A large database algorithm based on double factor encryption and decryption

By using two-factor encryption and decryption algorithm in the database, combined with content encryption and structure encryption technology, the problem of data leakage and low security in the medical industry of domestic databases is solved, and a higher level of database security and data protection effect is achieved.

CN118690413BActive Publication Date: 2025-05-09WUHAN MAJOR TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411157236.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-22
Publication Date
2025-05-09
Estimated Expiration
2044-08-22

AI Technical Summary

Technical Problem

Domestic databases have problems with data leakage and low system security in the medical industry, especially when facing hacker attacks, existing encryption methods are difficult to effectively protect data security.

Method used

A large database algorithm based on two-factor encryption and decryption is adopted to ensure the security of data during transmission and storage through content encryption, structure encryption and two-factor encryption and decryption technologies. The algorithm includes character, numerical, time and date data content encryption, file structure encryption and user identity verification to ensure the integrity and security of the data.

Benefits of technology

It improves the security of the database, reduces the risk of data leakage, realizes encryption of the data file structure, enhances the access efficiency of the system, and realizes isolation management of users in different units through key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118690413B_ABST
    Figure CN118690413B_ABST
Patent Text Reader

Abstract

The present invention relates to a large database algorithm based on double-factor encryption and decryption, belonging to the field of database technology, including content encryption and file structure encryption processing of the personal information part in the medical database file, realizing the safe storage of the database file written to the disk; when reading the database file, using parallel processing and buffer processing technology to realize the storage of personal information and public information in different buffers, and performing corresponding decryption processing on the personal information to obtain the original user record data. The present invention is compatible with traditional SQL statement query and segmented full-text search processing, realizing fast memory to disk and disk to memory data conversion. The present invention solves the problem of data security management and control of disk and memory buffer, improves the security of the database, and reduces the risk of data leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of databases, and in particular to a large database algorithm based on double-factor encryption and decryption. Background Art

[0002] As a key research topic in information security, data security has always been a hot topic of concern to many scholars, software practitioners and even ordinary people. With the wave of localization sweeping in, domestic operating systems based on LINUX and domestic databases based on MYSQL and POSTGRESQL are gradually being accepted by the public.

[0003] Medical informationization concerns the life, health and safety of everyone. Not only is the amount of data large, but also the security requirements are relatively high. This requires in-depth research on the database security of the medical industry. Because the domestic database is in the early stages of development, there are still data leaks in the data security industry, the system security factor is low, and data is often attacked by hackers. There are currently three main ways to encrypt data: encryption in the system, encryption on the client (DBMS outer layer), and encryption on the server (DBMS kernel layer). Both server-side and client-side encryption encrypt data content. The advantage of client-side encryption is that it will not increase the load on the database server, and it can realize online transmission encryption. This encryption method is usually implemented using database outer layer tools; server-side encryption requires operations on the database management system itself, which is core layer encryption. Without the cooperation of the database developer, its implementation is relatively difficult. Summary of the invention

[0004] The present invention is proposed to alleviate or solve at least one aspect or at least one point of the above problems.

[0005] A large database algorithm based on dual-factor encryption and decryption of the present invention comprises the following steps:

[0006] S1: Obtain content encryption factors from user record data of character type, numerical type, and time and date type through content encryption algorithm;

[0007] S2: Processing the file storing the content encryption factor through a text compression algorithm to obtain a compressed file and compression information;

[0008] S3: The disk sector information, the file offset information and the compression information stored in the file are subjected to a structural encryption algorithm to obtain a structural encryption factor;

[0009] S4: Processing the compressed file and the structural encryption factor through a dual-factor encryption algorithm to complete the encryption process and generate a database file;

[0010] S5: Complete user identity authentication by verifying user information and obtain the user's database access permission information;

[0011] S6: Read the database file from the disk into the memory read-write buffer;

[0012] S7: Decrypt the database file through a two-factor decryption algorithm to obtain a compressed file and a structure encryption factor;

[0013] S8: applying a structure encryption factor to a structure decryption algorithm to obtain disk sector information, file offset information and the compression information stored in the file;

[0014] S9: Obtain the content encryption factor through the disk sector information, file offset information and compression information stored in the file and the text decompression algorithm;

[0015] S10: The content encryption factor is passed through a content decryption algorithm to complete the decryption process and obtain user record data.

[0016] Preferably, the content encryption algorithm is used to process the user record data of character type, numerical type, time and date type into a unified text and then generate a content encryption factor through an encryption algorithm.

[0017] Preferably, the text compression algorithm uses a file processing algorithm in which adjacent characters share storage space, thereby saving storage space and obtaining relevant compression information.

[0018] Preferably, the structural encryption algorithm obtains the storage location of the user record data based on the disk sector information, file offset information and compression information stored in the file, and obtains the structural encryption factor after encryption.

[0019] Preferably, the content encryption algorithm and the two-factor encryption algorithm adopt symmetric encryption algorithms, including DES algorithm and AES algorithm; the structural encryption algorithm includes an asymmetric algorithm.

[0020] Preferably, the user identity authentication adopts MD5 algorithm.

[0021] Preferably, the two-factor decryption algorithm corresponds to the two-factor encryption algorithm; the structure decryption algorithm corresponds to the structure encryption algorithm, the text decompression algorithm corresponds to the text compression algorithm, and the content decryption algorithm corresponds to the content encryption algorithm.

[0022] Preferably, the compression information includes offset information of the content encryption factor stored in the text before and after compression.

[0023] Preferably, the content encryption algorithm and the two-factor encryption algorithm replace the encryption and decryption key pair to achieve separate isolation management of users from different units.

[0024] Beneficial effects of the present invention:

[0025] The present invention solves the data security control problem of disk and memory buffer. On the basis of the traditional encryption of data content only, the encryption of data file structure is added. At the same time, parallel processing and buffer processing of database data files are realized, the system access efficiency is improved, and the users of different units are separated and managed by replacing the encryption and decryption key pairs. The present invention improves the security of the database and reduces the risk of data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 The flowchart of a large database algorithm based on dual-factor encryption and decryption according to an exemplary embodiment of the present invention.

[0027] Figure 2 Schematic diagram of a content encryption algorithm according to an exemplary embodiment of the present invention.

[0028] Figure 3 It is a schematic diagram of a structural encryption algorithm of an exemplary embodiment of the present invention.

[0029] Figure 4 FIG. 4 is a schematic diagram of a two-factor encryption algorithm according to an exemplary embodiment of the present invention. DETAILED DESCRIPTION

[0030] The following description of the embodiments of the present invention with reference to the accompanying drawings is intended to explain the overall inventive concept of the present invention, and should not be construed as a limitation of the present invention. In the present invention, the same reference numerals represent the same or similar components.

[0031] The features described herein can be implemented in different forms and should not be construed as being limited to the examples described herein. Rather, the examples described herein have been provided to illustrate only some of the many possible ways to implement the methods, devices, and / or systems described herein, which will be clear after understanding the disclosure of the present invention.

[0032] Although terms such as "first", "second", and "third" may be used herein to describe various members, components, regions, layers, or portions, these members, components, regions, layers, or portions should not be limited by these terms. Instead, these terms are only used to distinguish one member, component, region, layer, or portion from another member, component, region, layer, or portion.

[0033] In the specification, when an element (such as a layer, a region, or a substrate) is described as being “on”, “connected to”, or “coupled to” another element, the element may be directly “on”, “connected to”, or “coupled to” another element, or one or more other elements may be present therebetween. Conversely, when an element is described as being “directly on”, “directly connected to”, or “directly coupled to” another element, there may be no other elements present therebetween.

[0034] The terms used herein are only used to describe various examples and are not intended to limit the disclosure. Unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. The terms "comprise", "include" and "have" indicate the presence of the described features, quantities, operations, components, elements and / or combinations thereof, but do not exclude the presence or addition of one or more other features, quantities, operations, components, elements and / or combinations thereof.

[0035] In order to enable those skilled in the art to use the contents of the present invention, the following exemplary embodiments may be provided in combination with specific application scenarios, specific systems, parameters of devices and components, and specific connection methods. However, for those skilled in the art, these embodiments are only examples, and the general principles defined herein may be applied to other embodiments and application scenarios without departing from the spirit and scope of the present invention.

[0036] According to an exemplary embodiment of the present invention, Figure 1-4 As shown, a large database algorithm based on two-factor encryption and decryption includes the following steps:

[0037] S1: Obtain content encryption factors from user record data of character type, numerical type, and time and date type through content encryption algorithm;

[0038] S2: Processing the file storing the content encryption factor through a text compression algorithm to obtain a compressed file and compression information;

[0039] S3: The disk sector information, the file offset information and the compression information stored in the file are subjected to a structural encryption algorithm to obtain a structural encryption factor;

[0040] S4: Processing the compressed file and the structural encryption factor through a dual-factor encryption algorithm to complete the encryption process and generate a database file;

[0041] S5: Complete user identity authentication by verifying user information and obtain the user's database access permission information;

[0042] S6: Read the database file from the disk into the memory read-write buffer;

[0043] S7: Decrypt the database file through a two-factor decryption algorithm to obtain a compressed file and a structure encryption factor;

[0044] S8: applying a structure encryption factor to a structure decryption algorithm to obtain disk sector information, file offset information and the compression information stored in the file;

[0045] S9: Obtain the content encryption factor through the disk sector information, file offset information and compression information stored in the file and the text decompression algorithm;

[0046] S10: The content encryption factor is passed through a content decryption algorithm to complete the decryption process and obtain user record data.

[0047] According to an exemplary embodiment of the present invention, Figure 1 , 2 As shown, the content encryption algorithm is used to uniformly process the user record data of character type, numerical type, and time and date type, and generate content encryption factors through the encryption algorithm. The data types currently supported by the database are mainly character type, numerical type, and time and date type. These data types need to be uniformly processed and encrypted after text processing.

[0048] According to an exemplary embodiment of the present invention, Figure 1 , 3 As shown, the text compression algorithm uses a file processing algorithm in which adjacent characters share storage space, saves storage space, and obtains relevant compression information. The compression ratio varies according to the character situation, and the user can also selectively compress and restore to form a personalized compression and decompression process; the compression information includes the offset information of the content encryption factor stored in the text before and after compression, so that the system can find the required data based on this information.

[0049] The structural encryption algorithm is to obtain the storage location of the user record data based on the disk sector information, file offset information and the compression information stored in the file, and obtain the structural encryption factor after encryption. The splicing storage of files is also a process from memory to disk. The file header information of the storage block can be controlled in the middle. By encrypting the file structure information stored in the file, the file information becomes ciphertext. The read and write permissions of the file control and the anti-tampering are determined by the offset algorithm control and the structural decryption algorithm control of the read information, which increases the difficulty for tamperers to modify the file.

[0050] The content encryption and two-factor encryption algorithms include symmetric encryption algorithms, including DES algorithm and AES algorithm; the structural encryption algorithms include asymmetric algorithms, including RSA algorithm, which can effectively prevent file structure information from being cracked and tampered with; the keys and encryption algorithms used in the encryption process need to comply with the basic cryptographic algorithms specified by the National Cryptography Administration Committee.

[0051] The user identity authentication adopts the MD5 algorithm. In addition to providing the user name and password, the user information may also be required to provide other relevant security credentials in accordance with the system security requirements, such as using a terminal key.

[0052] The two-factor decryption algorithm corresponds to the two-factor encryption algorithm; the structure decryption algorithm corresponds to the structure encryption algorithm, the text decompression algorithm corresponds to the text compression algorithm, and the content decryption algorithm corresponds to the content encryption algorithm. In the process of data conversion from memory to disk, writing to the database is implemented, and the data needs to be encrypted using the text compression algorithm, content encryption algorithm, structure encryption algorithm and two-factor encryption algorithm. In the process of data conversion from disk to memory, reading from the database is required, and the text decompression algorithm, content decryption algorithm, structure decryption algorithm and two-factor decryption algorithm are used.

[0053] The content encryption algorithm and the two-factor encryption algorithm replace the encryption and decryption key pair to achieve separate and isolated management of users from different units, ensuring the logical correctness of data reading and writing by multiple users, thereby taking into account both the system throughput and data isolation.

[0054] The algorithm of the present invention has a larger amount of calculation than the common database algorithm. Therefore, parallel processing and buffer processing technology are critical in the operation of the system, which can make full use of CPU resources, realize rapid processing of data input and output, and improve the operation efficiency and processing speed of the system. The present invention is compatible with traditional SQL statement query and segmented full-text search processing, and realizes rapid memory-to-disk and disk-to-memory data conversion.

[0055] Application examples:

[0056] A disease prevention and control center needs to process a large amount of information on suspected infectious diseases;

[0057] A large amount of personal information and medical information in a certain area is collected through medical software. Personal information needs to be kept confidential, and medical information needs to be publicly queried and statistically reported.

[0058] The database reading and writing logic is: first process the public data, and then separate different buffers for preprocessing.

[0059] Database writing process: For separate storage that needs to be encrypted, the files can be compressed and stored, and an asymmetric encryption algorithm can be used to prevent tampering. At the same time, the file content is encrypted. On the basis of content encryption and file structure encryption, a two-factor algorithm is used to obtain the encrypted database file and write it to the disk for storage;

[0060] Database reading process: read the database file from the disk into different buffers in the memory for storage, first perform public data processing, and for encrypted data, use the two-factor decryption algorithm, content encryption algorithm, and architecture encryption algorithm to encrypt layer by layer to obtain the original user record data before encryption;

[0061] Data is read in situ, which can be implemented with simple SQL queries and supports full-text search and lookup;

[0062] If data needs to be read off-site, it can be transferred in the form of file backup and processed with the same algorithm off-site, supporting query and full-text search.

[0063] The present invention achieves a higher level of database security by encrypting the content and structure of the database, thereby achieving the purpose of protecting privacy data.

[0064] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that changes may be made to the embodiments and combinations of elements may be made without departing from the principles and spirit of the invention, the scope of the invention being defined by the appended claims and their equivalents.

Claims

1. A large database algorithm based on two-factor encryption and decryption, characterized in that: The following steps are involved: S1: Obtain a content encryption factor by using a content encryption algorithm for user record data of character type, numerical type, and time and date type. The content encryption algorithm is used to generate a content encryption factor by using an encryption algorithm after unifying the text processing of the user record data of character type, numerical type, and time and date type; S2: Processing the file storing the content encryption factor by a text compression algorithm to obtain a compressed file and compression information, wherein the compression information includes offset information before and after the compression of the content encryption factor stored in the text; S3: The disk sector information, file offset information and the compression information stored in the file are subjected to a structural encryption algorithm to obtain a structural encryption factor; the structural encryption algorithm is to obtain the storage location of the user record data based on the disk sector information, file offset information and the compression information stored in the file, and obtain the structural encryption factor after encryption; S4: The compressed file and the structural encryption factor are processed by a two-factor encryption algorithm to complete the encryption process and generate a database file. The two-factor encryption algorithm replaces the encryption and decryption key pair to achieve separate and isolated management of users from different units and ensure the logical correctness of data reading and writing by multiple users; S5: Complete user identity authentication by verifying user information and obtain the user's database access permission information; S6: Read the database file from the disk into the memory read-write buffer; S7: Decrypt the database file through a two-factor decryption algorithm to obtain a compressed file and a structure encryption factor; S8: applying a structure encryption factor to a structure decryption algorithm to obtain disk sector information, file offset information and the compression information stored in the file; S9: Obtain the content encryption factor through the disk sector information, file offset information and compression information stored in the file and the text decompression algorithm; S10: The content encryption factor is passed through a content decryption algorithm to complete the decryption process and obtain user record data.

2. The large database algorithm based on dual-factor encryption and decryption according to claim 1 is characterized in that: The text compression algorithm uses a file processing algorithm in which adjacent characters share storage space, saves storage space, and obtains relevant compression information.

3. The large database algorithm based on dual-factor encryption and decryption according to claim 2 is characterized in that: The content encryption algorithm and the two-factor encryption algorithm adopt symmetric encryption algorithms, including the DES algorithm and the AES algorithm; the structural encryption algorithm includes an asymmetric algorithm.

4. The large database algorithm based on dual-factor encryption and decryption according to claim 3 is characterized in that: The user identity authentication adopts MD5 algorithm.

5. The large database algorithm based on dual-factor encryption and decryption according to claim 4 is characterized in that: The two-factor decryption algorithm corresponds to the two-factor encryption algorithm; the structure decryption algorithm corresponds to the structure encryption algorithm, the text decompression algorithm corresponds to the text compression algorithm, and the content decryption algorithm corresponds to the content encryption algorithm.

6. The large database algorithm based on dual-factor encryption and decryption according to claim 5 is characterized in that: The content encryption algorithm and the two-factor encryption algorithm replace the encryption and decryption key pairs to achieve separate isolation management of users from different units.

Citation Information

Patent Citations

  • Block store management for remote storage systems

    US10809920B1

  • Compression of encrypted data in database management systems

    US20080162521A1