Database change system, method, device, storage medium and program product

By using a dynamic signature mechanism in the database change system to verify the authorization status of the client, the problem that database change requests in the prior art are easily tampered with, and higher security and reliability are achieved.

CN119918035APending Publication Date: 2025-05-02CETC JINCANG (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411999132.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

In the prior art, database change requests initiated by devices are easily stolen or tampered with, increasing the possibility of unauthorized devices tampering with more requests and reducing the reliability and security of database changes.

Method used

The client generates a change request and determines real-time environment parameter data, generates a dynamic signature of the client based on the change request and real-time environment parameter data, and sends it with the device identification data to the server. The server determines whether the client is an authorized device based on the device identification data, and generates a server dynamic signature based on the client's dynamic signature and the device identification data. After verification is passed, the change request is executed.

Benefits of technology

Reduces the possibility of tampering with changes and improves the security and reliability of database changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119918035A_ABST
    Figure CN119918035A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a database change system, method and equipment, a storage medium and a program product. The method comprises the following steps: generating a change request through a client, determining equipment identification data and real-time environment parameter data at the moment, generating a client dynamic signature based on the change request and the real-time environment parameter data, and sending the client dynamic signature and the equipment identification data of the client to a server, after a server receives equipment identification data, whether a client is authorized equipment or not is determined based on the equipment identification data, when the client is determined to be authorized equipment, a server dynamic signature is generated based on a client dynamic signature and the equipment identification data, and the client dynamic signature is verified according to the server dynamic signature. And executing the change request when the verification is passed. The method is used for achieving the effects of reducing the possibility of tampering the change request and improving the safety and reliability of database change.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of database access management, and in particular to a database change system, method, device, storage medium and program product. Background Art

[0002] Changing the database table structure (such as adding new fields, modifying field types, deleting tables, etc.) is an important part of database management.

[0003] When a change request is received, the prior art reviews the device that initiated the change request through a limited management system to determine whether the device has the authority to perform the change operation, and performs the change on the database if the device has the authority to perform the change operation.

[0004] However, in the prior art, the change request initiated by the device is easily stolen or tampered with, which increases the possibility of unauthorized devices tampering with the change request, thereby reducing the reliability and security of the database change. Summary of the invention

[0005] The embodiments of the present application provide a database change system, method, device, storage medium and program product to reduce the possibility of tampering with change requests and improve the security and reliability of database changes.

[0006] In a first aspect, an embodiment of the present application provides a database modification system, including:

[0007] The client is used to generate a change request and determine the real-time environment parameter data, generate a client dynamic signature based on the change request and the real-time environment parameter data; and send the client dynamic signature and the client device identification data to the server;

[0008] The server is used to receive the client's dynamic signature and the client's device identification data; determine whether the client is an authorized device based on the device identification data, and when it is determined to be an authorized device, generate a server-side dynamic signature based on the client's dynamic signature and the device identification data; verify the client's dynamic signature based on the server-side dynamic signature, and execute the change request when the verification passes.

[0009] Optionally, when the client generates a client dynamic signature based on the change request and the real-time environment parameter data, it is specifically used to:

[0010] Generate a corresponding client hash value according to the real-time environment parameter data, where the client hash value is a hash value corresponding to the real-time environment parameter data generated by the client;

[0011] The client's hash value, real-time environmental parameter data and change request are processed through the client's device private key to generate a client dynamic signature.

[0012] Optionally, when the server generates a server dynamic signature based on the client dynamic signature and the device identification data, it is specifically used to:

[0013] Based on the authorization table, determine the device public key and device private key corresponding to the device identification data;

[0014] The client dynamic signature is decrypted through the device public key to obtain the real-time environment parameter data, the client hash value and the change request; the corresponding server hash value is generated according to the real-time environment parameter data, and the server hash value is the hash value corresponding to the real-time environment parameter data generated by the server;

[0015] The server-side hash value, real-time environmental parameter data, and change request are processed through the device private key to generate a server-side dynamic signature.

[0016] Optionally, when the server verifies the client dynamic signature based on the server dynamic signature, it is specifically used to:

[0017] Determine whether the server-side dynamic signature is consistent with the client-side dynamic signature, and if they are consistent, obtain the timestamp corresponding to the server-side dynamic signature and the timestamp corresponding to the client-side dynamic signature;

[0018] Determine the time difference between the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature. If the time difference does not exceed the preset time, determine that the client dynamic signature verification has passed. Otherwise, determine that the client dynamic signature verification has failed.

[0019] Optionally, the server is also used to:

[0020] receiving a registration request sent by a client, the registration request including device identification data of the client;

[0021] When it is determined that the registration request is valid, a device public key and a device private key corresponding to the client are generated; the device private key is sent to the client, and an authorization table is updated with the device identification data, device public key and device private key of the client; wherein the authorization table includes device identification data, device private keys and device public keys corresponding to multiple registered clients, and the multiple device identification data in the authorization table are used to determine whether the client is an authorized device.

[0022] In a second aspect, an embodiment of the present application provides a method for changing a database, which is applied to a client and includes:

[0023] Generate change requests and determine real-time environmental parameter data;

[0024] Generate client dynamic signature based on change request and real-time environment parameter data;

[0025] The client's dynamic signature and the client's device identification data are sent to the server; when the server determines that the client is an authorized device based on the device identification data, the client's dynamic signature is verified based on the server's dynamic signature, and the change request is executed when the verification passes; wherein the server's dynamic signature is generated by the server based on the client's dynamic signature and the device identification data.

[0026] Optionally, a client dynamic signature is generated based on the change request and real-time environment parameter data, specifically including:

[0027] Generate a corresponding client hash value according to the real-time environment parameter data, where the client hash value is a hash value corresponding to the real-time environment parameter data generated by the client;

[0028] The client's hash value, real-time environmental parameter data and change request are processed through the client's device private key to generate a client dynamic signature.

[0029] In a third aspect, an embodiment of the present application provides a method for changing a database, which is applied to a server, comprising:

[0030] Receiving a client dynamic signature and device identification data of the client sent by the client; the client dynamic signature is generated by the client based on the generated change request and corresponding real-time environment parameter data;

[0031] Determine whether the client is an authorized device based on the device identification data. When it is determined to be an authorized device, generate a server dynamic signature based on the client dynamic signature and the device identification data; verify the client dynamic signature based on the server dynamic signature, and execute the change request when the verification passes.

[0032] Optionally, when generating the server-side dynamic signature based on the client-side dynamic signature and the device identification data, the process specifically includes:

[0033] Based on the authorization table, determine the device public key and device private key corresponding to the device identification data;

[0034] The client dynamic signature is decrypted through the device public key to obtain the real-time environment parameter data, the client hash value and the change request; the corresponding server hash value is generated according to the real-time environment parameter data, and the server hash value is the hash value corresponding to the real-time environment parameter data generated by the server;

[0035] The server-side hash value, real-time environmental parameter data, and change request are processed through the device private key to generate a server-side dynamic signature.

[0036] Optionally, when verifying the client dynamic signature based on the server dynamic signature, it specifically includes:

[0037] Determine whether the server-side dynamic signature is consistent with the client-side dynamic signature, and if they are consistent, obtain the timestamp corresponding to the server-side dynamic signature and the timestamp corresponding to the client-side dynamic signature;

[0038] Determine the time difference between the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature. If the time difference does not exceed the preset time, determine that the client dynamic signature verification has passed. Otherwise, determine that the client dynamic signature verification has failed.

[0039] Optionally, it also includes:

[0040] receiving a registration request sent by a client, the registration request including device identification data of the client;

[0041] When it is determined that the registration request is valid, a device public key and a device private key corresponding to the client are generated; the device private key is sent to the client, and an authorization table is updated with the device identification data, device public key and device private key of the client; wherein the authorization table includes device identification data, device private keys and device public keys corresponding to multiple registered clients, and the multiple device identification data in the authorization table are used to determine whether the client is an authorized device.

[0042] In a fourth aspect, an embodiment of the present application provides a method for changing a database, which is applied to a client and includes:

[0043] A generation module, used to generate change requests and determine real-time environmental parameter data;

[0044] A first processing module, used to generate a client dynamic signature based on the change request and real-time environment parameter data;

[0045] The first processing module is also used to send the client's dynamic signature and the client's device identification data to the server; so that when the server determines that the client is an authorized device based on the device identification data, the client's dynamic signature is verified based on the server's dynamic signature, and the change request is executed when the verification passes; wherein the server's dynamic signature is generated by the server based on the client's dynamic signature and the device identification data.

[0046] Optionally, the first processing module is further used to generate a corresponding client hash value according to the real-time environment parameter data, where the client hash value is a hash value corresponding to the real-time environment parameter data generated by the client;

[0047] The client's hash value, real-time environmental parameter data and change request are processed through the client's device private key to generate a client dynamic signature.

[0048] In a fifth aspect, an embodiment of the present application provides a method for changing a database, which is applied to a server, and includes:

[0049] A receiving module, used for receiving a client dynamic signature and device identification data of the client sent by the client; the client dynamic signature is generated by the client based on the generated change request and the corresponding real-time environment parameter data;

[0050] The second processing module is used to determine whether the client is an authorized device based on the device identification data. When it is determined to be an authorized device, a server dynamic signature is generated based on the client dynamic signature and the device identification data; the client dynamic signature is verified based on the server dynamic signature, and the change request is executed when the verification passes.

[0051] Optionally, the second processing module is further used to determine the device public key and the device private key corresponding to the device identification data based on the authorization table;

[0052] The client dynamic signature is decrypted through the device public key to obtain the real-time environment parameter data, the client hash value and the change request; the corresponding server hash value is generated according to the real-time environment parameter data, and the server hash value is the hash value corresponding to the real-time environment parameter data generated by the server;

[0053] The server-side hash value, real-time environmental parameter data, and change request are processed through the device private key to generate a server-side dynamic signature.

[0054] Optionally, the second processing module is further used to determine whether the server-side dynamic signature is consistent with the client-side dynamic signature, and when it is determined that they are consistent, obtain a timestamp corresponding to the server-side dynamic signature and a timestamp corresponding to the client-side dynamic signature;

[0055] Determine the time difference between the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature. If the time difference does not exceed the preset time, determine that the client dynamic signature verification has passed. Otherwise, determine that the client dynamic signature verification has failed.

[0056] Optionally, the receiving module is further used to receive a registration request sent by the client, where the registration request includes device identification data of the client;

[0057] When it is determined that the registration request is valid, a device public key and a device private key corresponding to the client are generated; the device private key is sent to the client, and an authorization table is updated with the device identification data, device public key and device private key of the client; wherein the authorization table includes device identification data, device private keys and device public keys corresponding to multiple registered clients, and the multiple device identification data in the authorization table are used to determine whether the client is an authorized device.

[0058] In a sixth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;

[0059] Memory stores computer-executable instructions;

[0060] The processor executes the computer-executable instructions stored in the memory, so that the processor executes various possible implementations of the second aspect and / or the third aspect as described above.

[0061] In the seventh aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-readable storage medium is stored computer execution instructions, which, when executed by a processor, are used to implement various possible implementations of the second aspect and / or the third aspect as described above.

[0062] In an eighth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements various possible implementations of the second aspect and / or the third aspect as described above.

[0063] The database change system, method, device, storage medium and program product provided by the embodiment of the present application generate a change request through the client, and determine the device identification data and the real-time environmental parameter data at this time, generate a client dynamic signature based on the change request and the real-time environmental parameter data, and send the client dynamic signature and the client's device identification data to the server, so that after receiving the device identification data, the server determines whether the client is an authorized device based on the device identification data, and when it is determined to be an authorized device, generates a server dynamic signature based on the client dynamic signature and the device identification data, and verifies the client dynamic signature according to the server dynamic signature, and executes the change request when the verification passes. The present application reduces the possibility of tampering with the change request and improves the security and reliability of database changes. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0065] Figure 1 A schematic diagram of the prior art scenario provided for this application;

[0066] Figure 2 A schematic diagram of the structure of the database change system provided for this application;

[0067] Figure 3 Schematic diagram of the process of database modification provided in this application Figure 1 ;

[0068] Figure 4 Schematic diagram of the process of database modification provided in this application Figure 2 ;

[0069] Figure 5 Schematic diagram of the process of database modification provided in this application Figure 3 ;

[0070] Figure 6 A schematic diagram of the structure of the device for changing the database provided in this application;

[0071] Figure 7 A schematic diagram of the structure of the electronic device provided in this application.

[0072] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0073] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0074] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0075] The change of database table structure (such as adding fields, modifying field types, deleting tables, etc.) is an important part of database management. The change of database table structure has a significant impact on business processing and data storage. Therefore, when the database table structure is tampered with, it is easy to cause problems such as abnormal business processing, system data loss and tampering.

[0076] Figure 1 The schematic diagram of the prior art scenario provided for this application is as follows: Figure 1As shown, the scenario includes a client, a rights management system and a database, wherein the client includes client 1, client 2, ... and client n, where n is a positive integer. In the prior art, after any client device (e.g., client 1) of the client initiates a request to change the database table structure, the rights management system will review the rights of the user who initiated the request and open a modification channel to the authorized user, so that the user can perform a change operation on the database table structure through client 1. However, the database table structure change request initiated in the prior art is easily stolen or tampered with, thereby increasing the possibility of unauthorized client devices tampering with the database table structure change request, further reducing the reliability and security of database changes.

[0077] In addition, in the enterprise development environment, the approval and logging of database table structure changes usually rely on manual approval or third-party approval tools. However, relying on manual and third-party approval tools reduces database security and the reliability of approving database table structure change permissions.

[0078] The method for changing a database provided by the present application, when a client generates a change request, determines the real-time environment parameter data through the client, and determines the corresponding client hash value according to the real-time environment parameter data, processes the client hash value, the real-time environment parameter data and the change request through the device private key obtained by the client when registering, generates a client dynamic signature, and sends the client dynamic signature and the device identification data to the server, so that when the server receives the device identification data, it determines whether the device identification data exists in the authorization table, and when it is determined that it exists, further determines the device public key added by the client when registering in the authorization table, so as to parse and process the client dynamic signature, obtain the real-time environment parameter data, calculate and generate the server hash value based on the real-time environment parameter data, reconstruct the signature according to the server hash value, the change request and the real-time environment parameter data, and obtain the server dynamic signature. When the server dynamic signature is consistent with the client dynamic signature and the time difference corresponding to the two signature timestamps does not exceed the preset time, it is determined that the client dynamic signature verification is passed, and the change is executed based on the change request at this time, otherwise, the change request is rejected. Therefore, the present application reduces the possibility of tampering with the change request and improves the security and reliability of database changes.

[0079] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0080] Figure 2 The structural diagram of the database change system provided for this application is as follows: Figure 2 As shown, the database change system includes a client and a server. The client is used to generate a change request, determine the real-time environment parameter data, generate a client dynamic signature based on the change request and the real-time environment parameter data; send the client dynamic signature and the client device identification data to the server; the server is used to receive the client dynamic signature and the client device identification data; determine whether the client is an authorized device based on the device identification data, and generate a server dynamic signature based on the client dynamic signature and the device identification data when it is determined to be an authorized device; verify the client dynamic signature based on the server dynamic signature, and execute the change request when the verification passes.

[0081] Optionally, the real-time environment parameter data includes but is not limited to system timestamp, CPU (Central Processing Unit, central processing unit) usage rate, etc. The device identification data includes but is not limited to product_uuid (computer unique identifier).

[0082] Optionally, the server is also used to: receive a registration request sent by the client, the registration request including the client's device identification data; when it is determined that the registration request is valid, generate a device public key and a device private key corresponding to the client; send the device private key to the client, and update the authorization table with the client's device identification data, device public key and device private key; wherein the authorization table includes device identification data, device private keys and device public keys corresponding to multiple clients that have passed registration, and the multiple device identification data in the authorization table are used to determine whether the client is an authorized device.

[0083] Optionally, the authorization table includes but is not limited to device identification data, device public keys, device private keys, authorization time and authorization expiration time respectively corresponding to multiple clients.

[0084] In a possible embodiment, when a client accesses a server for the first time, it sends a registration request to the server. After receiving the registration request, the server determines the device identification data of the client based on the registration request, and upon receiving the authorization indication of the device identification data, determines that the registration request is valid, and generates the corresponding device public key and device private key based on the device identification data. The server sends the device private key to the client. The device identification data is added to the authorization table, a mapping relationship is added to the device identification data according to the corresponding device public key and device private key, the authorization time of the device identification data is determined (e.g., 8:00 on the same day), and the authorization expiration time is added to the device identification data based on the first preset time (e.g., one day) (e.g., 8:00 on the next day). In this embodiment, a unique device private key is sent to each authorized client during the client registration process, and the audit of database access is enhanced through different device private keys, so as to avoid tampering of change requests due to duplication of private keys, and further improve the reliability of database table structure changes.

[0085] Optionally, when the client generates a client dynamic signature based on the change request and real-time environment parameter data, it is specifically used to: generate a corresponding client hash value according to the real-time environment parameter data, the client hash value is the hash value corresponding to the real-time environment parameter data generated by the client; process the client hash value, real-time environment parameter data and change request through the client's device private key to generate a client dynamic signature.

[0086] In a possible embodiment, after the client generates a change request, it obtains the device identification data and determines the current real-time environment parameter data, and obtains the corresponding client hash value by processing the real-time environment parameter data. The client hash value, the change request, and the real-time environment parameter data are concatenated and processed using the device private key to obtain the client dynamic signature. The client dynamic signature and the device identification data are sent to the server through a SQL (Structured Query Language) statement.

[0087] Optionally, the client concatenates the client hash value, the change request, the real-time environment parameter data and the device identification data, and processes them using the device private key to obtain a client dynamic signature. This embodiment enhances the security and reliability of the device identification data.

[0088] This embodiment calculates the client hash value based on the current real-time environmental parameter data, and further uses the device private key to generate a client dynamic signature from the real-time environmental parameter data, change request and client hash value, thereby enhancing the data protection of real-time environmental parameter data and change requests, realizing the dynamic nature of the permission review process and the uniqueness of the signature, enhancing the identity review of the client, and further improving the security and reliability of database changes.

[0089] In a possible embodiment, after receiving the client's dynamic signature and device identification data, the server determines whether the device identification data exists in the authorization table, and when it is determined that the device identification data exists, determines the timestamp corresponding to the client's dynamic signature. When the timestamp does not exceed the authorization expiration time corresponding to the device identification data in the authorization table, it determines that the client is an authorized device, and generates a server dynamic signature based on the client's dynamic signature and the device identification data, so as to further verify the client's dynamic signature based on the server's dynamic signature, and executes this change request when the verification passes.

[0090] Exemplarily, when the verification fails, the server sends a feedback verification failure message to the client.

[0091] This embodiment generates a client dynamic signature based on real-time environmental parameter data and a change request and sends it to the server, so that when the server determines that the client is an authorized device, it generates a server dynamic signature and further verifies the client dynamic signature, and executes the change request after the verification is passed, thereby enhancing the reliability and accuracy of the review of database table structure change permissions and improving the security and reliability of database table structure changes.

[0092] Optionally, when the server generates a server dynamic signature based on the client dynamic signature and device identification data, it is specifically used to: determine the device public key and device private key corresponding to the device identification data based on the authorization table; decrypt the client dynamic signature through the device public key to obtain real-time environment parameter data, client hash value and change request; generate a corresponding server hash value based on the real-time environment parameter data, the server hash value is the hash value corresponding to the real-time environment parameter data generated by the server; process the server hash value, real-time environment parameter data and change request through the device private key to generate a server dynamic signature.

[0093] Optionally, when the server verifies the client dynamic signature based on the server dynamic signature, it is specifically used to: determine whether the server dynamic signature is consistent with the client dynamic signature, and when they are determined to be consistent, obtain the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature; determine the time difference between the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature, if the time difference does not exceed the preset time, determine that the client dynamic signature verification has passed, otherwise, determine that the client dynamic signature verification has failed.

[0094] In one possible embodiment, Figure 3 Schematic diagram of the process of database modification provided in this application Figure 1 ,like Figure 3 As shown, the server includes an identification unit, a parsing unit, a reconstruction unit and a verification unit. After receiving the client's dynamic signature and device identification data, the server determines the device public key and device private key corresponding to the device identification data when the identification unit determines that the device identification data exists in the authorization table, and sends the device public key to the parsing unit and the device private key to the reconstruction unit. The parsing unit uses the device public key to parse the client's dynamic signature, obtain the change request, real-time environment parameter data and client hash value, send the change request and real-time environment parameter data to the reconstruction unit, and send the client hash value to the verification unit.

[0095] Exemplarily, when the identification unit determines that the device identification data does not exist in the authorization table, an unauthorized notification is generated and sent to the client.

[0096] In a possible embodiment, a hash value is reconstructed according to the real-time environment parameter data by a reconstruction unit to obtain a server hash value, and a device private key is used to reconstruct a signature for the server hash value, the change request and the real-time environment parameter data to generate a server dynamic signature, and the server dynamic signature and the server hash value are sent to a verification unit. The verification unit determines whether the server hash value and the client hash value are consistent, and determines whether the server dynamic signature and the client dynamic signature are consistent. When the hash value and the dynamic signature are determined to be consistent, the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature are determined, and the time difference between the two timestamps is calculated to determine whether the time difference exceeds a preset time (e.g., five minutes). When it does not exceed the preset time, it is determined that the client dynamic signature verification is passed, and the database change is executed according to the change request.

[0097] Optionally, when executing a database change, the device identification data, device dynamic signature, and real-time environmental parameter data of the client that initiated the change request are recorded and stored in the audit log table. This embodiment improves the traceability of the change operation by recording the relevant information of the change operation in detail.

[0098] Exemplarily, when the time difference exceeds a preset time, it is determined that the client dynamic signature verification fails, and verification failure information is generated and sent to the client.

[0099] Exemplarily, when the verification unit determines that the server hash value and the client hash value are inconsistent, verification failure information is generated and sent to the client.

[0100] Exemplarily, when the verification unit determines that the server dynamic signature and the client dynamic signature are inconsistent, verification failure information is generated and sent to the client.

[0101] This embodiment, when it is determined that there is device identification data in the authorization table, determines the device public key to parse the client dynamic signature, reconstructs the hash value of the parsed fact environment parameter data to obtain the server hash value, and reconstructs the signature of the server hash value through the device private key to obtain the server dynamic signature, verifies the client dynamic signature according to the server hash value and the server dynamic signature and the corresponding timestamp, thereby enhancing the identity authentication of the client and improving the security and reliability of database changes.

[0102] Figure 4 Schematic diagram of the process of database modification provided in this application Figure 2 ,like Figure 4 As shown, in this embodiment Figure 3 Based on the embodiment, a method for changing a database is described in detail, and the method includes:

[0103] S401. The client obtains real-time environmental parameter data and generates a client hash value.

[0104] More specifically, the client generates a change request, obtains the current real-time environment parameter data, and calculates the hash value of the real-time environment parameter data to obtain the client hash value.

[0105] S402: The client generates a client dynamic signature based on the client hash value and device identification data.

[0106] More specifically, the client determines the device identification data and the device private key sent by the server, concatenates the client hash value, real-time environmental parameter data and change request through the device private key, and then encrypts the concatenated data through the device private key to obtain the client dynamic signature.

[0107] S403: The client sends the client dynamic signature and device identification data to the server.

[0108] More specifically, the client transmits the client dynamic signature and device identification data to the server through an SQL statement.

[0109] S404: The server determines the device public key and the device private key corresponding to the device identification data.

[0110] More specifically, when the server determines that the device identification data exists in the authorization table, it determines the device public key and the device private key mapped to the device identification data.

[0111] S405. The server parses the client's dynamic signature based on the device public key to obtain real-time environment parameter data, change request and client hash value.

[0112] S406: The server generates a server hash value and generates a server dynamic signature based on the device private key.

[0113] More specifically, the server recalculates the hash value based on the real-time environmental parameter data to obtain the server hash value, and encrypts the server hash value, real-time environmental parameter data and change request based on the device private key to obtain the server dynamic signature.

[0114] S407: The server verifies the client dynamic signature based on the server dynamic signature and the server hash value.

[0115] More specifically, the server compares the server hash value and the client hash value to see if they are consistent, and compares the server dynamic signature and the client dynamic signature to see if they are consistent. When it is determined that the server hash value and the client hash value are consistent and the server dynamic signature and the client dynamic signature are consistent, the server determines the time difference between the timestamp of generating the client dynamic signature and the timestamp of generating the server dynamic signature. When the time difference is two minutes, it is determined that it does not exceed the preset time of five minutes, and at this time it is determined that the client dynamic signature verification has passed.

[0116] S408: When the verification is passed, the server executes the database change according to the change request.

[0117] The method for database change provided in the embodiment of the present application generates a client hash value of the real-time environmental parameter data, and uses the device public key to process the client hash value, the real-time environmental parameter data and the change request to obtain a client dynamic signature, thereby reducing the probability of copying or tampering with the real-time environmental parameter data and the change request, and further enhancing the server's approval of the client's change authority, thereby improving the database security and the reliability of database changes.

[0118] Figure 5 A schematic diagram of the structure of the device for changing the database provided in this application Figure 1 , applied to the client, such as Figure 5 As shown, the database changing device 50 provided in this embodiment includes:

[0119] A generating module 501 is used to generate a change request and determine real-time environmental parameter data;

[0120] The first processing module 502 is used to generate a client dynamic signature based on the change request and the real-time environment parameter data;

[0121] The first processing module 502 is also used to send the client's dynamic signature and the client's device identification data to the server; so that when the server determines that the client is an authorized device based on the device identification data, the client's dynamic signature is verified based on the server's dynamic signature, and the change request is executed when the verification passes; wherein the server's dynamic signature is generated by the server based on the client's dynamic signature and the device identification data.

[0122] Optionally, the first processing module 502 is further configured to generate a corresponding client hash value according to the real-time environment parameter data, where the client hash value is a hash value corresponding to the real-time environment parameter data generated by the client;

[0123] The client's hash value, real-time environmental parameter data and change request are processed through the client's device private key to generate a client dynamic signature.

[0124] The database change device provided in this embodiment is applied to a client and can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and this embodiment will not be described in detail here.

[0125] Figure 6 A schematic diagram of the structure of the device for changing the database provided in this application Figure 2 , applied to the server, such as Figure 6 As shown, the database changing device 60 provided in this embodiment includes:

[0126] The receiving module 601 is used to receive the client dynamic signature and the device identification data of the client sent by the client; the client dynamic signature is generated by the client based on the generated change request and the corresponding real-time environment parameter data;

[0127] The second processing module 602 is used to determine whether the client is an authorized device based on the device identification data. When it is determined to be an authorized device, a server dynamic signature is generated based on the client dynamic signature and the device identification data; the client dynamic signature is verified based on the server dynamic signature, and the change request is executed when the verification passes.

[0128] Optionally, the second processing module 602 is further configured to determine a device public key and a device private key corresponding to the device identification data based on the authorization table;

[0129] The client dynamic signature is decrypted through the device public key to obtain the real-time environment parameter data, the client hash value and the change request; the corresponding server hash value is generated according to the real-time environment parameter data, and the server hash value is the hash value corresponding to the real-time environment parameter data generated by the server;

[0130] The server-side hash value, real-time environmental parameter data, and change request are processed through the device private key to generate a server-side dynamic signature.

[0131] Optionally, the second processing module 602 is further used to determine whether the server dynamic signature is consistent with the client dynamic signature, and when it is determined that they are consistent, obtain a timestamp corresponding to the server dynamic signature and a timestamp corresponding to the client dynamic signature;

[0132] Determine the time difference between the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature. If the time difference does not exceed the preset time, determine that the client dynamic signature verification has passed. Otherwise, determine that the client dynamic signature verification has failed.

[0133] Optionally, the receiving module 601 is further configured to receive a registration request sent by a client, where the registration request includes device identification data of the client;

[0134] When it is determined that the registration request is valid, a device public key and a device private key corresponding to the client are generated; the device private key is sent to the client, and an authorization table is updated with the device identification data, device public key and device private key of the client; wherein the authorization table includes device identification data, device private keys and device public keys corresponding to multiple registered clients, and the multiple device identification data in the authorization table are used to determine whether the client is an authorized device.

[0135] The database change device provided in this embodiment is applied to the server side and can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and this embodiment will not be described in detail here.

[0136] Figure 7 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 7 As shown, the electronic device 70 provided in this embodiment includes: at least one processor 701 and a memory 702. Optionally, the device 70 further includes a communication component 703. The processor 701, the memory 702 and the communication component 703 are connected via a bus 704.

[0137] In a specific implementation process, at least one processor 701 executes the computer-executable instructions stored in the memory 702, so that at least one processor 701 executes the above method.

[0138] The specific implementation process of the processor 701 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.

[0139] In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the invention can be directly implemented as a hardware processor, or can be implemented by a combination of hardware and software modules in the processor.

[0140] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk storage.

[0141] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of this application is not limited to only one bus or one type of bus.

[0142] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0143] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.

[0144] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special-purpose computer.

[0145] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (Application Specific Integrated Circuits, referred to as: ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0146] The division of units is only a logical function division, and there may be other divisions in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0147] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0148] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0149] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0150] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.

[0151] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary technical means in the art not disclosed by the present invention, are not limited to the precise structure described above and shown in the drawings, and may be modified and changed in various ways without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A database change system, characterized in that: include: The client is used to generate a change request, determine real-time environment parameter data, and generate a client dynamic signature based on the change request and the real-time environment parameter data; Sending the client dynamic signature and the device identification data of the client to the server; A server, used for receiving the client dynamic signature and the device identification data of the client; Determining whether the client is an authorized device according to the device identification data, and if it is determined to be an authorized device, generating a server dynamic signature based on the client dynamic signature and the device identification data; The client dynamic signature is verified based on the server dynamic signature, and the change request is executed when the verification passes.

2. The system according to claim 1, characterized in that When the client generates a client dynamic signature based on the change request and the real-time environment parameter data, the client is specifically used to: Generate a corresponding client hash value according to the real-time environment parameter data, wherein the client hash value is a hash value corresponding to the real-time environment parameter data generated by the client; The client hash value, real-time environment parameter data and change request are processed through the client's device private key to generate a client dynamic signature.

3. The system according to claim 2, characterized in that When the server generates the server dynamic signature based on the client dynamic signature and the device identification data, the server is specifically used to: Based on the authorization table, determine the device public key and the device private key corresponding to the device identification data; Decrypting the client dynamic signature through the device public key to obtain real-time environment parameter data, client hash value and the change request; Generate a corresponding server-side hash value according to the real-time environment parameter data, wherein the server-side hash value is a hash value corresponding to the real-time environment parameter data generated by the server; The server-side hash value, the real-time environmental parameter data and the change request are processed through the device private key to generate a server-side dynamic signature.

4. The system according to claim 3, characterized in that When the server verifies the client dynamic signature based on the server dynamic signature, the server is specifically used to: Determine whether the server-side dynamic signature is consistent with the client-side dynamic signature, and when they are determined to be consistent, obtain a timestamp corresponding to the server-side dynamic signature and a timestamp corresponding to the client-side dynamic signature; Determine the time difference between the timestamp corresponding to the server dynamic signature and the timestamp corresponding to the client dynamic signature. If the time difference does not exceed the preset time, determine that the client dynamic signature verification has passed; otherwise, determine that the client dynamic signature verification has failed.

5. The system according to any one of claims 1 to 4, characterized in that: The server is also used for: receiving a registration request sent by the client, wherein the registration request includes device identification data of the client; When it is determined that the registration request is valid, a device public key and a device private key corresponding to the client are generated; the device private key is sent to the client, and an authorization table is updated with the device identification data, the device public key and the device private key of the client; wherein the authorization table includes device identification data, device private keys and device public keys corresponding to multiple registered clients, respectively, and the multiple device identification data in the authorization table are used to determine whether the client is an authorized device.

6. A method for changing a database, characterized in that: Applied to the client, including: Generate change requests and determine real-time environmental parameter data; Generate a client dynamic signature based on the change request and the real-time environment parameter data; The client dynamic signature and the device identification data of the client are sent to the server; when the server determines that the client is an authorized device based on the device identification data, the client dynamic signature is verified based on the server dynamic signature, and the change request is executed when the verification passes; wherein the server dynamic signature is generated by the server based on the client dynamic signature and the device identification data.

7. A method for changing a database, characterized in that: Applied to the server, including: Receiving a client dynamic signature and device identification data of the client sent by a client; the client dynamic signature is generated by the client based on a generated change request and corresponding real-time environment parameter data; Determine whether the client is an authorized device based on the device identification data. When it is determined to be an authorized device, generate a server dynamic signature based on the client dynamic signature and the device identification data; verify the client dynamic signature based on the server dynamic signature, and execute the change request when the verification passes.

8. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to claim 6 or 7.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to claim 6 or 7 when executed by a processor.

10. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to claim 6 or 7 when being executed by a processor.