A Method for Managing Transparent Encryption Data Access Permissions in MySQL Database

By introducing hardware password machine file management function in MySQL database, parsing SQL statements to obtain user and operation information, and matching with domestic password machine permission information, the problem of lack of permission management of transparent data encryption function in MySQL database is solved, and permission control and unified management of encrypted data is realized.

CN115587113BActive Publication Date: 2025-07-18BEIJING JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211332363.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2025-07-18
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

The transparent data encryption function of MySQL database cannot distinguish user access rights, resulting in unauthorized users being able to access encrypted data, and lacking a unified permission management mechanism.

Method used

Add the hardware password machine file management function to the MySQL database, obtain user information and database operation information by parsing SQL statements, and match it with the permission information stored in the domestic password machine to realize permission management.

Benefits of technology

It realizes permission management for transparent encrypted data of MySQL database, prevents unauthorized users from accessing, and manages the access permissions of encrypted data, maintains the transparency and performance of the database.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115587113B_ABST
    Figure CN115587113B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for managing the access rights of transparently encrypted data in a MySQL database. This method realizes the unified rights management of users accessing transparently encrypted data for multiple MySQL databases that provide the function of transparent data encryption, based on database IP, database service port, database name, user name, and user IP information; the user access right information is stored in a domestic encryption machine. While ensuring the secure storage of MySQL database data on physical disks, this method differentiates the access rights of users to transparently encrypted data, solving the security problem that unauthorized users can access transparently encrypted data in the MySQL 5.7.33 version. This method does not affect the original normal functions of the MySQL database, is transparent to the upper-layer business software of the MySQL database, and has little impact on the database performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cyberspace security and relates to a method for managing access rights to transparently encrypted data in a MySQL database. Background Art

[0002] Relational databases can effectively manage data and are widely used in various fields, such as the open-source database MySQL. However, the MySQL database faces various security problems. For example, data is stored in plain text on the hardware disk. If the hardware disk storing the database is stolen, data leakage will occur. The MySQL database currently adopts the transparent data encryption method to ensure the secure storage of data on physical devices. Transparent data encryption encrypts the information stored in plain text in the database and then stores the generated ciphertext on the physical disk to ensure that data is not leaked through physical theft; at the same time, the key used for encryption will be managed. The entire transparent data encryption process is transparent to users, that is, users only need to select whether to use the transparent data encryption function without caring about the encryption process.

[0003] There are security problems with the transparent data encryption method of MySQL. For example: If there are both transparently encrypted tables and non-encrypted tables in the database, some legitimate database users need to access the database to complete their specific tasks, but the data in the encrypted tables should not be exposed to this user. That is, if some users only have the right to access non-encrypted tables and do not have the right to access encrypted tables, the transparent data encryption function of the database cannot well complete this task. Transparent data encryption only ensures that data is encrypted and stored on the physical disk. When any user wants to access this data, the database will decrypt the data and provide it for the user to access without distinguishing whether the user has the right to access the encrypted data. Therefore, in this case, only using a single transparent data encryption function of the database will bring some limitations to its application, resulting in poor application in some application scenarios.

[0004] In view of the problem that the transparent data encryption function used in the above-mentioned database lacks the user permission control function, this patent proposes a method for managing access rights to transparently encrypted data in a MySQL database.

[0005] The system framework of the method is as Figure 1 shown. The method for managing access rights to transparently encrypted data in MySQL is an improvement based on the existing MySQL database. This method implements a permission management method during the execution of MySQL SQL statements, and its operation process is as Figure 2 shown. This method solves the problem that the transparent data encryption function of MySQL lacks permission management on the premise of not conflicting with the original permission control function of MySQL. Summary of the Invention

[0006] The object of the present invention is to provide a method for managing the access rights of transparent data encryption in MySQL databases, which addresses the data security issues caused by the lack of discrimination of user access rights to encrypted data and the inability to uniformly manage the access rights to encrypted data in the current transparent data encryption function of MySQL databases. It realizes the access right management function that the current transparent data encryption function of MySQL databases does not have, and at the same time realizes the instant deployment for the business. The technical solution of the present invention is as follows:

[0007] A method for managing the access rights of transparently encrypted data in a MySQL database, characterized in that: according to the characteristics of the hardware cryptographic machine interface function, statements and functions for managing the hardware cryptographic machine file are added to the database, and statements and functions related to parsing database user information and access control are added to the function of parsing SQL statements in the original MySQL 5.7.33 database, so that the access rights of database users to transparently encrypted data are uniformly managed through the parsed access information and the permission information stored in the domestic cryptographic machine. The specific steps are as follows:

[0008] Step 1, according to the characteristics of the hardware cryptographic machine interface function, add statements and functions for accessing the permission information stored in the hardware encryption machine and processing related information;

[0009] Step 2, add relevant statements and functions for obtaining the operation information of the current database and the information of the operating user;

[0010] Step 3, according to the permission configuration information and the current user and database operation information, add relevant functions for identifying and managing the operation permissions;

[0011] Step 4, configure the relevant files and parameters required by this method, including calling header files, configuration files, and dynamic link libraries;

[0012] Step 5, modify the CMakeLists file of MySQL.

[0013] Adding statements and functions for accessing the permission information stored in the hardware encryption machine and processing related information according to the characteristics of the hardware cryptographic machine interface function includes:

[0014] First, read the local configuration file to obtain the specific path of the permission configuration information file stored in the encryption machine;

[0015] Based on the file management module in the domestic encryption machine, call the encryption machine API and pass in relevant parameters including the encryption machine handle, the path of the file to be read, the file name of the file to be read, the read start bit pointer, the read length, and the read buffer;

[0016] Turn off the encryption machine, convert the content in the read buffer into a string and return it;

[0017] Add the above method to the source file my_aes_openssl.cc that contains the implementation of MySQL's own encryption algorithm;

[0018] Implement a method to read the content of the file related to MySQL transparent encryption data access permission information stored in the encryption machine, and complete the implementation of calling the hardware cryptographic machine to read the permission management information.

[0019] The methods to implement parsing and processing the permission control information obtained and returned by calling the encryption machine include:

[0020] First, read the permission management information string obtained from the encryption machine and save it to the buffer. The obtained and returned access permission information is a string, and each permission control information is separated by the line break character "\n". Split each piece of permission management information according to the line break character "\n" and store it;

[0021] For each piece of permission management information obtained, use regular matching to store the current accessed database IP, database listening port, database name, and the user name and user IP information of the currently accessed database into corresponding variables respectively, and integrate this information into a permission information structure for subsequent permission control; each piece of permission control information consists of the current accessed database IP, database listening port, database name, and the user name and user IP information of the currently accessed database, and each information is separated by "-";

[0022] Return the information in the parsed permission management information structure for the user's subsequent permission control;

[0023] Implement the above method in a newly created source file get_table.cc, thus completing the implementation of parsing the permission control information.

[0024] Add relevant statements and functions for obtaining the operation information of the current database and the information of the operating user, including:

[0025] First, obtain the database information in this operation and store the database name;

[0026] Parse out the table name involved in the current operation and store it in the table name variable;

[0027] According to the obtained data table name, use operations such as alloc_table_share() and open_table_def() to obtain table information from the table structure cache, including table encryption information, etc., and store it in the table information variable

[0028] Use the original SQL parser of MySQL 5.7.33 to obtain the operation type of the current operation, such as operations like SQLCOM_SELECT, SQLCOM_ALTER_TABLE, SQLCOM_INSERT, SQLCOM_DELETE, etc., and store them in the operation type variable;

[0029] Implement the above method in the mysql_execute_command() function in the sql_parse.cc file, and add database operation information parsing code to parse information such as the operation type of the current operation, the target database name, the target table name, and the table structure of the table, so as to identify and judge the user access permissions later.

[0030] The methods for adding to obtain the user information of the current operation include:

[0031] First, obtain the original thread-safe context information security_context of MySQL 5.7.33;

[0032] Process the obtained security context information, and obtain the user name from it through the user() method and parse it into a string;

[0033] Process the obtained security context information, and obtain the IP information of the current user from it through the host_or_ip() method and parse it into a string;

[0034] Save the obtained and parsed user name and user IP information for subsequent permission management;

[0035] By adding relevant content parsing code in the mysql_execute_command() function in the sql_parse.cc file, parse the user name and user IP information of the user operating the current database, so as to identify and judge the user access permissions later.

[0036] According to the permission configuration information and the current user and database operation information, the related functions for identifying and managing the operation permissions include:

[0037] Add a method for controlling the start and stop of the permission management function. Control whether the current permission management function is enabled by setting parameters in the configuration file. Set whether the current database transparent data encryption permission management function is enabled by reading the permission control function enable flag in the configuration file. Implement this function by creating the check_priv_open() function and add it to the source file get_table.cc, thereby completing the implementation of the start and stop control of the permission management function.

[0038] The methods for adding access control permission checks include:

[0039] First, obtain the current database IP and listening port information from the configuration file;

[0040] Parse the information in the permission control information structure obtained from the hardware encryption machine one by one;

[0041] Parse the obtained database IP, database listening port Port, database name db, and the user name and user IP information of the currently accessing database;

[0042] Based on the string matching method, perform string matching on the parsed user database operation information, user information, and permission management information to check whether the operations of the current database user meet their permission requirements, and implement the operation of checking the permissions of the current database user. When the current operation information matches a certain permission control information with the user information, it proves that the operation of the current database user meets the access permissions for the transparently encrypted data that it possesses; if not, the user has no right to perform the operation, judge the operation permission and record it;

[0043] Return the result obtained in the permission matching process for the control module to use;

[0044] Add the above method to the source file get_table.cc, thereby implementing the implementation of the access control permission check method.

[0045] The method for adding access control to transparently encrypted data in the MySQL database includes:

[0046] First, determine whether to perform permission checks by judging whether the permission management module is started;

[0047] Judge whether permission checks are required based on the obtained user operation information, database information, and data table information. If permission checks are required, load the obtained permission management information into the current module, otherwise continue with the database operation;

[0048] Based on the original SQL statement parsing method of MySQL 5.7.33, add access permission control statements to its parsing process, and pass the parsed information into the permission check method implemented by the permission check module to perform permission checks, and decide whether to allow or block this operation based on the check results;

[0049] Add the above method to the mysql_execute_command() function in the sql_parse.cc file to implement that when this function is turned on, all MySQL database operations will check their permissions through this method to ensure that unauthorized users cannot access the transparently encrypted data, thereby implementing the implementation of the access control method.

[0050] Configure the relevant files and parameters required for this method, including calling header files, configuration files, and dynamic link libraries, including:

[0051] In the header file my_aes.h that declares the password algorithm, add the function names of the APIs that implement the reading permission management information by calling the hardware password machine in this method;

[0052] In the newly created header file get_table.h, add the function names of get_user() and split_user() that implement the parsing of permission management information in the permission management and control method implemented in this method;

[0053] In the header file get_table.h, add the structure name PRIV_USER() that stores the permission control information in the permission management and control method implemented in this method;

[0054] In the get+table.h header file, add the function name check_priv_open() that implements the start and stop control of the permission management module in the permission management and control method implemented in this method;

[0055] In the header file get_table.h, add the function name check_user() that implements the access control permission check in the permission management and control method implemented in this method;

[0056] Add the password machine header files fm_cpc_pub.h and fm_def.h to the mysql-5.7.33 / include directory;

[0057] Add the configuration file FMDevice.conf of the password machine to the / etc directory, correctly configure the IP, the number of configured links, and the log storage path, and add the dynamic library file libfmapiv100.so to the / usr / lib directory;

[0058] Add the configuration file priv.conf of the permission management module to the / etc directory and correctly configure information such as the path of the permission information file in the hardware encryption machine and the enable flag of the permission management module.

[0059] Modify the CMakeLists file of MySQL based on the MySQL database, including:

[0060] Modify the CMakeLists file in the / mysql-5.7.33 / mysys_ssl directory and add the instruction "target_link_libraries(mysys_ssl / usr / lib / libfmapiv100.so)";

[0061] Modify the CMakeLists file in the / mysql-5.7.33 / mysys_ssl directory, add the file name "get_table.cc", so that the get_table.cc file is compiled into the program when MySQL is compiled.

[0062] The advantages of the present invention are as follows: (1) This method solves the problem that the transparent encryption function of the MySQL 5.7.33 database does not distinguish user permissions, resulting in unauthorized database users accessing encrypted data; (2) Through information such as database IP, port, and database name, unified permission management can be realized for the transparent data encryption functions of multiple MySQL databases; (3) The modified MySQL database adds code for the transparent data encryption permission management function, which completely retains all the functions of the original transparent data encryption, and at the same time adds a permission control function, enabling immediate deployment for the business; (4) The present invention has few modifications to the original MySQL database and has good forward compatibility. Brief Description of the Drawings

[0063] Figure 1 It is a functional schematic diagram of the method for managing the access permission of transparent encrypted data in the MySQL database;

[0064] Figure 2 It is a flow schematic diagram of the method for managing the access permission of transparent encrypted data in the MySQL database; Detailed Embodiment

[0065] To achieve the invention purpose, the present invention adopts the following technical means:

[0066] Step 1, according to the characteristics of the hardware cryptographic machine interface function, add statements and functions for accessing the permission information stored in the hardware encryption machine and processing relevant information;

[0067] Step 2, add relevant statements and functions for obtaining the operation information of the current database and the information of the operating user;

[0068] Step 3, according to the permission configuration information and the current user and database operation information, add relevant functions for identifying and managing operation permissions;

[0069] Step 4, configure the relevant files and parameters required by this method, including calling header files, configuration files, and dynamic link libraries;

[0070] Step 5, modify the CMakeLists file of MySQL.

[0071] The specific process of the said Step 1 is as follows:

[0072] Step 11, method for adding and reading the content of the permission configuration information file in the domestic encryption machine: Based on the file management module in the domestic encryption machine, by calling the encryption machine API, a method for reading the content of the file related to the MySQL transparent encryption data access permission stored in the encryption machine is implemented, and it is added to the source file my_aes_openssl.cc that contains the implementation of the MySQL own encryption algorithm, thus completing the implementation of calling the hardware cryptographic machine to read the permission management information;

[0073] The specific implementation method of calling the hardware cryptographic machine to read the permission management information is as follows:

[0074] 11.1) First, read the local configuration file to obtain the specific path of the permission configuration information file stored in the encryption machine;

[0075] 11.2) Open the domestic cryptographic machine to obtain the handle of the domestic cryptographic machine;

[0076] 11.3) Call the API for reading files in the encryption machine, and pass in relevant parameters including the encryption machine handle, the path of the file to be read, the file name of the file to be read, the read start position pointer, the read length, and the read buffer;

[0077] 11.4) Close the hardware cryptographic machine;

[0078] 11.5) Convert the content in the read buffer into a string and return it.

[0079] Step 12, method for implementing the parsing and processing of the permission control information obtained and returned in Step 11: The access permission information obtained and returned in Step 11 is a string, where each permission control information is separated by the newline character "\n", and each permission control information consists of the current accessed database IP, database listening port, database name, and the user name and user IP information of the currently accessed database. Each information is separated by "-". By implementing a permission control information parsing method, each permission control information is parsed into a specific structure and stored for subsequent permission control; this method is implemented in a newly created source file get_table.cc, thus completing the implementation of the permission control information parsing;

[0080] The specific implementation method of the permission control information parsing is as follows:

[0081] 12.1) First, receive the permission management information string read in Step 11 and save it to the buffer;

[0082] 12.2) Split each permission management information according to the newline character "\n" and store it;

[0083] 12.3) Apply each piece of permission management information obtained in 12.2) in the way of regular matching, and store the currently accessed database IP, database listening port, database name, as well as the user name and user IP information of the currently accessed database into corresponding variables respectively, and integrate this information into a permission information structure;

[0084] 12.4) Return the information parsed in 12.3).

[0085] The specific process of step 2 is as follows:

[0086] Step 21, add a method to obtain the current database operation information: Add database operation information parsing code to the mysql_execute_command() function in the sql_parse.cc file to parse information such as the operation type, target database name, target table name, and table structure of the current operation, so as to identify and judge the permissions of user access later;

[0087] The specific implementation method for parsing the current database operation information is as follows:

[0088] 21.1) First, obtain the database information in this operation and store the database name;

[0089] 21.2) Parse out the table name involved in the current operation from the database information obtained in 21.1) and store it in the table name variable;

[0090] 21.3) According to the data table name obtained in 21.2), use operations such as alloc_table_share() and open_table_def() to obtain table information from the table structure cache; including table encryption information, etc., and store it in the table information variable;

[0091] 21.4) Use the original SQL parser of MySQL 5.7.33 to obtain the operation type of the current operation, such as operations like SQLCOM_SELECT, SQLCOM_ALTER_TABLE, SQLCOM_INSERT, SQLCOM_DELETE, etc., and store it in the operation type variable;

[0092] Step 22, add a method to obtain the user information of the current operation: Add relevant content parsing code to the mysql_execute_command() function in the sql_parse.cc file to parse the user name and user IP information of the user operating the current database, so as to identify and judge the permissions of user access later;

[0093] The specific implementation method for parsing the database user information of the current operation is as follows:

[0094] 22.1) First, obtain the original thread - safe context information security_context of MySQL 5.7.33;

[0095] 22.2) Obtain the user name from the security context information obtained in 22.1) through the user() method and parse it into a string;

[0096] 22.3) Obtain the IP information of the current user from the security context information obtained in 22.1) through the host_or_ip() method and parse it into a string;

[0097] 22.4) Save the information parsed in 22.2) and 22.3) for subsequent permission management.

[0098] The specific process of step 3 is as follows:

[0099] Step 31, add a method for starting and stopping the permission management function: This method can control whether the current permission management function is enabled by setting parameters in the configuration file, set whether the current database transparent data encryption permission management function is enabled by reading the permission control function enable flag in the configuration file, and implement this function by creating

[0100] the check_priv_open() function and add it to the source file get_table.cc, thus completing the implementation of starting and stopping the permission management function.

[0101] Step 32, add a method for checking access control permissions: Based on string matching, match the permission control information obtained through step 12 with the operation information and user information obtained through steps 21 and 22 to check whether the operations of the current database user meet their permission requirements, implement the operation of checking the permissions of the operations of the current database user, and add it to the source file get_table.cc, thus implementing the method of checking access control permissions;

[0102] The specific implementation method of checking access control permissions is as follows:

[0103] 32.1) First, obtain the current database IP and listening port information from the configuration file;

[0104] 32.2) Parse the information in the permission control information structure obtained through step 12 one by one;

[0105] 32.3) Parse the database IP, database listening port, database name, and the user name and user IP information of the current database access obtained through steps 21, 22, and 32.1);

[0106] 32.4) Perform string matching on the information parsed in 32.2) and 32.3), judge the operation permission and record it;

[0107] 32.5) Return the result obtained in 32.4) for the control module to use.

[0108] Step 33, method for adding access control for transparently encrypted data in the MySQL database: Based on the original SQL statement parsing method of MySQL 5.7.33, add access control statements in its parsing process, that is, add code in the mysql_execute_command() function in the sql_parse.cc file to implement the core operations of the permission management function, so that when this function is turned on, all MySQL database operations will be checked for their permissions through this method to ensure that unauthorized users cannot access the transparently encrypted data, thus realizing the implementation of the access control method;

[0109] The specific implementation method of the access control function is as follows:

[0110] 33.1) First, judge whether the permission management module is started according to the result returned in step 31 to decide whether to perform permission checking;

[0111] 33.2) Judge whether permission checking is required according to the operation information, database information and data table information obtained in steps 21 and 22;

[0112] 33.3) If permission checking is required, load the permission management information obtained by the method in step 12 into the current module;

[0113] 33.4) Pass the information parsed in 33.2) and 33.3) into the permission checking method implemented in step 32 for permission checking;

[0114] 33.5) Decide whether to allow or block this operation according to the result obtained in 33.4).

[0115] The specific process of step 4 is as follows:

[0116] Step 41, declare the operation method of the implemented hardware encryption machine: Add the function name of the API that calls the hardware cipher machine to implement reading the permission management information implemented in step 11 in the header file my_aes.h that declares the cryptographic algorithm.

[0117] Step 42, declare the implemented permission management and control method: Add the function names of get_user() and split_user() that parse permission management information implemented in Step 12 to the newly created get_table.h header file; add the structure name of PRIV_USER() that stores permission control information in the get_table.h header file; add the function name of check_priv_open() that implements the start and stop control of the permission management module in Step 31 to the get_table.h header file; add the function name of check_user() that implements access control permission check in Step 32 to the get_table.h header file.

[0118] Step 43, add the password machine header files fm_cpc_pub.h and fm_def.h to the mysql-5.7.33 / include directory.

[0119] Step 44, add the password machine configuration file FMDevice.conf to the / etc directory, correctly configure the IP, the number of configured connections, and the log storage path, and add the dynamic library file libfmapiv100.so to the / usr / lib directory.

[0120] Step 45, add the configuration file priV.conf of the permission management module to the / etc directory and correctly configure information such as the path of the permission information file in the hardware encryption machine and the start flag of the permission management module.

[0121] The specific process of the said Step 5 is as follows:

[0122] Step 51, modify the CMakeLists file in the / mysql-5.7.33 / mysys_ssl directory and add the instruction "target_link_libraries(mysys_ssl / usr / lib / libfmapiv100.so)".

[0123] Step 52, modify the CMakeLists file in the / mysql-5.7.33 / mysys_ssl directory and add the file name "get_table.cc" to compile the get_table.cc file into the program when MySQL is compiled.

[0124] Thus, this method has completed the implementation of the MySQL database transparent encryption data access permission management method.

Claims

1. A method for managing the access rights of transparently encrypted data in a MySQL database, characterized in that: According to the characteristics of the hardware cryptographic machine interface function, add statements and functions for the hardware cryptographic machine file management function to the database, and add statements and functions related to database user information parsing and permission control to the original MySQL 5.7.33 database SQL statement parsing function, so that the permission to uniformly manage the database user access to transparently encrypted data can be realized through the parsed access information and the permission information stored in the domestic cryptographic machine. The specific steps are as follows: Step 1, according to the characteristics of the hardware cryptographic machine interface function, add statements and functions to access the permission information stored in the hardware encryption machine and process relevant information; Step 2, add relevant statements and functions for obtaining the operation information of the current database and the information of the operating user; Step 3, add relevant functions for identifying and managing operation permissions according to the permission configuration information, the current user, and the database operation information; Step 4, configure the required relevant files and parameters, including calling header files, configuration files, and dynamic link libraries; Step 5, modify the CMakeLists file of MySQL; In step 1, according to the characteristics of the hardware cryptographic machine interface function, adding statements and functions to access the permission information stored in the hardware encryption machine and process relevant information includes: Read the local configuration file to obtain the specific path of the permission configuration information file stored in the encryption machine; Based on the file management module in the domestic encryption machine, by calling the encryption machine API and passing in relevant parameters, the relevant parameters include: encryption machine handle, path of the file to be read, file name of the file to be read, read start position pointer, read length, and read buffer; Close the encryption machine and convert the content in the read buffer into a string and return it; Add the above steps to the source file my_aes_openssl.cc that contains the implementation of the MySQL's own encryption algorithm; In step 2, adding relevant statements and functions for obtaining the operation information of the current database and the information of the operating user includes: Obtain the database information in this operation and store the database name; Parse out the table name involved in the current operation and store it in the table name variable; According to the obtained data table name, use the operations of the alloc_table_share() and open_table_def() functions to obtain the table encryption information from the table structure cache and store it in the table information variable; Use the original SQL parser of MySQL 5.7.33 to obtain the operation type of the current operation, including: SQLCOM_SELECT, SQLCOM_ALTER_TABLE, SQLCOM_INSERT, SQLCOM_DELETE operations, and store it in the operation type variable; Implement the above method in the mysql_execute_command() function in the sql_parse.cc file, and add database operation information parsing code to parse the operation type, target database name, target table name, and table structure information of the current operation, so as to identify and judge the permissions of user access later; In step 3, according to the permission configuration information, the current user, and the database operation information, adding relevant functions for identifying and managing operation permissions includes: Adding a method for controlling the start and stop of the permission management function. By setting parameters in the configuration file, it controls whether the current permission management function is enabled. By reading the permission control function enable flag in the configuration file, it sets whether the current database transparent data encryption permission management function is enabled. This function is implemented by creating the check_priv_open() function and adding it to the source file get_table.cc.

2. The method for managing MySQL database transparent encrypted data access permissions according to claim 1, wherein Implementing a method for parsing and processing the call to the encryption machine to obtain and return the permission control information includes: Reading the encryption machine to obtain the permission management information string and saving it to the buffer. The obtained and returned access permission information is a string, and each permission control information is separated by the newline character "\n". Each permission management information is split according to the newline character "\n" and stored. For each obtained permission management information, using the method of regular matching, the current accessed database IP, database listening port, database name, and the username and user IP information of the current accessed database are respectively stored in corresponding variables, and these information are integrated into a permission information structure for subsequent permission control. Each permission control information consists of the current accessed database IP, database listening port, database name, and the username and user IP information of the current accessed database, and each information is separated by "-". Returning the information in the parsed permission management information structure for the user's subsequent permission control. Implementing the above method in a newly created source file get_table.cc.

3. A method for managing the access permissions of transparently encrypted data in a MySQL database according to claim 1, characterized in that: Obtaining the original thread-safe context information security_context of MySQL 5.7.33; Processing the obtained security context information, and obtaining the username from it through the user() method and parsing it into a string; Processing the obtained security context information, and obtaining the IP information of the current user from it through the host_or_ip() method and parsing it into a string; Saving the obtained and parsed username and user IP information for subsequent permission management; By adding relevant content parsing code to the mysql_execute_command() function in the sql_parse.cc file, parsing the username and user IP information of the user currently operating the database, so as to identify and judge the permissions of the user's access later.

4. A method for managing the access permissions of transparently encrypted data in a MySQL database according to claim 1, characterized in that: Obtaining the current database IP and listening port information from the configuration file; Parsing each piece of information in the permission control information structure obtained from the hardware encryption machine one by one; Parse the obtained database IP, database listening port Port, database name db, and the user name and user IP information of the currently accessed database; Based on the string matching method, perform string matching on the parsed user database operation information, user information, and permission management information to check whether the operations of the current database user meet their permission requirements, and implement the operation of checking the permissions of the current database user. When a certain permission control information is matched between the current operation information and the user information, it proves that the operation of the current database user meets the access permission for the transparently encrypted data it possesses; If there is no match, the user has no right to perform the operation, determine the operation permission and record it; Return the result obtained during the permission matching process for the control module to use; Add the above steps to the source file get_table.cc; 5. A method for managing the access permission of transparently encrypted data in a MySQL database according to claim 4, characterized in that: Decide whether to perform permission checking by judging whether the permission management module is started; Judge whether permission checking is required according to the obtained user operation information, database information, and data table information. If permission checking is required, load the obtained permission management information into the current module, otherwise continue with the database operation; Based on the original SQL statement parsing method of MySQL 5.7.33, add an access permission control statement to its parsing process, pass the parsed information into the permission checking method implemented by the permission checking module, perform permission checking, and decide whether to allow or block this operation according to the checking result; Add the above method to the mysql_execute_command() function in the sql_parse.cc file to ensure that when this function is turned on, all MySQL database operations will be checked for their permissions by this method to prevent unauthorized users from accessing the transparently encrypted data, thus realizing the implementation of the access control method; 6. A method for managing MySQL database transparent encrypted data access permissions according to claim 1, characterized in that, The step 4 includes: Add the function name of the API that reads the permission management information by calling the hardware cryptographic machine implemented by this method in the header file my_aes.h that declares the password algorithm; Add the function names of get_user() and split_user() that parse the permission management information in the permission management and control method implemented by this method in the newly created header file get_table.h; Add the structure name of PRIV_USER() that stores the permission control information in the permission management and control method implemented by this method in the get_table.h header file; Add the function name of check_priv_open() that realizes the start and stop control of the permission management module in the permission management and control method implemented by this method in the get_table.h header file; Add the function name of check_user() that realizes the access control permission check in the permission management and control method implemented by this method in the get_table.h header file; Add the password machine header files fm_cpc_pub.h and fm_def.h to the mysql-5.7.33 / include directory; Add the password machine configuration file FMDevice.conf to the / etc directory and correctly configure the IP, the number of configured connections, and the log storage path, and add the dynamic library file libfmapiv100.so to the / usr / lib directory; Add the configuration file priv.conf of the permission management module to the / etc directory and correctly configure the path of the permission information file in the hardware encryption machine and the enable flag of the permission management module.

7. A method for managing the access rights of transparently encrypted data in a MySQL database according to claim 1, characterized in that Step 5 includes: Modify the CMakeLists file in the / mysql-5.7.33 / mysys_ssl directory and add the instruction "target_link_libraries(mysys_ssl / usr / lib / libfmapiv100.so)"; Modify the CMakeLists file in the / mysql-5.7.33 / mysys_ssl directory and add the file name "get_table.cc" so that the get_table.cc file is compiled into the program when MySQL is compiled.

Citation Information

Patent Citations

  • Method for enabling transparent encryption without restarting MySQL

    CN110807199A

  • Actuarial processing method and device

    US20210287298A1