Database encryption method and device, electronic equipment and storage medium

By hashing the database password and introducing multi-dimensional dynamic factors, combined with the use of the first and second encryption algorithms, the security risks in the existing database password encryption methods are solved, and the security of the password and the overall security of the database are significantly improved.

CN119939632APending Publication Date: 2025-05-06UNICLOUD TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510102422.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing database password encryption methods have problems such as insufficient password strength, easy encryption algorithms to be cracked, and security risks during encrypted storage and transmission, which affect the secure access of the database.

Method used

By hashing the original password entered by the user, a hash value with a fixed length is generated, and a multi-dimensional dynamic factor is introduced into the hash value to generate the database password. Then, the database password is encrypted and stored using the first encryption algorithm, and then, during the transmission process, the second encryption algorithm is used for encryption.

Benefits of technology

It improves the security of passwords during generation, storage and transmission, enhances the protection of database access information, and reduces the risk of information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939632A_ABST
    Figure CN119939632A_ABST
Patent Text Reader

Abstract

The invention provides a database encryption method and device, electronic equipment and a storage medium, and the method comprises the steps: carrying out Hash processing on an original password input by a user, generating a Hash value with a fixed length, and introducing a multi-dimensional dynamic factor into the Hash value to generate a database password; carrying out encryption processing on the generated database password through a first encryption algorithm, storing the encrypted database password into a database field, and carrying out information recording; and in response to transmission of the database password in the network, performing encryption processing on the database password in the transmission process through a second encryption algorithm. According to the method, the hash function, the dynamic factor and the complex encryption algorithm are introduced, so that the password has relatively high security in the generation, storage and transmission processes, and database access information is prevented from being leaked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of database encryption, and in particular, relates to a database encryption method, device, electronic device and storage medium. Background Art

[0002] As an important data asset, the database has many problems in the data asset management process when using the existing database password encryption method, such as insufficient password strength, encryption algorithm is easy to be cracked, and security risks in the encrypted storage and transmission process. Therefore, it is of great practical significance to develop a new database password encryption technology to improve the security of passwords and the overall security of the system.

[0003] Traditional database password encryption methods have the following security risks: (1) insufficient password strength and outdated encryption algorithm; (2) the encryption method is relatively simple and can be easily cracked by brute force; (3) there is no dedicated key management system and the key is easily leaked. The above factors seriously affect the secure access to the database. Summary of the invention

[0004] In view of this, the present application aims to propose a database encryption method, device, electronic device and storage medium to solve at least one of the above problems.

[0005] To achieve the above purpose, the technical solution of this application is implemented as follows: In a first aspect, the present application provides a database encryption method, comprising: Hash the original password entered by the user to generate a hash value with a fixed length, and introduce a multi-dimensional dynamic factor into the hash value to generate a database password; Encrypting the generated database password using a first encryption algorithm, storing the encrypted database password in a database field, and recording the information; In response to the database password being transmitted in the network, the database password is encrypted during transmission using a second encryption algorithm.

[0006] In the second aspect, based on the same inventive concept, the present application also provides a database encryption device, including: A password generation module is configured to perform hash processing on the original password input by the user to generate a hash value with a fixed length, and introduce a multi-dimensional dynamic factor into the hash value to generate a database password; An encryption storage module is configured to encrypt the generated database password using a first encryption algorithm, store the encrypted database password in a database field, and record the information; The encryption transmission module is configured to encrypt the database password during transmission by using a second encryption algorithm in response to the database password being transmitted in the network.

[0007] In a third aspect, based on the same inventive concept, the present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the first aspect is implemented.

[0008] In a fourth aspect, based on the same inventive concept, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the method described in the first aspect.

[0009] Compared with the prior art, the database encryption method, device, electronic device and storage medium described in this application have the following beneficial effects: The database encryption method, device, electronic device and storage medium described in the present application introduce hash functions, dynamic factors and complex encryption algorithms to ensure that the password has high security during generation, storage and transmission to protect database access information from leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0011] Figure 1 This is a flow chart of a database encryption method described in an embodiment of the present application; Figure 2 This is a schematic diagram of the structure of a database encryption device described in an embodiment of the present application; Figure 3 This is a schematic diagram of the hardware structure of the electronic device described in the embodiment of the present application. DETAILED DESCRIPTION

[0012] In order to make the objectives, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0013] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should be the usual meanings understood by people with ordinary skills in the field to which the present application belongs. The "first", "second" and similar words used in the embodiments of the present application do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0014] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0015] See also Figure 1 As shown, this embodiment provides a database encryption method, which specifically includes the following steps: Step S101: Hash the original password input by the user to generate a hash value with a fixed length, and introduce a multi-dimensional dynamic factor into the hash value to generate a database password.

[0016] Specifically, in this step, the present embodiment adopts a password complexity detection method to ensure that the password contains sufficient complexity. At the same time, a dynamic factor generation algorithm is used in the encryption process: combining dynamic factors such as timestamps and system random numbers to generate the final database password.

[0017] In some embodiments, the original password entered by the user is subjected to complexity detection, which includes limiting the original password entered by the user to meet a preset complexity condition, and checking whether the original password has a high similarity with a weak password library or personal information through a fuzzy matching algorithm; Perform the initial hashing of the original password after complexity check through the hash function to generate a basic hash value with a fixed length; A multidimensional dynamic factor is added to the basic hash value, the multidimensional dynamic factor is merged with the basic hash value, and the final database password is generated based on a memory-enhanced algorithm.

[0018] Specifically, in this embodiment, the original password is firstly subjected to complexity check, requiring the password entered by the user to meet the following conditions: Contain at least 1 uppercase letter, 1 lowercase letter, 1 number and 1 special character; ②The length is between 8 and 32 characters; ③The password cannot be more than 50% similar to the user’s historical password, username, email address or other personal information.

[0019] During the complexity detection phase, the system uses fuzzy matching algorithms (such as Levenshtein distance) to check whether the password has a high degree of similarity with the weak password database or personal information. For example, if the password entered by the user is P@ssword1, and the system detects that its edit distance with the common weak password password123 is less than 3, the user is required to reset the password.

[0020] The password is initially hashed using a hashing algorithm such as SHA-256 or SHA-512 to produce a base hash value of fixed length.

[0021] In order to enhance the uniqueness and anti-attack capability of the hash value, multi-dimensional dynamic factors are introduced based on the initial hash value. These factors come from the following dimensions:

[0022] 1. Timestamp factor: The system records the exact time (accurate to milliseconds) when the user generates the password, such as 2024-12-28T14:35:27.345. The timestamp is hashed to generate a time factor of fixed length.

[0023] 2. Random factor: The system generates a high-entropy random number (such as a 128-bit random number) as a random factor.

[0024] 3. User behavior factor: The system captures the user's behavioral characteristics when entering the password (such as keystroke time interval, keystroke speed), generates a characteristic value through statistical methods, and further hashes it to obtain the user behavior factor.

[0025] 4. Device environment factor: The system collects relevant information of the user's device (such as device ID, IP address, operating system version) and generates a device factor through hash processing.

[0026] The above dynamic factor is combined with the initial basic hash value H1, and the final database password is calculated using the memory-enhanced algorithm Argon2.

[0027] Step S102: encrypt the generated database password using a first encryption algorithm, store the encrypted database password in a database field, and record the information.

[0028] Specifically, in this step, the generated database password is fragmented (such as dividing the password into 3 or more segments), each segment is encrypted using an independent AES key, and the encrypted segments are stored in different database fields or tables. Even if the database is leaked, it is difficult to restore the complete password.

[0029] For example, the generated database password is divided into three segments (e.g., the password is 64 bytes, divided into three segments A, B, and C, each 16 bytes), and the three segments are encrypted using independent AES-256 keys (such as keys K1, K2, and K3). The encrypted segments are stored in different fields of the database.

[0030] Field 1: stores the encrypted fragment A.

[0031] Field 2: stores the encrypted fragment B.

[0032] Field 3: stores the encrypted fragment C.

[0033] The keys are dynamically generated by the key management system (KMS), and the key indexes (such as K1, K2, K3) are stored in the security module separately from the encryption shards.

[0034] For example, the key is automatically rotated once a month. For example, during the rotation, new keys K1', K2', and K3' are regenerated, and shards A, B, and C are re-encrypted and the database is updated.

[0035] Step S103: In response to the database password being transmitted in the network, the database password is encrypted during transmission using a second encryption algorithm.

[0036] Specifically, in this embodiment, when the database password needs to be transmitted in the network, an asymmetric encryption algorithm (such as RSA) will be used to encrypt the password. The sender uses the receiver's public key to encrypt the password to generate a ciphertext. After receiving the ciphertext, the receiver uses his own private key to decrypt it and restore the original database password.

[0037] In some embodiments, it further comprises: Before transmitting the encrypted password, the sender and receiver perform two-way authentication to verify the legitimacy of both parties' public and private keys.

[0038] Specifically, in this embodiment, before transmitting the encrypted password, the sender and the receiver perform a two-way identity authentication, for example, through a certificate-based identity authentication mechanism to ensure that the public keys and private keys of both parties are legal and credible.

[0039] Based on the above content, a database encryption method described in this embodiment can achieve the following technical effects: (1) Improved password security: By introducing hash functions, dynamic factors, and complex encryption algorithms, passwords have higher security during generation, storage, and transmission.

[0040] (2) Simplified password management process: The password generation and verification process of this application is automated, and users do not need to perform complex password setting and management work, thereby improving work efficiency.

[0041] (3) Good scalability and compatibility: The password encryption technology of this application can be applied to different types of database systems and supports multiple encryption algorithms and parameter configurations, with good scalability and compatibility.

[0042] It should be noted that the above describes some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0043] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, an embodiment of the present application further provides a database encryption device.

[0044] like Figure 2 As shown, the database encryption device comprises: The password generation module 11 is configured to perform hash processing on the original password input by the user to generate a hash value with a fixed length, and introduce a multi-dimensional dynamic factor into the hash value to generate a database password; The encryption storage module 12 is configured to encrypt the generated database password using a first encryption algorithm, store the encrypted database password in a database field, and record the information; The encryption transmission module 13 is configured to encrypt the database password during transmission by using a second encryption algorithm in response to the database password being transmitted in the network.

[0045] For the convenience of description, the above devices are described in terms of functions and are divided into various modules. Of course, when implementing the embodiments of the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0046] The device of the above embodiment is used to implement the corresponding method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0047] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, an embodiment of the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in any of the above embodiments is implemented.

[0048] Figure 3 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.

[0049] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0050] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0051] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0052] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0053] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).

[0054] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0055] The electronic device of the above embodiment is used to implement the corresponding method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0056] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the method described in any of the above embodiments.

[0057] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0058] The computer instructions stored in the storage medium of the above embodiments are used to enable the computer to execute the method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0059] A person skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0060] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power / ground connections to the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device may be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (that is, these details should be fully within the scope of understanding of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or with changes in these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0061] Although the present application has been described in conjunction with specific embodiments of the present application, many alternatives, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the discussed embodiments.

[0062] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present application.

Claims

1. A database encryption method, characterized in that: include: Hash the original password entered by the user to generate a hash value with a fixed length, and introduce a multi-dimensional dynamic factor into the hash value to generate a database password; Encrypting the generated database password using a first encryption algorithm, storing the encrypted database password in a database field, and recording the information; In response to the database password being transmitted in the network, the database password is encrypted during transmission using a second encryption algorithm.

2. The method according to claim 1, characterized in that The original password input by the user is hashed to generate a hash value with a fixed length, and a multi-dimensional dynamic factor is introduced into the hash value to generate a database password, including: Performing complexity check on the original password entered by the user, including limiting the original password entered by the user to meet the preset complexity conditions, and checking whether the original password has a high similarity with the weak password library or personal information through a fuzzy matching algorithm; Performing an initial hash on the original password after complexity detection using a hash algorithm to generate a basic hash value with a fixed length; A multidimensional dynamic factor is added to the basic hash value, the multidimensional dynamic factor is merged with the basic hash value, and a final database password is generated based on a memory enhancement algorithm.

3. The method according to claim 2, characterized in that: in, The multi-dimensional dynamic factors include at least a timestamp factor, a random factor, a user behavior factor and a device environment factor.

4. The method according to claim 1, characterized in that: The step of encrypting the generated database password by using a first encryption algorithm, storing the encrypted database password in a database field, and recording information includes: The generated database password is processed into fragments, each fragment is encrypted using an independent AES key, and the encrypted fragments are stored in different database fields, wherein the key is dynamically generated by a key management system, and the key index is stored separately from the encrypted fragments in a security module.

5. The method according to claim 1, characterized in that In response to the database password being transmitted in the network, encrypting the database password during transmission by using a second encryption algorithm includes: The sender encrypts the database password using the receiver's public key to generate ciphertext; After receiving the ciphertext, the recipient uses the private key to decrypt it to restore the original password.

6. The method according to claim 5, characterized in that Also includes: Before transmitting the encrypted password, the sender and receiver perform two-way authentication to verify the legitimacy of both parties' public and private keys.

7. A database encryption device, characterized in that: include: A password generation module is configured to perform hash processing on the original password input by the user to generate a hash value with a fixed length, and introduce a multi-dimensional dynamic factor into the hash value to generate a database password; An encryption storage module is configured to encrypt the generated database password using a first encryption algorithm, store the encrypted database password in a database field, and record the information; The encryption transmission module is configured to encrypt the database password during transmission by using a second encryption algorithm in response to the database password being transmitted in the network.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium, characterized in that: in, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 6.

Citation Information

Cited By

  • Abnormal password detection method and device and electronic equipment

    CN121603405A