A data masking coding method and system based on a Gaussian database
By using encoding and decoding functions in Gaussian databases to mask and encode medium and low-sensitive data, the problem of insufficient resource consumption and security of medium and low-sensitive data storage is solved, and efficient and secure data protection is achieved, suitable for large-scale data operations.
Patent Information
- Application Number
- CN202411871154.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-12-18
AI Technical Summary
In Gaussian databases, the storage of medium and low-sensitive data consumes a large amount of computing resources or cannot meet security requirements. The existing database data protection solutions are expensive and have poor flexibility, and there is a lack of effective solutions for large-scale data occlusion processing.
The data mask encoding method based on Gaussian database is adopted. By initializing the registered encoding and decoding functions in the database, the fields of the medium and low-sensitive data table are encoded, and the encoding functions and decoding functions are generated for data protection during storage and query. The encoded value consists of prefix, separator, digest, original value encoding and check bits.
Improves data security and integrity, reduces the risk of sensitive information leakage, maintains high performance and flexibility, is suitable for large-scale data operations without the need for additional database fields, and is easy to deploy and maintain.
Smart Images

Figure CN119848921B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data encoding, and particularly to a data masking encoding method and system based on a Gaussian database. Background Art
[0002] The Gaussian database is an efficient and organized data collection system designed for storing, managing, and quickly retrieving information. As a leading domestic enterprise-level database solution, the Gaussian database is widely used in multiple industry fields such as finance, telecommunications, government, and scientific research, and can effectively support large-scale data storage and complex data processing tasks.
[0003] Data stored in the database can generally be divided into three levels according to sensitivity: highly sensitive data, moderately sensitive data, and low-sensitive data. Highly sensitive data includes personal identity information, financial data, etc.; moderately sensitive data includes customer information, internal reports, etc.; low-sensitive data is public business information, etc. In the Gaussian database, highly sensitive data is protected by high-strength encryption algorithms (such as RSA, ECC, etc.), while medium and low-sensitive data is mainly protected by role-based access control (RBAC).
[0004] In daily database operation and maintenance, it is required to regularly maintain and upgrade the table structure in the Gaussian database, so operation and maintenance personnel will come into contact with the stored data. To improve data security and privacy protection, customers require masking processing of some table fields of medium and low-sensitive data to reduce the risk of sensitive information leakage.
[0005] For the storage of medium and low-sensitive data, if masking protection is required, considering the large amount and wide range of data involved, using high-strength encryption algorithms will consume a large amount of computing resources, which is obviously inappropriate.
[0006] In application scenarios with a large amount of data, such as when the number of stored rows in a database table reaches tens of millions, traditional encryption methods can meet the security requirements but cannot meet the high-performance requirements.
[0007] Currently, the general database data protection solutions on the market have high performance overhead and poor flexibility, are not suitable for large-scale data protection, and lack effective solutions for scenarios that require large-scale data masking processing.
[0008] In view of this, the present invention proposes a data masking encoding method and system based on a Gaussian database to ensure effective protection of data during storage. Summary of the Invention
[0009] To solve the problems that the storage of low-sensitivity data in a Gaussian database consumes a large amount of computing resources or fails to meet security requirements, etc., this application provides a data masking encoding method, system, device, and storage medium based on a Gaussian database to solve the above technical defect problems.
[0010] According to the first aspect of this application, a data masking encoding method based on a Gaussian database is proposed. The method includes the following steps:
[0011] S1. In the Gaussian database, perform function initialization registration on medium and low-sensitivity data table fields, where the functions include an encoding function and a decoding function;
[0012] S2. When writing or updating data to the data table fields of the Gaussian database, use the encoding function to perform encoding processing on the specified field to be encoded, generate an encoded value, and store the encoded value in the Gaussian database table field. The encoding function includes the process of converting the input string or table field into an encoded value, and the encoded value consists of a prefix, a separator, a digest, an original value encoding, and a check bit;
[0013] S3. When obtaining data from the Gaussian database table field, use the decoding function to perform decoding processing on the specified field to be decoded to obtain the original data before encoding.
[0014] Preferably, in step S2, the encoding processing specifically includes the following sub-steps:
[0015] S21. The user submits a data write or update request to the Gaussian database system through an SQL statement. The request specifies the database table to be written or updated, the fields in the table, and at least one field to be encoded;
[0016] S22. The Gaussian database system receives and parses the SQL statement to obtain the data to be written or updated and the information of the field to be encoded;
[0017] S23. Perform encoding processing on the value or string of the field to be encoded using a preset encoding function;
[0018] S24. Store the encoded value in the specified database table field to complete the data write or update operation.
[0019] Preferably, in step S3, the decoding processing specifically includes the following sub-steps:
[0020] S31. The user queries the database table data through an SQL query statement and specifies the database table field to be decoded in the query statement;
[0021] S32. According to the database table field information specified by the user, use a preset decoding function to perform decoding processing on the value of the field;
[0022] S33. Determine whether the decoding is successful. If the decoding is successful, return the decoded value as part of the query result. If the decoding fails, return a null value as the value of the corresponding field in the query result.
[0023] Preferably, in step S2, the input of the encoding function is a string or a table field, and the output is an encoded value. The encoded value includes a fixed 3-bit prefix ENC, a delimiter #, a 1-bit digest, the encoding of the original value, and a check bit. The total length is the sum of a fixed length of 6 bits and 133% of the length of the original string.
[0024] Preferably, in step S2, the encoding process includes: randomly selecting a group of digests, converting characters into binary data, dividing them into groups of 6 bits each, and mapping them to printable ASCII characters according to the digest, thereby realizing the encoding of the data.
[0025] Preferably, in step S2, the check bit is calculated based on the ASCII binary value of the encoded string and is used to detect whether the data has been tampered with.
[0026] Preferably, a data masking encoding method based on a Gaussian database proposed by the present application further includes:
[0027] Receive the input encoded value, and extract the last bit of the encoded value as the check bit;
[0028] Recalculate the part of the encoded value except the check bit to obtain a calculated check bit;
[0029] Compare the calculated check bit with the check bit of the encoded value. If the two are the same, the check passes and proceed to the next step;
[0030] After the check passes, obtain the digest information corresponding to the encoded value according to the information contained in the encoded string;
[0031] Use the digest information to perform a decoding operation on the encoded value. The decoding operation includes grouping the encoded string by every four characters and converting each group of characters into the corresponding three-byte binary data;
[0032] Restore the converted binary data to the original value before encoding by looking up the corresponding conversion rules in the digest information.
[0033] In a second aspect, the present application proposes a data masking encoding system based on a Gaussian database. The system includes:
[0034] An initialization registration module, configured to perform function initialization registration on medium and low-sensitivity data table fields in the Gaussian database, where the functions include an encoding function and a decoding function;
[0035] An encoding module, configured to, when writing or updating data to a data table field in a Gaussian database, use an encoding function to perform encoding processing on a specified field to be encoded, generate an encoded value, and store the encoded value in the Gaussian database table field, where the encoding function includes a process of converting an input string or table field into an encoded value, and the encoded value consists of a prefix, a delimiter, a digest, an original value encoding, and a check bit;
[0036] A decoding module, configured to, when obtaining data from a Gaussian database table field, use a decoding function to perform decoding processing on a specified field to be decoded and obtain the original data before encoding.
[0037] In a third aspect, the present application proposes a terminal device, including a processor, a memory, and a computer program stored in the memory, where the computer program is executed by the processor to implement the data masking encoding method based on a Gaussian database as described in any one of the above.
[0038] In a fourth aspect, the present application proposes a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the data masking encoding method based on a Gaussian database as described in any one of the above is implemented.
[0039] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0040] (1) Enhanced security: During the encoding process, a group of digests is randomly selected to increase the complexity of encoding, thereby improving the cracking difficulty. This method effectively prevents attackers from restoring data through brute force cracking and enhances the security of data.
[0041] (2) Data integrity: A check bit is added at the end of the encoded value to detect whether the data has been tampered with, thereby ensuring the integrity of data storage, preventing data damage or tampering, and further enhancing the overall security and reliability of the system.
[0042] (3) Flexibility: The present invention does not require adding new database fields and does not affect the storage design of the user's existing tables. It only needs to expand the length of the table fields, has high flexibility, and is easy to maintain.
[0043] (4) Easy to use: The method provided by the present invention can be seamlessly docked with a Gaussian database, reducing development costs, and providing a simple database API interface, which is convenient for rapid deployment and promotion and improves the data security level.
[0044] (5) High performance: The algorithm has high operating efficiency, can quickly perform conversion processing on binary data, is convenient for storage, supports large-scale data operations, and at the same time maintains a small processing overhead and low latency, ensuring fast response and high throughput. Description of the Drawings
[0045] Other features, objects, and advantages of the present application will become more apparent from the following detailed description of non - restrictive embodiments when read in conjunction with the accompanying drawings:
[0046] Figure 1 is a flowchart of a data masking encoding method based on a Gaussian database according to the present application;
[0047] Figure 2 is a schematic diagram of the execution process of encoding and decoding function initialization registration according to the present application;
[0048] Figure 3 is a schematic diagram of the execution process of an encoding operation according to the present application;
[0049] Figure 4 is a schematic diagram of the execution process of a decoding operation according to the present application;
[0050] Figure 5 is a structural diagram of a data masking encoding system based on a Gaussian database according to the present application;
[0051] Figure 6 is a schematic diagram of the structure of a computer system of an electronic device suitable for implementing the embodiments of the present application. Detailed Embodiments
[0052] The present application will be further described in detail below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and not to limit the invention. Additionally, it should be noted that for the sake of description, only parts related to the relevant invention are shown in the drawings.
[0053] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.
[0054] Figure 1 shows a flowchart of a data masking encoding method based on a Gaussian database according to the present application, as Figure 1 shown, the method includes the following steps:
[0055] S1. In the Gaussian database, perform function initialization registration on the medium - low sensitivity data table fields, where the functions include an encoding function and a decoding function.
[0056] That is, before using the encoding and decoding functions, the functions need to be registered in the Gaussian database, and they can be used continuously after successful registration.
[0057] S2. When writing or updating data to the fields of a Gauss database table, use an encoding function to encode the specified fields to be encoded, generate an encoded value, and store the encoded value in the Gauss database table field. The encoding function includes a process of converting the input string or table field into an encoded value, and the encoded value consists of a prefix, a delimiter, a digest, an original value encoding, and a check bit.
[0058] In this embodiment, the encoding process specifically includes the following sub-steps:
[0059] S21. The user submits a data write or update request to the Gauss database system through an SQL statement. The request specifies the database table to be written or updated, the fields in the table, and at least one field to be encoded.
[0060] S22. The Gauss database system receives and parses the SQL statement to obtain the data to be written or updated and the information of the fields to be encoded.
[0061] S23. Use a preset encoding function to encode the value or string of the field to be encoded.
[0062] S24. Store the encoded value in the specified database table field to complete the data write or update operation.
[0063] Preferably, the function name of the encoding function is: ShineBaseEncode, the input is: string or table field, and the output is: encoded value.
[0064] The encoding function described in this application is developed based on the Gauss database interface, supports being used as a database function, encodes the input string or table field, generates an encoded value and writes it into the database field. Its encoding description is as follows:
[0065] The encoded value consists of a prefix, a delimiter, a digest, an original value encoding, and a check bit.
[0066] Prefix: Use a fixed 3-bit prefix "ENC" to indicate that this field is encoded data.
[0067] Delimiter: Use "#" as the delimiter.
[0068] Digest: Use 1 bit to represent the digest information. Its range is: A, B, C, D, E. Each letter represents a group of digests. The system provides five groups of different digests. The digest consists of visible ASCII characters, and one group of digests is used for each encoding.
[0069] Original value encoding: Obtain a group of random digests, convert the characters into binary data, divide them into groups of 6 bits each, and map them to printable ASCII characters according to the digest to achieve data encoding.
[0070] Check digit: Obtain the ASCII binary value according to the encoded string, perform a left shift operation on the odd-numbered bits and then take the remainder, return the decimal value for the even-numbered bits, accumulate each decimal value, obtain the accumulated value and take the remainder of 10 to get the check code, and the check code is a number between 0 and 9.
[0071] Total length: The sum of a fixed length of 6 bits and 133% of the length of the original string.
[0072] Continue to refer to Figure 1 , the data masking encoding method based on the Gaussian database provided by this application further includes the following steps:
[0073] S3. When obtaining data from the Gaussian database table field, use the decoding function to perform decoding processing on the specified field to be decoded, and obtain the original data before encoding.
[0074] In this embodiment, the decoding process specifically includes the following sub-steps:
[0075] S31. The user queries the database table data through an SQL query statement and specifies the database table field to be decoded in the query statement;
[0076] S32. According to the database table field information specified by the user, use the preset decoding function to perform decoding processing on the value of the field;
[0077] S33. Determine whether the decoding is successful. If the decoding is successful, return the decoded value as part of the query result; if the decoding fails, return a null value as the value of the corresponding field in the query result.
[0078] Preferably, the function name of the decoding function is: ShineBaseDecode, the input is: the encoded string or field, and the output is: the original value before encoding.
[0079] The decoding function described in this application is developed based on the Gaussian database interface, supports being used as a database function, performs decoding processing on the input encoded string or field, and returns the decoded value. The decoding process is as follows:
[0080] Verify the encoding: Input the encoded value, obtain the last check digit, recalculate the check digit for the original value after encoding, compare the calculated check digit with the check digit of the encoding, and if they are the same, the verification passes.
[0081] Decode: After the verification passes, according to the encoded string information, obtain the digest information corresponding to the encoded value, and decode the encoded value according to the digest information. The decoded value is the original value before encoding. Decoding is to group the encoded string by four characters and convert it into three-byte binary data, and restore the original content by looking up the digest information.
[0082] The present invention can implement the encoding and decoding of the stored values of the fields in the Gaussian database table. As a function of the Gaussian database, it needs to be initialized and registered, and the access to the encoding function and the decoding function is managed through role-based access control (RBAC). The usage scenario of encoding is to perform encoding processing when writing or updating the data of the database fields. The usage scenario of decoding is to perform decoding processing when querying the database fields.
[0083] Figure 2 The execution flow diagram of the initialization and registration of the encoding and decoding functions is shown, as Figure 2 shown. First, copy the file compiled by the function to the working directory of Gaussian. Second, execute the function registration instruction. As follows:
[0084] Register the encoding function:
[0085] CREATE OR REPLACE FUNCTION ShineBaseEncode(text) RETURNS text AS 'libXyEncrypt.so', 'ShineBaseEncode' LANGUAGE C STRICT;
[0086] Register the decoding function:
[0087] CREATE OR REPLACE FUNCTION ShineBaseDecode(text) RETURNS text AS 'libXyEncrypt.so', 'ShineBaseDecode' LANGUAGE C STRICT;
[0088] Finally, verify whether the function is registered successfully. The verification encoding function is: select ShineBaseEncode('abc'); The verification decoding function is: select ShineBaseDecode('ENC#E8g9v4').
[0089] When writing or updating the data of the database table fields, for the medium and low sensitive fields to be protected, use the encoding function to encode the specified fields. Figure 3 The execution flow diagram of the encoding operation of the present application is shown, as Figure 3 shown. The present application completes the encoding operation through the following steps:
[0090] (1) When the user uses the SQL statement to update or write the database fields, specify the fields to be encoded.
[0091] (2) Encode the value or string of the given database field.
[0092] (3) Store the encoded value into the specified database table field.
[0093] Example: Take the table DICT_INFO as an example. The table DICT_INFO has three fields: DICT_KEY, DICT_NAME, and DICT_REMARK. The basic information is as follows:
[0094] Field Name Length Type DICT_KEY 10 String DICT_NAME 30 String DICT_REMARK 128 String
[0095] DICT_KEY DICT_NAME DICT_REMARK 001 INIT_PWD Initial Value
[0096] When inserting a piece of data, its value is as follows:
[0097] Writing scenario:
[0098] INSERT INTO DICT_INFO VALUES('001',ShineBaseEncode('INIT_PWD'),'Initial value')
[0099] The following is the information of the DICT_INFO table:
[0100] Note: "ENC#CGXSUF6uZFbZ2" is the value after encoding INIT_PWD.
[0101]
[0102] Update scenario: UPDATE DICT_INFO SET DICT_NAME=ShineBaseEncode('INIT_PAWD') WHERE DICT_KEY='001'
[0103] The following is the information of the DICT_INFO table:
[0104] DICT_KEY DICT_NAME DICT_REMARK 001 ENC#DHkYNVaOAV6A0 Initial Value
[0105] When querying the data of the database table field, specify the field to be decoded and decode the value of the field. Figure 4 The execution flow diagram of the decoding operation of this application is shown. As Figure 4 shown, the decoding operation is completed through the following steps:
[0106] (1) The user uses the SQL query statement to query the database table data and specifies the database table field to be decoded.
[0107] (2) According to the given database table field information, use the decoding function to decode.
[0108] (3) If the decoding is successful, return the decoded value. If the decoding fails, return a null value.
[0109] Example: Take the encoded table DICT_INFO as an example. The information stored in it is as follows, and DICT_NAME is the encoded value.
[0110] DICT_KEY DICT_NAME DICT_REMARK 001 ENC#DHkYNVaOAV6A0 Initial Value
[0111] Query the information of DICT_INFO:
[0112] SELECT DICT_KEY,ShineBaseDecode(DICT_NAME),DICT_REMA RK FROM DICT_INFO
[0113] The query results are as follows:
[0114] DICT_KEY DICT_NAME DICT_REMARK 001 INIT_PWD Initial Value
[0115] Encoding and decoding performance:
[0116] Function Length Time Consumed (per million times) Encoding 500 bytes 993 ms / million times Decoding 673 (encoded value of 500 bytes) 1174 ms / million times
[0117] Note: "Elapsed time (in millions of times)" is the cumulative time for executing the encoding one million times. Take "encoding" as an example. The total elapsed time for encoding 500 bytes one million times is 993 milliseconds.
[0118] The present invention is mainly used for encoding and decoding operations on medium and low-sensitive data stored in a Gaussian database to ensure the effective protection of data during storage, thereby reducing the risk of sensitive information leakage and meeting the needs of enterprises in protecting privacy data and compliance requirements.
[0119] Further referring to Figure 5 , as an implementation of the above method, in a second aspect, the present application provides a structural diagram of an embodiment of a data masking encoding system 500 based on a Gaussian database. This system can be specifically applied to various electronic devices. The system 500 includes the following modules:
[0120] An initialization registration module 510, configured to perform function initialization registration on medium and low-sensitive data table fields in a Gaussian database, where the functions include an encoding function and a decoding function;
[0121] An encoding module 520, configured to, when writing or updating data to a data table field in a Gaussian database, use the encoding function to perform encoding processing on the specified field to be encoded, generate an encoded value, and store the encoded value in the Gaussian database table field. The encoding function includes a process of converting the input string or table field into an encoded value, and the encoded value consists of a prefix, a delimiter, a digest, an original value encoding, and a check bit;
[0122] The decoding module 530 is configured to use a decoding function to perform decoding processing on a specified field to be decoded when obtaining data from a Gaussian database table field, so as to obtain the original data before encoding.
[0123] In a third aspect, the present application provides a terminal device, including a processor, a memory, and a computer program stored in the memory. The computer program is executed by the processor to implement the Gaussian database-based data masking and encoding method as described in any one of the above.
[0124] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the Gaussian database-based data masking and encoding method as described in any one of the above.
[0125] Next, refer to Figure 6 , which shows a schematic structural diagram of a computer system 600 suitable for implementing the terminal device or server of the embodiments of the present application. Figure 6 The shown terminal device or server is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0126] As Figure 6 shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage section 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the computer system 600 are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0127] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as required. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as required, so that the computer program read from it can be installed into the storage section 608 as required.
[0128] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above-described functions defined in the methods of the present application are performed. It should be noted that the computer-readable medium described in the present application can be a computer-readable signal medium, a computer-readable medium, or any combination of the two. The computer-readable medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0129] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).
[0130] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0131] The above description is only a preferred embodiment of this application and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in this application.
Claims
1. A data masking encoding method based on a Gaussian database, characterized in that The method includes the following steps: S1. In the Gaussian database, perform function initialization registration on the medium and low-sensitivity data table fields, where the functions include an encoding function and a decoding function; S2. When writing or updating data to the data table fields of the Gaussian database, use the encoding function to perform encoding processing on the specified field to be encoded, generate an encoded value, and store the encoded value into the Gaussian database table field. The encoding function includes a process of converting the input string or table field into an encoded value. The encoded value consists of a prefix, a delimiter, a digest, an original value encoding, and a check bit. The check bit is calculated based on the ASCII binary value of the encoded string and is used to detect whether the data has been tampered with. The encoding processing includes: randomly selecting a group of digests, converting characters into binary data, dividing them into groups of 6 bits each, and mapping them to printable ASCII characters according to the digest, thereby realizing data encoding; S3. When retrieving data from the Gaussian database table field, use the decoding function to perform decoding processing on the specified field to be decoded to obtain the original data before encoding.
2. The data masking encoding method based on the Gaussian database according to claim 1, wherein, In step S2, the encoding processing specifically includes the following sub-steps: S21. The user submits a data write or update request to the Gaussian database system through an SQL statement. The request specifies the database table to be written or updated, the fields in the table, and at least one field to be encoded; S22. The Gaussian database system receives and parses the SQL statement to obtain the data to be written or updated and the information of the field to be encoded; S23. Perform encoding processing on the value or string of the field to be encoded using a preset encoding function; S24. Store the encoded value into the specified database table field to complete the data write or update operation.
3. The data masking coding method based on a Gaussian database according to claim 1, wherein In step S3, the decoding processing specifically includes the following sub-steps: S31. The user queries the database table data through an SQL query statement and specifies the database table field to be decoded in the query statement; S32. According to the information of the database table field specified by the user, use a preset decoding function to perform decoding processing on the value of the field; S33. Determine whether the decoding is successful. If the decoding is successful, return the decoded value as part of the query result; if the decoding fails, return a null value as the value of the corresponding field in the query result.
4. The data masking encoding method based on the Gaussian database according to claim 1, characterized in that, In step S2, the input of the encoding function is a string or a table field, and the output is an encoded value. The encoded value includes a fixed 3-bit prefix ENC, a delimiter #, a 1-bit digest, an original value encoding, and a check bit. The total length is the sum of a fixed length of 6 bits and 133% of the original string length.
5. The data masking coding method based on a Gaussian database according to claim 1, characterized in that, It further includes: Receiving the input encoded value and extracting the last bit of the encoded value as the check bit; Recalculating the part of the encoded value except the check bit to obtain a calculated check bit; Comparing the calculated check bit with the check bit of the encoded value. If the two are the same, the verification passes and proceed to the next step; After the verification passes, according to the information contained in the encoded string, obtain the digest information corresponding to the encoded value; Perform a decoding operation on the encoded value using the abstract information, where the decoding operation includes grouping the encoded string into groups of every four characters and converting each group of characters into corresponding three-byte binary data; Restore the converted binary data to the original value before encoding by looking up the corresponding conversion rule in the abstract information.
6. A data masking coding system based on a Gaussian database, characterized in that, The system includes: An initialization registration module, configured to perform function initialization registration on the fields of the medium and low-sensitivity data table in the Gaussian database, where the functions include an encoding function and a decoding function; An encoding module, configured to, when writing or updating data to the fields of the data table in the Gaussian database, use the encoding function to perform encoding processing on the specified field to be encoded, generate an encoded value, and store the encoded value in the Gaussian database table field, where the encoding function includes a process of converting the input string or table field into an encoded value, and the encoded value consists of a prefix, a delimiter, an abstract, an original value encoding, and a check bit, and the check bit is calculated based on the ASCII binary value of the encoded string and is used to detect whether the data has been tampered with; the encoding processing includes: randomly selecting a group of abstracts, converting characters into binary data, dividing them into groups of 6 bits each, and mapping them to printable ASCII characters according to the abstract, thereby implementing data encoding; A decoding module, configured to, when obtaining data from the Gaussian database table field, use the decoding function to perform decoding processing on the specified field to be decoded to obtain the original data before encoding.
7. A terminal device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory, and the computer program is executed by the processor to implement the data masking encoding method based on the Gaussian database according to any one of claims 1 to 5.
8. A computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the data masking encoding method based on the Gaussian database according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
A method and a system for improving the safety of sensitive information of a database
CN109271797A
Secure transmission of sensitive data
CN109478221A
Data security management method and device based on multiple databases
CN118886056A