A data processing method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202310905165.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-21
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2043-07-21
AI Technical Summary
[0003]一般来说,数据库的透明数据加密功能仅支持AES(高级加密标准,AdvancedEncryption Standard)加密算法,不支持国密加密算法SM4
[0045]通过以上方案可知,本申请提供的一种数据处理方法,包括:在数据库管理系统的配置文件中设置全局参数;其中,所述全局参数用于记录使用的加密算法;当需要对目标数据进行透明加解密处理时,从所述配置文件中获取所述全局参数,并根据所述全局参数确定本次透明加解密处理使用的加密算法;若使用的加密算法为SM4加密算法,则通过所述数据库管理系统调用加密机,以在所述加密机中利用SM4加密算法对所述目标数据进行透明加解密处理。
Smart Images

Figure CN116842548B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a data processing method, apparatus, electronic device, and computer-readable storage medium. Background Technology
[0002] With the increasing use of databases, their security requires higher standards. Many products and projects need to support database encryption. Current data security requirements are quite stringent, especially in China, where many scenarios require the use of national cryptographic algorithms and prohibit software encryption; instead, certified and approved encryption machines must be used.
[0003] Generally, databases' transparent data encryption features only support the AES (Advanced Encryption Standard) encryption algorithm and not the Chinese national cryptographic algorithm SM4. Therefore, how to add support for the SM4 algorithm without affecting the database's transparent data encryption functionality is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] The purpose of this application is to provide a data processing method, apparatus, electronic device, and computer-readable storage medium that adds support for the national cryptographic encryption algorithm SM4 while ensuring that the transparent data encryption function of the database is not affected.
[0005] To achieve the above objectives, this application provides a data processing method, comprising:
[0006] Set global parameters in the database management system's configuration file; these global parameters are used to record the encryption algorithms used.
[0007] When transparent encryption and decryption of target data is required, the global parameters are obtained from the configuration file, and the encryption algorithm used for this transparent encryption and decryption process is determined based on the global parameters.
[0008] If the encryption algorithm used is SM4, then the database management system calls the encryption machine to transparently encrypt and decrypt the target data using the SM4 encryption algorithm in the encryption machine.
[0009] Before obtaining the global parameters from the configuration file, the process also includes:
[0010] Determine if this is the first time transparent encryption / decryption is being performed;
[0011] If so, the global parameters will be configured to the encryption algorithm used in this transparent encryption / decryption process;
[0012] If not, then proceed with the step of retrieving the global parameters from the configuration file.
[0013] The step of calling the encryption machine through the database management system includes:
[0014] The encryption machine can be directly accessed through the database management system.
[0015] Alternatively, the database management system may call the software library to invoke the encryption machine.
[0016] The database management system includes the MariaDB management system, and the software library includes OpenSSL.
[0017] The process of calling the encryption machine through the database management system further includes:
[0018] Obtain the key from the configuration file, and modify the key length to 128 bits to obtain the target key;
[0019] Accordingly, the transparent encryption and decryption processing of the target data using the SM4 encryption algorithm includes:
[0020] The target data is transparently encrypted and decrypted using the SM4 encryption algorithm based on the target key.
[0021] The process of transparently encrypting and decrypting the target data using the SM4 encryption algorithm in the encryption machine includes:
[0022] The target mode of the SM4 encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted and decrypted in the encryption machine using the target mode of the SM4 encryption algorithm.
[0023] The step of setting global parameters in the database management system configuration file includes:
[0024] Set global parameters in the MariaDB configuration file;
[0025] Accordingly, when transparent encryption and decryption of target data is required, the global parameters are obtained from the configuration file, and the encryption algorithm to be used is determined based on the global parameters, including:
[0026] When transparent encryption and decryption of target data is required, determine whether it is the first time transparent encryption and decryption is performed.
[0027] If so, the global parameters will be configured to the encryption algorithm used in this transparent encryption / decryption process;
[0028] If not, the global parameters are obtained from the configuration file, and the encryption algorithm used for this transparent encryption / decryption process is determined based on the global parameters.
[0029] Accordingly, if the encryption algorithm used is the SM4 encryption algorithm, then the database management system calls the encryption machine to perform transparent encryption and decryption processing on the target data using the SM4 encryption algorithm, including:
[0030] If the encryption algorithm used is SM4, then obtain the key from the configuration file and modify the key length to 128 bits to obtain the target key;
[0031] The encryption machine can be invoked directly via MariaDB, or via MariaDB and OpenSSL can be invoked via OpenSSL.
[0032] The target data is transparently encrypted and decrypted using the SM4 encryption algorithm based on the target key in the encryption machine.
[0033] Accordingly, the method further includes:
[0034] If the encryption algorithm used is AES, then the key is obtained from the configuration file, and openssl is called through MariaDB to call the encryption machine through openssl;
[0035] If the transparent encryption / decryption process is performed on the encryption plugin or storage engine, the target mode of the AES encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted / decrypted using the key based on the target mode of the AES encryption algorithm in the encryption machine.
[0036] If this transparent encryption / decryption process involves the cache copying part, then the target data is transparently encrypted / decrypted using the key in the encryption machine based on the preset mode of the AES encryption algorithm.
[0037] To achieve the above objectives, this application provides a data processing apparatus, comprising:
[0038] The configuration module is used to set global parameters in the configuration file of the database management system; wherein, the global parameters are used to record the encryption algorithm used;
[0039] The determination module is used to obtain the global parameters from the configuration file when transparent encryption and decryption processing of target data is required, and to determine the encryption algorithm to be used for this transparent encryption and decryption processing based on the global parameters.
[0040] The first processing module is used to call the encryption machine through the database management system when the encryption algorithm used is the SM4 encryption algorithm, so as to perform transparent encryption and decryption processing on the target data using the SM4 encryption algorithm in the encryption machine.
[0041] To achieve the above objectives, this application provides an electronic device, comprising:
[0042] Memory, used to store computer programs;
[0043] A processor for executing the computer program to implement the steps of the data processing method described above.
[0044] To achieve the above objectives, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the data processing method described above.
[0045] As can be seen from the above scheme, the data processing method provided in this application includes: setting global parameters in the configuration file of the database management system; wherein, the global parameters are used to record the encryption algorithm used; when transparent encryption and decryption processing of target data is required, the global parameters are obtained from the configuration file, and the encryption algorithm used for this transparent encryption and decryption processing is determined according to the global parameters; if the encryption algorithm used is the SM4 encryption algorithm, the encryption machine is called through the database management system to perform transparent encryption and decryption processing of the target data using the SM4 encryption algorithm in the encryption machine.
[0046] The data processing method provided in this application calls an encryption machine through a database management system to achieve transparent encryption and decryption of the SM4 encryption algorithm, enabling the database's transparent data encryption function to support the SM4 encryption algorithm. Simultaneously, global parameters are set in a configuration file to record the encryption algorithm used, ensuring consistency of the encryption algorithm during use without altering the original AES encryption algorithm process. This application also discloses a data processing device, an electronic device, and a computer-readable storage medium, which can achieve the same technical effects.
[0047] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit this application. Attached Figure Description
[0048] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. The drawings are used to provide a further understanding of this disclosure and constitute a part of the specification. They are used together with the following detailed description to explain this disclosure, but do not constitute a limitation of this disclosure. In the drawings:
[0049] Figure 1 This is a flowchart illustrating a data processing method according to an exemplary embodiment;
[0050] Figure 2 A diagram illustrating different modes of the AES encryption algorithm used in different parts of MariaDB;
[0051] Figure 3 This is a flowchart illustrating the execution of an encryption algorithm according to an exemplary embodiment;
[0052] Figure 4 This is a flowchart illustrating an invocation of an encryption machine according to an exemplary embodiment;
[0053] Figure 5 This is a flowchart illustrating an embodiment of obtaining a decrypted keyfile.
[0054] Figure 6 A flowchart illustrating another data processing method according to an exemplary embodiment;
[0055] Figure 7 This is a structural diagram of a data processing apparatus according to an exemplary embodiment;
[0056] Figure 8 This is a structural diagram of an electronic device according to an exemplary embodiment. Detailed Implementation
[0057] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Furthermore, in the embodiments of this application, "first," "second," etc., are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0058] This application discloses a data processing method that adds support for the national cryptographic algorithm SM4 while ensuring that the transparent data encryption function of the database is not affected.
[0059] See Figure 1 A flowchart illustrating a data processing method according to an exemplary embodiment, such as... Figure 1 As shown, it includes:
[0060] S101: Set global parameters in the configuration file of the database management system; wherein, the global parameters are used to record the encryption algorithm used;
[0061] This embodiment can be applied to MariaDB (an open-source database). The purpose of this embodiment is to enable MariaDB's Transparent Data Encryption (TDE) function to support the Chinese national cryptographic algorithm SM4. Chinese national cryptographic algorithms, also known as commercial cryptography, refer to technologies capable of performing encryption, decryption, and authentication functions using commercial cryptographic algorithms. This includes cryptographic algorithm programming techniques and the implementation techniques of cryptographic algorithm chips and encryption cards. SM4 is a symmetric encryption algorithm within the Chinese national cryptographic algorithm. The SM4 block cipher algorithm is an iterative block cipher algorithm composed of encryption / decryption algorithms and key expansion algorithms.
[0062] It is understandable that block ciphers have five modes of operation: Electronic Codebook (ECB), Cipher Block Chaining (CBC), Counter (CTR), Cipher Feedback (CFB), and Output Feedback (OFB). Both the AES and SM4 encryption algorithms have these five modes.
[0063] It's important to note that different parts of MariaDB use different encryption methods for AES encryption. MariaDB primarily uses encryption in three areas: Encryption Plugins, Storage Engine Encryption, and Replication Cache Encryption. For example... Figure 2As shown, the algorithm mode used by Encryption Plugins is configured in the "File Key Management" configuration item in the configuration file, and is therefore configurable. The algorithm mode used by the log in Replication CacheEncryption is fixed at AES_ECB. The algorithm mode used by Storage EngineEncryption is configured in the "File Key Management" configuration item in the configuration file.
[0064] Because different parts of the MariaDB process use different encryption algorithms, maintaining algorithm consistency is necessary after supporting the SM4 encryption algorithm. Therefore, this embodiment sets a global parameter in the database management system's configuration file to record the encryption algorithm used, specifically either the SM4 encryption algorithm or the AES encryption algorithm. The configuration file in MariaDB is server.cnf.
[0065] S102: When transparent encryption and decryption processing of target data is required, the global parameters are obtained from the configuration file, and the encryption algorithm used for this transparent encryption and decryption processing is determined according to the global parameters;
[0066] Since MariaDB itself does not support encryption algorithms other than AES_CBC and AES_CTR, it cannot recognize the SM4 encryption algorithm. Therefore, in this embodiment, when transparent encryption and decryption of target data is required, global parameters are obtained from the configuration file. These global parameters determine the encryption algorithm used for this encryption and decryption process, which may include the SM4 encryption algorithm and the AES encryption algorithm, thus achieving the recognition of the SM4 encryption algorithm.
[0067] Transparent encryption (TDE) means that the encryption is imperceptible to the user. When a user opens or edits a specified file, the system automatically encrypts unencrypted files and automatically decrypts encrypted files. The file is ciphertext on the hard drive and plaintext in memory. Once the user leaves the environment, the application cannot open it because it cannot receive the automatic decryption service, thus protecting the file content. TDE technology achieves this effect by being transparent to the client. After the client connects to the server, the database content seen through SQL commands is normal, not ciphertext. However, if the database file is directly copied or the database disk is removed, the file content seen will be ciphertext.
[0068] As a feasible implementation, before obtaining the global parameters from the configuration file, the method further includes: determining whether transparent encryption / decryption is being performed for the first time; if so, configuring the global parameters to the encryption algorithm used in this transparent encryption / decryption process; if not, performing the step of obtaining the global parameters from the configuration file.
[0069] In specific implementation, such as Figure 3 As shown, after the MariaDB management system starts up and needs to perform transparent encryption / decryption on target data, it determines whether this is the first time such a process is being performed. If it is, the global parameters in the configuration file are configured with the encryption algorithm to be used for this transparent encryption / decryption process, which can include SM4 or AES encryption algorithms. Then, subsequent encryption / decryption processing is executed. If this is not the first time, the global parameter configuration step is skipped to ensure that the global parameters can only be configured once, thus ensuring consistency of the encryption algorithm during use. Furthermore, if this is not the first time, the global parameters are retrieved from the configuration file, and the encryption algorithm to be used for this transparent encryption / decryption process is determined based on these global parameters.
[0070] S103: If the encryption algorithm used is the SM4 encryption algorithm, then the database management system calls the encryption machine to transparently encrypt and decrypt the target data using the SM4 encryption algorithm in the encryption machine.
[0071] In practical implementation, if the encryption algorithm used is SM4, the encryption machine is invoked through the database management system. The encryption machine is a host encryption device that has been authenticated and approved for use. The encryption machine and the host communicate using the TCP / IP protocol (Transmission Control Protocol / Internet Protocol). The encryption machine then uses the SM4 encryption algorithm to transparently encrypt and decrypt the target data.
[0072] As one possible implementation, calling the encryption machine through the database management system includes: directly calling the encryption machine through the database management system. As another possible implementation, calling the encryption machine through the database management system includes: calling a software library through the database management system to call the encryption machine through the software library.
[0073] In this embodiment, the encryption and decryption process is implemented by calling the encryption machine's interface. To increase compatibility, the encryption machine calling interface can be added to the database management system's own program, i.e., to the MariaDB program itself. Alternatively, encryption machine support can be added to a software library, which may include OpenSSL (Open Secure Sockets Layer), i.e., extending the SM4 encryption algorithm into OpenSSL. These two methods serve as different approaches to supporting the SM4 encryption algorithm and can both be configured, with different priorities and applicable scenarios. Modifying MariaDB itself to add the encryption machine calling interface is suitable for scenarios where the original OpenSSL needs to be retained, or where modifying the OpenSSL program is not allowed and modifications can only be made at the MariaDB level. Adding encryption machine calls by modifying OpenSSL is applicable when OpenSSL can be modified; by adding encryption machine calls at the OpenSSL level, even if the MariaDB code does not support this encryption machine, it can still be supported through OpenSSL modifications. Taking the SM4_EXT encryption algorithm as an example, the judgment and invocation mechanisms of the two methods are as follows: Figure 4 As shown, it first determines whether MariaDB supports this encryption algorithm. If it does, it uses the MariaDB-level call SM4_EXT_DB. If it does not, it determines whether OpenSSL supports this encryption algorithm. If it does, it uses the MariaDB-level call SM4_EXT_SSL. If it does not, it returns an error.
[0074] As a feasible implementation method, the target data is transparently encrypted and decrypted using the SM4 encryption algorithm in the encryption machine, including: determining the target mode of the SM4 encryption algorithm according to the configuration file, and transparently encrypting and decrypting the target data using the target mode of the SM4 encryption algorithm in the encryption machine.
[0075] As discussed above, the SM4 encryption algorithm has multiple modes, and the specific mode used for encryption and decryption can be configured in the configuration file. Unlike the AES encryption algorithm, for the SM4 encryption algorithm, whether in the encryption plugin, storage engine, or cache replication, the target mode is determined through the configuration file to ensure consistency of the encryption algorithm during use, while not changing the original AES encryption algorithm process.
[0076] In other words, the transparent encryption / decryption process based on the SM4 encryption algorithm provided in this embodiment is embedded within the AES encryption process, and the designed process will not affect the original functionality of MariaDB. MariaDB supports encrypting data and also supports removing data encryption, i.e., decrypting data. The specific encryption algorithm is used for encryption by configuring the encryption algorithm in `file_key_management`. If the configured encryption algorithm is AES_CBC or AES_CTR, the original code process is followed. If the configured encryption algorithm is SM4, it is used exclusively. The same cleanup effect is achieved for the SM4 encryption algorithm by cleaning up the TDE, allowing flexible switching between various encryption algorithms.
[0077] Based on this embodiment, as a preferred implementation, before calling the encryption machine through the database management system, the method further includes: obtaining a key from the configuration file and modifying the length of the key to 128 bits to obtain a target key; correspondingly, the transparent encryption and decryption processing of the target data using the SM4 encryption algorithm includes: transparently encrypting and decrypting the target data based on the target key using the SM4 encryption algorithm.
[0078] It's important to note that in MariaDB, the key length for all AES encryption algorithms is 256 bits, which is the default. The key length for SM4 is 128 bits. The process includes a check to determine if SM4 is used; if it is, the key length is 128 bits. Therefore, before using SM4 for encryption / decryption, the key length obtained from the configuration file needs to be modified.
[0079] like Figure 5 As shown, the encryption algorithm is read from the configuration file, and the length of the key parameter is obtained. The key length of the AES algorithm is 256. It is determined whether it is the SM4 encryption algorithm. If it is, the key length is modified to 128, and then the key is used to decrypt the encrypted keyfile to obtain the decrypted keyfile. If not, the key is used directly to decrypt the encrypted keyfile to obtain the decrypted keyfile.
[0080] The data processing method provided in this application embodiment calls an encryption machine through a database management system to achieve transparent encryption and decryption processing of the SM4 encryption algorithm, enabling the database's transparent data encryption function to support the SM4 encryption algorithm. Simultaneously, global parameters are set in the configuration file to record the encryption algorithm used, ensuring consistency of the encryption algorithm during use, while not altering the original AES encryption algorithm process.
[0081] This application discloses a data processing method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution. Specifically:
[0082] See Figure 6 A flowchart illustrating another data processing method according to an exemplary embodiment, such as Figure 6 As shown, it includes:
[0083] S201: Set global parameters in the MariaDB configuration file; wherein, the global parameters are used to record the encryption algorithm used;
[0084] In this embodiment, a global parameter is set in the MariaDB configuration file server.cnf to record the encryption algorithm used.
[0085] S202: When transparent encryption and decryption processing of target data is required, determine whether it is the first time transparent encryption and decryption processing is performed; if yes, configure the global parameters to the encryption algorithm used in this transparent encryption and decryption processing; if no, obtain the global parameters from the configuration file and determine the encryption algorithm used in this transparent encryption and decryption processing based on the global parameters.
[0086] In practice, when transparent encryption / decryption of target data is required, it is determined whether this is the first time such processing is being performed. If it is, the global parameters in the configuration file are configured with the encryption algorithm to be used for this transparent encryption / decryption process, which can include SM4 or AES encryption algorithms. Then, subsequent encryption / decryption processing is executed. If this is not the first time transparent encryption / decryption is being performed, the global parameter configuration step is skipped to ensure that the global parameters can only be configured once, thus ensuring consistency of the encryption algorithm during use. Furthermore, if this is not the first time transparent encryption / decryption is being performed, the global parameters are retrieved from the configuration file, and the encryption algorithm to be used for this transparent encryption / decryption process is determined based on the global parameters.
[0087] S203: If the encryption algorithm used is SM4 encryption algorithm, then obtain the key from the configuration file, modify the length of the key to 128 bits to obtain the target key;
[0088] In practice, if the encryption algorithm used is SM4, the key is obtained from the configuration file, and the key length is modified to 128 bits to obtain the target key.
[0089] S204: Directly call the encryption machine via MariaDB, or call OpenSSL via MariaDB to call the encryption machine via OpenSSL;
[0090] In practice, if the encryption algorithm used is SM4, the encryption machine can be called directly through MariaDB, or OpenSSL can be called through MariaDB to call the encryption machine through OpenSSL.
[0091] S205: In the encryption machine, the target data is transparently encrypted and decrypted based on the target key using the SM4 encryption algorithm;
[0092] In practice, the target mode of the SM4 encryption algorithm is determined from the configuration file. The encryption machine then uses this target mode and the target key to transparently encrypt and decrypt the target data. Whether it's the encryption plugin, the storage engine, or the cache replication, the encryption and decryption processes all use the target mode determined by the configuration file, ensuring the consistency of the encryption algorithm during use.
[0093] S206: If the encryption algorithm used is AES, then the key is obtained from the configuration file, and openssl is called via MariaDB to call the encryption machine via openssl; if this transparent encryption / decryption process is part of the encryption plugin or storage engine, then the target mode of the AES encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted / decrypted in the encryption machine using the target mode of the AES encryption algorithm based on the key; if this transparent encryption / decryption process is part of the cache copying process, then the target data is transparently encrypted / decrypted in the encryption machine using the preset mode of the AES encryption algorithm based on the key.
[0094] In practical implementation, if the encryption algorithm used is AES, the key is obtained from the configuration file, and openssl is invoked via MariaDB to call the encryption machine. If this transparent encryption / decryption process involves the encryption plugin or storage engine, the target mode of the AES encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted / decrypted in the encryption machine using the target mode of the AES encryption algorithm and the key. If this transparent encryption / decryption process involves the cache copying part, the target data is transparently encrypted / decrypted in the encryption machine using the preset mode of the AES encryption algorithm and the key.
[0095] Therefore, this embodiment, while ensuring that the original MariaDB workflow remains unaffected, supports the invocation of the encryption machine within MariaDB's TDE function and embeds support for the SM4 national cryptographic algorithm within the AES encryption algorithm. For the SM4 encryption algorithm, multiple methods are used to connect to the encryption machine, allowing for future integration with various different encryption machines. Only the encryption machine invocation process needs to be standardized and have a unified interface. There is no need to develop multiple clients for data encryption and decryption; the encryption is seamless for the clients. Only MariaDB programs (including clients remotely connected to the database) experience transparent data encryption; other tools or programs see the database file as encrypted. Furthermore, it allows for easy rollback and switching between unencrypted and various encryption algorithms.
[0096] The following describes a data processing apparatus provided in an embodiment of this application. The data processing apparatus described below and the data processing method described above can be referred to each other.
[0097] See Figure 7 A structural diagram of a data processing apparatus according to an exemplary embodiment is shown, such as... Figure 7 As shown, it includes:
[0098] The configuration module 701 is used to set global parameters in the configuration file of the database management system; wherein, the global parameters are used to record the encryption algorithm used;
[0099] The determination module 702 is used to obtain the global parameters from the configuration file when transparent encryption and decryption processing of target data is required, and to determine the encryption algorithm used for this transparent encryption and decryption processing based on the global parameters.
[0100] The first processing module 703 is used to call the encryption machine through the database management system when the encryption algorithm used is the SM4 encryption algorithm, so as to perform transparent encryption and decryption processing on the target data using the SM4 encryption algorithm in the encryption machine.
[0101] The data processing apparatus provided in this application embodiment calls an encryption machine through a database management system to achieve transparent encryption and decryption processing of the SM4 encryption algorithm, enabling the database's transparent data encryption function to support the SM4 encryption algorithm. Simultaneously, global parameters are set in the configuration file to record the encryption algorithm used, ensuring consistency of the encryption algorithm during use, while not altering the original AES encryption algorithm process.
[0102] Based on the above embodiments, as a preferred embodiment, it further includes:
[0103] The judgment module is used to determine whether transparent encryption and decryption processing is being performed for the first time; if yes, the workflow of the configuration module is started; if no, the workflow of the determination module 702 is started.
[0104] The configuration module is used to configure the global parameters to the encryption algorithm used in this transparent encryption and decryption process.
[0105] Based on the above embodiments, as a preferred embodiment, the first processing module 703 is specifically used to: when the encryption algorithm used is the SM4 encryption algorithm, directly call the encryption machine through the database management system to perform transparent encryption and decryption processing on the target data using the SM4 encryption algorithm in the encryption machine.
[0106] Based on the above embodiments, as a preferred implementation, the first processing module 703 is specifically used to: when the encryption algorithm used is the SM4 encryption algorithm, call the software library through the database management system to call the encryption machine through the software library, and use the SM4 encryption algorithm in the encryption machine to perform transparent encryption and decryption processing on the target data.
[0107] Based on the above embodiments, as a preferred implementation, the database management system includes the MariaDB management system, and the software library includes OpenSSL.
[0108] Based on the above embodiments, as a preferred embodiment, it further includes:
[0109] The modification module is used to obtain a key from the configuration file and modify the length of the key to 128 bits to obtain the target key;
[0110] Accordingly, the first processing module 703 is specifically used to: when the encryption algorithm used is the SM4 encryption algorithm, call the encryption machine through the database management system to use the SM4 encryption algorithm to transparently encrypt and decrypt the target data based on the target key.
[0111] Accordingly, the first processing module 703 is specifically used to: when the encryption algorithm used is the SM4 encryption algorithm, determine the target mode of the SM4 encryption algorithm according to the configuration file, and call the encryption machine through the database management system to perform transparent encryption and decryption processing on the target data in the encryption machine using the target mode of the SM4 encryption algorithm.
[0112] Based on the above embodiments, as a preferred implementation, the setting module 701 is specifically used to: set global parameters in the MariaDB configuration file;
[0113] Accordingly, the determining module 702 is specifically used to: when transparent encryption and decryption processing of target data is required, determine whether it is the first time transparent encryption and decryption processing is performed; if yes, configure the global parameter as the encryption algorithm used in this transparent encryption and decryption processing; if no, obtain the global parameter from the configuration file, and determine the encryption algorithm used in this transparent encryption and decryption processing based on the global parameter.
[0114] Accordingly, the first processing module 703 is specifically used for: when the encryption algorithm used is the SM4 encryption algorithm, obtaining the key from the configuration file, modifying the length of the key to 128 bits to obtain the target key; directly calling the encryption machine via MariaDB, or calling OpenSSL via MariaDB to call the encryption machine via OpenSSL; and transparently encrypting and decrypting the target data based on the target key using the SM4 encryption algorithm in the encryption machine.
[0115] Accordingly, the device also includes:
[0116] The second processing module is used to obtain a key from the configuration file when the encryption algorithm used is AES, and call OpenSSL via MariaDB to call the encryption machine via OpenSSL; if the current transparent encryption and decryption processing is the processing of the encryption plugin part or the storage engine part, then the target mode of the AES encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted and decrypted in the encryption machine using the target mode of the AES encryption algorithm based on the key; if the current transparent encryption and decryption processing is the processing of the cache copying part, then the target data is transparently encrypted and decrypted in the encryption machine using the preset mode of the AES encryption algorithm based on the key.
[0117] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0118] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide an electronic device. Figure 8 This is a structural diagram of an electronic device according to an exemplary embodiment, such as... Figure 8 As shown, the electronic device includes:
[0119] Communication interface 1 enables information exchange with other devices, such as network devices;
[0120] Processor 2 is connected to communication interface 1 to enable information interaction with other devices and to execute the data processing methods provided by one or more of the above-mentioned technical solutions when running computer programs. The computer program is stored in memory 3.
[0121] Of course, in practical applications, the various components in an electronic device are coupled together through bus system 4. It can be understood that bus system 4 is used to achieve communication and connection between these components. In addition to the data bus, bus system 4 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 8 The general will label all buses as Bus System 4.
[0122] The memory 3 in this embodiment is used to store various types of data to support the operation of the electronic device. Examples of such data include any computer program used to operate on the electronic device.
[0123] It is understood that memory 3 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 3 described in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.
[0124] The methods disclosed in the embodiments of this application can be applied to processor 2, or implemented by processor 2. Processor 2 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 2 or by instructions in the form of software. The processor 2 may be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 2 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory 3. Processor 2 reads the program in memory 3 and completes the steps of the aforementioned method in combination with its hardware.
[0125] When processor 2 executes the program, it implements the corresponding processes in the various methods of the embodiments of this application. For the sake of brevity, these will not be described in detail here.
[0126] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a memory 3 that stores a computer program, which can be executed by a processor 2 to complete the steps described in the aforementioned method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
[0127] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
[0128] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device (which may be a personal computer, server, network device, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
[0129] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data processing method, characterized in that, include: Set global parameters in the database management system's configuration file; these global parameters are used to record the encryption algorithms used. When transparent encryption and decryption of target data is required, the global parameters are obtained from the configuration file, and the encryption algorithm used for this transparent encryption and decryption process is determined based on the global parameters. If the encryption algorithm used is the SM4 encryption algorithm, then the database management system calls the encryption machine to transparently encrypt and decrypt the target data using the SM4 encryption algorithm in the encryption machine; The step of setting global parameters in the database management system configuration file includes: Set global parameters in the MariaDB configuration file; Accordingly, when transparent encryption and decryption of target data is required, the global parameters are obtained from the configuration file, and the encryption algorithm to be used is determined based on the global parameters, including: When transparent encryption and decryption of target data is required, determine whether it is the first time transparent encryption and decryption is performed. If so, the global parameters will be configured to the encryption algorithm used in this transparent encryption / decryption process; If not, the global parameters are obtained from the configuration file, and the encryption algorithm used for this transparent encryption / decryption process is determined based on the global parameters. Accordingly, if the encryption algorithm used is the SM4 encryption algorithm, then the database management system calls the encryption machine to perform transparent encryption and decryption processing on the target data using the SM4 encryption algorithm, including: If the encryption algorithm used is SM4, then obtain the key from the configuration file and modify the key length to 128 bits to obtain the target key; The encryption machine can be invoked directly via MariaDB, or via MariaDB and OpenSSL can be invoked via OpenSSL. The target data is transparently encrypted and decrypted using the SM4 encryption algorithm based on the target key in the encryption machine. Accordingly, the method further includes: If the encryption algorithm used is AES, then the key is obtained from the configuration file, and openssl is called through MariaDB to call the encryption machine through openssl; If the transparent encryption / decryption process is performed on the encryption plugin or storage engine, the target mode of the AES encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted / decrypted using the key based on the target mode of the AES encryption algorithm in the encryption machine. If this transparent encryption / decryption process involves the cache copying part, then the target data is transparently encrypted / decrypted using the key in the encryption machine based on the preset mode of the AES encryption algorithm.
2. The data processing method according to claim 1, characterized in that, Before retrieving the global parameters from the configuration file, the process also includes: Determine if this is the first time transparent encryption / decryption is being performed; If so, the global parameters will be configured to the encryption algorithm used in this transparent encryption / decryption process; If not, then proceed with the step of retrieving the global parameters from the configuration file.
3. The data processing method according to claim 1, characterized in that, The step of calling the encryption machine through the database management system includes: The encryption machine can be directly accessed through the database management system. Alternatively, the database management system may call the software library to invoke the encryption machine.
4. The data processing method according to claim 3, characterized in that, The database management system includes the MariaDB management system, and the software library includes OpenSSL.
5. The data processing method according to claim 1, characterized in that, Before calling the encryption machine through the database management system, the process also includes: Obtain the key from the configuration file, and modify the key length to 128 bits to obtain the target key; Accordingly, the transparent encryption and decryption processing of the target data using the SM4 encryption algorithm includes: The target data is transparently encrypted and decrypted using the SM4 encryption algorithm based on the target key.
6. The data processing method according to claim 1, characterized in that, The target data is transparently encrypted and decrypted using the SM4 encryption algorithm in the encryption machine, including: The target mode of the SM4 encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted and decrypted in the encryption machine using the target mode of the SM4 encryption algorithm.
7. A data processing apparatus, characterized in that, include: The configuration module is used to set global parameters in the configuration file of the database management system; wherein, the global parameters are used to record the encryption algorithm used; The determination module is used to obtain the global parameters from the configuration file when transparent encryption and decryption processing of target data is required, and to determine the encryption algorithm to be used for this transparent encryption and decryption processing based on the global parameters. The first processing module is used to call the encryption machine through the database management system when the encryption algorithm used is the SM4 encryption algorithm, so as to transparently encrypt and decrypt the target data using the SM4 encryption algorithm in the encryption machine; Specifically, the setting module is used to: set global parameters in the MariaDB configuration file; Accordingly, the determining module is specifically used to: when transparent encryption and decryption processing of target data is required, determine whether it is the first time transparent encryption and decryption processing is performed; if so, configure the global parameter as the encryption algorithm used in this transparent encryption and decryption processing; if not, obtain the global parameter from the configuration file, and determine the encryption algorithm used in this transparent encryption and decryption processing based on the global parameter. Accordingly, the first processing module is specifically used for: when the encryption algorithm used is the SM4 encryption algorithm, obtaining the key from the configuration file, modifying the length of the key to 128 bits to obtain the target key; directly calling the encryption machine via MariaDB, or calling OpenSSL via MariaDB to call the encryption machine via OpenSSL; and transparently encrypting and decrypting the target data based on the target key using the SM4 encryption algorithm in the encryption machine. Accordingly, the device also includes: The second processing module is used to obtain a key from the configuration file when the encryption algorithm used is AES, and call OpenSSL via MariaDB to call the encryption machine via OpenSSL; if the current transparent encryption and decryption processing is the processing of the encryption plugin part or the storage engine part, then the target mode of the AES encryption algorithm is determined according to the configuration file, and the target data is transparently encrypted and decrypted in the encryption machine using the target mode of the AES encryption algorithm based on the key; if the current transparent encryption and decryption processing is the processing of the cache copying part, then the target data is transparently encrypted and decrypted in the encryption machine using the preset mode of the AES encryption algorithm based on the key.
8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the steps of the data processing method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the data processing method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
MySQL transparent data encryption method and device based on cipher machine equipment
CN114491579A
Method and system for deriving database table key based on domestic cipher machine
CN116248253A