A database security control method and system including a network partitioning function
The multi-node deployment with real-time load-based heuristic weighted round-robin load balancing addresses the instability of single-node platforms by dynamically adjusting server weights, ensuring efficient and stable distribution of database access requests across network zones.
Patent Information
- Application Number
- CN202411286049.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-13
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-09-13
AI Technical Summary
The existing database security control platform is mainly deployed in a single node, which is difficult to meet the user access requirements in multiple network partition environments, especially when there are high access volumes.
The multi-node deployment method is adopted, user requests are intercepted through an interceptor, subnet information is queried and routed to the corresponding DSC service within the subnet, and the optimal DSC service is selected for processing in combination with the load balancing algorithm, and the weight is dynamically adjusted using the heuristic optimization weighted polling load balancing algorithm based on real-time load.
It realizes more balanced allocation of request load in a multi-network partition environment, improves the overall performance and stability of the system, and avoids the problem of insufficient processing capabilities of single nodes.
Smart Images

Figure CN119249481B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a database security control method and system with a network partitioning function, and belongs to the field of database security. Background Art
[0002] With the advent of the digital age, enterprises have been paying increasing attention to database security. Although traditional database clients can connect to and operate databases, their functions in database security control are very basic. To improve the security of database use, a database security control (DSC) platform, as an effective security solution, is being used by more and more enterprises.
[0003] The use of database security control platforms is mainly distributed in multiple industries represented by the financial industry. The reason is obvious. Financial institutions often have a large amount of sensitive data, such as customer identity information, transaction records, etc. If data is leaked or illegally accessed, serious consequences may occur. Therefore, the financial industry has a particularly urgent need for database security control platforms. In addition, the medical, government, and manufacturing industries also have extensive applications for database security control platforms. Without exception, the data in these industries involves multiple aspects such as personal privacy, data security, and production processes, and all have high requirements for data security.
[0004] A database security control platform can ensure data security and privacy by identifying sensitive data, restricting access rights, and monitoring data usage. At the same time, it can also control users' access rights to sensitive data. Through measures such as identity authentication, permission management, and access auditing, it ensures that only authorized personnel can access sensitive data and system resources, realizes the monitoring of abnormal data usage behaviors, and can detect and alarm in a timely manner. In short, a database security control platform can effectively protect enterprises' data, prevent data leakage, tampering, or illegal access, and ensure data security.
[0005] Existing database security control platforms are mainly deployed in a single-node manner. This deployment method is simple in form and low in deployment difficulty, but the disadvantage is that all access requests will be submitted to this node. If the total amount of access requests is not large, a single node can withstand and process them; however, if the total amount of access requests is very large, it will exceed the processing capacity of a single node and affect the stable operation of the entire database security control platform. In addition, in the user's network environment, multiple network partitions are often divided, and the networks between different partitions may be isolated. Therefore, the single-node deployment method is difficult to meet the user access requirements in a multi-network partition environment. Brief Description of the Drawings
[0006] Figure 1 It is a flowchart of the method of the present invention. Summary of the Invention
[0007] To solve the problems existing in the prior art, the present invention proposes a database security control method and system with a network partitioning function. Network partitioning refers to dividing a large network into several smaller sub-networks, thereby improving network performance, security, and management efficiency. Network partitioning can be carried out at different levels and angles. In a common network partitioning in an IPv4 network, a large IP address range is divided into multiple subnets through subnet division, and each subnet has its own IP address range, which helps to improve network performance and reduce the size of the broadcast domain. The present invention adopts a multi-node deployment method, that is, one to multiple sets of database security control services are deployed in each network partition; when a user submits an access request, a corresponding database security control service in a selected network partition is automatically selected according to the request information to process the request.
[0008] Specifically, a database security control method with a network partitioning function includes the following steps:
[0009] (1) User request: The user submits an access request to the database security control platform through a Web browser, and the request contains the id of the target database to be accessed;
[0010] (2) Interceptor intercepts the request: The interceptor finds that the user request contains the id of the target database, queries the subnet information corresponding to the target database, and attaches the subnet information to the request;
[0011] (3) Nginx server routes the request: According to the subnet information in the above request, the request is routed to the DSC service within the corresponding subnet.
[0012] (4) Load balancing within the subnet: When the Nginx server routes the user access request to the corresponding subnet, if multiple sets of DSC services are deployed in the subnet, load balancing needs to be performed for selection calculation, and finally the optimal DSC service is determined to be provided to the user.
[0013] Further, in step (4), the load balancing process is as follows:
[0014] 4.1 Initialization: The DSC service set is S = {s1, s2,..., s n}, where n is the total number of DSC services in the subnet, s i is the i-th DSC service, 1 ≤ i ≤ n, w i is the weight of the i-th DSC service, and the initial weights are all 0.5. Set the initial weight list W = {w1, w2,..., w n}, set the current position pointer p = 1, that is, pointing to the 1st DSC service;
[0015] 4.2 Calculate the real-time load, which is divided into:
[0016] a) Calculate the load factor: For s i the CPU usage rate C of the server where it is located i , and the corresponding CPU load factor For s i the memory occupancy rate M of the server where it is located i , and the corresponding memory load factor is
[0017] b) Calculate the real-time load: The combined load factor of CPU and memory is
[0018] 4.3 Weight update: Calculate the average load The weight update strategy is where, w i ′ is the updated weight, and w i is the weight before update.
[0019] 4.4 Select the server: When w p ′ > 0.5, select the DSC service s p to process the request, where s p and w p ′ are the DSC service pointed to by the pointer p and its weight respectively; when w p ′ ≤ 0.5, move the pointer p one position backward, and repeat this step until a DSC service with a weight greater than 0.5 is found or all DSC services are traversed; if there is no DSC service with a weight greater than 0.5, select the DSC service with the highest weight;
[0020] 4.5 Process the request: Send the request to the selected DSC service s p ;
[0021] 4.6 Update the pointer: Move the pointer p one position backward. If the pointer p has reached the end of the list, reset it to the starting position of the list.
[0022] 4.7 Go back to step 4.2 to continue processing new user requests.
[0023] Based on the above method, the present invention further proposes a database security control system including a network partitioning function, and the system includes:
[0024] (1) User request module: In this module, the user submits an access request to the database security control platform through a Web browser, and the request contains the id of the target database to be accessed;
[0025] (2) Interceptor intercepts the request module: The interceptor in this module discovers that the user request module contains the ID of the target database, queries the subnet information corresponding to the target database, and attaches the subnet information to the request module;
[0026] (3) Nginx server routes the request module: This module routes the request to the DSC service within the corresponding subnet according to the subnet information in the above request module.
[0027] (4) Load balancing module within the subnet: When the Nginx server routes the user access request to the corresponding subnet, if multiple sets of DSC services are deployed in this subnet, this module performs selection calculations through load balancing and finally determines the optimal DSC service to provide to the user.
[0028] Furthermore, in the load balancing module within the subnet, the load balancing process is as follows:
[0029] 4.1 Initialization: The set of DSC services is S = {s1, s2, …, s n}, where n is the total number of DSC services within the subnet, s i is the i-th DSC service, 1 ≤ i ≤ n, w i is the weight of the i-th DSC service, the initial weights are all 0.5, set the initial weight list W = {w1, w2, …, w n}, set the current position pointer p = 1, that is, pointing to the 1st DSC service;
[0030] 4.2 Calculate the real-time load, which is divided into:
[0031] a) Calculate the load factor: For the CPU usage rate C i of the server where s i is located, the corresponding CPU load factor For the memory occupancy rate M i of the server where s i is located, the corresponding memory load factor is
[0032] b) Calculate the real-time load: The combined load factor of CPU and memory is
[0033] 4.3 Weight update: Calculate the average load The weight update strategy is Among them, w i ′ is the updated weight, and w i is the weight before update.
[0034] 4.4 Select the server: When w p ′ > 0.5, select the DSC service sp Process the request, s p and w p ′ are the DSC service pointed to by pointer p and its weight respectively; w p ′ ≤ 0.5, move the pointer p one position backward, and repeat this step until a DSC service with a weight greater than 0.5 is found or all DSC services are traversed; if there is no DSC service with a weight greater than 0.5, select the DSC service with the highest weight;
[0035] 4.5 Process the request: Send the request to the selected DSC service s p ;
[0036] 4.6 Update the pointer: Move the pointer p one position backward. If the pointer p has reached the end of the list, reset it to the starting position of the list.
[0037] 4.7 Go back to step 4.2 to continue processing new user requests.
[0038] After adopting the present invention, an heuristic optimization weighted round - robin load - balancing algorithm based on real - time load can be implemented. This algorithm dynamically adjusts the weights by calculating the actual load conditions of the servers, enabling it to better reflect the true state of the current servers and making more accurate request allocations accordingly; meanwhile, when calculating the real - time load, this algorithm uses a heuristic function to consider the comprehensive load factors of CPU and memory. This heuristic method helps to find the optimal solution faster while avoiding overly complex calculation processes; in addition, this algorithm updates the weights based on the comparison results of real - time load and average load, which can ensure more fair and efficient utilization of resources. Specific implementation manners
[0039] It can be seen from Figure 1 that the specific method steps of the present invention are as follows:
[0040] (1) User request: The user submits an access request to the database security control platform through a Web browser. The request contains the id of the target database to be accessed;
[0041] (2) Interceptor intercepts the request: The interceptor plays a role in pre - processing requests and responses in the system. When the interceptor discovers that the user request contains the id of the target database, it queries the subnet information corresponding to the target database and attaches the subnet information to the request;
[0042] (3) Nginx server routes the request: According to the subnet information in the request, the request is routed to the DSC service within the corresponding subnet. This request - based routing mechanism enables Nginx to flexibly handle complex network topologies and ensures that requests are correctly sent to the target service;
[0043] (4) Load balancing within a subnet: One or more DSC services are deployed in each subnet. When the Nginx server routes the user's access request to the corresponding subnet, if the subnet has multiple DSC services deployed, load balancing is required to select and calculate, and finally determine the optimal DSC service to provide to the user.
[0044] The specific process of the load balancing algorithm is as follows:
[0045] 1) Initialization: DSC service set S = {s1, s2, ..., s n}, where n represents the total number of DSC services in the subnet, s i represents the i-th DSC service, 1≤i≤n, w i represents the weight of the ith DSC service. The initial weights are all 0.5. Set the initial weight list W = {w1,w2,…,w n}, set the current position pointer p = 1, that is, point to the first DSC service;
[0046] 2) Real-time load calculation
[0047] Calculate the load of each DSC service server in real time;
[0048] a) Calculate the load factor:
[0049] oFor s i CPU usage of the server C i , the corresponding CPU load factor F cpu,i The function expression is When C i When the value of is small, F cpu,i The function value grows slowly, but when C i When the value of is large, F cpu,i The function value grows faster; this means that the higher the CPU load, the greater the impact on the CPU load factor. i =0.9, F cpu,i The value of is 1, which means the load factor reaches the highest;
[0050] oFor s i The memory usage of the server M i , the corresponding memory load factor F mem,i The function expression is When M i When the value of is small, F mem,i The function value grows slowly, but when M i When the value of is large, F mem,i The function value grows faster; this means that the higher the memory load, the greater the impact on the memory load factor. i =0.9, Fmem,i The value is 1, which means the load factor reaches the highest;
[0051] b) Calculate the real-time load comprehensively:
[0052] o Calculate the comprehensive load factor F of the CPU and memory i , and its calculation formula is
[0053] This function can achieve: when the load factors F cpu,i and F mem,i are both relatively small, the comprehensive load factor F i has a relatively small value; once one or even both of the load factors F cpu,i and F mem,i have relatively large values, the comprehensive load factor F i will have a relatively large value;
[0054] 3) Weight update method
[0055] Calculate the average load Its calculation formula is The weight update is based on the comparison result between the real-time load and the average load. Increase its weight when the server load is low and decrease its weight when the load is high. Accordingly, design the following weight update strategy:
[0056] Among them, w i ′ is the updated weight, and w i is the weight before update.
[0057] 4) Select a server
[0058] o If w p ′>0.5, then select the DSC service s p to process the request, where s p and w p ′ are the DSC service pointed to by the pointer p and its weight respectively;
[0059] o Otherwise, move the pointer p one position backward and repeat this step until a DSC service with a weight greater than 0.5 is found or all DSC services are traversed;
[0060] o If there is no DSC service with a weight greater than 0.5, then select the DSC service with the highest weight;
[0061] 5) Process the request
[0062] o Send the request to the selected DSC service s p for processing;
[0063] 6) Update the pointer:
[0064] o Move the pointer p one position backward. If the pointer p has reached the end of the list, reset it to the start position of the list.
[0065] 7) Go back to step 2) to continue processing new user requests
[0066] Through the above method, the heuristic optimization weighted round-robin load balancing algorithm based on real-time load can be implemented. This algorithm can dynamically adjust the weights according to the real-time performance of the server, so as to distribute the request load more evenly and improve the overall performance and stability of the system.
[0067] A more specific example:
[0068] 1) Initialization: Assume there are 3 DSC services in the subnet, named s1, s2, and s3 respectively. The initial weights are all 0.5. Therefore, initialize the weight list W = {0.5, 0.5, 0.5}, and the current position pointer p = 1.
[0069] 2) Real-time load calculation
[0070] Calculate the load of the servers where each DSC service is located in real time;
[0071] a) Calculate the load factor:
[0072] For the CPU usage rate C1 = 0.7 and memory occupancy rate M1 = 0.5 of the server where s1 is located.
[0073] For the CPU usage rate C2 = 0.3 and memory occupancy rate M2 = 0.8 of the server where s2 is located.
[0074] For the CPU usage rate C3 = 0.9 and memory occupancy rate M3 = 0.2 of the server where s3 is located.
[0075] Calculate the CPU load factors of each server:
[0076] F cpu,1 = 0.471
[0077] F cpu,2 = 0.037
[0078] F cpu,3 = 1.000
[0079] Calculate the memory load factors of each server:
[0080] F mem,1 = 0.172
[0081] F mem,2 = 0.702
[0082] F mem,3= 0.011
[0083] b) Calculate the real-time load comprehensively:
[0084] o Calculate the comprehensive load factor F of the CPU and memory i , and its calculation formula is
[0085]
[0086] Use the above formula to calculate the comprehensive load factors F1, F2, and F3 of each DSC service, and the results are respectively:
[0087] F1 = 0.245
[0088] F2 = 0.493
[0089] F3 = 1.000
[0090] 3) Weight update method
[0091] Calculate the average load The update of the weight is based on the comparison result between the real-time load and the average load. w i ′ is the updated weight, w1′ = 0.712, w2′ = 0.926, w3′ = 0.211.
[0092] 4) Select a server
[0093] o If w1′ > 0.5, select DSC service s1 to process the request;
[0094] 5) Process the request
[0095] o Send the request to the selected DSC service s1 for processing;
[0096] 6) Update the pointer:
[0097] o Move the pointer p one position backward, p = 2.
[0098] 7) Go back to step 2) to continue processing new user requests.
[0099] From the calculation results of the embodiments, it can be seen that the present invention can dynamically adjust the weight according to the real-time performance of the server, while it is difficult for some other traditional load balancing algorithms to do this. For example, some algorithms may preset fixed weight ratios, resulting in failure to respond in time when the server performance changes.
[0100] Then, the present invention can make adaptive adjustments according to the real-time load situation of the server, better balancing the load between servers. In contrast, some algorithms may only focus on a single metric, which may lead to uneven load.
[0101] In addition, each step of the algorithm of the present invention is relatively simple and clear, easy to understand and implement. Moreover, with the addition or removal of new services, only the initial weight list needs to be modified accordingly, without having to redesign the entire algorithm, which has good scalability.
[0102] The units, devices, or modules described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. For the convenience of description, when describing the above devices, they are divided into various modules according to functions and described separately. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware, or the modules implementing the same function can be realized by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0103] Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, the method steps can be logically programmed to enable the controller to be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be regarded as a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and the structures within the hardware component.
[0104] The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment, where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0105] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of this application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, mobile terminal, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0106] The various embodiments in this specification are described in a progressive manner. For the same or similar parts between the various embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. This application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on.
[0107] The specific embodiments described above have further elaborated on the purpose, technical solution, and beneficial effects of this application. It should be understood that the above are only specific embodiments of this application and are not used to limit the protection scope of this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application should be included in the protection scope of this application.
Claims
1. A database security control method including a network partitioning function, characterized in that: The method includes the following steps: (1) User request: The user submits an access request to the database security control platform through a Web browser, and the request contains the id of the target database to be accessed; (2) Interceptor intercepts the request: The interceptor finds that the user request contains the id of the target database, queries the subnet information corresponding to the target database, and attaches the subnet information to the request; (3) Nginx server routes the request: According to the subnet information in the above request, the request is routed to the DSC service within the corresponding subnet; (4) Load balancing within the subnet: When the Nginx server routes the user access request to the corresponding subnet, if multiple sets of DSC services are deployed in the subnet, load balancing needs to be performed for selection calculation, and finally the optimal DSC service is determined and provided to the user; In step (4), the load balancing process is as follows: (4.1)Initialization: The DSC service set is S = {s1, s2, …, s n}, where n is the total number of DSC services in the subnet, s i is the i-th DSC service, 1 ≤ i ≤ n, w i is the weight of the i-th DSC service, and the initial weights are all 0.
5. Set the initial weight list W = {w1, w2, …, w n}, set the current position pointer p = 1, that is, pointing to the 1st DSC service; (4.2) Calculate the real-time load, which is divided into: a) Calculate the load factor: For s i The CPU usage rate C of the server where it is located i , the corresponding CPU load factor ; For s i The memory occupancy rate M of the server where it is located i , the corresponding memory load factor is ; b) Calculate the real-time load: The combined load factor of CPU and memory is ; (4.3)Weight update: Calculate the average load , and the weight update strategy is , where is the updated weight, and w i is the weight before update; (4.4)Select server: When > 0.5, select DSC service s p Process the request, s p and are the DSC service pointed to by pointer p and its weight respectively; When ≤ 0.5, move the pointer p one position backward and repeat this step until a DSC service with a weight greater than 0.5 is found or all DSC services are traversed; if there is no DSC service with a weight greater than 0.5, select the DSC service with the highest weight; (4.5) Process the request: Send the request to the selected DSC service s p ; (4.6) Update the pointer: Move the pointer p one position backward. If the pointer p has reached the end of the list, reset it to the starting position of the list; (4.7) Go back to step (4.2) to continue processing new user requests.
2. A database security control system including a network partitioning function, characterized in that: The system includes: (1) User request module: In this module, the user submits an access request to the database security control platform through a Web browser, and the request contains the id of the target database to be accessed; (2) Interceptor intercepts request module: The interceptor in this module finds that the user request module contains the id of the target database, queries the subnet information corresponding to the target database, and attaches the subnet information to the request module; (3) Nginx server routes request module: This module routes the request to the DSC service within the corresponding subnet according to the subnet information in the above request module; (4) Load balancing within subnet module: When the Nginx server routes request module routes the user access request to the corresponding subnet, if multiple sets of DSC services are deployed in the subnet, this module performs selection calculation through load balancing, and finally determines the optimal DSC service and provides it to the user; In the load balancing within subnet module, the load balancing process is as follows: (4.1) Initialization: The DSC service set is S = {s1, s2, …, s n}, where n is the total number of DSC services in the subnet, and s i is the i-th DSC service, 1 ≤ i ≤ n, and w i is the weight of the i-th DSC service, and the initial weights are all 0.
5. Set the initial weight list W = {w1, w2, …, w n}, set the current position pointer p = 1, that is, pointing to the first DSC service; (4.2) Calculate the real-time load, which is divided into: a) Calculate the load factor: For s i CPU usage rate C of the server where it is located i , the corresponding CPU load factor ; For s i memory occupancy rate M of the server where it is located i , the corresponding memory load factor is ; b) Calculate the real-time load: The combined load factor of the CPU and memory is ; (4.3)Weight update: Calculate the average load , and the weight update strategy is , where is the updated weight, and w i is the weight before update; (4.4)Select server: When > 0.5, select DSC service s p Process the request, s p and are the DSC service pointed to by pointer p and its weight respectively; When ≤ 0.5, move the pointer p one position backward and repeat this step until a DSC service with a weight greater than 0.5 is found or all DSC services are traversed; if there is no DSC service with a weight greater than 0.5, select the DSC service with the highest weight; (4.5) Process request: Send the request to the selected DSC service s p ; (4.6) Update the pointer: Move the pointer p one position backward. If the pointer p has reached the end of the list, reset it to the starting position of the list; (4.7) Go back to step (4.2) to continue processing new user requests.
Citation Information
Patent Citations
Decentralized network service method and device, equipment and readable storage medium
CN110213114A
System with Nginx load balancing technology
CN113110933A