in this embodiment, and there is no need to perform repeated fusion.

[0139] Second Embodiment:

[0140] As Figure 3 shown, Figure 3 is a flowchart of the second embodiment of a data fusion method provided by this application; in this embodiment, it may further include:

[0141] Step S301-11: Determine whether the to-be-fused database and the target database are homologous databases of the same user;

[0142] Step S301-12: If so, assign a first global unique identifier to the fusion key attribute information of the fusion key information;

[0143] Step S301-13: Assign a second global unique identifier to the fusion data key information of the fusion key information;

[0144] Step S301-14: Determine whether the first globally unique identifier is recorded in the key attribute fusion mapping table of the target database, and whether the second globally unique identifier is recorded in the data key fusion mapping table of the target database;

[0145] Step S301-15: If not, then execute the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database, that is, execute Step S102. If so, it means that the fusion key information has been fused and migrated to the target database, and there is no need to repeat the fusion. The specific implementation processes of Step S301-11 and Step S301-12 can refer to the relevant content of Step S201-11 and Step S201-12 above, and will not be elaborated here.

[0146] The purpose of Step S301-13 is to assign a second globally unique identifier to the fused data key information. It can also be understood that the fusion data key table in the database to be fused for recording or storing the fused data key information is expanded, and a globally unique identifier (UUID), that is, the second globally unique identifier, is added to each record. Here, the first globally unique identifier and the second globally unique identifier are only for clarity of expression and do not limit the number or order of the globally unique identifiers. The globally unique identifiers of the fusion key attribute information can be set separately according to their quantities, and the globally unique identifiers of the fused data key information can be set separately according to their quantities, as long as the global uniqueness can be guaranteed. As shown in Table 9 below:

[0147] Table 9 (Table 9 stores the fused data key information of the fusion data key table in the database to be fused)

[0148]

[0149] At this time, the fused key attribute information stored in the fused key attribute table in the database to be fused is the content shown in Table 10 below (it can be derived from Table 9), as shown in Table 10:

[0150] CtxID MEKID ... UUID 17 2365 ... "86ae913e-166a-431a-a392-18fcfab606dc" 23 2365 ... "814fb937-7730-4cc4-a54b-6b96fbff471b"

[0151] It should be noted that in the fused key attribute table, each record is associated with MEKID, DEKID, UUID, and specific attributes, that is, information such as CtxID, MEKID, DEKID, UUID. Therefore, MEKID and DEKID can be obtained through CtxID.

[0152] Similar to the above first embodiment, a globally unique identifier can also be assigned to the data key information in the target database. It can also be understood that the data key table in the target database used to record or store the data key information is extended, and a globally unique identifier (UUID) is added to each record, as shown in Table 11 below:

[0153]

[0154] At this time, the key attribute information stored in the key attribute table in the target database is the content shown in Table 12 below (which can be derived from Table 11). Table 12 is shown as follows:

[0155] CtxID MEKID ... UUID 17 2365 ... "3979e26b-f722-4e03-a24e-b83b747365ca" 23 2365 ... "2e379bc8-562a-4f49-873a-84eae485079a"

[0156] Similar to the key attribute information recorded in the above key attribute table, the fused data key table exists in the key repository of the database to be fused, and can also exist in the key repository of the target database, which can be set according to specific requirements.

[0157] Regarding determining whether the first globally unique identifier of the fused key attribute information in step S301-14 is recorded in the key attribute fusion mapping table in the target database, specifically, the first globally unique identifier is compared with the globally unique identifier in the key attribute fusion mapping table. The content of step S201-13 can be referred to and will not be repeated here. Regarding determining whether the second globally unique identifier of the fused data key information matches the globally unique identifier in the data key fusion mapping table in the target database, the purpose is to determine whether the second globally unique identifier (UUID) corresponding to the fused data key information in the database to be fused has been recorded in the target database, which can be determined by comparing the fields of the two. Thus, it is possible to avoid duplicate fusion and / or avoid problems such as wasted storage space and maintenance costs caused by additional redundancy. In this embodiment, the key attribute fusion mapping table is used to record the mapping relationship between the fused key attribute identification information and the key attribute identification information, and the first globally unique identifier corresponding to the fused key attribute identification information; the data key fusion mapping table is used to record the mapping relationship between the fused data key identification information and the data key identification information, and the second globally unique identifier corresponding to the fused data key identification information.

[0158] The data key fusion mapping table can be referred to as shown in Table 13 below (Table 13 is the data key fusion mapping table in the target database, that is: DEK Fusion Mapping Table):

[0159]

[0160] Among them, the UUID field in Table 13 is the primary key. <MEKID_SRC,DEKID_SRC> and <MEKID_SRC,DEKID> have unique constraints. For each conflicting <MEKID_SRC,DEKID_SRC> record, a new DEKID is assigned to it in the table, otherwise DEKID_SRC is continued to be used as the DEKID.

[0161] The key attribute fusion mapping table (CC fusion mapping table) can be referred to as shown in Table 14:

[0162]

[0163] Based on the examples of Table 9 to Table 14 provided above, it can be known that the UUID = 2b1bc79a - b291 - 4a92 - b865 - 8aba080f46e2 in Table 9 is compared with the UUID in Table 13 (DEK fusion mapping table), and no UUID matching the UUID = 2b1bc79a - b291 - 4a92 - b865 - 8aba080f46e2 in Table 9 is found in Table 13. The UUID = 814fb937 - 7730 - 4cc4 - a54b - 6b96fbff471b in Table 10 is compared with the UUID in Table 14 (CC fusion mapping table), and no UUID matching the UUID = 814fb937 - 7730 - 4cc4 - a54b - 6b96fbff471b in Table 10 is found in Table 14. Therefore, the determination result is no, and step S102 is executed, that is, the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database is executed.

[0164] In this embodiment, the specific implementation process of step S102 may include:

[0165] Step S102 - 21: Determine whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information, and determine whether the fusion data key identification information corresponding to the fusion data key information matches the data key identification information corresponding to the data key information;

[0166] Among them, regarding determining whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information, reference can be made to the description in the first embodiment above, and details are not described here again.

[0167] Regarding determining whether the fusion data key identification information corresponding to the fusion data key information matches the data key identification information corresponding to the data key information, the specific description is as follows:

[0168] The fusion data key identification information corresponding to the fusion data key information is DEKID. The purpose of determining whether the fusion data key identification information corresponding to the fusion data key information in step S102-21 matches the data key identification information corresponding to the data key information is to determine whether the fusion data key identification information in the database to be fused and the data key identification information in the target database match. In other words, it is to determine whether the fusion data key identification information recorded in the fusion data key table (DEK Table in the database to be fused) of the database to be fused is recorded in the data key table (DEK Table in the target database) of the target database. The specific implementation method can be to compare the fusion data key identification information with the data key identification information in the target database. If they are the same, it is considered a match. Continuing with the examples from Table 9 to Table 12 above, for example: Compare the DEKID = 2 recorded in the fusion data key table of the database to be fused with the DEKID recorded in the data key table of the target database. It is found that the DEKID of the second record in the data key table of the target database is also equal to 2, which is the same as the fusion data key identification information in the fusion data key table. Then it is determined that there is a matching DEKID in the data key table of the target database, and then step S103 is entered.

[0169] It can be understood that when the determination result of step S102-21 is yes, the fusion data key information can be recorded in the data key table of the target database, and step S103 does not need to be executed.

[0170] The specific implementation process of step S103 can include:

[0171] Step S103-21: Allocate new key attribute identification information for the fusion key attribute identification information, and allocate new data key identification information for the fusion data key identification information;

[0172] Regarding allocating new key attribute identification information for the fusion key attribute identification information, reference can be made to the content of step S103-11 in the first embodiment above, and details will not be elaborated here.

[0173] Regarding allocating new data key identification information for the fusion data key identification information, the above example can be followed. The purpose of step S103-21 is to re-allocate a new identification information for the fusion data key identification information with DEKID = 1. For example: DEKID = 9.

[0174] Step S103-22: Re-encrypt the new data key identification information and the fused data key information corresponding to the new data key identification information, that is, re-encrypt DEKID = 9 and DEK, and at the same time, associated fields can be updated.

[0175] The specific implementation process based on the above Step S105 may include:

[0176] Step S104-21: Replace the fused key identification information in the fused key information with the target key attribute information of the new key attribute identification information, record it in the target database, and replace the fused data key identification information with the new data key identification information, and the master key identification information corresponding to the fused data key identification information as the target key information, record it in the target database. Wherein, the master key identification information is the identification information of the master key information for encrypting the fused data key identification information.

[0177] Regarding replacing the fused key identification information in the fused key information with the target key attribute information of the new key attribute identification information and recording it in the target database, reference can be made to the content of Step S104-11 in the first embodiment above, which will not be elaborated here.

[0178] Regarding replacing the fused data key identification information with the new data key identification information, and using the master key identification information corresponding to the fused data key identification information as the target key information and recording it in the target database, the above example can be followed, as shown in Table 15 (Data Key Table of the Target Database):

[0179]

[0180] The key attribute table in the target database is shown in Table 16, for example:

[0181] CtxID MEKID ... UUID 17 2365 ... "3979e26b-f722-4e03-a24e-b83b747365ca" 23 2365 ... "2e379bc8-562a-4f49-873a-84eae485079a" 30 2365 ... "f01b28a2-82e1-4704-b337-891b1d398593"

[0182] The specific implementation process of Step S105 may include:

[0183] Step S105-21: Record the mapping relationship between the new key attribute identification information and the fused key attribute identification information in the target database, and record the mapping relationship between the new data key identification information and the fused data key identification information in the target database.

[0184] As described in the first embodiment regarding "recording the mapping relationship between the new key attribute identification information and the fused key attribute identification information into the target database", similarly, in order to avoid repeated fusion and / or problems such as wasted storage space and maintenance costs caused by additional redundancy, the mapping relationship between the new key attribute identification information and the fused key attribute identification information can be recorded into the key attribute fusion mapping table of the target database; and the mapping relationship between the new key attribute identification information and the fused key attribute identification information can be recorded into the data key fusion mapping table of the target database. As shown in Table 17 below (Table 17 represents the information of the data key fusion mapping table in the target database):

[0185]

[0186] Table 18 represents the information of the key attribute fusion mapping table in the target database:

[0187]

[0188] The above is the description of the first embodiment and the second embodiment. The first embodiment and the second embodiment are respectively described for the association relationships existing between two or more databases. The first embodiment mainly describes the scenario where there is no association relationship between the database to be fused and the target database. At this time, the conflict problem of CtxID needs to be solved; the second embodiment mainly describes the scenario of the association relationship where the database to be fused and the target database are homologous databases of the same user. At this time, the conflict problems of DEKID and CtxID need to be solved.

[0189] The above tables only give illustrative examples for explaining the first and second embodiments for easy understanding, and are not used to limit the content of the technical solutions of the present application.

[0190] Based on the above content, this embodiment may further include:

[0191] Step S106: Determine whether the ciphertext data to be fused corresponding to the fused key information in the database to be fused is empty;

[0192] Step S107: If not, determine the ciphertext data to be fused fused into the target database as the target ciphertext data;

[0193] Step S108: Obtain the fused key identification information in the target ciphertext data; for example: obtain CtxID_SRC from the ciphertext header of the target ciphertext data.

[0194] Step S109: Determine the new key identification information that has the mapping relationship with the obtained fusion key identification information; specifically, it can be to determine the CtxID (new key identification information) that has the mapping relationship with CtxID_SRC in the key attribute fusion mapping table.

[0195] Step S1010: Update the fusion key identification information in the target ciphertext data to the new key identification information.

[0196] When the determination result of step S106 is yes, there is no need to perform the fusion of ciphertext data. For example: for a periodic task, a fusion or migration task is performed every week, but in a certain period, the user deletes the historical data, and at this time, the ciphertext data to be fused is empty.

[0197] Based on the above content, combined with Figure 4 A schematic description of the data interaction process or data transmission process of a data fusion method provided by this application is as follows. Figure 4 As shown Figure 4 is a timing diagram of a data fusion method provided by this application.

[0198] The database to be fused sends key meta-information to the target database, including relevant information such as DEK, MEK, Ctx, etc. (including the assigned UUID at this time). The target database searches in its key repository according to the received key meta-information to determine whether there is a matching UUID. If not, a new key identification information assigned for the fusion key identification information is added to the key repository of the target database (which can be in the form of a data key table and a key attribute table in combination with the above embodiments). And update the target database (which can be to update the fusion mapping table for storing key-related information in combination with the above embodiments). Pull the fusion key information, obtain CtxID_SRC in the key meta-information, obtain the CtxID corresponding to CtxID_SRC from the fusion mapping table of the target database, and update the information associated with the ciphertext data according to CtxID.

[0199] The above is a description of an embodiment of a data fusion method provided by this application. The data fusion method reallocates the key ID for conflicting key IDs, and updates the meta-information of the fused ciphertext data based on this, so that the ciphertext data does not need to be decrypted during the fusion process, and at the same time, the data ownership will not be changed, that is, only ciphertext metadata is involved in the fusion process, and data decryption is not involved. Therefore, there is no risk of data leakage. Further, since data decryption is not involved, the fusion process is not restricted by the environment. In the case of unauthorized access, only data decryption errors are involved, and the data content of the encrypted data still cannot be obtained. Therefore, the data security can be effectively improved. Furthermore, by assigning a globally unique identifier to the fusion key attribute information in the fusion key information to be fused, or by assigning globally unique identifiers to the fusion key attribute information and the fusion data key information respectively, the repeated fusion of the fusion key information can be avoided, that is, it can be determined whether the globally unique identifier is recorded in the target database. If not, it means that the fusion key information has not been fused, and vice versa.

[0200] The above is a specific description of an embodiment of a data fusion method provided by this application. Corresponding to the foregoing embodiment of a data fusion method provided, this application also discloses an embodiment of a data fusion device. Please refer to Figure 5 , since the device embodiment is basically similar to the method embodiment, the description is relatively simple. For related parts, please refer to the partial description of the method embodiment. The device embodiment described below is only illustrative.

[0201] As Figure 5 shown, Figure 5 is a schematic structural diagram of a data fusion device provided by this application. The data fusion device may include:

[0202] An acquisition unit 501, configured to acquire the fusion key attribute information to be fused in the database to be fused;

[0203] A determination unit 502, configured to determine whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database;

[0204] An allocation unit 503, configured to, when the determination result of the determination unit 502 is yes, allocate a new key identification information for the fusion key identification information;

[0205] A first recording unit 504, configured to record the target key information obtained by replacing the fusion key identification information in the fusion key information with the new key identification information into the target database;

[0206] A second recording unit 505, configured to record the mapping relationship between the fusion key identification information and the new key identification information into the target database.

[0207] The first embodiment:

[0208] It may further include: a first determination unit, a first allocation unit, and a second determination unit.

[0209] The first determination unit is configured to determine whether the database to be fused and the target database are homologous databases of the same user;

[0210] The first allocation unit is configured to, when the determination result of the first determination unit is negative, allocate a globally unique identifier to the fusion key attribute information of the fusion key information;

[0211] The second determination unit is configured to determine whether the globally unique identifier is recorded in the key attribute fusion mapping table of the target database. Specifically, it may be to determine whether the globally unique identifier of the fusion key attribute information in the fusion key information matches the globally unique identifier of the key attribute information in the key attribute fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between key attribute identification information and the globally unique identifier corresponding to the key attribute identification information.

[0212] Further, it may further include: the second allocation subunit, configured to allocate a globally unique identifier to the key attribute information of the key information in the target database;

[0213] The determination unit 502 may specifically be configured to determine whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information.

[0214] The allocation unit 503 may specifically be configured to allocate a new key attribute identification information to the fusion key attribute identification information.

[0215] The first recording unit 504 may specifically be configured to record the target key information obtained by replacing the fusion key identification information in the fusion key information with the new key attribute identification information into the target database. Specifically, it may be recorded into the key repository of the target database, for example: the key attribute table.

[0216] The second recording unit 505 may specifically be configured to record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information into the target database. Specifically, it may be recorded into the key attribute fusion mapping table of the target database.

[0217] Second Embodiment:

[0218] It may further include: a first determination unit, a first allocation unit, a second allocation unit, and a second determination unit.

[0219] The first determination unit is configured to determine whether the database to be fused and the target database are homologous databases of the same user;

[0220] The first allocation unit is configured to, when the determination result of the first determination unit is yes, allocate a first globally unique identifier to the fusion key attribute information of the fusion key information;

[0221] The second allocation unit is configured to allocate a second globally unique identifier to the fusion data key information of the fusion key information;

[0222] The second determination unit is configured to determine whether the first globally unique identifier is recorded in the key attribute fusion mapping table of the target database, and whether the second globally unique identifier is recorded in the data key fusion mapping table of the target database. Specifically, it may be used to determine whether the globally unique identifier of the fusion key attribute information matches the globally unique identifier of the key attribute information in the key attribute fusion mapping table of the target database; and, determine whether the globally unique identifier of the fusion data key information matches the globally unique identifier of the data key information in the data key fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between the fusion key attribute identification information and the key attribute identification information and the globally unique identifier corresponding to the key attribute identification information; the data key fusion mapping table is used to record the mapping relationship between the fusion data key identification information and the data key identification information, and the globally unique identifier corresponding to the data key identification information. If not, then perform the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database.

[0223] Of course, it may further include: the third allocation unit and the fourth allocation unit. The third allocation unit may be used to allocate a globally unique identifier to the key attribute information of the key information in the target database; the fourth allocation unit may be used to allocate a globally unique identifier to the data key information of the key information.

[0224] The determining unit 502 may specifically be configured to determine whether the fusion key attribute identification information matches the key attribute identification information in the key attribute fusion mapping table of the target database; and determine whether the fusion data key identification information matches the data key identification information in the data key fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between the fusion key attribute identification information and the key attribute identification information, as well as the first globally unique identifier; and the data key fusion mapping table is used to record the mapping relationship between the fusion data key identification information and the data key identification information, as well as the second globally unique identifier.

[0225] The allocating unit 503 may specifically include: an allocating subunit and an encrypting subunit.

[0226] The allocating subunit is configured to allocate new key attribute identification information for the fusion key attribute identification information, and allocate new data key identification information for the fusion data key identification information;

[0227] The encrypting subunit is configured to re-encrypt the new data key identification information and the fusion data key information corresponding to the new data key identification information.

[0228] The first recording unit 504 may specifically be configured to replace the fusion key identification information in the fusion key information with the target key attribute information of the new key attribute identification information, record it in the target database, and replace the fusion data key identification information with the new data key identification information, and the master key identification information corresponding to the fusion data key identification information as the target data key information, record it in the target database; wherein, the master key identification information is the identification information of the master key information for encrypting the fusion data key identification information.

[0229] The second recording unit 505 may specifically be configured to record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the target database, and record the mapping relationship between the new data key identification information and the fusion data key identification information in the target database. Specifically, it may be configured to record the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the key attribute fusion mapping table of the target database; and record the mapping relationship between the new data key identification information and the fusion data key identification information in the data key fusion mapping table of the target database.

[0230] Regardless of the first embodiment or the second embodiment, it may further include:

[0231] The ciphertext data determination unit is configured to determine whether the ciphertext data to be fused corresponding to the fusion key information in the database to be fused is empty;

[0232] The target data determination unit is configured to, when the determination result of the ciphertext data determination unit is negative, determine the ciphertext data to be fused that is fused into the target database as the target ciphertext data;

[0233] The information acquisition unit is configured to acquire the fusion key identification information in the target ciphertext data;

[0234] The relationship determination unit is configured to determine the new key identification information having the mapping relationship with the acquired fusion key identification information;

[0235] The update unit is configured to update the fusion key identification information in the target ciphertext data to the new key identification information.

[0236] The above is a description of a data fusion device provided by the present application. The specific content of the device can be referred to the description of the above data fusion method, and the corresponding content will not be repeated here.

[0237] Based on the above, the present application provides a computer storage medium for storing data generated by a network platform and a program for processing the data generated by the network platform;

[0238] When the program is read and executed by a processor, it executes the steps in the above data fusion method.

[0239] Based on the above, the present application further provides an electronic device, as Figure 6 shown, Figure 6 is a schematic structural diagram of an embodiment of an electronic device provided by the present application. The embodiment of the electronic device may include:

[0240] A processor 601;

[0241] A memory 602 for storing a program for processing data generated by a network platform. When the program is read and executed by the processor, it executes the steps in the above data fusion method.

[0242] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0243] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0244] 1. A computer-readable medium includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory media such as modulated data signals and carrier waves.

[0245] 2. Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0246] Although the present application is disclosed above in preferred embodiments, it is not intended to limit the present application. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application should be determined by the scope defined by the claims of the present application.

Claims

1. A data fusion method, comprising: obtaining the fusion key information to be fused in the database to be fused; determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database; the database to be fused and the target database are not homologous databases of the same user; if so, assigning new key identification information to the fusion key identification information; replacing the fusion key identification information in the fusion key information with the target key information of the new key identification information, and recording it in the target database; recording the mapping relationship between the fusion key identification information and the new key identification information in the target database.

2. The data fusion method according to claim 1, further comprising: determining whether the database to be fused and the target database are homologous databases of the same user; if so, assigning a globally unique identifier to the fusion key attribute information of the fusion key information; determining whether the globally unique identifier is recorded in the key attribute fusion mapping table of the target database; if not, performing the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database.

3. The data fusion method according to claim 2, wherein determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database, comprising: determining whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information; if so, the new key identification information assigned to the fusion key identification information includes: if so, assigning new key attribute identification information to the fusion key attribute identification information; the step of replacing the fusion key identification information in the fusion key information with the target key information of the new key identification information and recording it in the target database includes: replacing the fusion key identification information in the fusion key information with the target key information of the new key attribute identification information and recording it in the target database; the step of recording the mapping relationship between the fusion key identification information and the new key identification information in the target database includes: recording the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the target database.

4. The data fusion method according to claim 3, wherein recording the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the target database, comprising: recording the mapping relationship between the new key attribute identification information and the fusion key attribute identification information in the key attribute fusion mapping table of the target database.

5. The data fusion method according to claim 3, wherein determining whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information, comprising: Determine whether the fusion key attribute identification information matches the key attribute identification information in the key attribute fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between key attribute identification information and the globally unique identifier.

6. The data fusion method according to claim 1, further comprises: Determine whether the database to be fused and the target database are homologous databases of the same user; If so, assign a first globally unique identifier to the fusion key attribute information of the fusion key information; Assign a second globally unique identifier to the fusion data key information of the fusion key information; Determine whether the first globally unique identifier is recorded in the key attribute fusion mapping table of the target database, and whether the second globally unique identifier is recorded in the data key fusion mapping table of the target database; If not, perform the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database.

7. The data fusion method according to claim 6, the step of determining whether the fusion key identification information in the fusion key information matches the key identification information of the key information in the target database, comprises: Determine whether the fusion key attribute identification information corresponding to the fusion key attribute information matches the key attribute identification information corresponding to the key attribute information, and determine whether the fusion data key identification information corresponding to the fusion data key information matches the data key identification information corresponding to the data key information; If so, the new key identification information assigned to the fusion key identification information includes: Assign a new key attribute identification information to the fusion key attribute identification information, and assign a new data key identification information to the fusion data key identification information; Re-encrypt the new data key identification information and the fusion data key information corresponding to the new data key identification information; The step of recording the target key information obtained by replacing the fusion key identification information in the fusion key information with the new key identification information into the target database includes: Record the target key attribute information obtained by replacing the fusion key identification information in the fusion key information with the new key attribute identification information into the target database, and record the fusion data key identification information replaced with the new data key identification information and the master key identification information corresponding to the fusion data key identification information as the target data key information into the target database; wherein, the master key identification information is the identification information of the master key information for encrypting the fusion data key identification information; The step of recording the mapping relationship between the fusion key identification information and the new key identification information into the target database includes: Record the mapping relationship between the new key attribute identification information and the fused key attribute identification information into the target database, and record the mapping relationship between the new data key identification information and the fused data key identification information into the target database.

8. The data fusion method according to claim 7, determining whether the fused key attribute identification information corresponding to the fused key attribute information matches the key attribute identification information corresponding to the key attribute information, and determining whether the fused data key identification information corresponding to the fused data key information matches the data key identification information corresponding to the data key information, comprises: determining whether the fused key attribute identification information matches the key attribute identification information in the key attribute fusion mapping table of the target database; and determining whether the fused data key identification information matches the data key identification information in the data key fusion mapping table of the target database; wherein, the key attribute fusion mapping table is used to record the mapping relationship between the fused key attribute identification information and the key attribute identification information, and the first globally unique identifier; the data key fusion mapping table is used to record the mapping relationship between the fused data key identification information and the data key identification information, and the second globally unique identifier.

9. The data fusion method according to claim 7, recording the mapping relationship between the new key attribute identification information and the fused key attribute identification information into the target database, comprises: recording the mapping relationship between the new key attribute identification information and the fused key attribute identification information into the key attribute fusion mapping table of the target database; The recording the mapping relationship between the new data key identification information and the fused data key identification information into the target database comprises: recording the mapping relationship between the new data key identification information and the fused data key identification information into the data key fusion mapping table of the target database.

10. The data fusion method according to claim 1, further comprises: determining whether the encrypted data to be fused corresponding to the fused key information in the database to be fused is empty; if not, determining the encrypted data to be fused fused into the target database as the target encrypted data; obtaining the fused key identification information in the target encrypted data; determining the new key identification information having the mapping relationship with the obtained fused key identification information; updating the fused key identification information in the target encrypted data to the new key identification information.

11. A data fusion device, comprises: an obtaining unit, configured to obtain the fused key attribute information to be fused in the database to be fused; a determining unit, configured to determine whether the fused key identification information in the fused key information matches the key identification information of the key information in the target database; the database to be fused and the target database are not homologous databases of the same user. An allocation unit, configured to allocate new key identification information to the fusion key identification information when the determination result of the determination unit is yes; A first recording unit, configured to record, into the target database, the target key information obtained by replacing the fusion key identification information in the fusion key information with the new key identification information; A second recording unit, configured to record, into the target database, the mapping relationship between the fusion key identification information and the new key identification information.

12. A computer storage medium, configured to store data generated by a network platform and a program for processing the data generated by the network platform; When the program is read and executed by a processor, it executes the data fusion method according to any one of claims 1-10 above.

13. An electronic device, comprising: a processor; a memory, configured to store a program for processing data generated by a network platform, and when the program is read and executed by the processor, it executes the data fusion method according to any one of claims 1-10 above.

Citation Information

Patent Citations

  • Key management method and apparatus, computer device and storage medium

    CN108123800A

  • Quantum key management method, device and system

    CN114760047A