Database design method and system supporting multiple privacy protection schemes
By introducing multiple privacy protection layers into database design and supporting multiple privacy protection solutions, the shortcomings of existing database design in protecting sensitive data are solved, and more powerful privacy protection capabilities and system scalability are achieved.
Patent Information
- Application Number
- CN202510099725.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-06
AI Technical Summary
Existing database designs are difficult to effectively protect sensitive data, especially in complex business scenarios. A single security means cannot meet different needs, limiting the database's ability to protect private data.
Design a database design method that supports multi-privacy protection solutions. By building a multi-privacy protection layer between the user layer and the database layer, including protocol processing module, policy configuration system, policy routing module, core algorithm system, basic cryptographic system and database assembly system, multi-level protection of sensitive data is achieved.
It realizes the diversified privacy protection of sensitive data by the database, improves the privacy protection capabilities of the database, ensures the scalability and maintainability of the system, and is suitable for complex business scenarios in different industries.
Smart Images

Figure CN119938645A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a database design method and system supporting multiple privacy protection schemes, belonging to the technical field of database planning and design. Background Art
[0002] Database design is an indispensable and important part of information system development and construction. It is the process of converting actual business requirements into an operational database structure, including determining the entities, attributes and relationships of the database, as well as determining the data storage and data access methods. The quality of database design directly affects the reliability, effectiveness and maintainability of the information system.
[0003] At present, database systems are used in all walks of life, and their importance is self-evident. In industries such as finance, electricity, and transportation that are related to the national economy and people's livelihood, database systems store a large amount of user privacy data. At present, most of the domestic industry data is stored in plain text in the databases of various institutions and cloud platforms. The addition, deletion, modification, and query operations brought about by related business activities will directly operate on these sensitive data, which is very likely to cause data leakage. With the frequent occurrence of privacy leakage incidents, database privacy protection has become a research hotspot in recent years.
[0004] Database design is crucial for planning, storing, and managing the database structure of information. It ensures that the data structure is clear and orderly, improves the efficiency of data access, and protects the data from illegal access and modification. At present, the database design technology that supports the privacy protection of sensitive data is in the preliminary stage of research, and there is no large-scale application practice in this field by large institutions. In addition, the business activities of key infrastructure platforms such as domestic finance and transportation are relatively complex, and a single security method cannot meet the security requirements of different business scenarios, further limiting the database's ability to protect private data. Therefore, a good database design should also provide a general design method to enhance the privacy protection capabilities of sensitive data, while taking into account the scalability and maintainability of the system. Summary of the invention
[0005] In order to solve the above problems, the present invention proposes a database design method and system that supports multiple privacy protection schemes, which can improve the privacy protection capability of the database for sensitive data.
[0006] The technical solution adopted by the present invention to solve the technical problem is: In a first aspect, an embodiment of the present invention provides a database design method supporting multiple privacy protection schemes, comprising the following steps: Constructing multiple privacy protection layers between the user layer and the database layer, wherein the multiple privacy protection layers include a protocol processing module, a policy configuration system, a policy routing module, a core algorithm system, a basic cryptographic system, and a database compilation system; The protocol processing module, the policy configuration system, the policy routing module, the core algorithm system, the basic password system and the database assembly system are sequentially connected and arranged between the user layer and the database layer; When the designed database is privacy protected, the execution process of database operation instructions is as follows: After receiving the database execution command sent by the user layer, the protocol processing module parses out all its fields and sends all the fields to the policy configuration system; The policy configuration system queries whether these fields contain "private fields". If not, the database execution command is directly passed to the database layer for execution. Otherwise, the policy configuration system queries the privacy protection method corresponding to the "private field" and passes it to the corresponding algorithm engine for processing through the policy routing module. When all the algorithm engines involved in the "private fields" have been processed, all the information will be aggregated into the database compilation system; The database assembly system completes the reassembly of database operation instructions and sends the assembled instructions to the database layer for execution.
[0007] As a possible implementation of this embodiment, the protocol processing module receives the instruction sent by the user layer according to the preset protocol, and is responsible for the preliminary analysis of the instruction and then forwards it to other subsystems for further processing according to the instruction type; The policy configuration system records the mapping relationship between the data field and its protection algorithm, and also records the metadata information and related key information of all supported privacy protection algorithms; The policy routing module sets the routing to implement the specific data field and its corresponding privacy protection scheme; The core algorithm system sets the engine of all privacy protection algorithms supported; The basic cryptographic system sets a basic cryptographic operator; The database compilation system converts the user-level database operation instructions into privacy protection operation instructions according to predefined rules.
[0008] As a possible implementation manner of this embodiment, the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
[0009] As a possible implementation of this embodiment, when the existing privacy protection policy cannot meet the current business needs, the database design method also includes a security policy adding process to add a new privacy protection scheme.
[0010] As a possible implementation of this embodiment, the security policy adding process includes: When the protocol processing module receives the "add security policy" instruction, it forwards it to the policy configuration system and the policy configuration system completes the parsing of the new security policy instruction; The policy configuration system queries whether the newly added security policy already exists. If it does, the policy configuration system determines that the newly added instruction is a duplicate execution, and ignores the instruction after returning a successful execution. If the newly added security policy does not exist, the policy configuration system queries whether the core algorithm engine specified in the newly added instruction is ready, and completes the registration of the newly added security policy configuration information after the algorithm engine is ready. After the policy configuration system completes the registration of the newly added security policy, it notifies the policy routing module to establish the routing relationship of <security policy—> algorithm engine>.
[0011] As a possible implementation of this embodiment, when the security policy adopted by some private fields changes, the database design method further includes a security policy update process to perform a security policy update operation.
[0012] As a possible implementation of this embodiment, when updating the security policy, the database design method further includes the following steps: Construct an update coordination module to parse the policy update protocol; Build a policy update system to record the update plans of supported privacy protection algorithms; The update coordination module is connected to the protocol processing module, the policy configuration system and the policy update system respectively, and the policy update system is connected to the core algorithm system.
[0013] As a possible implementation of this embodiment, the update scheme of the supported privacy protection algorithm includes: when the protection method of a data field is changed (for example, from deterministic encryption (DET) to order-preserving encryption (OPE)), the actual database operation method is specified by one or more update strategies built into the policy update system.
[0014] As a possible implementation of this embodiment, the security policy update process includes: When the protocol processing module receives the "update security policy" instruction, it forwards it to the update coordination module to complete further parsing of the instruction; The update coordination module parses the security policy update information, where the security policy update information at least includes the old policy name, the new policy name and the policy update method; The update coordination module calls the policy configuration system to complete the check before the policy update. If the current security policy of the affected field does not match the policy to be updated specified in the instruction, it will be ignored; if it matches, it will further check whether the new security policy has been configured in the policy configuration system and the algorithm engine is ready; After completing all checks, the update coordination module calls the policy update system to perform the policy update operation according to the update method of the policy to be updated specified by the instruction; The policy update system updates the private fields according to the specified policy to be updated, and needs to call the algorithm engine corresponding to the new security policy to process all affected data; The strategy update system calls the database assembly system to complete the assembly of database update instructions; When all affected data have been updated, the policy update system notifies the policy configuration system to complete the update of the private field configuration information; The policy routing module performs the operation of updating routing relations.
[0015] In a second aspect, an embodiment of the present invention provides a database system supporting multiple privacy protection schemes, including a user layer and a database layer, and also including multiple privacy protection layers, wherein the multiple privacy protection layers include a protocol processing module, a policy configuration system, a policy routing module, a core algorithm system, a basic cryptographic system, and a database assembly system; the protocol processing module, the policy configuration system, the policy routing module, the core algorithm system, the basic cryptographic system, and the database assembly system are connected in sequence and arranged between the user layer and the database layer; The execution process of database operation instructions when the database system performs privacy protection is as follows: After receiving the database execution command sent by the user layer, the protocol processing module parses out all its fields and sends all the fields to the policy configuration system; The policy configuration system queries whether these fields contain "private fields". If not, the database execution command is directly passed to the database layer for execution. Otherwise, the policy configuration system queries the privacy protection method corresponding to the "private field" and passes it to the corresponding algorithm engine for processing through the policy routing module. When all the algorithm engines involved in the "private fields" have been processed, all the information will be aggregated into the database compilation system; The database assembly system completes the reassembly of database operation instructions and sends the assembled instructions to the database layer for execution.
[0016] The beneficial effects of the technical solution of the embodiment of the present invention are as follows: Unlike current database products that can only support one or several simple privacy protection schemes through customization, the present invention provides an architectural design that flexibly supports multiple privacy protection schemes, effectively realizing the support of a single database product for most privacy protection schemes on the market, which can not only give full play to the advantages of various privacy protection schemes, but also improve the database's privacy protection capabilities for sensitive data, and ensure that the database system has good scalability and maintainability. Using the database system designed by the present invention, users in different industries can flexibly choose appropriate security schemes and combinations of multiple security schemes according to different business scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a flow chart of a database design method supporting multiple privacy protection schemes according to an exemplary embodiment; Figure 2 is a schematic diagram of the structure of a database system supporting multiple privacy protection schemes according to an exemplary embodiment; Figure 3 It is an execution flow chart of database operation instructions in a database system supporting multiple privacy protection schemes of the present invention; Figure 4 It is a new security strategy design flow chart of the database system supporting multiple privacy protection schemes of the present invention; Figure 5 The present invention supports a security policy update flow chart for a database system with multiple privacy protection schemes. DETAILED DESCRIPTION
[0018] In order to more clearly illustrate the technical features of the solution of the present invention, the present invention is described in detail below through specific implementation methods and in conjunction with the accompanying drawings.
[0019] like Figure 1 As shown, a database design method supporting multiple privacy protection schemes provided by an embodiment of the present invention includes the following steps: Constructing multiple privacy protection layers between the user layer and the database layer, wherein the multiple privacy protection layers include a protocol processing module, a policy configuration system, a policy routing module, a core algorithm system, a basic cryptographic system, and a database compilation system; The protocol processing module, the policy configuration system, the policy routing module, the core algorithm system, the basic password system and the database assembly system are sequentially connected and arranged between the user layer and the database layer; When the designed database is privacy protected, the execution process of database operation instructions is as follows: After receiving the database execution command sent by the user layer, the protocol processing module parses out all its fields and sends all the fields to the policy configuration system; The policy configuration system queries whether these fields contain "private fields". If not, the database execution command is directly passed to the database layer for execution. Otherwise, the policy configuration system queries the privacy protection method corresponding to the "private field" and passes it to the corresponding algorithm engine for processing through the policy routing module. When all the algorithm engines involved in the "private fields" have been processed, all the information will be aggregated into the database compilation system; The database assembly system completes the reassembly of database operation instructions and sends the assembled instructions to the database layer for execution.
[0020] As a possible implementation of this embodiment, the protocol processing module receives the instruction sent by the user layer according to the preset protocol, and is responsible for the preliminary analysis of the instruction and then forwards it to other subsystems for further processing according to the instruction type; The policy configuration system records the mapping relationship between the data field and its protection algorithm, and also records the metadata information and related key information of all supported privacy protection algorithms; The policy routing module sets the routing to implement the specific data field and its corresponding privacy protection scheme; The core algorithm system sets the engine of all privacy protection algorithms supported; The basic cryptographic system sets a basic cryptographic operator; The database compilation system converts the user-level database operation instructions into privacy protection operation instructions according to predefined rules.
[0021] As a possible implementation manner of this embodiment, the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
[0022] As a possible implementation of this embodiment, when the existing privacy protection policy cannot meet the current business needs, the database design method also includes a security policy adding process to add a new privacy protection scheme.
[0023] As a possible implementation of this embodiment, the security policy adding process includes: When the protocol processing module receives the "add security policy" instruction, it forwards it to the policy configuration system and the policy configuration system completes the parsing of the new security policy instruction; The policy configuration system queries whether the newly added security policy already exists. If it does, the policy configuration system determines that the newly added instruction is a duplicate execution, and ignores the instruction after returning a successful execution. If the newly added security policy does not exist, the policy configuration system queries whether the core algorithm engine specified in the newly added instruction is ready, and completes the registration of the newly added security policy configuration information after the algorithm engine is ready. After the policy configuration system completes the registration of the newly added security policy, it notifies the policy routing module to establish the routing relationship of <security policy—> algorithm engine>.
[0024] As a possible implementation of this embodiment, when the security policy adopted by some private fields changes, the database design method further includes a security policy update process to perform a security policy update operation.
[0025] As a possible implementation of this embodiment, when updating the security policy, the database design method further includes the following steps: Construct an update coordination module to parse the policy update protocol; Build a policy update system to record the update plans of supported privacy protection algorithms; The update coordination module is connected to the protocol processing module, the policy configuration system and the policy update system respectively, and the policy update system is connected to the core algorithm system.
[0026] As a possible implementation of this embodiment, the update scheme of the supported privacy protection algorithm includes: when the protection method of a data field is changed (for example, from deterministic encryption (DET) to order-preserving encryption (OPE)), the actual database operation method is specified by one or more update strategies built into the policy update system.
[0027] As a possible implementation of this embodiment, the security policy update process includes: When the protocol processing module receives the "update security policy" instruction, it forwards it to the update coordination module to complete further parsing of the instruction; The update coordination module parses the security policy update information, where the security policy update information at least includes the old policy name, the new policy name and the policy update method; The update coordination module calls the policy configuration system to complete the check before the policy update. If the current security policy of the affected field does not match the policy to be updated specified in the instruction, it will be ignored; if it matches, it will further check whether the new security policy has been configured in the policy configuration system and the algorithm engine is ready; After completing all checks, the update coordination module calls the policy update system to perform the policy update operation according to the update method of the policy to be updated specified by the instruction; The policy update system updates the private fields according to the specified policy to be updated, and needs to call the algorithm engine corresponding to the new security policy to process all affected data; The strategy update system calls the database assembly system to complete the assembly of database update instructions; When all affected data have been updated, the policy update system notifies the policy configuration system to complete the update of the private field configuration information; The policy routing module performs the operation of updating routing relations.
[0028] like Figure 2 As shown, an embodiment of the present invention provides a database system supporting multiple privacy protection schemes, including a user layer and a database layer, and multiple privacy protection layers arranged between the user layer and the database layer, wherein the multiple privacy protection layers include a protocol processing module, a policy configuration system, a policy routing module, a core algorithm system, a basic cryptographic system, and a database assembly system; the protocol processing module, the policy configuration system, the policy routing module, the core algorithm system, the basic cryptographic system, and the database assembly system are connected in sequence and arranged between the user layer and the database layer.
[0029] Unlike current database products that can only support one or several simple privacy protection solutions through customization, the present invention provides an architectural design that flexibly supports multiple privacy protection solutions. Traditional databases are generally divided into a user layer (including necessary drivers, database clients and related protocols, tools, etc.) and a database layer (including database agents, database logs, database instances, etc.). Figure 2 As shown, the present invention increases the privacy protection capability of traditional database products by adding a new "privacy protection layer". Through this privacy protection layer, the database can implement multiple privacy protection solutions without upgrading while maintaining good scalability; at the same time, users can adapt to the "privacy protection layer" without changing the way they operate the database.
[0030] The "privacy protection layer" mainly includes subsystems such as "policy configuration system", "policy update system", "core algorithm system", "basic password system" and "database compilation system", as well as necessary service components such as protocol processing module, update coordination module, and policy routing module. The main functions of each subsystem and module are as follows: Policy configuration system: records the mapping relationship between data fields and their protection algorithms, and also records the metadata information and related key information of all privacy protection algorithms supported by the system; Policy update system: records the update schemes of the privacy protection algorithms supported by the system. For example, when the protection method of a data field is changed from deterministic encryption (DET) to order-preserving encryption (OPE), the actual database operation method can be specified by one or more update policies built into the policy update system. Core algorithm system: contains the implementation engines of all privacy protection algorithms supported by the current system, such as deterministic encryption, order-preserving encryption, and order-revealing encryption. Basic cryptographic system: includes the implementation of basic cryptographic operators, such as symmetric encryption and decryption, digest algorithm, signature verification, etc. Database assembly system: converts user-level database operation instructions into privacy protection operation instructions according to pre-defined rules. For example, replaces plaintext field instructions in SQL statements with ciphertext field instructions converted by the privacy protection scheme. Protocol processing module: receives instructions sent by the user layer according to the preset protocol, and is responsible for the initial analysis of the instructions and forwards them to other subsystems for further processing according to the instruction type; Update coordination module: implements the parsing function of the policy update protocol; Policy routing module: implements the routing function of specific fields and their corresponding privacy protection schemes.
[0031] The core algorithm is a common privacy computing technology, including but not limited to deterministic encryption, order-preserving encryption, etc., and is implemented by respective algorithm engines; the update strategy must be determined based on the availability requirements of the database data, including but not limited to in-place update, shadow table update, auxiliary column update and other strategies.
[0032] The detailed implementation process of the present invention is given below, and the database system proposed by the present invention is further described in detail in conjunction with the accompanying drawings.
[0033] 1. Database operation instruction execution process.
[0034] like Figure 3 As shown, the user layer sends a database execution instruction (such as an SQL statement): (1) After receiving the statement, the protocol processing module parses all the fields involved in the statement and sends all the fields to the policy configuration system; (2) The policy configuration system queries whether these fields contain "private fields" (i.e., fields that have been encrypted and protected using a privacy protection scheme, rather than original plaintext fields); (3) If the instruction does not contain any "private fields", the statement can be directly passed to the database layer for execution; otherwise, the policy configuration system queries the privacy protection method corresponding to the "private field" and passes it to the specific algorithm engine for processing through the policy routing module; (4) When all the algorithm engines involved in the "private fields" have completed processing, all information will be aggregated into the database compilation system; (5) The database assembly system completes the reassembly of database operation instructions and sends the assembled instructions to the database layer for execution.
[0035] So far, the present invention has completed the task of protecting data privacy without the user layer and the database layer being aware of it.
[0036] 2. Add new process to security policy.
[0037] When the existing privacy protection strategy cannot meet the current business needs, the system needs to add a new privacy protection solution, such as Figure 4 As shown: (1) When the protocol processing module receives the "add security policy" instruction, it forwards it to the policy configuration system, which then completes the parsing of the new security policy instruction; (2) The policy configuration system queries whether the newly added security policy already exists. If it does, the policy configuration system determines that the newly added instruction is a duplicate execution and ignores the instruction after returning a successful execution. (3) If the newly added security policy does not exist, the policy configuration system queries whether the core algorithm engine specified in the newly added instruction is ready, and completes the registration of the newly added security policy configuration information after the algorithm engine is ready; (4) After the policy configuration system completes the registration of the new security policy, it notifies the policy routing module to complete the establishment of the routing relationship of <security policy -> algorithm engine>.
[0038] 3. Security policy update process.
[0039] As business needs change, when the security policies used by some "private fields" change, such as changing a sensitive field from the current deterministic encryption policy to an order-preserving encryption policy, you need to execute the security policy update process (the policy update process is also applicable to adding a privacy protection policy to a currently unprotected common field). Figure 5 As shown: (1) When the protocol processing module receives the "update security policy" instruction, it forwards it to the update coordination module to complete further analysis of the instruction; (2) The update coordination module parses the necessary information for security policy updates, such as the old policy name, the new policy name, and the policy update method; (3) The update coordination module calls the policy configuration system to complete the necessary checks before the policy update, such as whether the current security policy of the affected field matches the policy to be updated specified in the instruction. If not, it is ignored; if it matches, it further checks whether the new security policy has been configured in the policy configuration system and the algorithm engine is ready; (4) After completing all checks, the update coordination module calls the policy update system to perform policy update operations according to the update method specified by the instruction; Since the update of security policies may involve a large number of database operations and the update process may affect the availability of database external services, it is necessary to choose a suitable update method based on the characteristics of the business. To this end, the policy update system supports multiple update policies and supports users to add customized update policies; (5) The policy update system updates the private fields according to the specified update policy, and needs to call the algorithm engine corresponding to the new security policy to process all affected data (depending on the specific business situation, it may also need to call the algorithm engine corresponding to the old security policy for coordinated processing); (6) The strategy update system calls the database assembly system to complete the assembly of database update instructions; (7) When all affected data have been updated, the policy update system notifies the policy configuration system to complete the update of the private field configuration information; (8) The policy routing module completes the update of routing relations.
[0040] The present invention provides an architectural design that flexibly supports multiple privacy protection schemes, effectively realizing the support of a single database product for most privacy protection schemes on the market. It can not only give full play to the advantages of various privacy protection schemes, but also improve the database's privacy protection capabilities for sensitive data, and ensure that the database system has good scalability and maintainability.
[0041] By utilizing the database system designed by the present invention, users in different industries can flexibly select appropriate security solutions and combinations of multiple security solutions according to different business scenarios.
[0042] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A database design method supporting multiple privacy protection schemes, characterized in that: The steps include: Constructing multiple privacy protection layers between the user layer and the database layer, wherein the multiple privacy protection layers include a protocol processing module, a policy configuration system, a policy routing module, a core algorithm system, a basic cryptographic system, and a database compilation system; The protocol processing module, the policy configuration system, the policy routing module, the core algorithm system, the basic password system and the database assembly system are sequentially connected and arranged between the user layer and the database layer; When the designed database is privacy protected, the execution process of database operation instructions is as follows: After receiving the database execution command sent by the user layer, the protocol processing module parses out all its fields and sends all the fields to the policy configuration system; The policy configuration system queries whether these fields contain "private fields". If not, the database execution command is directly passed to the database layer for execution; otherwise, the policy configuration system queries the privacy protection method corresponding to the "private field" and passes it to the corresponding algorithm engine for processing through the policy routing module; When all the algorithm engines involved in the "private fields" have been processed, all the information will be aggregated into the database compilation system; The database assembly system completes the reassembly of database operation instructions and sends the assembled instructions to the database layer for execution.
2. The database design method supporting multiple privacy protection schemes according to claim 1, characterized in that: The protocol processing module receives the instructions sent by the user layer according to the preset protocol, and is responsible for the preliminary analysis of the instructions and forwards them to other subsystems for further processing according to the instruction type; The policy configuration system records the mapping relationship between the data field and its protection algorithm, and also records the metadata information and related key information of all supported privacy protection algorithms; The policy routing module sets the routing to implement the specific data field and its corresponding privacy protection scheme; The core algorithm system sets the engine of all privacy protection algorithms supported; The basic cryptographic system sets a basic cryptographic operator; The database compilation system converts the user-level database operation instructions into privacy protection operation instructions according to predefined rules.
3. The database design method supporting multiple privacy protection schemes according to claim 2, characterized in that: The privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm and an order-revealing encryption algorithm.
4. The database design method supporting multiple privacy protection schemes according to any one of claims 1 to 3, characterized in that: When the existing privacy protection strategy cannot meet the current business needs, the database design method also includes a security strategy addition process to add a new privacy protection solution.
5. The database design method supporting multiple privacy protection schemes according to claim 4, characterized in that: The security policy adding process includes: When the protocol processing module receives the "add security policy" instruction, it forwards it to the policy configuration system, which then completes the parsing of the new security policy instruction; The policy configuration system queries whether the newly added security policy already exists. If it does, the policy configuration system determines that the newly added instruction is a duplicate execution, and ignores the instruction after returning a successful execution. If the newly added security policy does not exist, the policy configuration system queries whether the core algorithm engine specified in the newly added instruction is ready, and completes the registration of the newly added security policy configuration information after the algorithm engine is ready. After the policy configuration system completes the registration of the newly added security policy, it notifies the policy routing module to establish the routing relationship of <security policy—> algorithm engine>.
6. The database design method supporting multiple privacy protection schemes according to any one of claims 1 to 3, characterized in that: When the security policy adopted by some private fields changes, the database design method also includes a security policy update process to perform a security policy update operation.
7. The database design method supporting multiple privacy protection schemes according to claim 6, characterized in that: When updating the security policy, the database design method further includes the following steps: Construct an update coordination module to parse the policy update protocol; Build a policy update system to record the update plans of supported privacy protection algorithms; The update coordination module is connected to the protocol processing module, the policy configuration system and the policy update system respectively, and the policy update system is connected to the core algorithm system.
8. The database design method supporting multiple privacy protection schemes according to claim 7, characterized in that: The supported update schemes of the privacy protection algorithm include: when the protection method of a data field is changed, the actual database operation method is specified by one or more update policies built into the policy update system.
9. The database design method supporting multiple privacy protection schemes according to claim 7, characterized in that: The security policy update process includes: When the protocol processing module receives the "update security policy" instruction, it forwards it to the update coordination module to complete further analysis of the instruction; The update coordination module parses the security policy update information, where the security policy update information at least includes the old policy name, the new policy name and the policy update method; The update coordination module calls the policy configuration system to complete the check before the policy update. If the current security policy of the affected field does not match the policy to be updated specified in the instruction, it will be ignored; if it matches, it will further check whether the new security policy has been configured in the policy configuration system and the algorithm engine is ready; After completing all checks, the update coordination module calls the policy update system to perform the policy update operation according to the update method of the policy to be updated specified by the instruction; The policy update system updates the private fields according to the specified policy to be updated, and needs to call the algorithm engine corresponding to the new security policy to process all affected data; The strategy update system calls the database assembly system to complete the assembly of database update instructions; When all affected data have been updated, the policy update system notifies the policy configuration system to complete the update of the private field configuration information; The policy routing module performs the operation of updating routing relations.
10. A database system supporting multiple privacy protection schemes, comprising a user layer and a database layer, characterized in that: It also includes multiple privacy protection layers, which include a protocol processing module, a policy configuration system, a policy routing module, a core algorithm system, a basic cryptographic system, and a database compilation system; the protocol processing module, the policy configuration system, the policy routing module, the core algorithm system, the basic cryptographic system, and the database compilation system are sequentially connected and arranged between the user layer and the database layer; The execution process of database operation instructions when the database system performs privacy protection is as follows: After receiving the database execution command sent by the user layer, the protocol processing module parses out all its fields and sends all the fields to the policy configuration system; The policy configuration system queries whether these fields contain "private fields". If not, the database execution command is directly passed to the database layer for execution; otherwise, the policy configuration system queries the privacy protection method corresponding to the "private field" and passes it to the corresponding algorithm engine for processing through the policy routing module; When all the algorithm engines involved in the "private fields" have been processed, all the information will be aggregated into the database compilation system; The database assembly system completes the reassembly of database operation instructions and sends the assembled instructions to the database layer for execution.
Citation Information
Patent Citations
Data protection method and device
CN110443059A
Data desensitization method and device, nonvolatile storage medium and electronic equipment
CN118332592A
Data encryption method and device, electronic equipment and storage medium
CN119150315A
System and method for data privacy policy generation and implementation
US20230259650A1