Cross-domain query method, device and storage medium of database
By introducing proxy access system and gateway system into the database cross-domain query system, the problems of insufficient security protection of traditional databases and high maintenance costs of query granularity control are solved, and higher security and flexibility are achieved.
Patent Information
- Application Number
- CN202510348134.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-03-24
AI Technical Summary
The security protection of traditional databases is insufficient, and the maintenance cost of achieving query granularity control is too high.
By introducing terminal systems, public network gateway systems, intranet gateway systems and proxy access systems into the cross-domain query system of the database, cross-domain query methods are realized. The proxy access system performs permission verification and injection protection processing on database access requests, and performs user access checksum request query verification through intranet gateways and public gateways.
Improves the security of the database, reduces maintenance costs, and realizes fine-grained data control and flexible query management.
Smart Images

Figure CN119884439B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data query, and in particular to a cross-domain query method, device and storage medium for a database. Background Art
[0002] In the traditional database direct access method, opening the database port means exposing the database to the external network environment, which is vulnerable to various network attacks. For example, attackers may use port vulnerabilities to perform SQL injection, brute force password cracking and other malicious behaviors. Once the database is breached, sensitive data stored in it, such as user personal information and commercial secrets, will face the risk of leakage, causing serious losses to enterprises or individuals.
[0003] Database connection information often contains sensitive content, such as server addresses, user names, passwords, etc. If it is directly exposed to the external environment and obtained maliciously, attackers can easily bypass security measures and directly access the database, completely controlling the data in the database, further exacerbating the risk of data leakage. Due to the lack of an intermediate access control mechanism, it is difficult to conduct a comprehensive audit and monitoring of database access. If abnormal data access or data leakage occurs, it is difficult to trace which user accessed the data, when, and by what method, which brings great difficulties to the investigation and handling of security incidents.
[0004] The access control mechanism of traditional databases is relatively extensive. Usually, only simple permission allocation can be performed based on user accounts, which makes it difficult to achieve fine-grained control of data. For example, in an enterprise environment, employees in different departments and positions have different access requirements for data. Some may only need to view part of the data, while others may need to modify the data. However, it is difficult to accurately limit the access rights of each user to specific data rows or columns in the traditional direct access method, resulting in excessive or insufficient permissions, which cannot meet the enterprise's requirements for refined management of data access. Traditional databases use API interfaces to achieve granular control. It is necessary to develop corresponding APIs for each specific query scenario, which is a huge workload, especially when business needs are diverse and constantly changing. For example, in an e-commerce system, different pages and modules have very different query requirements for product data, user data, order data, etc. The development team needs to write independent APIs for each requirement, which consumes a lot of manpower, material resources and time costs. New query requirements require code modification, which has high maintenance costs, and it is difficult to support dynamic SQL query requirements. Complex firewall rules need to be configured for cross-network access.
[0005] Therefore, a new technology is needed to solve the technical problems of insufficient security protection of traditional databases and high maintenance costs for query granularity control. Summary of the invention
[0006] The main purpose of the present invention is to solve the technical problems that the security protection of traditional databases is insufficient and the maintenance cost of query granularity control is too high.
[0007] A first aspect of the present invention provides a cross-domain query method for a database, the cross-domain query method for the database is applied to a cross-domain query system for the database, the cross-domain query system for the database comprises: a terminal system, a public network gateway system, an intranet gateway system, and a proxy access system, wherein the public network gateway system is communicatively connected to the intranet gateway system, the intranet gateway system is communicatively connected to the proxy access system, and the cross-domain query method for the database comprises:
[0008] The terminal system receives a database access request, and performs a connection test on the intranet gateway system according to the database access request to obtain a test result;
[0009] When the test result is qualified, the database access request is sent to the intranet gateway system;
[0010] When the test result is unqualified, a public network access request is sent to the public network gateway system;
[0011] The public network gateway system receives the public network access request, performs a legality verification process on the public network access request, and obtains a verification result;
[0012] When the verification result is qualified, obtaining the database access request from the terminal system, and sending the database access request to the intranet gateway system;
[0013] The intranet gateway system receives the database access request and transmits the database access request to the proxy access system;
[0014] The proxy access system receives the database access request, performs permission verification and injection protection processing on the database access request, generates query parameters, and performs query processing in a preset database based on the query parameters to obtain query data, and sends the query data to the intranet gateway system;
[0015] The intranet gateway system receives the query data, and based on the communication link between the terminal system and the intranet gateway system, transmits the query data to the terminal system.
[0016] Optionally, in a first implementation of the first aspect of the present invention, the proxy access system receives the database access request, performs permission verification and injection protection processing on the database access request, and generates query parameters including:
[0017] The proxy access system receives the database access request;
[0018] Parsing the SQL statement of the database access request to determine the scheme and table requested to be accessed;
[0019] Based on the permission settings of the scheme and table, determine whether the database access request has access permissions;
[0020] If the access right is granted, determining whether the SQL statement of the database access request contains a non-query statement;
[0021] When no non-query statement is included, the query size control setting of the scheme and the table is read, the query size control setting is written into the database access request, and a query restriction request is generated;
[0022] The query restriction request is protected and compiled to generate query parameters.
[0023] Optionally, in a second implementation of the first aspect of the present invention, the determining whether the SQL statement of the database access request includes a non-query statement includes:
[0024] Determine whether the SQL statement of the database access request starts with a SELECT string;
[0025] When it starts with a SELECT string, it is determined whether the SQL statement of the database access request contains an INSERT string, an UPDATE string, or a DELETE string.
[0026] Optionally, in a third implementation manner of the first aspect of the present invention, writing the query size control setting into the database access request to generate a query restriction request includes:
[0027] The LIMIT clause and the SELECT clause corresponding to the query size control setting are written into the SQL statement of the database access request to generate a query restriction request.
[0028] Optionally, in a fourth implementation manner of the first aspect of the present invention, the intranet gateway system receives the database access request, and transmits the database access request to the proxy access system, comprising:
[0029] The intranet gateway system receives the database access request;
[0030] Determining whether the client certificate corresponding to the database access request is data in a preset registry;
[0031] When the data is in a preset registration table, the data access request is converted into proxy access data, and the proxy access data is transmitted to the proxy access system.
[0032] Optionally, in a fifth implementation manner of the first aspect of the present invention, converting the data access request into proxy access data includes:
[0033] According to the preset token parameters and HTTP protocol, the data access request is encapsulated to generate proxy access data.
[0034] Optionally, in a sixth implementation of the first aspect of the present invention, the public network gateway system receives the public network access request, performs a legitimacy verification process on the public network access request, and obtains a verification result including:
[0035] The public network gateway system receives the public network access request;
[0036] Determine whether the source IP address of the public network access request is in the access control table or determine whether the source device of the public network access request is a trusted terminal;
[0037] When the source IP address is in the access control table and / or the source device is a trusted terminal, a qualified verification result is generated;
[0038] When the source IP address is not in the access control table and the source device is not a trusted terminal, an unqualified verification result is generated.
[0039] A second aspect of the present invention provides a cross-domain query device for a database, comprising: a memory and at least one processor, wherein instructions are stored in the memory, and the memory and the at least one processor are interconnected via a line; the at least one processor calls the instructions in the memory so that the cross-domain query device for the database executes the above-mentioned cross-domain query method for the database.
[0040] A third aspect of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, which, when executed on a computer, enable the computer to execute the above-mentioned cross-domain query method of the database.
[0041] In the embodiment of the present invention, both the intranet gateway and the public network gateway need to query the database through the proxy access system. The unified external interface in the proxy access system makes it unnecessary to customize the API for each query, which improves the flexibility of data query and reduces the maintenance cost, thus overcoming the problem of high maintenance cost of the database in query granularity control. The database is hidden in the proxy access system and is not directly exposed to the outside. By setting user access verification and request query verification on the intranet gateway, the public network gateway, and the proxy access system, the security of the database is improved, thus overcoming the problem of insufficient security protection of traditional databases. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 A schematic diagram of an embodiment of a cross-domain query method for a database in an embodiment of the present invention;
[0043] Figure 2 A schematic diagram of a specific embodiment of step 104 in an embodiment of the present invention;
[0044] Figure 3 This is a schematic diagram of a specific embodiment of step 106 in an embodiment of the present invention;
[0045] Figure 4 A schematic diagram of a specific embodiment of step 107 in an embodiment of the present invention;
[0046] Figure 5 The figure is a schematic diagram of an embodiment of a cross-domain query device for a database in an embodiment of the present invention. DETAILED DESCRIPTION
[0047] The embodiments of the present invention provide a cross-domain query method, device and storage medium for a database.
[0048] The embodiments disclosed in the present invention will be described in more detail below with reference to the accompanying drawings. Although certain embodiments disclosed in the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as being limited to the embodiments described herein, which are instead provided for a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments disclosed in the present invention are only for exemplary purposes and are not intended to limit the scope of protection disclosed in the present invention.
[0049] In the description of the embodiments disclosed in the present invention, the term "including" and similar terms should be understood as open inclusion, that is, "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc. may refer to different or the same objects. Other explicit and implicit definitions may also be included below.
[0050] For ease of understanding, the specific process of the embodiment of the present invention is described below. Figure 1 , an embodiment of a cross-domain query method for a database in an embodiment of the present invention, the cross-domain query method for a database is applied to a cross-domain query system for a database, the cross-domain query system for a database comprises: a terminal system, a public network gateway system, an intranet gateway system, and a proxy access system, wherein the public network gateway system is communicatively connected to the intranet gateway system, the intranet gateway system is communicatively connected to the proxy access system, and the cross-domain query method for a database comprises:
[0051] 101. The terminal system receives a database access request, and performs a connection test on the intranet gateway system according to the database access request to obtain a test result;
[0052] In this embodiment, upon receiving a database access request from a user, a terminal system such as a mobile phone or a computer detects a connection with the intranet gateway system and obtains a test result by detecting the response speed of the signal and the data transmission speed.
[0053] 102. When the test result is qualified, the database access request is sent to the intranet gateway system;
[0054] In this embodiment, if the terminal system determines that the test result is qualified, the database access request input by the user is sent to the intranet gateway system without the need to execute it through another channel.
[0055] 103. When the test result is unqualified, a public network access request is sent to the public network gateway system;
[0056] In this embodiment, a local DNS server is deployed in the intranet to resolve the database service address to the intranet IP. The client installs intelligent DNS software (such as Acrylic, MaraDNS, etc.) or dynamically switches the DNS server through a programming interface. For example, when the client starts, it first tries to resolve the intranet DNS. If the resolution fails (such as timeout or error), it switches to the public network DNS server, and the terminal system sends a public network access request to the public network gateway system.
[0057] 104. The public network gateway system receives the public network access request, performs a validity verification process on the public network access request, and obtains a verification result;
[0058] In this embodiment, a public network access request is received in the public network gateway system, and the public network gateway is an enterprise-level firewall or reverse proxy server (such as Nginx, HAProxy, etc.). Taking Nginx as an example, the access control policy is configured: verify the legitimacy of the source, assuming that a legitimate client needs to carry a specific request header or certificate. In the Nginx configuration, the map module can be used to check whether the request header exists. If the request header contains X-Client-Authenticate and the value is "valid", a qualified verification result is generated, otherwise the connection is rejected.
[0059] For details, please refer to Figure 2 , Figure 2 This is a schematic diagram of a specific embodiment of step 104 in an embodiment of the present invention, and step 104 includes the following specific embodiments:
[0060] 1041. The public network gateway system receives the public network access request;
[0061] 1042. Determine whether the source IP address of the public network access request is in the access control table or determine whether the source device of the public network access request is a trusted terminal;
[0062] 1043. When the source IP address is in the access control table and / or the source device is a trusted terminal, a qualified verification result is generated;
[0063] 1044. When the source IP address is not in the access control table and the source device is not a trusted terminal, an unqualified verification result is generated.
[0064] In steps 1041-1044, in the location configuration of database access, add conditional judgment: if the IP address of the public network access request belongs to the public network whitelist range (such as 192.168.1.0 / 24 and 10.0.0.0 / 24), the connection will be accepted. If it is not in the whitelist, further analysis is performed to determine whether the source device is a trusted terminal. An unqualified verification result will be generated only if the source IP address is not in the access control table and the source device is not a trusted terminal. As long as the source IP address is in the access control table and the source device is a trusted terminal, a qualified verification result will be generated.
[0065] 105. When the verification result is qualified, obtaining the database access request from the terminal system, and sending the database access request to the intranet gateway system;
[0066] In this embodiment, when the verification result is qualified, it means that the terminal system is a registered device or a legal device, then a database access request is obtained from the terminal system and the database access request is forwarded to the intranet gateway. At this time, the public network gateway system acts as a signal transmission intermediary to extend the access of users who are not in the specified LAN network environment.
[0067] 106. The intranet gateway system receives the database access request and transmits the database access request to the proxy access system;
[0068] In this embodiment, the intranet gateway can receive the database access request sent directly from the terminal system in step 102, or can receive the database access request sent from the public network gateway as a transmission intermediary, and then send the database access request to the proxy access system.
[0069] For details, please refer to Figure 3 , Figure 3 This is a schematic diagram of a specific embodiment of step 106 in an embodiment of the present invention, and step 106 includes the following specific embodiments:
[0070] 1061. The intranet gateway system receives the database access request;
[0071] 1062. Determine whether the client certificate corresponding to the database access request is data in a preset registry;
[0072] 1063. When the data is in a preset registry, the data access request is converted into proxy access data, and the proxy access data is transmitted to the proxy access system.
[0073] In steps 1061-1063, the intranet gateway can further limit the database access request device to be a designated registered device, and needs to register information before connecting to the intranet gateway in the intranet, distribute client certificates after being recognized by the intranet, and register the client certificates in the intranet gateway. After receiving the database access request, verify the client certificate of the database access request, and after confirming that it is qualified, convert the data access request into proxy access data, and transmit the proxy access data to the proxy access system.
[0074] Furthermore, in step 1063, “converting the data access request into proxy access data” includes the following specific implementations:
[0075] 10631. According to the preset token parameters and HTTP protocol, encapsulate the data access request to generate proxy access data.
[0076] In step 10631, after the intranet gateway (assuming Nginx is used) receives the request, it forwards it to the database proxy program through the HTTP protocol. There may be multiple intranet gateway connections to the database, but each intranet gateway is set with a specific token parameter. The token parameter and the HTTP protocol are used to encapsulate the data access request to generate proxy access data, so that the proxy access system can verify the legitimacy of the intranet gateway and connect to the database after confirming the legitimacy.
[0077] 107. The proxy access system receives the database access request, performs permission verification and injection protection processing on the database access request, generates query parameters, performs query processing in a preset database based on the query parameters, obtains query data, and sends the query data to the intranet gateway system;
[0078] In this embodiment, after receiving the database access request, the proxy access system performs permission verification and injection protection processing on the database access request and generates query parameters. In this process, at least the following steps are performed:
[0079] (1) Query permission verification, judging the legitimacy and permission verification based on the token carried in the http request header. (2) Verifying the legitimacy of SQL statements. (3) Semantic data operation conversion, converting data into execution parameters, isolating the database from direct contact with external request commands.
[0080] The query parameters are then sent to the database for query execution, query data is obtained after execution, and the query data is sent to the intranet gateway system.
[0081] For details, please refer to Figure 4 , Figure 4 This is a schematic diagram of a specific embodiment of step 107 in an embodiment of the present invention. In step 107, "the proxy access system receives the database access request, performs permission verification and injection protection processing on the database access request, and generates query parameters" includes the following specific embodiments:
[0082] 1071. The proxy access system receives the database access request;
[0083] 1072. Parse the SQL statement of the database access request to determine the scheme and table requested to be accessed;
[0084] 1073. Based on the permission settings of the scheme and the table, determine whether the database access request has access rights;
[0085] 1074. When the access right is granted, determining whether the SQL statement of the database access request contains a non-query statement;
[0086] 1075. When no non-query statement is included, the query size control setting of the scheme and the table is read, the query size control setting is written into the database access request, and a query restriction request is generated;
[0087] 1076. Perform protection compilation processing on the query restriction request to generate query parameters.
[0088] In steps 1071-1076, query permission verification is performed, and the legitimacy and permission are determined based on the token carried in the http request header. The legitimacy of the SQL statement is checked, including data permission verification (scheme and table cannot be accessed without permission), and only SQL queries are allowed. Query result set size control is performed, and the query size control setting is written into the database access request to generate a query restriction request to prevent the database from crashing due to querying a large amount of data. SQL injection protection is performed, and the query restriction request is protected and compiled to generate query parameters. In addition to using regular expressions for simple syntax checks, the database agent can use parameterized queries to isolate SQL injections. For example, when connecting to a database, use a parameterized query library instead of directly spelling SQL:
[0089] from sqlalchemy import create_engine, text
[0090] engine = create_engine("postgresql: / / user:password@localhost / db")
[0091] def execute_query(sql_statement, params=None):
[0092] # Assume that SQL has passed the previous verification
[0093] with engine.connect() as connection:
[0094] result = connection.execute(text(sql_statement), params)
[0095] return result.fetchall()
[0096] Here we use SQLAlchemy's text and execute methods to effectively prevent SQL injection and ensure that parameters and SQL statements are separated.
[0097] Specifically, in step 1074, "determining whether the SQL statement of the database access request contains a non-query statement" includes the following specific implementation methods:
[0098] 10741. Determine whether the SQL statement of the database access request starts with a SELECT string;
[0099] 10742. When it starts with a SELECT string, determine whether the SQL statement of the database access request contains an INSERT string, an UPDATE string, or a DELETE string.
[0100] In steps 10741-10742, regular filtering is used to first determine the SELECT string, and then filter the INSERT string, UPDATE string, and DELETE string to avoid requests for unauthorized access to the table. The table access permissions in the SQL statement are checked through regular expressions, and only query operations are allowed.
[0101] Specifically, in step 1075, "writing the query size control setting into the database access request to generate a query restriction request" includes the following specific implementation methods:
[0102] 10751. Write the LIMIT clause and SELECT clause corresponding to the query size control setting into the SQL statement of the database access request to generate a query restriction request.
[0103] In step 10751, add a LIMIT clause when querying the database, add a default limit of 1,000 records, and specify the SELECT clause to select a query range such as the first 5 pages or 16-40 pages to generate a query limit request.
[0104] Furthermore, after step 107, the following specific implementations are also included:
[0105] 1077. The proxy access system writes the query record corresponding to the database access request into a preset query history database, wherein the query record includes: query time, request IP address, query statement, and query data.
[0106] In step 1077, whenever the proxy access system processes a query request, it records the user's query history and uses the logging library to record information such as the user ID, IP address, query content, and result set size.
[0107] 108. The intranet gateway system receives the query data, and based on the communication link between the terminal system and the intranet gateway system, transmits the query data to the terminal system.
[0108] In this embodiment, after the intranet gateway system receives the query data, if the scheme is to be transferred through the public network gateway, the query data is transmitted to the terminal system using the link of the intranet gateway-public network gateway-terminal system. If the intranet gateway is directly connected to the terminal system, the query data is transmitted to the terminal system through the link of the intranet gateway-terminal system.
[0109] In the embodiment of the present invention, both the intranet gateway and the public network gateway need to query the database through the proxy access system. The unified external interface in the proxy access system makes it unnecessary to customize the API for each query, which improves the flexibility of data query and reduces the maintenance cost, thus overcoming the problem of high maintenance cost of the database in query granularity control. The database is hidden in the proxy access system and is not directly exposed to the outside. By setting user access verification and request query verification on the intranet gateway, the public network gateway, and the proxy access system, the security of the database is improved, thus overcoming the problem of insufficient security protection of traditional databases.
[0110] Figure 5 : is a schematic diagram of the structure of a cross-domain query device for a database provided by an embodiment of the present invention. The cross-domain query device 500 for the database may have relatively large differences due to different configurations or performances, and may include one or more processors (central processing units, CPU) 510 (for example, one or more processors) and a memory 520, and one or more storage media 530 (for example, one or more mass storage devices) storing application programs 533 or data 532. Among them, the memory 520 and the storage medium 530 can be short-term storage or permanent storage. The program stored in the storage medium 530 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations in the cross-domain query device 500 for the database. Furthermore, the processor 510 may be configured to communicate with the storage medium 530 to execute a series of instruction operations in the storage medium 530 on the cross-domain query device 500 for the database.
[0111] The database-based cross-domain query device 500 may also include one or more power supplies 540, one or more wired or wireless network interfaces 550, one or more input and output interfaces 560, and / or one or more operating systems 531, such as Windows Server, Mac OS X, Unix, Linux, Free BSD, etc. Those skilled in the art will appreciate that Figure 5The cross-domain query device structure of the database shown does not constitute a limitation on the cross-domain query device based on the database, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.
[0112] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions are executed on a computer, the computer executes the steps of the cross-domain query method of the database.
[0113] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0114] In addition, although each operation is described in a specific order, this should be understood as requiring such operation to be performed in the specific order shown or in a sequential order, or requiring that all illustrated operations should be performed to obtain desired results. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single implementation in combination. On the contrary, the various features described in the context of a single implementation can also be implemented in multiple implementations individually or in any suitable sub-combination mode.
[0115] Although the subject matter has been described in language specific to structural features and / or methodological logical actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims.
Claims
1. A cross-domain query method for a database, characterized in that: The cross-domain query method of the database is applied to the cross-domain query system of the database, and the cross-domain query system of the database includes: a terminal system, a public network gateway system, an intranet gateway system, and a proxy access system, wherein the public network gateway system is communicatively connected to the intranet gateway system, and the intranet gateway system is communicatively connected to the proxy access system. The cross-domain query method of the database includes: The terminal system receives a database access request, and performs a connection test on the intranet gateway system according to the database access request to obtain a test result; When the test result is qualified, the database access request is sent to the intranet gateway system; When the test result is unqualified, a public network access request is sent to the public network gateway system; The public network gateway system receives the public network access request, performs a legality verification process on the public network access request, and obtains a verification result; When the verification result is qualified, obtaining the database access request from the terminal system, and sending the database access request to the intranet gateway system; The intranet gateway system receives the database access request and transmits the database access request to the proxy access system; The proxy access system receives the database access request, performs permission verification and injection protection processing on the database access request, generates query parameters, and performs query processing in a preset database based on the query parameters to obtain query data, and sends the query data to the intranet gateway system; The intranet gateway system receives the query data, and based on the communication link between the terminal system and the intranet gateway system, transmits the query data to the terminal system.
2. The cross-domain query method of a database according to claim 1, characterized in that: The proxy access system receives the database access request, performs permission verification and injection protection processing on the database access request, and generates query parameters including: The proxy access system receives the database access request; Parsing the SQL statement of the database access request to determine the scheme and table requested to be accessed; Based on the permission settings of the scheme and table, determine whether the database access request has access permissions; If the access right is granted, determining whether the SQL statement of the database access request contains a non-query statement; When no non-query statement is included, the query size control setting of the scheme and the table is read, the query size control setting is written into the database access request, and a query restriction request is generated; The query restriction request is protected and compiled to generate query parameters.
3. The cross-domain query method of a database according to claim 2, characterized in that: The determining whether the SQL statement of the database access request contains a non-query statement comprises: Determine whether the SQL statement of the database access request starts with a SELECT string; When it starts with a SELECT string, it is determined whether the SQL statement of the database access request contains an INSERT string, an UPDATE string, or a DELETE string.
4. The cross-domain query method of a database according to claim 2, characterized in that: Writing the query size control setting into the database access request to generate a query restriction request comprises: The LIMIT clause and the SELECT clause corresponding to the query size control setting are written into the SQL statement of the database access request to generate a query restriction request.
5. The cross-domain query method of a database according to claim 1, characterized in that: The intranet gateway system receives the database access request, and transmits the database access request to the proxy access system, comprising: The intranet gateway system receives the database access request; Determining whether the client certificate corresponding to the database access request is data in a preset registry; When the data is in a preset registration table, the data access request is converted into proxy access data, and the proxy access data is transmitted to the proxy access system.
6. The cross-domain query method of a database according to claim 5, characterized in that: The converting the data access request into proxy access data comprises: According to the preset token parameters and HTTP protocol, the data access request is encapsulated to generate proxy access data.
7. The cross-domain query method of a database according to claim 1, characterized in that: The public network gateway system receives the public network access request, performs a validity check on the public network access request, and obtains a check result including: The public network gateway system receives the public network access request; Determine whether the source IP address of the public network access request is in the access control table or determine whether the source device of the public network access request is a trusted terminal; When the source IP address is in the access control table and / or the source device is a trusted terminal, a qualified verification result is generated; When the source IP address is not in the access control table and the source device is not a trusted terminal, an unqualified verification result is generated.
8. The cross-domain query method of a database according to claim 1, characterized in that: After sending the query data to the intranet gateway system, the method further includes: The proxy access system writes the query record corresponding to the database access request into a preset query history database, wherein the query record includes: query time, request IP address, query statement, and query data.
9. A cross-domain query device for a database, characterized in that: The cross-domain query device for a database comprises: a memory and at least one processor, the memory stores instructions, and the memory and the at least one processor are interconnected via a line; The at least one processor calls the instruction in the memory to enable the cross-domain query device of the database to execute the cross-domain query method of the database according to any one of claims 1-8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the cross-domain query method of a database according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Application cross-domain roaming method
CN114584425A
Program control method for network devices and network system
EP2040418A1