SQL statement-based data processing method, electronic device, and storage medium
By constructing the data flow chart of SQL statements and identifying the encryption operation nodes, the problem of incomplete identification of illegal SQL statements in the existing technology is solved, and precise interception and processing of SQL statements is realized, database security is enhanced and maintenance costs are reduced.
Patent Information
- Application Number
- CN202510199025.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-24
AI Technical Summary
The prior art has problems of incomplete coverage when identifying and blocking illegal SQL statements, especially when complex queries and multi-table associations, and the maintenance cost of static rulesets is high, making it difficult to adapt to changes in business needs and database structure.
By constructing the data flow chart of SQL statements, analyzing the syntax and identifying the encryption operation nodes, and determining whether the SQL statement is an illegal statement. The method includes constructing a multi-level data flow graph, identifying the encryption operation node, and determining the illegal level and processing strategy of the SQL statement based on the node flow chain.
It realizes precise identification and interception of SQL statements, avoids business logic errors or data corruption caused by executing illegal SQL statements, enhances the security of sensitive data in the database, and reduces maintenance costs.
Smart Images

Figure CN119691814B_ABST
Abstract
Claims
1. A data processing method based on SQL statements, characterized in that: The method comprises: Get the SQL statement to be processed; A corresponding data flow graph is constructed by analyzing the syntax in the SQL statement, wherein the data flow graph includes multiple levels, each level includes at least one node, and the edge connecting the nodes in adjacent levels indicates that the node in the previous level in the adjacent levels depends on one or more nodes in the next level through assignment or operation, and the nodes in the lowest level are the data columns involved in the SQL statement; In the bottom level of the data flow graph, nodes corresponding to the non-encrypted data columns are marked with a first mark, and nodes corresponding to the encrypted data columns are marked with a second mark; Flow the nodes into the chain, perform the third marking on the nodes obtained by computing the nodes containing the second marking, perform the first marking on the nodes obtained by computing or assigning only the nodes containing the first marking, perform the fourth marking on the nodes obtained by only assigning the nodes containing the second marking, and perform the fifth marking on the nodes obtained by only assigning the nodes containing the third marking; Displaying a data flow graph with a mark, wherein a node with the third mark represents an encryption operation node; Identify whether there is an encryption operation node among all the nodes in the data flow graph, wherein the encryption operation node represents a node obtained by operating the node corresponding to the encrypted data column; When there is an encryption operation node, the SQL statement is determined to be an illegal SQL statement.
2. The data processing method based on SQL statements according to claim 1, characterized in that: The nodes and edges in the data flow graph form a plurality of node flow chains; after determining that the SQL statement is an illegal SQL statement, the method further includes: The node flow chain where the encryption operation node is located is regarded as an illegal node flow chain; The SQL statement is intercepted, and interception information including an error output result is output, where the error output result is a result corresponding to a node at the top level in the illegal node flow chain.
3. The data processing method based on SQL statements according to claim 1, characterized in that: The method further comprises: Identifying the number of encryption operation nodes in the data flow graph; Based on the number of the encryption operation nodes, the illegality level of the SQL statement is determined.
4. The data processing method based on SQL statements according to claim 3 is characterized in that: After determining the illegal level of the SQL statement based on the number of the encryption operation nodes, the method further includes: Based on the illegal level of the SQL statement, determining a processing strategy corresponding to the SQL statement, the processing strategy including interception processing or rewriting processing; The processing strategy is executed on the SQL statement.
5. The data processing method based on SQL statements according to claim 1, characterized in that: After determining that the SQL statement is an illegal SQL statement, the method further includes: Receiving an execution instruction for the illegal SQL statement; Based on the running instruction, determining a restricted data column in the illegal SQL statement corresponding to the encryption operation node, wherein the restricted data column is an encrypted data column participating in the operation in the illegal SQL statement; According to the read / write type corresponding to each restricted data column, modify the data value corresponding to each restricted data column to generate a modified SQL statement; The modified SQL statement is sent to a target database server, wherein the target database server is used to execute the modified SQL statement.
6. The data processing method based on SQL statements according to claim 5 is characterized in that: The modifying the data value corresponding to each restricted data column according to the read / write type corresponding to each restricted data column includes: According to the read / write type corresponding to each restricted data column, marking each restricted data column as a write restricted data column or a read restricted data column; The data value corresponding to each read-restricted data column is decrypted and modified, and the data value corresponding to each write-restricted data column is encrypted and modified.
7. The data processing method based on SQL statements according to claim 6 is characterized in that: The decrypting and modifying the data value corresponding to each read-restricted data column, and encrypting and modifying the data value corresponding to each write-restricted data column, further includes: Obtain a target decryption function corresponding to each read-restricted data column and a target encryption function corresponding to each write-restricted data column; Decrypt and modify the data value corresponding to each read restricted data column according to the target decryption function corresponding to each read restricted data column; and According to the target decryption function corresponding to each write restricted data column, the data value corresponding to each write restricted data column is encrypted and modified.
8. An electronic device, characterized in that: include: one or more processors; a memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors execute the data processing method based on SQL statements as described in any one of claims 1 to 7.
9. A storage medium, characterized in that: The storage medium stores executable instructions, and when the instructions are executed by the processor, the processor executes the data processing method based on SQL statements according to any one of claims 1 to 7.
Citation Information
Patent Citations
Transparent database encrypting method of application layer
CN102968455A
Table field level encryption and security access control method and system
CN114462059A