Quantum encryption method, quantum encryption server, and quantum encryption system

By acquiring and backing up encryption policies from a pre-defined policy platform using a quantum encryption server, the data security problem of database encryption systems during service interruptions is solved. This enables quantum encryption processing to continue even in the event of a failure, thereby improving data security and reliability.

CN119652499BActive Publication Date: 2025-12-05中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411539277.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2025-12-05
Estimated Expiration
2044-10-31

AI Technical Summary

Technical Problem

In existing technologies, database encryption systems cannot obtain encryption policies when services are interrupted, leading to data encryption failure and affecting data security.

Method used

A quantum encryption server is used to obtain the target policy from a pre-set policy platform, encrypt and back it up, encrypt database data, and use quantum key distribution technology to ensure data security.

Benefits of technology

Even in the event of a failure in the quantum encryption server or policy platform, the policy can be recovered and quantum encryption processing of the database can continue, improving the security and reliability of data encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652499B_ABST
    Figure CN119652499B_ABST
Patent Text Reader

Abstract

This application discloses a quantum encryption method, a quantum encryption server, and a quantum encryption system for databases. The method includes: obtaining a target policy from a preset policy platform, the preset policy platform being configured to provide a policy for quantum encryption processing of the database; encrypting the target policy to obtain an encrypted target policy, and backing up the encrypted target policy; and performing quantum encryption processing on the database according to the target policy or the encrypted target policy. Thus, by using quantum key distribution technology, database encryption is achieved, making the encryption process more secure. Furthermore, because the quantum encryption server performs real-time backup of the encrypted target policy, even if the quantum encryption server or policy platform fails, the policy can be recovered and quantum encryption processing of the database can continue.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of quantum programming, and more particularly, to a quantum encryption method for a database, a quantum encryption server, and a quantum encryption system. BACKGROUND

[0002] In the digital world, the importance of data is increasingly high. In the related art, in order to protect data, a database encryption method is usually used. However, once the system service is interrupted, the corresponding strategy cannot be obtained, resulting in failure of data encryption and affecting the security of data. SUMMARY

[0003] The present application provides a quantum encryption method for a database, a quantum encryption server, and a quantum encryption system.

[0004] The present application provides a quantum encryption method for a database, a quantum encryption server, and a quantum encryption system.

[0005] The target strategy is obtained from a preset strategy platform configured to provide a strategy for quantum encryption processing of the database;

[0006] The target strategy is encrypted to obtain an encrypted target strategy, and the encrypted target strategy is backed up;

[0007] The database is subjected to the quantum encryption processing according to the target strategy or the encrypted target strategy.

[0008] Thus, the present application provides a quantum encryption method for a database. First, the quantum encryption server obtains a target strategy from a preset strategy platform configured to provide a strategy for quantum encryption processing of the database. Then, the quantum encryption server encrypts the target strategy to obtain an encrypted target strategy, and backs up the encrypted target strategy. Finally, the quantum encryption server subjects the database to quantum encryption processing according to the target strategy or the encrypted target strategy. In this way, the quantum key distribution technology is used to encrypt the database, making the encryption process more secure. Moreover, the quantum encryption server backs up the encrypted target strategy in real time, so that even if the quantum encryption server or the strategy platform fails, the strategy can be restored and the quantum encryption processing of the database can continue.

[0009] In some embodiments, the preset strategy platform is configured by the following steps:

[0010] Based on a preset deployment document, a strategy platform corresponding to the preset deployment document is constructed;

[0011] The strategy platform is configured based on a preset platform configuration file, and the preset strategy platform is obtained.

[0012] Thus, first, a strategy platform corresponding to a preset deployment document is constructed based on the preset deployment document, and the deployment document provides detailed guidance and steps for constructing the strategy platform. Then, the strategy platform is configured based on a preset platform configuration file, and the preset strategy platform is obtained, and the preset platform configuration file includes all parameters and settings required for the preset strategy platform to run. In this way, by configuring the deployed strategy platform, it is ensured that the strategy platform can work as expected to provide strategies for quantum encryption processing of the database.

[0013] In some embodiments, the strategy platform is configured based on a preset platform configuration file to obtain a preset strategy platform, including:

[0014] According to the preset platform configuration file, a server identifier corresponding to the database is configured to obtain a temporary strategy platform, and the server identifier is used to indicate an application server for quantum encryption processing of the database.

[0015] According to the preset platform configuration file, the sensitive table and the sensitive field of the database are determined.

[0016] According to the preset platform configuration file, the strategy for quantum encryption processing of the sensitive table and the sensitive field is configured to obtain the preset strategy platform.

[0017] Thus, first, according to the preset platform configuration file, a server identifier corresponding to the database is configured to obtain a temporary strategy platform, and the server identifier is used to indicate an application server for quantum encryption processing of the database. Then, according to the preset platform configuration file, the sensitive table and the sensitive field of the database are determined. Finally, according to the preset platform configuration file, the strategy for quantum encryption processing of the sensitive table and the sensitive field is configured to obtain the preset strategy platform. In this way, the preset strategy platform is obtained, which can provide strategies for quantum encryption processing of the database. These strategies define how to encrypt sensitive data in the database at the quantum level and how to manage the encryption process. The preset strategy platform is the basis for the quantum encryption server to perform quantum encryption processing.

[0018] In some embodiments, the method further includes:

[0019] A quantum encryption and decryption plug-in is constructed according to the obtained preset plug-in configuration file, and the preset plug-in configuration file includes a server identifier.

[0020] Thus, first, the quantum encryption server constructs a quantum encryption and decryption plug-in according to the obtained preset plug-in configuration file, the preset plug-in configuration file including all parameters and settings required for constructing the plug-in, and the server identifier is included. In this way, the quantum encryption server can construct and configure a quantum encryption and decryption plug-in, which can perform quantum-level encryption and decryption on sensitive data in the database.

[0021] In some embodiments, the target policy is obtained from the preset policy platform, including:

[0022] According to the server identifier, the target policy is obtained from the preset policy platform.

[0023] Thus, according to the server identifier, the quantum encryption server obtains the target policy from the preset policy platform. In this way, the quantum encryption server can ensure that only the correct application server obtains the appropriate encryption policy, thereby ensuring that the data in the database is encrypted at the quantum level according to the established security standards.

[0024] In some embodiments, the target policy is encrypted to obtain an encrypted target policy, and the encrypted target policy is backed up, including:

[0025] The target policy is encrypted based on the quantum encryption and decryption plug-in and a preset encryption algorithm to obtain the target encryption policy;

[0026] The target encryption policy is backed up at a target location.

[0027] Thus, first, based on the quantum encryption and decryption plug-in and a preset encryption algorithm, the quantum encryption server encrypts the target policy to obtain the target encryption policy. Next, the quantum encryption server backs up the target encryption policy at a target location. In this way, the quantum encryption server not only protects the security of the target policy, but also ensures the persistence and reliability of the policy. In the event of any failure or data loss, the backed up policy can be quickly recovered to maintain business continuity and data security. In addition, by encrypting the target policy, the target policy remains secure even if it is leaked.

[0028] In some embodiments, the quantum encryption processing of the database according to the target policy or the encrypted target policy includes:

[0029] In the case where the application server corresponding to the server identifier is running normally, the quantum encryption processing of the database according to the target policy is performed based on the quantum encryption and decryption plug-in.

[0030] Thus, in the case that the application server corresponding to the server identifier is running normally, the quantum encryption server performs quantum encryption processing on the database according to the target policy based on the quantum encryption and decryption plug-in. In this way, the quantum encryption server can ensure that the sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage, thereby enhancing the confidentiality of the sensitive data in the database.

[0031] In some embodiments, the quantum encryption processing on the database according to the target policy based on the quantum encryption and decryption plug-in includes:

[0032] obtaining a quantum key from a key management platform of the preset policy platform;

[0033] performing encryption processing on the sensitive table and the sensitive field according to the target policy and the quantum key based on the quantum encryption and decryption plug-in, so as to implement the quantum encryption processing on the database.

[0034] Thus, first, the quantum encryption server obtains a quantum key from a key management platform of the preset policy platform. Then, the quantum encryption server performs encryption processing on the sensitive table and the sensitive field according to the target policy and the quantum key based on the quantum encryption and decryption plug-in, so as to implement the quantum encryption processing on the database. In this way, the quantum encryption server can ensure that the sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage, thereby enhancing the confidentiality of the sensitive data in the database.

[0035] In some embodiments, the quantum encryption processing on the database according to the target policy or the encryption target policy includes:

[0036] In the case that the application server is running abnormally, performing the quantum encryption processing on the database according to the encryption target policy based on the quantum encryption and decryption plug-in.

[0037] Thus, in the case that the application server is running abnormally, the quantum encryption server performs quantum encryption processing on the database according to the encryption target policy based on the quantum encryption and decryption plug-in. In this way, the quantum encryption server can ensure that the sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage, even in the case that the application server is running abnormally.

[0038] In some embodiments, the quantum encryption processing on the database according to the encryption target policy based on the quantum encryption and decryption plug-in includes:

[0039] obtaining the encryption target policy;

[0040] decrypt the encryption target policy to obtain the target policy;

[0041] obtain a quantum key from a key management platform of the preset policy platform;

[0042] based on the quantum encryption and decryption plug-in, encrypt the sensitive table and the sensitive field according to the target policy and the quantum key to implement the quantum encryption processing on the database.

[0043] In this way, first, the quantum encryption server obtains an encryption target policy. Next, the quantum encryption server decrypts the encryption target policy to obtain a target policy. Then, the quantum encryption server obtains a quantum key from a key management platform of a preset policy platform. Finally, the quantum encryption server encrypts the sensitive table and the sensitive field according to the target policy and the quantum key based on the quantum encryption and decryption plug-in to implement the quantum encryption processing on the database. In this way, the quantum encryption server can ensure that the sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage.

[0044] The application embodiment provides a quantum encryption server, which comprises a memory and a processor, and the memory stores a computer program.

[0045] The application embodiment provides a quantum encryption system, which comprises the quantum encryption server, a quantum database encryption policy platform and a database.

[0046] The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, and the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing on the database.

[0047] The quantum encryption and decryption plug-in is configured to encrypt the target policy to obtain an encryption target policy, and backup the encryption target policy.

[0048] The quantum encryption and decryption plug-in is configured to perform the quantum encryption processing on the database according to the target policy or the encryption target policy.

[0049] Thus, the embodiment of the present application provides a quantum encryption system, which comprises a quantum encryption server, a quantum database encryption strategy platform and a database. The quantum encryption server is configured to obtain a target strategy from the quantum database encryption strategy platform, and the quantum database encryption strategy platform is configured to provide a strategy for quantum encryption processing of the database. A quantum encryption and decryption plug-in is configured to encrypt the target strategy to obtain an encrypted target strategy, and backup the encrypted target strategy. The quantum encryption and decryption plug-in is configured to perform quantum encryption processing on the database according to the target strategy or the encrypted target strategy. In this way, through quantum key distribution technology, encryption of the database is realized, so that the encryption process is more secure. Moreover, since the quantum encryption server will backup the encrypted target strategy in real time, even in the case of failure of the quantum encryption server or the strategy platform, the strategy can be restored and the quantum encryption processing of the database can continue.

[0050] Additional aspects and advantages of the embodiments of the present application will be in part apparent and in part pointed out hereinafter. BRIEF DESCRIPTION OF DRAWINGS

[0051] The above and / or additional aspects and advantages of the present application will become apparent and be readily appreciated from the following description, including the appended drawings.

[0052] Figure 1 is one of the flowcharts of the quantum encryption method according to some embodiments of the present application;

[0053] Figure 2 is a structural schematic diagram of the quantum encryption system according to some embodiments of the present application;

[0054] Figure 3 is another flowchart of the quantum encryption method according to some embodiments of the present application;

[0055] Figure 4 is a third flowchart of the quantum encryption method according to some embodiments of the present application;

[0056] Figure 5 is a fourth flowchart of the quantum encryption method according to some embodiments of the present application;

[0057] Figure 6 is a fifth flowchart of the quantum encryption method according to some embodiments of the present application;

[0058] Figure 7 is a sixth flowchart of the quantum encryption method according to some embodiments of the present application;

[0059] Figure 8 is a seventh flowchart of the quantum encryption method according to some embodiments of the present application;

[0060] Figure 9 Figure 8 is a flowchart of a quantum encryption method according to some embodiments of the present application;

[0061] Figure 10 Figure 9 is a flowchart of a quantum encryption method according to some embodiments of the present application;

[0062] Figure 11 Figure 10 is a flowchart of a quantum encryption method according to some embodiments of the present application;

[0063] Figure 12 Figure 11 is a schematic diagram of a quantum encryption system according to some embodiments of the present application. DETAILED DESCRIPTION

[0064] Embodiments of the present application are described in detail below with reference to the accompanying drawings, in which like reference numerals refer to like elements or elements with similar functions throughout the description. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the embodiments of the present application, and should not be understood as limiting the embodiments of the present application.

[0065] In the digital world, the importance of data is increasingly prominent, becoming the core asset of enterprise operation and development. These data include personal information, financial data, business secrets, etc. If these data are stolen, it will cause significant harm to individuals, enterprises and even the entire society.

[0066] In order to protect these valuable data, enterprises usually use database encryption to ensure the security of data during storage and transmission. In related technologies, database encryption is based on application encryption and decryption plug-ins to analyze the sql of business, to realize encryption and decryption of sensitive fields, so that even if the data is illegally obtained, it cannot be easily interpreted, thereby effectively preventing data leakage and misuse.

[0067] First, the user configures policy information such as data source, encrypted table, and encrypted field on the policy platform. When the business application system starts, the encryption and decryption plug-in is automatically initialized, which will call the policy platform query policy interface through an http request to obtain the application policy information. Then, the policy information is cached in the memory of the business application system, and a corresponding listener is created to dynamically obtain policy changes.

[0068] However, in real-world applications, the business application system may experience service interruptions, such as server failure, network problems, etc. of the business application system, resulting in the inability to obtain the corresponding encryption policy. In this case, if the database encryption completely relies on normal system services, then once the service is interrupted, the data encryption may fail, thereby affecting the security of the data.

[0069] Based on the above problems, referring to Figure 1 The embodiment of the application provides a quantum encryption method for a database, and the method comprises the following steps:

[0070] 011: obtaining a target policy from a preset policy platform;

[0071] 012: encrypting the target policy to obtain an encrypted target policy, and backing up the encrypted target policy;

[0072] 013: performing quantum encryption processing on the database according to the target policy or the encrypted target policy.

[0073] The embodiment of the application further provides a quantum encryption server comprising a memory and a processor. The quantum encryption method for a database according to the embodiment of the application can be implemented by the quantum encryption server according to the embodiment of the application. Specifically, the memory stores a computer program, and the processor is configured to obtain a target policy from a preset policy platform, encrypt the target policy to obtain an encrypted target policy, back up the encrypted target policy, and perform quantum encryption processing on the database according to the target policy or the encrypted target policy.

[0074] The embodiment of the application further provides a quantum encryption system. The quantum encryption method for a database according to the embodiment of the application can be implemented by the quantum encryption system according to the embodiment of the application. Specifically, the quantum encryption system comprises a quantum encryption server and a quantum encryption and decryption plug-in. The quantum encryption server is configured to obtain a target policy from a preset policy platform. The quantum encryption and decryption plug-in is capable of encrypting the target policy to obtain an encrypted target policy, and backing up the encrypted target policy. The quantum encryption and decryption plug-in is capable of performing quantum encryption processing on the database according to the target policy or the encrypted target policy.

[0075] Specifically, the database refers to a database used for quantum database encryption.

[0076] Quantum database encryption refers to a method for protecting the security of data in a database by using quantum computing principles and technologies, combining quantum key distribution technology, quantum random number generation technology and other quantum encryption technologies to provide higher security than traditional encryption methods.

[0077] Quantum key distribution technology refers to a mechanism for establishing a secure key exchange between two communicating parties by using quantum mechanics. Since any measurement of a quantum state will change the quantum state, any attempt at eavesdropping will be immediately discovered, thereby ensuring the secure exchange of the key.

[0078] Quantum random number generation technology refers to the use of quantum phenomena such as quantum entanglement or quantum tunneling by quantum random number generators to generate truly random numbers that can be used as encryption keys, making the encryption process more difficult to predict and crack.

[0079] Pre-set policy platform refers to a management system that integrates various security policies and rules, providing security configuration and policy management for various applications and services. The pre-set policy platform allows administrators to define and configure various security policies, such as the selection of encryption algorithms, key management rules, access control policies, and more.

[0080] Target policy refers to the policy information corresponding to the quantum encryption server used by the user.

[0081] Quantum encryption server refers to a server used to implement quantum database encryption technology, which uses the principles of quantum mechanics to encrypt databases, providing theoretically unbreakable encryption security.

[0082] Quantum encryption processing refers to the method of encrypting the database that needs to be encrypted based on quantum database encryption technology.

[0083] Please refer to Figure 2 , Figure 2 is a structural diagram of a quantum encryption system. The quantum encryption system includes a quantum encryption server, a quantum database encryption policy platform, and a database. The quantum encryption server is the server that performs the actual encryption operation. The quantum encryption server integrates quantum encryption technology, providing higher security than traditional encryption methods. The quantum encryption server integrates quantum encryption and decryption plugins that provide encryption-related functions such as data encryption and decryption.

[0084] The quantum database encryption policy platform receives table structure information from the database and interacts with the quantum encryption server through encryption and decryption plugins. The quantum database encryption policy platform includes encryption algorithms for quantum databases, key management rules, and encryption policies. The quantum database encryption policy platform includes a policy platform and a key management platform, which is used to manage and distribute keys. The key management platform includes key generation, storage, distribution, rotation, and destruction functions to ensure the security and compliance of the keys.

[0085] The database is directly connected to the quantum encryption and decryption plugin, implying that all data stored in the database will be encrypted by the plugin. The database may include business data, user data, and other sensitive information, so it needs to be encrypted to protect the security of the data.

[0086] The quantum encryption server first obtains a target policy from a preset policy platform. The preset policy platform is configured to provide policies for quantum encryption processing of the database, which can include selection of encryption algorithms, key management rules, encryption levels, etc.

[0087] Then, the quantum encryption server encrypts the obtained target policy to obtain an encrypted target policy, so as to protect the policy itself from unauthorized access. The encrypted target policy is backed up to prevent loss or damage of the policy.

[0088] Finally, the quantum encryption server performs quantum encryption processing on the database according to the target policy or the encrypted target policy.

[0089] In summary, the embodiments of the present application provide a quantum encryption method for a database, a quantum encryption server and a quantum encryption system. First, the quantum encryption server obtains a target policy from a preset policy platform. The preset policy platform is configured to provide policies for quantum encryption processing of the database. Then, the quantum encryption server encrypts the target policy to obtain an encrypted target policy, and backs up the encrypted target policy. Finally, the quantum encryption server performs quantum encryption processing on the database according to the target policy or the encrypted target policy. In this way, through quantum key distribution technology, the database is encrypted, making the encryption process more secure. Moreover, since the quantum encryption server backs up the encrypted target policy in real time, even if the quantum encryption server or the policy platform fails, the policy can be restored and the quantum encryption processing of the database can continue.

[0090] Please refer to Figure 3 In some embodiments, the preset policy platform is configured by the following steps:

[0091] 021: Based on the preset deployment document, a policy platform corresponding to the preset deployment document is constructed;

[0092] 022: Based on the preset platform configuration file, the policy platform is configured to obtain the preset policy platform.

[0093] Specifically, the preset deployment document refers to a document that provides detailed guidance and steps for constructing a policy platform.

[0094] The preset platform configuration file refers to a file that includes all parameters and settings required for the operation of the policy platform, such as database connection information, selection of encryption algorithms, key management rules, etc.

[0095] First, the quantum encryption server constructs a policy platform according to the preset deployment document, including installing necessary software and hardware components, and setting the initial configuration of the policy platform.

[0096] Next, the quantum encryption server configures the policy platform using the preset platform configuration file. By configuring the policy platform, the quantum encryption server can ensure that the policy platform works as expected, thereby obtaining a preset policy platform.

[0097] The preset policy platform is a configured policy platform that can provide policies for quantum encryption processing of the database. These policies define how to encrypt data in the database and how to manage the encryption process. The preset policy platform is the basis for the quantum encryption server to perform quantum encryption processing.

[0098] In this way, by configuring the deployed policy platform, the policy platform can work as expected to provide policies for quantum encryption processing of the database.

[0099] Referring to Figure 4 In some embodiments, step 022 (configuring the policy platform based on the preset platform configuration file to obtain a preset policy platform) includes:

[0100] 0221: According to the preset platform configuration file, configure the server identifier corresponding to the database to obtain a temporary policy platform;

[0101] 0222: According to the preset platform configuration file, determine the sensitive tables and sensitive fields of the database;

[0102] 0223: According to the preset platform configuration file, configure the policy for quantum encryption processing of the sensitive tables and sensitive fields to obtain a preset policy platform.

[0103] Specifically, the server identifier is used to distinguish different quantum encryption servers, ensuring that the quantum encryption server can perform quantum encryption processing on the target database according to the correct policy information. For example, the unique IP address of the quantum encryption server, the host name of the quantum encryption server, and the universally unique identifier of the quantum encryption server, etc.

[0104] First, according to the preset platform configuration file, configure the quantum encryption server identifier corresponding to the database. This identifier is used to indicate the quantum encryption server responsible for quantum encryption processing of the database.

[0105] Next, according to the preset platform configuration file, determine the sensitive tables and sensitive fields in the database. Sensitive tables and sensitive fields refer to database tables and fields that store sensitive information and need special protection, involving analysis of the database structure and identification of tables and fields that need to be encrypted according to the importance and sensitivity of the data.

[0106] Finally, the quantum encryption server configures the strategy for quantum encryption processing of sensitive tables and fields according to the preset platform configuration file, including selecting appropriate quantum encryption algorithms, setting encryption key management rules, and defining encryption levels. Through this process, the quantum encryption server can ensure that sensitive data is protected at the highest level during storage and transmission, thereby obtaining the preset strategy platform.

[0107] In this way, the preset strategy platform is obtained, which can provide strategies for quantum encryption processing of databases. These strategies define how to perform quantum-level encryption of sensitive data in the database and how to manage the encryption process. The preset strategy platform is the basis for the quantum encryption server to perform quantum encryption processing.

[0108] Referring to Figure 5 In some embodiments, the method further comprises:

[0109] 014: Constructing a quantum encryption and decryption plug-in according to the obtained preset plug-in configuration file.

[0110] In some embodiments, the quantum encryption system can also construct a quantum encryption and decryption plug-in according to the obtained preset plug-in configuration file.

[0111] In some embodiments, the processor is further configured to construct a quantum encryption and decryption plug-in according to the obtained preset plug-in configuration file.

[0112] Specifically, the preset plug-in configuration file refers to a file that includes all parameters and settings required to construct a quantum encryption and decryption plug-in, including server identification, etc.

[0113] The quantum encryption server constructs a quantum encryption and decryption plug-in according to the obtained preset plug-in configuration file. In some embodiments, the steps of constructing the quantum encryption and decryption plug-in include:

[0114] First, the quantum encryption server reads the preset plug-in configuration file, which contains the information required to construct and configure the quantum encryption and decryption plug-in. Second, according to the parameters and settings in the configuration file, the quantum encryption server generates the code of the quantum encryption and decryption plug-in. Third, the quantum encryption server compiles the generated plug-in code into an executable file and deploys it to the quantum encryption server. In this way, the quantum encryption server can use this plug-in to perform quantum encryption processing on the database.

[0115] In this way, the quantum encryption server can construct and configure a quantum encryption and decryption plug-in that can perform quantum-level encryption and decryption of sensitive data in the database.

[0116] Referring to Figure 6In some embodiments, the step 011 (obtaining the target policy from the preset policy platform) comprises:

[0117] 0111: obtaining the target policy from the preset policy platform according to the server identification.

[0118] In some embodiments, the quantum encryption server is configured to obtain the target policy from the preset policy platform according to the server identification.

[0119] In some embodiments, the processor is further configured to obtain the target policy from the preset policy platform according to the server identification.

[0120] Specifically, the quantum encryption server first connects the preset policy platform with its own identification. Once connected to the policy platform, the quantum encryption server obtains the corresponding target policy according to the server identification. In some embodiments, after obtaining the target policy, the quantum encryption server may verify the validity of the target policy to ensure that the target policy is the latest and suitable for the current application server and database environment. And prepare for the execution of the target policy, including parsing the policy content, setting the encryption algorithm, preparing the encryption key, etc.

[0121] In this way, the quantum encryption server can ensure that only the correct application server obtains the appropriate encryption policy, thereby ensuring that the data in the database is encrypted at the quantum level according to the established security standards.

[0122] Please refer to Figure 7 In some embodiments, the step 012 (encrypting the target policy to obtain an encrypted target policy and backing up the encrypted target policy) comprises:

[0123] 0121: encrypting the target policy based on the quantum encryption and decryption plug-in and the preset encryption algorithm to obtain a target encrypted policy;

[0124] 0122: backing up the target encrypted policy to a target location.

[0125] In some embodiments, the quantum encryption and decryption plug-in is configured to encrypt the target policy based on the quantum encryption and decryption plug-in and the preset encryption algorithm to obtain a target encrypted policy. And backup the target encrypted policy to a target location.

[0126] In some embodiments, the processor is further configured to encrypt the target policy based on the quantum encryption and decryption plug-in and the preset encryption algorithm to obtain a target encrypted policy. And backup the target encrypted policy to a target location.

[0127] Specifically, the target location refers to a secure location for storing the target encrypted policy.

[0128] The preset encryption algorithm refers to a symmetric encryption algorithm, which is an encryption technology in which the same key is used for data encryption and decryption, including AES encryption algorithm, DES encryption algorithm, and 3DES encryption algorithm, etc.

[0129] Using the preset encryption algorithm and the quantum encryption and decryption plug-in, the quantum encryption server encrypts the target policy. The target policy is a set of defined rules and parameters that indicate how the quantum encryption server processes quantum encryption of data in the database. Through encryption processing, the target policy is converted into a target encryption policy, which can only be correctly decrypted and executed through the quantum encryption and decryption plug-in. Then, the quantum encryption server backs up the target encryption policy to the target location.

[0130] In this way, the quantum encryption server not only protects the security of the target policy, but also ensures the persistence and reliability of the policy. In the event of any failure or data loss, the backed up policy can be quickly recovered to maintain business continuity and data security. In addition, by encrypting the target policy, it is ensured that even if the target encryption policy is leaked, the target policy remains secure.

[0131] See Figure 8 In some embodiments, step 013 (quantum encryption processing of the database according to the target policy or the encrypted target policy) comprises:

[0132] 0131: In the case where the application server corresponding to the server identifier is running normally, quantum encryption processing of the database according to the target policy based on the quantum encryption and decryption plug-in.

[0133] In some embodiments, the quantum encryption and decryption plug-in is used for quantum encryption processing of the database according to the target policy based on the quantum encryption and decryption plug-in in the case where the application server corresponding to the server identifier is running normally.

[0134] In some embodiments, the processor is further configured to perform quantum encryption processing of the database according to the target policy based on the quantum encryption and decryption plug-in in the case where the application server corresponding to the server identifier is running normally.

[0135] Specifically, the application server refers to the quantum encryption server selected by the user.

[0136] The quantum encryption server first checks the running state of the application server corresponding to the server identifier. When the application server is running normally, and the quantum encryption and decryption plug-in has been correctly installed on the application server and is in a usable state. Then, the quantum encryption server parses the target policy to extract the parameters and rules required for encryption. These policies define how to perform quantum encryption on sensitive data in the database, including selecting which encryption algorithm to use, how to manage encryption keys, and so on.

[0137] Finally, based on the quantum encryption and decryption plug-in and the target policy, the quantum encryption server performs quantum encryption on sensitive data in the database.

[0138] In this way, the quantum encryption server can ensure that sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage, thereby enhancing the confidentiality of sensitive data in the database.

[0139] For details, please refer to Figure 9 In some embodiments, step 0131 (performing quantum encryption on the database based on the quantum encryption and decryption plug-in and the target policy) includes:

[0140] 01311: obtaining a quantum key from a key management platform connected to the preset policy platform;

[0141] 01312: performing encryption processing on the sensitive table and the sensitive field based on the quantum encryption and decryption plug-in and the target policy and the quantum key, to implement quantum encryption processing on the database.

[0142] In some embodiments, the quantum encryption and decryption plug-in is further configured to obtain a quantum key from a key management platform connected to the preset policy platform, and perform encryption processing on the sensitive table and the sensitive field based on the quantum encryption and decryption plug-in and the target policy and the quantum key, to implement quantum encryption processing on the database.

[0143] In some embodiments, the processor is further configured to obtain a quantum key from a key management platform connected to the preset policy platform, and perform encryption processing on the sensitive table and the sensitive field based on the quantum encryption and decryption plug-in and the target policy and the quantum key, to implement quantum encryption processing on the database.

[0144] Specifically, first, the connection between the preset policy platform and the key management platform is established. Then, when needed, the quantum encryption server obtains the required quantum key from the key management platform through the preset policy platform through a secure channel. Then, the quantum encryption server performs encryption processing on the sensitive table and the sensitive field based on the quantum encryption and decryption plug-in and the target policy and the quantum key, to implement quantum encryption processing on the database.

[0145] In this way, the quantum encryption server can ensure that the sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage, thereby enhancing the confidentiality of the sensitive data in the database.

[0146] Referring to Figure 10 In some embodiments, the step 013 (quantum encryption processing of the database according to the target policy or the encrypted target policy) comprises:

[0147] 0132: In the case of an abnormal running of the application server, the quantum encryption processing of the database according to the encrypted target policy based on the quantum encryption and decryption plug-in.

[0148] In some embodiments, the quantum encryption and decryption plug-in is further used for, in the case of an abnormal running of the application server, quantum encryption processing of the database according to the encrypted target policy based on the quantum encryption and decryption plug-in.

[0149] In some embodiments, the processor is used for, in the case of an abnormal running of the application server, quantum encryption processing of the database according to the encrypted target policy based on the quantum encryption and decryption plug-in.

[0150] Specifically, the quantum encryption server continuously monitors its own running state. If an abnormal running is detected, for example, a failure, a response timeout or a service interruption, the quantum encryption server will start the plug-in escape mechanism. That is, the quantum encryption processing of the database according to the previously backed up encrypted target policy.

[0151] In this way, the quantum encryption server can ensure that the sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage, thereby enhancing the confidentiality of the sensitive data in the database.

[0152] Referring to Figure 11 In some embodiments, the step 0132 (quantum encryption processing of the database according to the encrypted target policy based on the quantum encryption and decryption plug-in) comprises:

[0153] 01321: Obtain the encrypted target policy;

[0154] 01322: Decrypt the encrypted target policy to obtain the target policy;

[0155] 01323: Obtain the quantum key from the key management platform of the preset policy platform;

[0156] 01324: Based on the quantum encryption and decryption plug-in, encrypt the sensitive table and the sensitive field according to the target policy and the quantum key, to realize the quantum encryption processing of the database.

[0157] In some embodiments, the quantum encryption server further obtains an encryption target policy, decrypts the encryption target policy to obtain an original target policy, obtains a quantum key from a key management platform of a preset policy platform, and encrypts sensitive tables and sensitive fields according to the target policy and the quantum key based on the quantum encryption and decryption plug-in, to implement quantum encryption processing on the database.

[0158] In some embodiments, the processor further obtains an encryption target policy, decrypts the encryption target policy to obtain an original target policy, obtains a quantum key from a key management platform of a preset policy platform, and encrypts sensitive tables and sensitive fields according to the target policy and the quantum key based on the quantum encryption and decryption plug-in, to implement quantum encryption processing on the database.

[0159] Specifically, first, the quantum encryption server obtains an encryption target policy. The encryption target policy is obtained by the quantum encryption and decryption plug-in from a place where the quantum encryption server stores the encryption target policy. Next, the quantum encryption server decrypts the encryption target policy to obtain an original target policy. The decryption process uses the quantum encryption and decryption plug-in on the quantum encryption server and a corresponding decryption key. The decrypted target policy contains specific instructions on how to perform quantum encryption on sensitive data in the database. Then, the quantum encryption server obtains a quantum key from a key management platform of a preset policy platform. Finally, the quantum encryption server encrypts sensitive tables and sensitive fields according to the target policy and the quantum key based on the quantum encryption and decryption plug-in, to implement quantum encryption processing on the database.

[0160] In this way, the quantum encryption server can ensure that sensitive data in the database is protected at the quantum level, and can resist various security threats during data transmission and storage.

[0161] The embodiments of the present application provide a quantum encryption server, which comprises a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the method described above is implemented.

[0162] Please refer to Figure 11 The embodiments of the present application provide a quantum encryption system, which comprises a quantum encryption server, a quantum database encryption policy platform and a database. The quantum encryption server comprises a quantum encryption and decryption plug-in.

[0163] The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform. The quantum database encryption policy platform is configured to provide a policy for quantum encryption processing on the database.

[0164] The quantum encryption and decryption plug-in is configured to encrypt the target policy to obtain an encrypted target policy, and backup the encrypted target policy.

[0165] The quantum encryption and decryption plug-in is configured to perform quantum encryption processing on the database according to the target policy or the encrypted target policy.

[0166] In summary, the embodiment of the application provides a quantum encryption system, which includes a business database, a quantum database encryption policy platform, and a quantum encryption server. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, and the quantum database encryption policy platform is configured to provide a policy for performing quantum encryption processing on a database. The quantum encryption and decryption plug-in is configured to encrypt the target policy to obtain an encrypted target policy, and backup the encrypted target policy. The quantum encryption and decryption plug-in is configured to perform quantum encryption processing on the database according to the target policy or the encrypted target policy. In this way, through quantum key distribution technology, the encryption of the database is realized, and the encryption process is more secure. Moreover, since the quantum encryption server will backup the encrypted target policy in real time, even if the quantum encryption server or the policy platform fails, the policy can be restored and the quantum encryption processing of the database can continue.

[0167] The quantum encryption method for the database is described in detail below with an example. Please refer to Figure 12 , Figure 12 is a structure diagram of a specific example of the quantum encryption system. Nacos is an open source service discovery and configuration management platform, which is used to build a cloud native application.

[0168] As Figure 12 First, deploy the policy platform according to the deployment document. After deployment, configure the data source in the policy platform, that is, configure the business database that needs to be processed by quantum encryption. Configure the corresponding policy for the table and field that needs to be encrypted in the business database. After data migration is completed, set the running mode of the sensitive table to ciphertext mode. Data migration refers to quantum encryption processing of sensitive data already stored in the business database.

[0169] As Figure 12 Second, after the policy platform sets the policy, it publishes the policy information of the application to nacos, including data source connection information, sensitive table, sensitive field, encryption algorithm, running mode, pseudo key, and the like. When the policy platform updates the policy, nacos can also dynamically listen to the policy changes.

[0170] As Figure 12Thirdly, after the integration of the quantum encryption and decryption plug-in is completed, the business application initiates an http request to call the strategy platform to obtain the configuration interface. Then, the application configuration information and the connection information of nacos are obtained according to the quantum encryption server identifier. After obtaining the connection information, the nacosServer is created to pull the strategy information on nacos. At the same time, the nacos listener is also created to dynamically obtain the strategy changes. Finally, the collected strategy information is cached in the memory of the quantum encryption server. The symmetric encryption processing is performed on the strategy information to obtain the encrypted backup strategy information, which is cached in the reserved position of the quantum encryption server.

[0171] After the obtained strategy information is cached in the memory, the quantum encryption server automatically parses the business database and performs quantum encryption and decryption processing on the business database when performing database encryption. However, if the quantum encryption service is restarted, the strategy information in the memory will be emptied, and the plug-in needs to be reinitialized to obtain the strategy. If the strategy platform service fails at this time, the plug-in cannot obtain the strategy information from the strategy platform, and the quantum encryption server will automatically downgrade to obtain the encrypted backup strategy information, decrypt the encrypted backup strategy information to obtain the corresponding strategy information, and save the strategy information in the memory of the quantum encryption server.

[0172] In this way, the quantum encryption server can realize the encryption and decryption of sensitive data, thereby protecting the sensitive data. Figure 12 Fourthly, the quantum encryption server can realize the encryption and decryption of sensitive data, thereby protecting the sensitive data.

[0173] The application also provides a computer readable storage medium containing a computer program. When the computer program is executed by one or more processors, the one or more processors execute the method of the application.

[0174] It can be understood that the computer program includes computer program code. The computer program code can be in the form of source code, object code, executable files or some intermediate forms. The computer readable storage medium can include any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM) and software distribution medium.

[0175] In the description of the specification, the description of the terms "specifically", "further", "particularly", "understandably" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiments or examples are included in at least one embodiment or example of the present application. In the present specification, the illustrative expression of the above terms does not intend to refer to the same embodiment or example. Also, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. Furthermore, the person skilled in the art can combine and combine the different embodiments or examples described in the specification and the features of the different embodiments or examples without contradiction.

[0176] Any process or method descriptions or descriptions of the flow diagrams in the flow charts described herein and elsewhere can be understood as representing code modules, segments, or portions of code which include one or more executable instructions for performing specific logic functions or steps in the process, and that the various embodiments of the application include the use of one or more of these processes or methods, where appropriate. The various embodiments of the application may, in some instances, also include structure for performing the steps or functions of these processes or methods.

[0177] Although the embodiments of the present application have been shown and described above, it is understood that the above-described embodiments are exemplary, and should not be construed as limiting the present application, and those ordinarily skilled in the art can make changes, modifications, substitutions and variations to the above-described embodiments within the scope of the present application.

Claims

1. A quantum encryption method for a database, characterized by, The method comprises: obtaining a target policy from a preset policy platform, wherein the preset policy platform is configured to provide a policy for quantum encryption processing of the database, the preset policy platform is preconfigured with a quantum encryption and decryption plug-in, and the policy comprises selection of an encryption algorithm, key management rules and an encryption level; encrypting the target policy to obtain an encrypted target policy, and backing up the encrypted target policy; performing the quantum encryption processing on the database according to the target policy or the encrypted target policy; the quantum encryption processing on the database according to the target policy or the encrypted target policy comprises: in a case where an application server corresponding to a server identifier is running normally, performing the quantum encryption processing on the database according to the target policy based on the quantum encryption and decryption plug-in, and the preset policy platform is configured with the server identifier; the quantum encryption processing on the database according to the target policy or the encrypted target policy comprises: in a case where the application server is running abnormally, performing the quantum encryption processing on the database according to the encrypted target policy based on the quantum encryption and decryption plug-in.

2. The method of claim 1, wherein, The preset policy platform is configured through the following steps: constructing a policy platform corresponding to a preset deployment document based on the preset deployment document; configuring the policy platform based on a preset platform configuration file to obtain the preset policy platform.

3. The method of claim 2, wherein, The configuration of the policy platform based on the preset platform configuration file to obtain the preset policy platform comprises: configuring a server identifier corresponding to the database according to the preset platform configuration file to obtain a temporary policy platform, and the server identifier is used to indicate an application server for quantum encryption processing of the database; determining sensitive tables and sensitive fields of the database according to the preset platform configuration file; configuring the policy for quantum encryption processing of the sensitive tables and the sensitive fields according to the preset platform configuration file to obtain the preset policy platform.

4. The method of claim 3, wherein, The method further comprises: constructing the quantum encryption and decryption plug-in according to a preset plug-in configuration file, and the preset plug-in configuration file comprises a server identifier.

5. The method of claim 4, wherein, The obtaining of the target policy from the preset policy platform comprises: obtaining the target policy from the preset policy platform according to the server identifier.

6. The method of claim 4, wherein, The encryption of the target policy to obtain an encrypted target policy, and the backup of the encrypted target policy comprise: performing encryption processing on the target policy based on the quantum encryption and decryption plug-in and a preset encryption algorithm to obtain the encrypted target policy; backing up the encrypted target policy in a target position.

7. The method of claim 3, wherein, The quantum encryption processing on the database according to the target policy based on the quantum encryption and decryption plug-in comprises: obtaining a quantum key from a key management platform connected to the preset policy platform; performing encryption processing on the sensitive tables and the sensitive fields according to the target policy and the quantum key based on the quantum encryption and decryption plug-in to implement the quantum encryption processing on the database.

8. The method of claim 3, wherein, The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database.

9. A quantum encryption server, characterized by, The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database.

10. A quantum encryption system, characterized by, The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption policy platform is configured to provide a policy for quantum encryption processing of the database. The quantum encryption server is configured to obtain a target policy from the quantum database encryption policy platform, the quantum database encryption

Citation Information

Patent Citations

  • Encrypted database system and method based on quantum key distribution technology, storage method and query method

    CN107800537A

  • Data encryption method and device, equipment, storage medium and program product

    CN117494169A