Database access method and device and electronic equipment

By introducing a post-authentication mechanism and fingerprint user table mechanism in the database access system, the problem of manually configuring and updating the database account password is solved, reducing management costs and workload.

CN119939549AInactive Publication Date: 2025-05-06BEIJING YUANYUAN SHUAN TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411949517.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When the database account password changes, all database management tools that use these account passwords need to be manually configured and updated, resulting in a significant increase in management costs and workload.

Method used

Through the introduction of a post-authentication mechanism, a user identity authentication operation is performed using predefined SQL commands, and a fingerprint user table is generated based on the authenticated user identity information. After determining that the fingerprint user table includes relevant user identity information, the corresponding database access operation is performed according to the database access permissions.

Benefits of technology

There is no need to change the database account password, and periodically update the verification information. All database management tools that use these account passwords do not require manual configuration and update, which greatly reduces management costs and workload.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939549A_ABST
    Figure CN119939549A_ABST
Patent Text Reader

Abstract

The invention discloses a database access method and device and electronic equipment, and relates to the technical field of databases, and the method comprises the following steps: obtaining an SQL command; executing a user identity authentication operation based on a first SQL command in the SQL commands; if the user identity authentication is successful, generating a fingerprint user table according to the authenticated user identity information; and when determining that the fingerprint user table comprises the user identity information related to the second SQL command, executing a database access operation corresponding to the second SQL command according to the database access permission. Compared with the prior art, a post-authentication mechanism is introduced, verification information can be periodically updated under the requirement that a database login credential needs to be periodically changed, database account passwords do not need to be changed, all database management tools using the account passwords do not need to be manually configured and updated, and the database management efficiency is improved. Therefore, the management cost and the workload are greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of database technology, and in particular to a database access method, device and electronic device. Background Art

[0002] In current database management systems, in order to achieve effective management and access control of database resources, each database user is usually assigned corresponding account information, which includes the user's unique identification and the database account password used to verify the user's identity. By configuring corresponding access rights for each user, the system can achieve refined access control.

[0003] However, in order to ensure the security of the database, the database account password needs to be changed regularly. When the database account password is changed, all database management tools that use these accounts and passwords need to be manually configured and updated accordingly, which greatly increases management costs and workload. Summary of the invention

[0004] In view of this, the present application provides a database access method, device and electronic device, the main purpose of which is to solve the current problem that when the database account password is changed, all database management tools using these account passwords need to be manually configured and updated accordingly, which greatly increases the management cost and workload.

[0005] According to a first aspect of the present application, a database access method is provided, comprising:

[0006] Get SQL commands;

[0007] Execute a user identity authentication operation based on a first SQL command in the SQL commands, wherein the first SQL command is a predefined command that requires executing a user identity authentication operation;

[0008] If the user identity authentication is successful, a fingerprint user table is generated based on the authenticated user identity information;

[0009] If it is determined that the fingerprint user table includes user identity information related to a second SQL command, a database access operation corresponding to the second SQL command is performed according to database access rights, wherein the second SQL command is a command in the SQL commands other than the first SQL command and the third SQL command, and the third SQL command is a command for connecting a database management tool and a database.

[0010] According to a second aspect of the present application, a database access device is provided, comprising:

[0011] Acquisition module, used to obtain SQL commands;

[0012] A first authentication module, configured to perform a user identity authentication operation based on a first SQL command among the SQL commands, wherein the first SQL command is a predefined command that requires a user identity authentication operation to be performed;

[0013] A generation module is used to generate a fingerprint user table according to the authenticated user identity information if the user identity authentication is successful;

[0014] The first determination module is used to determine that the fingerprint user table includes user identity information related to the second SQL command, and then execute a database access operation corresponding to the second SQL command according to the database access permission, wherein the second SQL command is a command in the SQL command except the first SQL command and the third SQL command, and the third SQL command is a command for connecting the database management tool and the database.

[0015] According to a third aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the database access method described in the first aspect is implemented.

[0016] According to a fourth aspect of the present application, an electronic device is provided, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the database access method described in the first aspect when executing the computer program.

[0017] By means of the above technical scheme, a database access method, device and electronic device provided by the present application can obtain SQL commands; perform user identity authentication operations based on the first SQL command in the SQL commands, wherein the first SQL command is a predefined command that needs to perform user identity authentication operations; if the user identity authentication is successful, generate a fingerprint user table according to the authenticated user identity information; determine that the fingerprint user table includes user identity information related to the second SQL command, and then execute the database access operation corresponding to the second SQL command according to the database access rights, wherein the second SQL command is a command in the SQL commands except the first SQL command and the third SQL command, and the third SQL command is a command for connecting the database management tool and the database.

[0018] Compared with the current existing technology, this application introduces a post-authentication mechanism, which allows the use of additional verification information to authenticate the user identity for the first SQL command. When the database login credentials need to change periodically, the verification information only needs to be updated periodically without changing the database account and password. All database management tools that use these account and password do not need to be manually configured and updated, thereby greatly reducing management costs and workload.

[0019] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0021] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0022] Figure 1 A flowchart of a database access method provided by an embodiment of the present disclosure;

[0023] Figure 2 A flowchart of a database access method provided by an embodiment of the present disclosure;

[0024] Figure 3 A flowchart of a post-authentication process provided by an embodiment of the present disclosure;

[0025] Figure 4 A schematic diagram of the structure of a database access device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0026] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to aid understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description. It should be noted that the embodiments of the present disclosure and the features therein may be combined with each other without conflict.

[0027] The following describes the database access method, device and electronic device according to the embodiments of the present disclosure with reference to the accompanying drawings.

[0028] In order to reduce management costs and workload. This embodiment provides a database access method, such as Figure 1 As shown, the method includes:

[0029] Step 101: Get SQL command.

[0030] For the embodiments of the present disclosure, the execution entity may be a database access control system, wherein the database access control system may be used to control and manage access rights to the database to ensure that only authorized users can perform specific database operations.

[0031] like Figure 2 As shown, the database access control system may include a database protocol parsing module, an SQL parsing module and a post-authentication module.

[0032] The database protocol parsing module may be used to monitor and parse the communication traffic data between the database management tool and the database to extract relevant information of the database management tool, which may include basic connection information and SQL related information.

[0033] The basic connection information may include but is not limited to the database connection port, connection time, connection duration and other basic information; the SQL related information may be the SQL query statement extracted from the communication traffic data, which may include the query type (such as SELECT, INSERT, UPDATE, DELETE, etc.), query content, query parameters, etc.

[0034] The SQL parsing module can be used to parse the SQL commands of SQL-related information in the database protocol parsing module, identify the first SQL command pre-defined in the SQL command that needs to perform an authentication operation, and send the first SQL command to the post-authentication module for interactive authentication to complete user identity authentication. For the specific process, see step 102 of the embodiment.

[0035] Step 102: Perform a user identity authentication operation based on a first SQL command in the SQL commands.

[0036] The first SQL command is a predefined command that requires executing a user identity authentication operation.

[0037] For the embodiments of the present disclosure, the first SQL command in the SQL command can be identified based on preset rules. As a possible implementation method, if the SQL command meets the preset rules, the SQL command is determined to be the first SQL command, wherein the preset rules can be determined based on the text pattern, specific keywords, command structure or command context of the first SQL command.

[0038] For the embodiments of the present disclosure, the post-authentication module can perform user authentication operations based on the first SQL command in the SQL command. Through the post-authentication mechanism, the security of database access is improved through an additional real identity authentication step without changing the original access user password; and through the post-authentication mechanism, when the database login credentials need to be changed periodically, there is no need to change the configuration of the original database access tool, thereby reducing management complexity and cost.

[0039] As a possible implementation method, the first SQL command may include a custom authentication method, and the database access control system may send the first authentication information to the user according to the custom authentication method; after the user receives the first authentication information, it is necessary to send it back to the database access control system. After the database access control system receives the second authentication information sent by the user, it is necessary to verify whether the second authentication information is the first authentication information; if the second authentication information is the first authentication information, it is determined that the authentication of the first SQL command is successful, and the execution of the first SQL command is allowed. If the second authentication information is not the first authentication information, it is determined that the authentication of the first SQL command fails, and the execution of the first SQL command is refused.

[0040] Among them, the custom authentication method may include sending a verification code, using biometric data, device fingerprint recognition and other non-traditional authentication methods. The verification information may include but is not limited to passwords, verification codes, fingerprint data, facial recognition data and other data information used to verify the identity of the user. The first verification information may be the verification information sent to the user by the database access control system during the authentication process. The second verification information may be the verification information sent back to the database access control system by the user according to the requirements of the database access control system.

[0041] For the disclosed embodiments, the post-authentication method of the present application supports multiple verification methods, such as mobile phone SMS verification code, email link verification, etc., which solves the problem of database account leakage and sharing abuse from a mechanism perspective.

[0042] For example, Figure 3 As shown, the user enters a first SQL command for executing an authentication operation in the SQL editor of the database management tool, such as user xxx login, where user may represent a user, xxx may represent a user ID, and login may represent a command for the system to start an authentication process.

[0043] After receiving the first SQL command, the database access control system can send a verification code to the user's mobile phone or email according to the custom authentication method in the first SQL command, such as sending a verification code. If the verification code has been sent, the system returns a successful request. After the user receives the verification code in the mobile phone or email, he can enter another SQL command in the database management tool to submit the verification code, such as user xxx token xxx, where user can represent the user, the first xxx can represent the user ID, token can instruct the system to submit a command for the verification code, and the second xxx can represent the verification code received by the user.

[0044] After receiving the verification code submitted by the user, the database access control system can verify whether the verification code submitted by the user is correct. If the verification code is correct, it can be considered that the user has passed the post-authentication stage (i.e. Figure 3 In phase 2 of the REST API, users can perform database access operations with corresponding access permissions, such as query, update, delete, etc.

[0045] Step 103: If the user identity authentication is successful, a fingerprint user table is generated according to the authenticated user identity information.

[0046] The database access control system may include a connection context fingerprint extraction module. The connection context fingerprint extraction module may further extract fingerprint information for the connection context based on the connection basic information extracted by the database protocol analysis module, and the fingerprint information may include terminal fingerprint information and database access fingerprint information.

[0047] Fingerprint information can be generated by combining one or more of the terminal fingerprint information and the database access fingerprint information.

[0048] For the embodiment of the present disclosure, after executing the user identity authentication operation based on the first SQL command and determining that the user identity authentication is successful, the post-authentication module can generate a fingerprint user table by obtaining the first fingerprint information in the connection context fingerprint extraction module and the user identity information corresponding to the first fingerprint information, wherein the fingerprint user table may include the first fingerprint information, the user identity information corresponding to the first fingerprint information, and the effective time of the first fingerprint information. The first fingerprint information may be the fingerprint information of the user identity authentication executed by the first SQL command, and may include terminal fingerprint information and database access fingerprint information. The fingerprint user table may be as shown in Table 1 below.

[0049] Terminal fingerprint information Database access fingerprint information User identity information Validity period Source IP, host name Tools, database account Post-authentication module for users 24 hours

[0050] Table 1

[0051] The terminal fingerprint information can be used to identify the terminal device that initiates the database connection. The terminal fingerprint information may include a source IP address and a host name, wherein the source IP address can be used to characterize the IP address of the terminal device that initiates the database connection, and the host name can be used to characterize the host name of the terminal device that initiates the database connection.

[0052] Database access fingerprint information can be used to identify specific applications and user accounts that access the database. Database access fingerprint information may include tools and database accounts, where tools may be the name and version of management tools or applications used to access the database, and database accounts may be account information used to log in to the database.

[0053] The user identity information may be the identity of a user who has passed authentication in a post-authentication module.

[0054] The validity period can be used to define the validity period of the first fingerprint information in the database access control system, for example, 24 hours. During the validity period, the database access control system can consider the first fingerprint information to be credible, and the fingerprint information may need to be re-authenticated after the timeout.

[0055] Correspondingly, if the authentication duration of the first fingerprint information exceeds the effective duration, the user authentication operation is re-executed based on the first SQL command, wherein the authentication duration is the time interval from the last successful authentication time point of the user to the current time point; if the user authentication is successful, the effective duration of the corresponding first fingerprint information in the fingerprint user table is updated, thereby ensuring the timeliness of the first fingerprint information and improving the security of the database access management and control system.

[0056] Step 104: Determine that the fingerprint user table includes user identity information related to the second SQL command, and then execute a database access operation corresponding to the second SQL command according to the database access permission.

[0057] Among them, the second SQL command is a command in the SQL command except the first SQL command and the third SQL command. The second SQL command can be an SQL command actively initiated by a database user and can be used to perform data operations or queries on the database. The second SQL command can include but is not limited to SQL operations such as SELECT, INSERT, UPDATE, and DELETE.

[0058] The third SQL command is a command for connecting the database management tool and the database.

[0059] For the embodiments of the present disclosure, Figure 2As shown, the database access control system may also include an access control module and a connection behavior whitelist module. The connection behavior whitelist has a connection behavior library of the database management tool built in, and the connection behavior library can be used to identify the standard SQL command (i.e., the third SQL command) executed by the database management tool during the process of logging in and connecting to the database.

[0060] When the database management tool attempts to connect to the database, the connection behavior whitelist module can identify and mark the third SQL command connecting the database management tool and the database, so that the access control module can identify and process the third SQL command.

[0061] As a possible implementation method, the connection behavior library may include connection behavior rules and connection behaviors corresponding to the connection behavior rules. The SQL command may be matched with the connection behavior rules in the connection behavior library. If the SQL command conforms to any one of the connection behavior rules in the connection behavior library, the SQL command may be considered to be a connection behavior command (i.e., the SQL command is determined to be the third SQL command).

[0062] For the third SQL command marked by the connection behavior whitelist module, the access control module can release it (i.e., allow the database management tool to connect to the database). For the second SQL command executed by the user, the access control module can use the second fingerprint information of the second SQL command extracted by the connection context fingerprint extraction module to query the fingerprint user table of the post-authentication module. The second fingerprint information can be the fingerprint information of the user identity authentication executing the second SQL command.

[0063] If the user identity information corresponding to the second fingerprint information is not found in the fingerprint user table, the database access control system can block the execution of the second SQL command and send blocking information to the user. The blocking information is used to prompt the user to perform authentication operations to reduce the risk of unauthorized access.

[0064] If the user identity information corresponding to the second fingerprint information is queried in the fingerprint user table, the access control module can manage the second SQL command executed by the user according to the user access policy, that is, according to the database access rights, execute the database access operation corresponding to the second SQL command, such as restricting access to specific data tables, fields or operations, ensuring that the user's operations comply with the security policy, improving the security of the database, and realizing more fine-grained access control.

[0065] For example, the configuration rules in the database access control system may stipulate that the target user has the authority to perform any operation (such as query, update, etc.) on table1, but does not have the authority to perform any operation on table2.

[0066] If the database access control system cannot verify or identify the user identity information of the target user, then the database access control system will not allow the target user to perform any operations, that is, whether trying to access table1 or table2, the database access control system will reject it to ensure that only authenticated users can access the database.

[0067] If the database access control system successfully verifies the user identity information of the target user, the database access control system may allow the target user to perform a query operation on table1 (select * from table1) according to the configuration rules, and the database access control system may prevent the target user from performing a query operation on table2 (select * from table2) according to the configuration rules.

[0068] In summary, according to a database access method disclosed in the present invention, an SQL command can be obtained; a user authentication operation is performed based on the first SQL command in the SQL command, wherein the first SQL command is a predefined command that needs to perform a user authentication operation; if the user authentication is successful, a fingerprint user table is generated according to the authenticated user identity information; it is determined that the fingerprint user table includes user identity information related to the second SQL command, and then, according to the database access rights, a database access operation corresponding to the second SQL command is performed, wherein the second SQL command is a command in the SQL command other than the first SQL command and the third SQL command, and the third SQL command is a command for connecting a database management tool and a database. For the disclosed embodiment, the present application allows the use of additional verification information to authenticate the user identity for the first SQL command by introducing a post-authentication mechanism. Under the requirement that the database login credentials need to change periodically, the verification information can be periodically updated without changing the database account password. All database management tools that use these account passwords do not need to be manually configured and updated, thereby greatly reducing management costs and workload.

[0069] Based on the above Figure 1 The specific implementation of the method shown in this embodiment provides a database access device, such as Figure 4 As shown, the device includes: an acquisition module 31, a first authentication module 32, a generation module 33, and a first determination module 34;

[0070] An acquisition module 31 is used to acquire SQL commands;

[0071] A first authentication module 32, configured to perform a user identity authentication operation based on a first SQL command among the SQL commands, wherein the first SQL command is a predefined command that requires a user identity authentication operation to be performed;

[0072] A generating module 33, for generating a fingerprint user table according to the authenticated user identity information if the user identity authentication is successful;

[0073] The first determination module 34 is used to determine that the fingerprint user table includes user identity information related to the second SQL command, and then execute a database access operation corresponding to the second SQL command according to the database access permission, wherein the second SQL command is a command in the SQL command except the first SQL command and the third SQL command, and the third SQL command is a command for connecting the database management tool and the database.

[0074] In a specific application scenario, the first SQL command includes a custom authentication method; the first authentication module 32 can be used to send first verification information to the user according to the custom authentication method; receive second verification information sent by the user, and verify whether the second verification information is the first verification information; if the second verification information is the first verification information, it is determined that the user identity authentication is successful; if the second verification information is not the first verification information, it is determined that the user identity authentication has failed.

[0075] In a specific application scenario, the fingerprint user table includes at least first fingerprint information and user identity information corresponding to the first fingerprint information, wherein the first fingerprint information is fingerprint information for executing user identity authentication with the first SQL command; the first determination module 34 can be used to extract second fingerprint information of the second SQL command, wherein the second fingerprint information is fingerprint information for executing user identity authentication with the second SQL command; if user identity information corresponding to the second fingerprint information is queried in the fingerprint user table, it is determined that the fingerprint user table includes user identity information related to the second SQL command.

[0076] In a specific application scenario, the fingerprint user table also includes the validity period of the first fingerprint information, and the device also includes: a second authentication module 35 and an update module 36;

[0077] A second authentication module 35 is configured to re-perform the user identity authentication operation based on the first SQL command if the authentication duration of the first fingerprint information exceeds the valid duration, wherein the authentication duration is the time interval from the last successful authentication time point of the user to the current time point;

[0078] The updating module 36 is used to update the validity period of the corresponding first fingerprint information in the fingerprint user table if the user identity authentication is successful.

[0079] In a specific application scenario, the device further includes: a blocking module 37 and a sending module 38;

[0080] A blocking module 37, configured to block the execution of the second SQL command if the user identity information corresponding to the second fingerprint information is not found in the fingerprint user table;

[0081] The sending module 38 is used to send blocking information to the user, where the blocking information is used to prompt the user to perform an authentication operation.

[0082] In a specific application scenario, the device further includes: a second determination module 39, a connection module 40;

[0083] A second determining module 39, configured to identify a third SQL command in the SQL command;

[0084] The connection module 40 is used to connect the database management tool and the database in response to the third SQL command.

[0085] In a specific application scenario, the second determination module 39 may be used to match the SQL command with a connection behavior rule in a connection behavior library;

[0086] If the SQL command complies with the connection behavior rule, the SQL command is determined to be the third SQL command.

[0087] It should be noted that for other corresponding descriptions of the functional units involved in the database access device provided in this embodiment, please refer to Figure 1 The corresponding description of the method in will not be repeated here.

[0088] Based on the above Figure 1 The method shown in the present disclosure, accordingly, also provides a computer-readable storage medium having a computer program stored thereon, which implements the above-mentioned Figure 1 The method shown.

[0089] Based on this understanding, the technical solution of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of various implementation scenarios of the present disclosure.

[0090] Based on the above Figure 1 The method shown, and Figure 4 In order to achieve the above-mentioned purpose, the embodiment of the present disclosure also provides an electronic device, which includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to achieve the above-mentioned Figure 1 The method shown.

[0091] Optionally, the above-mentioned physical device may also include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a WI-FI module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and the optional user interface may also include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface), etc.

[0092] Those skilled in the art will appreciate that the above-mentioned physical device structure provided by the present disclosure does not constitute a limitation on the physical device, and may include more or fewer components, or a combination of certain components, or different arrangements of components.

[0093] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the above-mentioned physical device, and supports the operation of the information processing program and other software and / or programs. The network communication module is used to realize the communication between the components inside the storage medium, and the communication with other hardware and software in the information processing physical device.

[0094] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present disclosure can be implemented by means of software plus necessary general hardware platforms, or by hardware. Compared with the prior art, the database access method, device and electronic device provided by the present disclosure obtain SQL commands; perform user identity authentication operations based on the first SQL command in the SQL command, wherein the first SQL command is a predefined command that needs to perform user identity authentication operations; if the user identity authentication is successful, a fingerprint user table is generated according to the authenticated user identity information; it is determined that the fingerprint user table includes user identity information related to the second SQL command, and then, according to the database access rights, the database access operation corresponding to the second SQL command is performed, wherein the second SQL command is a command in the SQL command other than the first SQL command and the third SQL command, and the third SQL command is a command for connecting a database management tool and a database. For the embodiment of the present disclosure, the present application allows the use of additional verification information to authenticate the user identity for the first SQL command by introducing a post-authentication mechanism. Under the requirement that the database login credentials need to change periodically, the verification information can be periodically updated without changing the database account password. All database management tools using these account passwords do not need to be manually configured and updated, thereby greatly reducing management costs and workload.

[0095] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0096] The above is only a specific implementation of the present application, so that those skilled in the art can understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments herein, but will conform to the widest scope consistent with the principles and novel features applied for herein.

Claims

1. A database access method, characterized in that: include: Get SQL commands; Execute a user identity authentication operation based on a first SQL command in the SQL commands, wherein the first SQL command is a predefined command that requires executing a user identity authentication operation; If the user identity authentication is successful, a fingerprint user table is generated based on the authenticated user identity information; If it is determined that the fingerprint user table includes user identity information related to a second SQL command, a database access operation corresponding to the second SQL command is performed according to database access rights, wherein the second SQL command is a command in the SQL commands other than the first SQL command and the third SQL command, and the third SQL command is a command for connecting a database management tool and a database.

2. The method according to claim 1, characterized in that The first SQL command includes a custom authentication method; The performing of the user identity authentication operation based on the first SQL command in the SQL commands includes: According to the custom authentication method, sending first verification information to the user; Receiving second verification information sent by the user, and verifying whether the second verification information is the first verification information; If the second verification information is the same as the first verification information, it is determined that the user identity authentication is successful; If the second verification information is not the first verification information, it is determined that the user identity authentication has failed.

3. The method according to claim 1, characterized in that The fingerprint user table includes at least first fingerprint information and user identity information corresponding to the first fingerprint information, wherein the first fingerprint information is fingerprint information for executing user identity authentication of the first SQL command; The determining that the fingerprint user table includes user identity information related to the second SQL command includes: Extracting second fingerprint information of the second SQL command, where the second fingerprint information is fingerprint information of the second SQL command executing user identity authentication; If the user identity information corresponding to the second fingerprint information is found in the fingerprint user table, it is determined that the fingerprint user table includes the user identity information related to the second SQL command.

4. The method according to claim 3, characterized in that: The fingerprint user table also includes the validity period of the first fingerprint information, and the method further includes: If the authentication time of the first fingerprint information exceeds the valid time, re-perform the user identity authentication operation based on the first SQL command, wherein the authentication time is the time interval from the last successful authentication time point of the user to the current time point; If the user identity authentication is successful, the validity period of the corresponding first fingerprint information in the fingerprint user table is updated.

5. The method according to claim 3, characterized in that: The method further comprises: If the user identity information corresponding to the second fingerprint information is not found in the fingerprint user table, blocking the execution of the second SQL command; Sending blocking information to the user, wherein the blocking information is used to prompt the user to perform an authentication operation.

6. The method according to claim 1, characterized in that The method further comprises: Identifying a third SQL command among the SQL commands; In response to the third SQL command, the database management tool and the database are connected.

7. The method according to claim 6, characterized in that The identifying a third SQL command in the SQL commands includes: Matching the SQL command with the connection behavior rules in the connection behavior library; If the SQL command complies with the connection behavior rule, the SQL command is determined to be the third SQL command.

8. A database access device, characterized in that: include: Acquisition module, used to obtain SQL commands; A first authentication module, configured to perform a user identity authentication operation based on a first SQL command among the SQL commands, wherein the first SQL command is a predefined command that requires a user identity authentication operation to be performed; A generation module is used to generate a fingerprint user table according to the authenticated user identity information if the user identity authentication is successful; The first determination module is used to determine that the fingerprint user table includes user identity information related to the second SQL command, and then execute a database access operation corresponding to the second SQL command according to the database access permission, wherein the second SQL command is a command in the SQL command except the first SQL command and the third SQL command, and the third SQL command is a command for connecting the database management tool and the database.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. An electronic device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Client authentication method and device

    CN102202040A

  • Database access permission control method and device and electronic equipment

    CN111756752A

  • Access control method and system of data warehouse and electronic equipment

    CN113392415A

  • Security authentication method and device, electronic equipment and storage medium

    CN114697063A

  • Device fingerprint updating for single sign on authentication

    US20150237049A1