Data Processing Method, Apparatus, Device, Storage Medium and Computer Program Product

By introducing middleware between the user and the database and using quantum encryption channels to isolate the user and the database, and storing the key independently in the registration center, the problems of data leakage and unauthorized access in traditional database solutions are solved, and secure data processing and transmission are achieved.

CN118487839BActive Publication Date: 2025-07-22BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410699973.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-31
Publication Date
2025-07-22
Estimated Expiration
2044-05-31

AI Technical Summary

Technical Problem

When traditional database storage solutions face complex network security threats, there are problems of data leakage, tampering and unauthorized access, especially in cloud computing and IoT environments.

Method used

By introducing middleware between the user and the database, the quantum encryption channel is used to isolate the user and the database, and the key is stored independently in the registration center to realize the encryption and decryption operation, and a quantum encryption channel is set up between the user and the middleware, the middleware and the registration center, and the registration center and the database to ensure the security of data transmission.

Benefits of technology

On the premise of ensuring the security of data transmission, data processing is isolated and secure, preventing unauthorized access and data leakage, and improving the security of the database system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118487839B_ABST
    Figure CN118487839B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data processing method, apparatus, device, storage medium, and computer program product, which relate to technical fields such as encryption and decryption, middleware, and quantum anti-eavesdropping. The method includes: receiving an access request transmitted by a user through a first quantum encryption channel; in response to the quantum state of the first quantum encryption channel remaining unchanged, extracting a data processing instruction from the access request, and initiating a key acquisition request corresponding to the encryption and decryption information included in the data processing instruction to a registration center through a second quantum encryption channel; using the target key received through the second quantum encryption channel with an unchanged quantum state to process the encryption and decryption information, obtaining a rewritten instruction including the encrypted and decrypted information; sending the rewritten instruction to a database through a third quantum encryption channel, and receiving a processing response information returned by the third quantum encryption channel with an unchanged quantum state. Applying this method can not only isolate the user from the data but also achieve the secure transmission of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, specifically to technical fields such as encryption and decryption, middleware, quantum anti-eavesdropping, etc. In particular, it relates to a data processing method, apparatus, electronic device, computer-readable storage medium, and computer program product applied to middleware located between a user, a registration center, and a database. Background Art

[0002] Traditional database storage solutions have shown obvious weaknesses in the face of increasingly complex network security threats. Problems such as data leakage, tampering, and unauthorized access frequently occur, posing serious challenges to the data security of enterprises and individuals.

[0003] In addition, with the rapid development of cloud computing, big data, and Internet of Things technologies, the scale of databases has been continuously expanding, further exacerbating security risks. Summary of the Invention

[0004] Embodiments of the present disclosure propose a data processing method, apparatus, electronic device, computer-readable storage medium, and computer program product.

[0005] In a first aspect, embodiments of the present disclosure propose a data processing method applied to middleware located between a user, a registration center, and a database, including: receiving an access request sent by the user through a first quantum encryption channel; in response to the quantum state of the first quantum encryption channel remaining unchanged, extracting a data processing instruction from the access request, and initiating a key acquisition request corresponding to the encryption and decryption information included in the data processing instruction to the registration center through a second quantum encryption channel; using the target key received through the second quantum encryption channel with an unchanged quantum state to process the encryption and decryption information, obtaining a rewritten instruction including the encrypted and decrypted information; sending the rewritten instruction to the database through a third quantum encryption channel, and receiving a processing response message returned by the third quantum encryption channel with an unchanged quantum state.

[0006] In a second aspect, an embodiment of the present disclosure proposes a data processing device, which is applied to a middleware located between a user and a registration center and a database, including: an access request receiving unit, configured to receive an access request passed in by the user through a first quantum encryption channel; a key acquisition request initiating unit, configured to extract a data processing instruction from the access request in response to the quantum state of the first quantum encryption channel not changing, and initiate a key acquisition request corresponding to the encryption and decryption information contained in the data processing instruction to the registration center through a second quantum encryption channel; an encryption and decryption processing unit, configured to use the target key received through the second quantum encryption channel whose quantum state has not changed, to process the encryption and decryption information to obtain a rewritten instruction containing the encrypted and decrypted information; a rewritten instruction processing unit, configured to send the rewritten instruction to the database through a third quantum encryption channel, and receive processing response information returned by the third quantum encryption channel whose quantum state has not changed.

[0007] In a third aspect, an embodiment of the present disclosure provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can implement the data processing method described in the first aspect when executing.

[0008] In a fourth aspect, an embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions, which are used to enable a computer to implement the data processing method described in the first aspect when executed.

[0009] In a fifth aspect, an embodiment of the present disclosure provides a computer program product including a computer program, which, when executed by a processor, can implement the steps of the data processing method described in the first aspect.

[0010] Compared with the original solution in which the user directly initiates a data access request to the database that actually stores the data and processes it, the data processing method provided by the present invention, by being applied to a middleware located between the user and the registration center and the database, is able to isolate the two by adding a middleware between the user and the database, and independently store the key used to encrypt and decrypt the data stored in the database in the added registration center, so that the key and the data are also isolated, and both are connected to each other through the middleware in response to the access request initiated by the user, and by setting up quantum encryption channels between the user and the middleware, between the middleware and the registration center, and between the middleware and the database to ensure the security of data transmission, data processing can be achieved under the premise of fully ensuring the security of data transmission.

[0011] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood from the following description. Description of the Drawings

[0012] Other features, objects, and advantages of the present disclosure will become more apparent from the following detailed description of non-limiting embodiments read with reference to the accompanying drawings:

[0013] Figure 1 is an exemplary system architecture to which the present disclosure can be applied;

[0014] Figure 2 is a flowchart of a data processing method provided by an embodiment of the present disclosure;

[0015] Figure 3 is a flowchart of a method for initiating a key acquisition request provided by an embodiment of the present disclosure;

[0016] Figure 4 is a block diagram of the structure of a registration center provided by an embodiment of the present disclosure;

[0017] Figure 5 is a flowchart of a method for processing an eavesdropped quantum encryption channel provided by an embodiment of the present disclosure;

[0018] Figure 6 is a schematic flowchart of processing encrypted information included in an access request initiated by a user provided by an embodiment of the present disclosure;

[0019] Figure 7 is a schematic flowchart of processing decryption information included in an access request initiated by a user provided by an embodiment of the present disclosure;

[0020] Figure 8 is a block diagram of the structure of a data processing device provided by an embodiment of the present disclosure;

[0021] Figure 9 is a schematic diagram of the structure of an electronic device suitable for executing the data processing method provided by an embodiment of the present disclosure. Detailed Embodiments

[0022] The exemplary embodiments of the present disclosure will be described below in conjunction with the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted in the following description for clarity and conciseness. It should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.

[0023] In the technical solution of the present disclosure, the processing of the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information complies with the provisions of relevant laws and regulations and does not violate public order and good customs.

[0024] Figure 1 An exemplary system architecture 100 is shown, which can apply the embodiments of the data processing method, apparatus, electronic device, and computer-readable storage medium of the present disclosure.

[0025] As Figure 1 shown, the system architecture 100 may include terminal devices 101, 102, 103, middleware 104, registration center 105, and database 106. The middleware 104 is located between the terminal devices 101, 102, 103 and the registration center 105, and between the terminal devices 101, 102, 103 and the database 106, and is used to isolate the terminal devices 101, 102, 103 from the registration center 105 and the database 106. The security of data transmission between the terminal devices 101, 102, 103, middleware 104, registration center 105, and database 106 is guaranteed through a quantum-based quantum encryption channel.

[0026] Users can use the terminal devices 101, 102, 103 to interact with the database 106 through the middleware 104. During the interaction with the database 106, the middleware 104 can also interact with the registration center 105 to ensure the secure sending or receiving of messages to / from the database 106. Various applications for implementing information communication between them can be installed on the terminal devices 101, 102, 103, middleware 104, registration center 105, and database 106, such as data access applications, encryption / decryption applications, data transmission applications, etc.

[0027] The terminal devices 101, 102, 103, the middleware 104, the registration center 105, and the database 106 can all be hardware or software. When the terminal devices 101, 102, 103 are hardware, they can be various electronic devices with a display screen, including but not limited to smartphones, tablet computers, laptop computers, desktop computers, and so on; when the terminal devices 101, 102, 103 are software, they can be installed in the above-listed electronic devices, and can be implemented as multiple software or software modules, or can be implemented as a single software or software module, and no specific limitation is made here. When the middleware 104, the registration center 105, and the database 106 are hardware, they can be implemented as a distributed server cluster composed of multiple servers carrying corresponding services, or can be implemented as a single server carrying corresponding services; when the middleware 104, the registration center 105, and the database 106 are software, they can be implemented as multiple software or software modules, or can be implemented as a single software or software module, and no specific limitation is made here.

[0028] The middleware 104 can provide various services through various built-in applications. Taking the data processing application that can provide data processing services based on security as an example, when the middleware 104 runs this data processing application, the following effects can be achieved: First, receive the access requests passed in by the user through the terminal devices 101, 102, 103 through the first quantum encryption channel; then, when the quantum state of the first quantum encryption channel does not change before and after receiving the access request, extract the data processing instruction from the access request, and initiate a key acquisition request corresponding to the encryption and decryption information contained in the data processing instruction to the registration center 104 through the second quantum encryption channel; then, use the target key returned by the registration center 104 received through the second quantum encryption channel whose quantum state does not change before and after initiating the key acquisition request to process the encryption and decryption information, and obtain a rewritten instruction containing the encrypted and decrypted information; finally, send the rewritten instruction to the database 106 through the third quantum encryption channel, and receive the processing response information returned by the third quantum encryption channel whose quantum state does not change before and after the instruction is sent.

[0029] Furthermore, the middleware 104 can also send it to the user using the terminal devices 101, 102, 103 through the first quantum encryption channel according to the processing response information.

[0030] The data processing method provided in each subsequent embodiment of the present disclosure is executed by the middleware between the user and the database, which has fully isolated the user and the database. Correspondingly, the data processing device is generally also set in the middleware 105.

[0031] It should be understood, Figure 1The numbers of the terminal devices, middleware, registration center, and database in [it] are merely illustrative. According to actual requirements, there can be any number of terminal devices, middleware, registration center, and database.

[0032] Please refer to Figure 2 , Figure 2 which is a flowchart of a data processing method provided by an embodiment of the present disclosure. The process 200 includes the following steps:

[0033] Step 201: Receive an access request sent by a user through a first quantum encryption channel;

[0034] The purpose of this step is that the execution entity of the data processing method (such as Figure 1 the middleware 104 shown) receives, through the first quantum encryption channel pre-established between the user side (such as Figure 1 the terminal devices 101, 102, 103 shown) and the execution entity, the access request sent by the user side expressing its intention to initiate an access request to the database (such as Figure 1 the database 106 shown). However, since the present disclosure adds middleware directly between the user side and the database, this middleware will intercept the access request that the user side originally expected to directly send to the database, thereby realizing the isolation between the user and the database and being beneficial to ensuring data security.

[0035] Among them, the quantum encryption channel is an advanced communication encryption technology involving the principles of quantum mechanics, and the construction of the quantum encryption channel can be realized through the following key steps:

[0036] 1) Quantum key distribution: Quantum key distribution is the core step of the quantum encryption channel. This usually involves preparing two entangled quantum pairs (such as EPR particle pairs) and sending them to the two parties of communication (assumed to be user A and user B) respectively. Due to the characteristics of quantum entanglement, there will be a kind of "telepathy" between these two particles, that is, the state change of one particle will immediately affect the state of the other particle;

[0037] 2) Quantum state transmission: User A performs a joint measurement on the particle it holds (such as particle 1) and another particle with an unknown quantum state (such as particle 3), and then sends the measurement result to user B through a classical channel (non-quantum channel). User B performs corresponding operations according to the received information and the particle it holds (such as particle 2) to reconstruct the whole picture of particle 3; Classical communication and confirmation: During the whole process, user A and user B also need to communicate through the classical channel to confirm the correctness of the measurement result and eliminate the interference of possible eavesdroppers.

[0038] The reason why a quantum encryption channel can achieve eavesdropping prevention is mainly due to the uncertainty principle of quantum states. According to the uncertainty principle of quantum mechanics, any measurement of a quantum state will change its state, which makes it impossible for an eavesdropper (such as user C) to attempt to steal information without being detected by both communicating parties (user A and user B). Because any measurement by user C will change the quantum state in transmission, and this change will be detected by user A and user B through the entanglement relationship.

[0039] In addition, it also relies on the remote "telepathy" ability of quantum entanglement: as mentioned above, there is a kind of remote telepathy between entangled quantum pairs. This property enables user A and user B to share a secure key without worrying about the key being stolen during transmission. Because any operation on the entangled quantum pair will immediately affect the other particle, making the eavesdropping behavior obvious.

[0040] And the auxiliary role of the classical channel. Although quantum teleportation seemingly enables superluminal information transmission, in fact, it still requires the assistance of the classical channel. This is because quantum entanglement itself does not directly transmit information, but indirectly realizes information transmission by changing the state of entangled particles. And the classical channel is used to transmit measurement results and confirmation information to ensure the accuracy and security of communication.

[0041] Step 202: In response to the quantum state of the first quantum encryption channel remaining unchanged, extract the data processing instruction from the access request, and initiate a key acquisition request corresponding to the encryption and decryption information included in the data processing instruction to the registration center through the second quantum encryption channel;

[0042] Based on step 201, in the case where the quantum state of the first quantum encryption channel remains unchanged before and after the access request is initiated at the user end, it can be determined that no third party has eavesdropped on the first quantum encryption channel. Therefore, the above-mentioned execution entity extracts the data processing instruction from the securely received access request, which characterizes what kind of processing the user expects to perform on the data in the database, and initiates a key acquisition request corresponding to the encryption and decryption information included in the data processing instruction to the registration center (such as Figure 1 the registration center 105 shown). Among them, the second quantum encryption channel is a quantum encryption channel pre-established between the middleware and the registration center. In the current embodiment, the registration center is at least used to store the keys corresponding to encryption and decryption, so as to perform corresponding encryption and decryption operations on the encryption and decryption information. Of course, it is not excluded that the registration center can also be used to store other information and achieve other purposes.

[0043] Step 203: Use the target key received through the second quantum encryption channel with an unchanged quantum state to process the encryption and decryption information, and obtain a rewritten instruction containing the encrypted and decrypted information.

[0044] On the basis of step 202, this step is intended to be performed by the above-mentioned execution subject using the target key received through the second quantum encryption channel whose quantum state does not change before and after the key acquisition request is initiated and returned by the registration center to process the encryption and decryption information contained in the data processing instruction, wherein the encryption and decryption information can be processed by the target key to obtain the encrypted and decrypted information, and the encryption and decryption information in the data processing instruction can be replaced by the encrypted and decrypted information to obtain the rewritten instruction.

[0045] Step 204: Send the rewritten instruction to the database through the third quantum encryption channel, and receive the processing response information returned by the third quantum encryption channel whose quantum state has not changed.

[0046] On the basis of step 203, this step aims to send the rewritten instruction to the database (for example, Figure 1 The database 106 shown in the figure) receives the processing response information returned by the third quantum encryption channel whose quantum state has not changed before and after the rewritten instruction is sent. The third quantum encryption channel is a quantum encryption channel pre-established between the middleware and the database. The processing response information is the response information returned by the database after the data processing requirement conveyed in the rewritten instruction is processed. The response information returned varies according to the type of data processing requirement.

[0047] Compared with the original solution in which the user directly initiates a data access request to the database that actually stores the data and performs processing, the data processing method provided in the embodiment of the present disclosure, by being applied to a middleware located between the user and the registration center and the database, is able to isolate the two by adding a middleware between the user and the database, and independently store the key used to encrypt and decrypt the data stored in the database in the added registration center, so that the key and the data are also isolated, and both are connected to each other through the middleware in response to the access request initiated by the user, and by setting up quantum encryption channels between the user and the middleware, between the middleware and the registration center, and between the middleware and the database to ensure the security of data transmission, data processing can be achieved under the premise of fully ensuring the security of data transmission.

[0048] In order to further ensure the security of the access request processing provided by step 202 in process 200, this embodiment also Figure 3 A specific processing method is provided. A complete new embodiment can be obtained by replacing step 202 in process 200 with the steps included in the following process 300. The process 300 includes the following steps:

[0049] Step 301: In response to the quantum state of the first quantum encryption channel remaining unchanged, extract the user's identity information from the access request;

[0050] The purpose of this step is for the above-mentioned execution entity to extract the identity information of the user who initiated the access request from the access request when it is found that the quantum state of the first quantum encryption channel has not changed before and after receiving the access request. For example, the user's username, identity number, identity code, etc., any information that can uniquely identify a user.

[0051] Step 302: Determine the actual access rights corresponding to the identity information;

[0052] Based on Step 301, the purpose of this step is for the above-mentioned execution entity to determine the actual access rights corresponding to the identity information. For example, it can be done by looking up a table in an association table that pre-records the association relationship between different identity information and different access rights, and querying to determine the actual access rights corresponding to this identity information. Specifically, the actual operating entity of this step can be the middleware, or other entities that the middleware can control or remotely access.

[0053] An implementation method including but not limited to can be:

[0054] First, initiate a permission query request corresponding to the identity information to the registration center through the second quantum encryption channel; then, use the permission query result received through the second quantum encryption channel with an unchanged quantum state to determine the actual access rights. That is, in this embodiment, by enabling the registration center to not only have the ability to store keys but also have the ability to record different permissions of different users, and then using the second quantum encryption channel established between the middleware and the registration center, the secure confirmation of the permissions of the user is realized.

[0055] Step 303: In response to the actual access rights including the access right to the middleware, extract the data processing instruction from the access request;

[0056] Based on Step 302, the purpose of this step is for the above-mentioned execution entity to perform the operation of extracting the data processing instruction from the access request only when the received actual access rights include the access right to the middleware as the current execution entity. That is, an additional authentication operation of the permissions held by the user is performed before the data processing instruction to avoid an inappropriate response to an access request initiated by a user without permission.

[0057] Step 304: Initiate a key acquisition request corresponding to the encryption and decryption information included in the data processing instruction to the registration center through the second quantum encryption channel.

[0058] That is, the technical solution provided by steps 301 - 304 in this embodiment is equivalent to, on the basis of the technical solution provided in step 202 of process 200, additionally performing authentication on whether the user who initiated the access request has the access permission to the middleware according to the identity information of the user included in the access request after receiving the access request and before extracting the data processing instruction from the access request, so as to ensure that only users with relevant permissions can initiate the access permission. Among them, whether the user has the access permission to the middleware can be simply equivalent to whether the user has the access permission to the database. Of course, in complex scenarios, the access permission to the middleware can also be different from the access permission to the database.

[0059] To deepen the understanding of the capabilities of the registration center as a main body, this embodiment is also based on Figure 3 the two capabilities required by the corresponding embodiment for the registration center, and through Figure 4 shows a specific structural schematic diagram of a registration center:

[0060] As Figure 4 shown, the registration center 400 is divided into two parts, namely the authentication registration center 410 and the key management center 420. Among them, the authentication registration center 410 is where users directly register information such as identities and encrypted fields of databases. Since data is automatically encrypted for storage / automatically decrypted through the database middleware, before officially using the database, 2 types of information need to be registered in the authentication registration center 410: the identity information of the user and the database information to be encrypted / decrypted. Among them, the identity information of the user includes: user identity, AK (Access Key), SK (Secret Key), environment IP, device information, etc.; the database information for encryption / decryption includes: database name, data table name, column field information.

[0061] The key management center 420, after users register relevant information in the authentication registration center 410, will uniformly manage the user's identity information, environment information, and database information for encryption / decryption. This key management center 420 will automatically manage the passwords required for encrypting / decrypting the database, and users do not need to care about the password content, so there is no need to worry about password loss.

[0062] Furthermore, to enhance the encryption strength of the key, the registration center can be controlled to set corresponding keys for different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields respectively. In particular, the separately set keys are different from each other, so as to achieve one encryption key for one database, one encryption key for one data table, one encryption key for one column, one encryption key for one row, and even one encryption key for one field. Since there is a separate encryption and decryption key for each part, even if the hacker steals the entire database, because the keys for each part of the data are different, it is almost impossible for the hacker to crack all the content, thus increasing the data security level as much as possible.

[0063] Specifically, the above-mentioned keys may include: a symmetric key generated based on a symmetric encryption algorithm or a public key and a private key generated based on an asymmetric encryption algorithm. Among them, the public key is held by the user and is used to generate the encrypted information in the encryption and decryption information, and the private key is held by the registration center and is used to decrypt the encrypted information obtained after encrypting with the supporting public key.

[0064] Furthermore, the key update frequency can be determined according to the access frequencies of the database, the database, the row, the column, and the field. The key update frequency is proportional to the access frequency, and the keys of the corresponding part of the data are updated according to the key update frequency. This can reduce the potential security risks that may be brought by using a single key for a long time as much as possible.

[0065] Based on any of the above embodiments, on the basis of having elaborated on how to process the quantum encryption channel that has been confirmed not to be wiretapped, this embodiment also provides a method for confirming a wiretapped quantum encryption channel and how to process such a quantum encryption channel through the Figure 5 flow 500 shown, including the following steps:

[0066] Step 501: In response to the change in the quantum state of the corresponding quantum encryption channel before and after the data sending or data receiving behavior through any quantum encryption channel, determine that the corresponding quantum encryption channel has been wiretapped, and discard the data received or sent through the corresponding quantum encryption channel;

[0067] Among them, any quantum encryption channel includes at least one of the first quantum encryption channel, the second quantum encryption channel, and the third quantum encryption channel.

[0068] That is, this step aims to determine that the corresponding quantum encryption channel has been wiretapped and discard the data received or sent through the corresponding quantum encryption channel when the above-mentioned execution entity detects a change in the quantum state of the corresponding quantum encryption channel before and after the data sending or data receiving behavior through any quantum encryption channel.

[0069] Step 502: Destroy the wiretapped quantum encryption channel and reconstruct a new quantum encryption channel between the same communication entities based on a new encryption method;

[0070] Based on step 501, this step aims to have the above-mentioned executing entity destroy the wiretapped quantum encryption channel and reconstruct a new quantum encryption channel between the same communication entities based on a new encryption method, so as to avoid being wiretapped again as much as possible.

[0071] Step 503: In response to the quantum state of the new quantum encryption channel remaining unchanged before and after a preset number of consecutive test data transmission behaviors, determine that the new quantum encryption channel is in a secure transmission state without being wiretapped.

[0072] Based on step 502, this step aims to have the above-mentioned executing entity determine that the new quantum encryption channel is in a secure transmission state without being wiretapped when the quantum state of the new quantum encryption channel remains unchanged before and after a preset number of consecutive test data transmission behaviors (such as 10 consecutive times).

[0073] These implementation steps 501 - 503 provide a solution for determining a quantum encryption channel whose quantum state has changed before and after data sending or receiving as a wiretapped quantum encryption channel, and avoid the wiretapped data from continuing to take effect by discarding the data previously received or sent through it. Further, steps 502 and 503 also provide an implementation method for how to re - establish a quantum encryption channel that can be confirmed to be untapped subsequently.

[0074] It should be noted that the solution provided in step 501 can exist independently in combination with the above - mentioned embodiments, that is, it can independently form a new embodiment without steps 502 - 503 subsequently. This embodiment only exists as a preferred embodiment when the two - part solutions exist simultaneously.

[0075] For the convenience of understanding the specific process when a user specifically implements data processing through the above - mentioned solution, the following also separately shows Figure 6 and Figure 7 how to complete data encryption operations and data decryption operations by the above - mentioned various executing entities:

[0076] Figure 6 The encryption operation shown is the operation performed when the data processing instruction is any one of a data addition instruction, a data update instruction, or a data deletion instruction. At this time, the processing response information corresponds to a notification information of any one of data addition completed, data update completed, or data deletion completed.

[0077] Such as Figure 6As shown, user 61 first initiates an access request to middleware 62. In step 610, middleware 62 determines whether user 61 has the permission to access middleware 62 based on this access request. When it is determined that the relevant permission exists, in step 620, it parses the data processing instruction (such as an SQL instruction, Structured Query Language) in the access request, otherwise it rejects; in step 630, it determines whether there are columns that need to be encrypted based on the parsing result. When it is determined that there are columns that need to be encrypted, in step 640, it obtains the key corresponding to this column from registration center 63 (the interaction with the registration center can be broken down into steps 641 and 642). When there are no columns that need to be encrypted, it can directly send the SQL instruction to database 64 for specific execution; then in step 650, it uses the obtained key to rewrite the original SQL instruction, and then in step 660, it forwards the rewritten instruction to database 64 for specific execution.

[0078] Figure 7 The decryption operation shown is the operation performed when the data processing instruction is specifically a data reading instruction, and the processing response information correspondingly is the result feedback information containing the read plaintext data.

[0079] As Figure 7 As shown, user 61 first initiates an access request to middleware 62. In step 710, middleware 62 determines whether user 61 has the permission to access middleware 62 based on this access request. When it is determined that the relevant permission exists, in step 720, it parses the data processing instruction (such as an SQL instruction, Structured Query Language) in the access request, otherwise it rejects; in step 730, it determines whether there are columns that need to be decrypted based on the parsing result. When it is determined that there are columns that need to be decrypted, in step 740, it rewrites the SQL instruction, and in step 750, it sends the rewritten instruction to database 64 for specific execution. When there are no columns that need to be decrypted, it can directly send the SQL instruction to database 64 for specific execution; database 64 sends the read ciphertext data to middleware 62, and middleware 62 then determines in step 760 whether there are encrypted columns. If so, in step 770, it obtains the key corresponding to this column from registration center 63 (the interaction with the registration center can be broken down into steps 771 and 772) to decrypt the encrypted column, otherwise it can directly return the data of the columns that do not need to be decrypted to user 61.

[0080] Further referring to Figure 8 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a data processing device. This device embodiment corresponds to Figure 2 the method embodiment shown, and this device can be specifically applied to various electronic devices.

[0081] As Figure 8 shown, the data processing apparatus 800 in this embodiment may include: an access request receiving unit 801, a key acquisition request initiating unit 802, an encryption / decryption processing unit 803, and a rewritten instruction processing unit 804. Among them, the access request receiving unit 801 is configured to receive an access request incoming from a user through a first quantum encryption channel; the key acquisition request initiating unit 802 is configured to, in response to the quantum state of the first quantum encryption channel not changing, extract a data processing instruction from the access request, and initiate a key acquisition request corresponding to the encryption / decryption information included in the data processing instruction to a registration center through a second quantum encryption channel; the encryption / decryption processing unit 803 is configured to use the target key received through the second quantum encryption channel with an unchanged quantum state to process the encryption / decryption information to obtain a rewritten instruction including the encrypted / decrypted information; the rewritten instruction processing unit 804 is configured to send the rewritten instruction to a database through a third quantum encryption channel and receive a processing response message returned by the third quantum encryption channel with an unchanged quantum state.

[0082] In this embodiment, in the data processing apparatus 800: the specific processing of the access request receiving unit 801, the key acquisition request initiating unit 802, the encryption / decryption processing unit 803, and the rewritten instruction processing unit 804 and the technical effects brought thereby can respectively refer to Figure 2 the relevant descriptions of steps 201-204 in the corresponding embodiment, which will not be elaborated here.

[0083] In some optional implementation manners of this embodiment, the data processing apparatus 800 may further include:

[0084] an identity information extraction unit, configured to extract the identity information of a user from the access request before extracting the data processing instruction from the access request;

[0085] an actual access permission determination unit, configured to determine the actual access permission corresponding to the identity information;

[0086] a data processing instruction extraction step execution unit, configured to, in response to the actual access permission including the access permission to middleware, execute the step of extracting the data processing instruction from the access request.

[0087] In some optional implementation manners of this embodiment, the actual access permission determination unit is further configured to:

[0088] initiate a permission query request corresponding to the identity information to a registration center through a second quantum encryption channel;

[0089] Determine the actual access permission by using the permission query result received through the second quantum encryption channel whose quantum state has not changed.

[0090] In some optional implementation manners of this embodiment, the data processing device 800 may further include:

[0091] A wiretapping determination and processing unit, configured to determine that the corresponding quantum encryption channel has been wiretapped and discard the data received or sent through the corresponding quantum encryption channel in response to the change in the quantum state of the corresponding quantum encryption channel before and after the data sending or data receiving behavior through any quantum encryption channel; wherein, any quantum encryption channel includes at least one of the first quantum encryption channel, the second quantum encryption channel, and the third quantum encryption channel.

[0092] In some optional implementation manners of this embodiment, the data processing device 800 may further include:

[0093] A destruction and reconstruction unit, configured to destroy the wiretapped quantum encryption channel and reconstruct a new quantum encryption channel between the same communication entities based on a new encryption method;

[0094] A new quantum encryption channel security determination unit, configured to determine that the new quantum encryption channel is in a secure transmission state without being wiretapped in response to the quantum state of the new quantum encryption channel not changing before and after a preset number of consecutive test data transmission behaviors.

[0095] In some optional implementation manners of this embodiment, when the data processing instruction is any one of a data addition instruction, a data update instruction, or a data deletion instruction, the encryption and decryption information corresponds to encryption information, and the processing response information corresponds to a notification information of any one of data addition completion, data update completion, or data deletion completion.

[0096] In some optional implementation manners of this embodiment, when the data processing instruction is a data reading instruction, the encryption and decryption information corresponds to decryption information, and the processing response information corresponds to a result feedback information including the read plaintext data.

[0097] In some optional implementation manners of this embodiment, the registration center sets corresponding keys for different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields respectively.

[0098] In some optional implementation manners of this embodiment, the keys set by the registration center for different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields respectively are different from each other.

[0099] In some optional implementations of this embodiment, the data processing device 800 may further include:

[0100] A key update frequency determination unit is configured to determine a corresponding key update frequency according to the access frequency of the database, the database, the row, the column, and the field; wherein the key update frequency is proportional to the access frequency;

[0101] The key updating unit is configured to update the key of the corresponding part of the data according to the key updating frequency.

[0102] In some optional implementations of this embodiment, the key includes: a symmetric key generated based on a symmetric encryption algorithm or a public key and a private key generated based on an asymmetric encryption algorithm; wherein the public key is held by the user and used to generate encrypted information in encrypted and decrypted information, and the private key is held by the registration center and used to decrypt encrypted information encrypted using the matching public key.

[0103] This embodiment exists as a device embodiment corresponding to the above method embodiment. Compared with the original scheme in which the user directly initiates a data access request to the database that actually stores the data and processes it, the data processing device provided by the embodiment of the present disclosure, by applying to the middleware located between the user and the registration center and the database, can isolate the key from the data by adding a middleware between the user and the database, and independently store the key used to encrypt and decrypt the data stored in the database in the added registration center, so that the key and the data are also isolated, and both are connected to each other through the middleware in response to the access request initiated by the user, and the security of data transmission is ensured by setting up a quantum encryption channel between the user and the middleware, between the middleware and the registration center, and between the middleware and the database, so that data processing can be realized under the premise of fully ensuring the security of data transmission.

[0104] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can implement the data processing method described in any of the above embodiments when executing.

[0105] According to an embodiment of the present disclosure, the present disclosure further provides a readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to implement the data processing method described in any of the above embodiments when executed.

[0106] According to an embodiment of the present disclosure, the present disclosure further provides a computer program product, which can implement the data processing method described in any of the above embodiments when executed by a processor.

[0107] Figure 9 FIG. shows a schematic block diagram of an exemplary electronic device 900 that can be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementations of the present disclosure described and / or claimed herein.

[0108] As Figure 9 shown, the device 900 includes a computing unit 901 that can perform various appropriate actions and processes in accordance with a computer program stored in a read-only memory (ROM) 902 or a computer program loaded from a storage unit 908 into a random access memory (RAM) 903. In the RAM 903, various programs and data required for the operation of the device 900 can also be stored. The computing unit 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.

[0109] A plurality of components in the device 900 are connected to the I / O interface 905, including: an input unit 906, such as, for example, a keyboard, a mouse, etc.; an output unit 907, such as, for example, various types of displays, speakers, etc.; a storage unit 908, such as, for example, a magnetic disk, an optical disk, etc.; and a communication unit 909, such as, for example, a network card, a modem, a wireless communication transceiver, etc. The communication unit 909 allows the device 900 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0110] The computing unit 901 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 901 executes the various methods and processes described above, such as the data processing method. For example, in some embodiments, the data processing method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 908. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 900 via the ROM 902 and / or the communication unit 909. When the computer program is loaded into the RAM 903 and executed by the computing unit 901, one or more steps of the data processing method described above can be executed. Alternatively, in other embodiments, the computing unit 901 can be configured to execute the data processing method by any other suitable means (e.g., by means of firmware).

[0111] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0112] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0113] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0114] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0115] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0116] A computer system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The relationship between the client and the server is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and virtual private servers (VPS) services.

[0117] Compared with the original solution in which the user directly initiates a data access request to the database that actually stores the data and processes it, the technical solution provided by the embodiment of the present disclosure, by being applied to the middleware located between the user and the registration center and the database, is able to isolate the two by adding a middleware between the user and the database, and independently store the key used to encrypt and decrypt the data stored in the database in the added registration center, so that the key and the data are also isolated, and both are connected to each other through the middleware in response to the access request initiated by the user, and by setting up quantum encryption channels between the user and the middleware, between the middleware and the registration center, and between the middleware and the database to ensure the security of data transmission, data processing can be achieved under the premise of fully ensuring the security of data transmission.

[0118] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.

[0119] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A data processing method, wherein, Applied to the middleware located between the user, the registration center, and the database, the method includes: Extract data processing instructions from the user's incoming access request received through the first quantum encryption channel with unchanged quantum state; In response to the data processing instruction indicating to store the data to be encrypted in the database, initiate a key acquisition request corresponding to the data to be encrypted to the registration center through the second quantum encryption channel, and use the key received through the second quantum encryption channel with unchanged quantum state to encrypt the data to be encrypted, obtaining a rewritten instruction containing the encrypted information; send the rewritten instruction to the database through the third quantum encryption channel, and receive the processing response information returned by the third quantum encryption channel with unchanged quantum state; In response to the data processing instruction indicating to read the encrypted data stored in the database, send the rewritten data processing instruction to the database through the third quantum encryption channel, and receive the encrypted data returned by the third quantum encryption channel with unchanged quantum state; initiate a key acquisition request corresponding to the encrypted data to the registration center through the second quantum encryption channel, and use the key received through the second quantum encryption channel with unchanged quantum state to decrypt the encrypted data, and return the decrypted data to the user.

2. The method according to claim 1, further comprising: Before extracting the data processing instructions from the access request, extract the identity information of the user from the access request; Determine the actual access permission corresponding to the identity information; In response to the actual access permission including the access permission to the middleware, execute the step of extracting the data processing instructions from the access request.

3. The method according to claim 2, wherein, Determining the actual access permission corresponding to the identity information includes: Initiate a permission query request corresponding to the identity information to the registration center through the second quantum encryption channel; Use the permission query result received through the second quantum encryption channel with unchanged quantum state to determine the actual access permission.

4. The method according to claim 1, further comprising: In response to the quantum state of the corresponding quantum encryption channel changing before and after the data sending or receiving behavior through any quantum encryption channel, determine that the corresponding quantum encryption channel has been wiretapped, and discard the data received or sent through the corresponding quantum encryption channel; wherein, the any quantum encryption channel includes at least one of the first quantum encryption channel, the second quantum encryption channel, and the third quantum encryption channel.

5. The method according to claim 4, further comprising: Destroy the wiretapped quantum encryption channel, and reconstruct a new quantum encryption channel between the same communication entities based on a new encryption method; In response to the quantum state of the new quantum encryption channel remaining unchanged before and after a preset number of consecutive test data transmission behaviors, determine that the new quantum encryption channel is in a secure transmission state without being wiretapped.

6. The method according to claim 1, wherein, When the data processing instruction is any one of a data addition instruction, a data update instruction, or a data deletion instruction, the encryption and decryption information correspondingly is encryption information, and the processing response information correspondingly is a notification information of any one of data addition completion, data update completion, or data deletion completion.

7. The method according to claim 1, wherein When the data processing instruction is a data reading instruction, the encryption and decryption information correspondingly is decryption information, and the processing response information correspondingly is a result feedback information including the read plaintext data.

8. The method according to claim 1, wherein For different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields in the registration center, corresponding secret keys are respectively set.

9. The method according to claim 8, wherein, The secret keys respectively set for different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields in the registration center are different from each other.

10. The method according to claim 8, further comprising: Determining a corresponding secret key update frequency according to the access frequencies of the database, the database, the row, the column, and the field; wherein, the secret key update frequency is proportional to the access frequency; Updating the secret keys of the corresponding part of the data according to the secret key update frequency.

11. The method according to any one of claims 8-10, wherein, The secret key includes: a symmetric key generated based on a symmetric encryption algorithm or a public key and a private key generated based on an asymmetric encryption algorithm; wherein, the public key is held by the user and is used to generate the encryption information in the encryption and decryption information, and the private key is held by the registration center and is used to decrypt the encryption information obtained after being encrypted with the supporting public key.

12. A data processing device, wherein, Applied to a middleware located between the user, the registration center, and the database, the device includes: An instruction extraction unit configured to extract a data processing instruction from an access request incoming from the user received through a first quantum encryption channel with an unchanged quantum state. A first processing unit configured to, in response to the data processing instruction indicating to store the data to be encrypted into the database, initiate a key acquisition request corresponding to the data to be encrypted to the registration center through a second quantum encryption channel, and use the key received through the second quantum encryption channel with an unchanged quantum state to perform an encryption process on the data to be encrypted, obtaining a rewritten instruction including the encrypted information; sending the rewritten instruction to the database through a third quantum encryption channel, and receiving a processing response information returned by the third quantum encryption channel with an unchanged quantum state. A second processing unit configured to, in response to the data processing instruction indicating to read the encrypted data stored in the database, send a rewritten data processing instruction to the database through the third quantum encryption channel, and receive the encrypted data returned by the third quantum encryption channel with an unchanged quantum state; initiate a key acquisition request corresponding to the encrypted data to the registration center through the second quantum encryption channel, and use the key received through the second quantum encryption channel with an unchanged quantum state to perform a decryption process on the encrypted data, and return the decrypted data to the user.

13. The device according to claim 12, further comprising: An identity information extraction unit, configured to extract the identity information of the user from the access request before extracting a data processing instruction from the access request; An actual access permission determination unit, configured to determine an actual access permission corresponding to the identity information; An extraction data processing instruction step execution unit, configured to execute the step of extracting a data processing instruction from the access request in response to the actual access permission including an access permission to the middleware.

14. The apparatus according to claim 13, wherein, The actual access permission determination unit is further configured to: Initiate a permission query request corresponding to the identity information to the registration center through the second quantum encryption channel; Determine the actual access permission by using a permission query result received through the second quantum encryption channel in which the quantum state has not changed.

15. The apparatus according to claim 12, further comprising: An eavesdropping determination and processing unit, configured to determine that a corresponding quantum encryption channel has been eavesdropped and discard data received or sent through the corresponding quantum encryption channel in response to a change in the quantum state of the corresponding quantum encryption channel before and after a data sending or data receiving behavior through any quantum encryption channel; wherein, the any quantum encryption channel includes at least one of the first quantum encryption channel, the second quantum encryption channel, and the third quantum encryption channel.

16. The apparatus according to claim 15, further comprising: A destruction and reconstruction unit, configured to destroy an eavesdropped quantum encryption channel and reconstruct a new quantum encryption channel between the same communication entities based on a new encryption method; A new quantum encryption channel security determination unit, configured to determine that the new quantum encryption channel is in a secure transmission state without being eavesdropped in response to the quantum state of the new quantum encryption channel not changing before and after a preset number of consecutive test data transmission behaviors.

17. The device according to claim 12, wherein, When the data processing instruction is any one of a data addition instruction, a data update instruction, or a data deletion instruction, the encryption and decryption information corresponds to encryption information, and the processing response information corresponds to a notification information of any one of data addition completed, data update completed, or data deletion completed.

18. The apparatus according to claim 12, wherein When the data processing instruction is a data reading instruction, the encryption and decryption information corresponds to decryption information, and the processing response information corresponds to a result feedback information including the read plaintext data.

19. The apparatus according to claim 12, wherein, The registration center is provided with corresponding keys for different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields, respectively.

20. The apparatus according to claim 19, wherein, The keys respectively set for different databases, different data tables in the database, different rows in the data table, different columns in the data table, and different fields of the registration center are different from each other.

21. The apparatus according to claim 19, further comprising: A key update frequency determination unit, configured to determine a corresponding key update frequency according to the access frequencies of the database, the database, the row, the column, and the field; wherein, the key update frequency is proportional to the access frequency. A key update unit, configured to update the key of the corresponding part of the data according to the key update frequency.

22. The apparatus according to any one of claims 19-21, wherein, The key includes: a symmetric key generated based on a symmetric encryption algorithm or a public key and a private key generated based on an asymmetric encryption algorithm; wherein, the public key is held by the user and is used to generate the encryption information in the encryption and decryption information, and the private key is held by the registration center and is used to decrypt the encryption information obtained after being encrypted with the matching public key.

23. An electronic device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the data processing method according to any one of claims 1-11.

24. A non-transitory computer-readable storage medium storing computer instructions, the computer instructions being used to cause the computer to execute the data processing method according to any one of claims 1-11.

25. A computer program product, comprising a computer program, the computer program realizing the steps of the data processing method according to any one of claims 1-11 when executed by a processor.

Citation Information

Patent Citations

  • Eavesdropping detection methods, data transmission methods, devices and systems

    CN107370546A

  • Dual-channel information transmission method oriented to quantum key distribution

    CN109150518A