Database security protocol design method and system supporting multiple privacy protection schemes
By designing a database security protocol that supports multiple privacy protection solutions, the problem that the existing technology cannot meet the security needs of complex business scenarios is solved, and the database can effectively protect private data and has good scalability.
Patent Information
- Application Number
- CN202510103878.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The existing technology is difficult to effectively support multiple privacy protection solutions, and cannot meet the complex security needs of different business scenarios, which limits the database's ability to protect private data.
A database security protocol supporting multiple privacy protection solutions was designed, and functions such as database statement execution and security solution change are realized through the protocol initial module, security protocol body module, security protocol header processing module, type configuration module, protocol assembly module, protocol sending module and privacy protection layer.
This protocol is designed independently of the current database architecture, meets the privacy protection needs of different business scenarios, has good scalability, and can give full play to the advantages of each privacy protection solution.
Smart Images

Figure CN119939665A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a database security protocol design method and system supporting multiple privacy protection schemes, belonging to the technical field of database security. Background Art
[0002] As the core of information system, database not only carries a large amount of key data, but also provides efficient and reliable information services to various users. At present, database system is applied to all walks of life, and its importance is self-evident.
[0003] In order to prevent attacks and maintain data integrity and reliability, database security has become a top priority for the information security system. Currently, most domestic industry data is stored in the databases of various institutions and cloud platforms. The addition, deletion, modification, and query operations brought about by related business activities will directly operate on these sensitive data. Database privacy protection has become a research hotspot in recent years. At present, the relevant technology is in the initial stage of research, and no large-scale application practice in this field has been carried out by large institutions. In addition, the business activities of domestic key infrastructure platforms are relatively complex, and a single security method cannot meet the security needs of different business scenarios, further limiting the database's ability to protect privacy data.
[0004] Supporting multiple privacy protection schemes will inevitably require the user side to be able to flexibly query and control the protection schemes adopted by different fields of the database, and support operations such as database statement pass-through, statement rewriting, and security scheme changes. However, there is currently no corresponding mature solution. The database protocol is a set of rules and standards used to specify how to exchange, query, and manage data between database management systems (DBMS). It breaks through the barriers between different DBMSs, allowing various types of data to interact and share on different DBMSs. Therefore, the present invention proposes a database security protocol design method and system that supports multiple privacy protection schemes. Summary of the invention
[0005] In order to solve the above problems, the present invention proposes a database security protocol design method and system that supports multiple privacy protection schemes, which can realize functions such as database statement execution and security scheme change, and give full play to the advantages of various privacy protection schemes.
[0006] The technical solution adopted by the present invention to solve the technical problem is: In a first aspect, an embodiment of the present invention provides a database security protocol design method supporting multiple privacy protection schemes, comprising the following steps: The protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; The security protocol body module identifies all fields of the security policy instruction and completes the parsing and encapsulation of the fields according to different instruction types; The security protocol header processing module encapsulates the sender's identity information; The type configuration module queries the type codes corresponding to different business meanings; The protocol assembly module assembles the security protocol header and the security protocol body based on the type code corresponding to the query different business meanings; The protocol sending module sends the assembled security protocol to the privacy protection layer in the form of a long connection or a short connection; The privacy protection layer parses the assembled security protocol and sends the parsed database operation instructions to the database layer for execution.
[0007] As a possible implementation of this embodiment, when the security protocol header processing module encapsulates the identity information of the sender, it also encapsulates security information used for key negotiation and decryption.
[0008] As a possible implementation of this embodiment, the security protocol header processing module and the security protocol body module adopt an extensible identification method for each field, and each field is encapsulated in a predefined "type-length-value" three-segment method.
[0009] As a possible implementation of this embodiment, the database security protocol design method further includes the following steps: Build basic cryptographic modules and random number generators to encrypt the protocol body.
[0010] As a possible implementation of this embodiment, the database security protocol design method further includes the following steps: Construct a load balancing module and set it between the protocol sending module and the privacy protection layer. Use a load balancing strategy to ensure balanced resource consumption of different privacy protection layers.
[0011] As a possible implementation manner of this embodiment, the privacy protection layer includes a privacy protection algorithm and an engine thereof, and the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
[0012] In a second aspect, an embodiment of the present invention provides a database security system supporting multiple privacy protection schemes, including a protocol initialization module, a security protocol body module, a security protocol header processing module, a type configuration module, a protocol assembly module, a protocol sending module and a privacy protection layer; The protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; the security protocol body module identifies all fields of the security policy instructions, and completes the parsing and encapsulation of the fields according to different instruction types; the security protocol header processing module encapsulates the identity information of the sender; the type configuration module queries the type code corresponding to different business meanings; the protocol assembly module assembles the security protocol header and the security protocol body based on the query of the type code corresponding to different business meanings; the protocol sending module sends the assembled security protocol to the privacy protection layer in the form of a long connection or a short connection; the privacy protection layer parses the assembled security protocol, and sends the parsed database operation instructions to the database layer for execution.
[0013] As a possible implementation of this embodiment, the database security system further includes a basic password module and a random number generator, and the basic password module and the random number generator are used to encrypt the protocol body.
[0014] As a possible implementation of this embodiment, the database security system further includes a load balancing module, which is arranged between the protocol sending module and the privacy protection layer, and is used to adopt a load balancing strategy to ensure balanced resource consumption of different privacy protection layers.
[0015] As a possible implementation manner of this embodiment, the privacy protection layer includes a privacy protection algorithm and an engine thereof, and the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
[0016] The beneficial effects of the technical solution of the embodiment of the present invention are as follows: A database security protocol design method supporting multiple privacy protection schemes according to the technical solution of the embodiment of the present invention includes the following steps: the protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; the security protocol body module identifies all fields of the security policy instructions, and completes the parsing and encapsulation of the fields according to different instruction types; the security protocol header processing module encapsulates the identity information of the sender; the type configuration module queries the type code corresponding to different business meanings; the protocol assembly module assembles the security protocol header and the security protocol body based on the query of the type code corresponding to different business meanings; the protocol sending module sends the assembled security protocol to the privacy protection layer in the form of a long connection or a short connection; the privacy protection layer parses the assembled security protocol and sends the parsed database operation instructions to the database layer for execution. The database security protocol of the present invention is independent of the current database architecture design, effectively meets the needs of different database products for privacy protection schemes in different business scenarios, and has good scalability. Users in different industries realize functions such as database statement execution and security scheme change through the combination of different fields of the database security protocol of the present invention, which can not only give full play to the advantages of each scheme, but also ensure that the system has good scalability. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a flow chart of a database security protocol design method supporting multiple privacy protection schemes according to an exemplary embodiment; Figure 2 is a schematic diagram of the structure of a database security system supporting multiple privacy protection schemes according to an exemplary embodiment; Figure 3 It is a schematic diagram of the security protocol structure using the present invention; Figure 4 The invention is a flow chart for encapsulating the security protocol. DETAILED DESCRIPTION
[0018] In order to more clearly illustrate the technical features of the solution of the present invention, the present invention is described in detail below through specific implementation methods and in conjunction with the accompanying drawings.
[0019] like Figure 1 As shown, a database security protocol design method supporting multiple privacy protection schemes provided by an embodiment of the present invention includes the following steps: The protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; The security protocol body module identifies all fields of the security policy instruction and completes the parsing and encapsulation of the fields according to different instruction types; The security protocol header processing module encapsulates the sender's identity information; The type configuration module queries the type codes corresponding to different business meanings; The protocol assembly module assembles the security protocol header and the security protocol body based on the type code corresponding to the query different business meanings; The protocol sending module sends the assembled security protocol to the privacy protection layer in the form of a long connection or a short connection; The privacy protection layer parses the assembled security protocol and sends the parsed database operation instructions to the database layer for execution.
[0020] As a possible implementation of this embodiment, when the security protocol header processing module encapsulates the identity information of the sender, it also encapsulates security information used for key negotiation and decryption.
[0021] As a possible implementation of this embodiment, the security protocol header processing module and the security protocol body module adopt an extensible identification method for each field, and each field is encapsulated in a predefined "type-length-value" three-segment method.
[0022] As a possible implementation of this embodiment, the database security protocol design method further includes the following steps: Build basic cryptographic modules and random number generators to encrypt the protocol body.
[0023] As a possible implementation of this embodiment, the database security protocol design method further includes the following steps: Construct a load balancing module and set it between the protocol sending module and the privacy protection layer. Use a load balancing strategy to ensure balanced resource consumption of different privacy protection layers.
[0024] As a possible implementation manner of this embodiment, the privacy protection layer includes a privacy protection algorithm and an engine thereof, and the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
[0025] like Figure 2 As shown, a database security system supporting multiple privacy protection schemes provided by an embodiment of the present invention includes a protocol initialization module, a security protocol body module, a security protocol header processing module, a type configuration module, a protocol assembly module, a protocol sending module and a privacy protection layer; The protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; the security protocol body module identifies all fields of the security policy instructions, and completes the parsing and encapsulation of the fields according to different instruction types; the security protocol header processing module encapsulates the identity information of the sender; the type configuration module queries the type code corresponding to different business meanings; the protocol assembly module assembles the security protocol header and the security protocol body based on the query of the type code corresponding to different business meanings; the protocol sending module sends the assembled security protocol to the privacy protection layer in the form of a long connection or a short connection; the privacy protection layer parses the assembled security protocol, and sends the parsed database operation instructions to the database layer for execution.
[0026] As a possible implementation of this embodiment, the database security system further includes a basic password module and a random number generator, and the basic password module and the random number generator are used to encrypt the protocol body.
[0027] As a possible implementation of this embodiment, the database security system further includes a load balancing module, which is arranged between the protocol sending module and the privacy protection layer, and is used to adopt a load balancing strategy to ensure balanced resource consumption of different privacy protection layers.
[0028] As a possible implementation manner of this embodiment, the privacy protection layer includes a privacy protection algorithm and an engine thereof, and the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
[0029] Figure 2 The schematic diagram of the database security system of the present invention is shown, wherein the "user layer" is the security protocol design architecture and module composition involved in the present invention. Traditional databases are generally divided into a user layer (including necessary drivers, database clients and related protocols, tools, etc.) and a database layer (including database agents, database logs, database instances, etc.). Based on the "privacy protection layer", the present invention adds multiple privacy solution capabilities to traditional database products and realizes transparent perception of security solutions at the database layer. In order to achieve control over the "privacy protection layer", the present invention adds a security protocol design and implementation logic to the user layer, which is compatible with the database operation habits of the current user side, and also adds support for security policy instructions.
[0030] like Figure 2As shown in the figure, the security protocol processing module is mainly divided into a protocol initialization module, a security protocol body processing module, a security protocol header processing module, a type configuration module, a protocol assembly and sending module, and optionally, it may also include a necessary password implementation module and a random number generation module. Among them, the protocol initialization module performs necessary format verification on the database instructions (such as ordinary SQL) and security policy instructions (such as adding a security policy to a certain field or changing the security plan, etc.) issued by the user. Subsequently, the security protocol body module identifies all fields of the security policy instructions and completes the parsing and encapsulation of the fields according to different instruction types. After that, the security protocol header processing module encapsulates the identity information of the sender and other contents. Optionally, it can also encapsulate necessary security information for key negotiation and decryption. The protocol header and the protocol body use a well-scalable identification method for each field, and each field is encapsulated in a predefined "type-length-value" three-segment method. When subsequent fields change, the protocol can also provide support without updating. The type code corresponding to different business meanings can be queried through the type configuration module. After the protocol assembly is completed, it is sent to the privacy protection layer for processing in the form of a long connection or a short connection. Optionally, a load balancing strategy may be used to ensure balanced resource consumption of different privacy protection layers.
[0031] Figure 3 The structure of the security protocol is shown. The protocol header and the protocol body have independent start characters and support multiple versions. The third field identifies the length of the entire protocol header / body for subsequent processing. Starting from the fourth field, both the protocol header and the protocol body adopt the three-segment filling method of "type-length-value".
[0032] For the protocol header, Figure 3 The sender identity information and random number information are listed in the protocol. Since the protocol is parsed in a three-part manner of "type-length-value", the order of the two can change. In addition, when a new protocol header field needs to be added later, the correct parsing of the receiving end can be achieved by simply configuring the type identifier.
[0033] For the protocol body, Figure 3The currently supported two types of instructions are listed in the table: operation and management. Operation instructions include SQL statements sent by users and security policy query instructions (such as querying the privacy protection scheme of a certain field, etc.); management instructions mainly involve security scheme change instructions, such as adding / changing the privacy protection policy of a certain field. Therefore, for the specific protocol content, only one of the two types of operation instructions can be selected, and the receiving end shall distinguish them according to the type code. For simple instructions, the instruction value only needs to copy its content, such as a select statement, and the instruction value field is the complete SQL statement; for complex instructions, for example, when specifying a field to be changed from privacy protection scheme A to privacy protection scheme B, because it is necessary to specify the "field name", "original protection scheme", "target protection scheme" and other contents, and at the same time, other contents such as the changed "operation strategy" (such as in-place replacement strategy, shadow table strategy, etc.) may be specified, which will make the "instruction value" more confusing. For this reason, if Figure 3 As shown, instruction values can be further parsed and encapsulated by using a further nested "type-length-value" three-segment filling method.
[0034] The detailed implementation process of the present invention is given below, and combined with Figure 4 The present invention is described in further detail.
[0035] (1) The user sends (via the client, API, etc.) a security policy instruction to the protocol initialization module; (2) The protocol initialization module performs format verification on the received parameters; (3) The instructions that pass the verification are processed by the security protocol body processing module. According to the received instruction type, the corresponding type code is obtained from the type configuration module, and the instruction length and specific value are further analyzed, and the instruction is encapsulated according to the "type-length-value" three-segment format; (4) If the instruction type is a complex instruction, the instruction is segmented and encapsulated by using a nested "type-length-value" method; step (3) is repeated until all complex instructions are encapsulated; (5) Obtain necessary information such as the current protocol body version number, fill in the protocol body identifier, and calculate the protocol body length according to the instructions completed in step (4) to complete the encapsulation of the protocol body; (6) The security protocol header processing module obtains the identity information of the instruction initiator, queries the type code corresponding to the identity information from the type configuration module, and further parses the identity information and completes the encapsulation of the identity information; (7) If the current protocol body needs to be encrypted, the security protocol header processing module calls the password module, random number generator and other necessary components to complete the encryption of the protocol body; at the same time, it completes the encapsulation of necessary decryption information; (8) The security protocol header processing module obtains necessary information such as the current protocol header version number, fills in the protocol header identifier, and calculates the length information based on the protocol body length (if encryption is required, the ciphertext length) and other fields in the protocol header to complete the encapsulation of the protocol header; (9) Send the agreement content.
[0036] Unlike current database products that can only support one or several simple privacy protection schemes through protocol customization, the present invention provides a database security protocol design that flexibly supports multiple privacy protection schemes. Through this design, the needs of different database products for privacy protection schemes in different business scenarios are effectively met, and it has good scalability. The design of this database security protocol is independent of the current database architecture design. Therefore, traditional databases can be adapted with almost no changes. At the same time, since the design of the security protocol fully considers the operating habits of the current application, the user side only needs to add the control logic of multiple privacy protection schemes, and all other database application logic does not need to be changed.
[0037] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A database security protocol design method supporting multiple privacy protection schemes, characterized in that: The steps include: The protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; The security protocol body module identifies all fields of the security policy instruction and completes the parsing and encapsulation of the fields according to different instruction types; The security protocol header processing module encapsulates the sender's identity information; The type configuration module queries the type codes corresponding to different business meanings; The protocol assembly module assembles the security protocol header and the security protocol body based on the type code corresponding to the query different business meanings; The protocol sending module sends the assembled security protocol to the privacy protection layer in the form of a long connection or a short connection; The privacy protection layer parses the assembled security protocol and sends the parsed database operation instructions to the database layer for execution.
2. The database security protocol design method supporting multiple privacy protection schemes according to claim 1 is characterized in that: When the security protocol header processing module encapsulates the identity information of the sender, it also encapsulates the security information used for key negotiation and decryption.
3. The database security protocol design method supporting multiple privacy protection schemes according to claim 1 is characterized in that: The security protocol header processing module and the security protocol body module adopt an extensible identification method for each field, and each field is encapsulated in a predefined "type-length-value" three-segment method.
4. The database security protocol design method supporting multiple privacy protection schemes according to claim 1 is characterized in that: The following steps are also included: Build basic cryptographic modules and random number generators to encrypt the protocol body.
5. The database security protocol design method supporting multiple privacy protection schemes according to claim 1 is characterized in that: The following steps are also included: Construct a load balancing module and set it between the protocol sending module and the privacy protection layer. Use a load balancing strategy to ensure balanced resource consumption of different privacy protection layers.
6. The method for designing a database security protocol supporting multiple privacy protection schemes according to any one of claims 1 to 5, characterized in that: The privacy protection layer includes a privacy protection algorithm and an engine thereof, and the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
7. A database security system supporting multiple privacy protection schemes, characterized in that: It includes protocol initialization module, security protocol body module, security protocol header processing module, type configuration module, protocol assembly module, protocol sending module and privacy protection layer; The protocol initialization module performs format verification on the database operation instructions and security policy instructions issued by the user layer; the security protocol body module identifies all fields of the security policy instructions and completes the parsing and encapsulation of the fields according to different instruction types; the security protocol header processing module encapsulates the identity information of the sender; The type configuration module queries the type codes corresponding to different business meanings; The protocol assembly module assembles the security protocol header and the security protocol body based on the type code corresponding to different business meanings; the protocol sending module sends the assembled security protocol to the privacy protection layer using a long connection or a short connection; the privacy protection layer parses the assembled security protocol and sends the parsed database operation instructions to the database layer for execution.
8. The database security system supporting multiple privacy protection schemes according to claim 7, characterized in that: It also includes a basic password module and a random number generator, which are used to encrypt the protocol body.
9. The database security system supporting multiple privacy protection schemes according to claim 7, characterized in that: It also includes a load balancing module, which is arranged between the protocol sending module and the privacy protection layer and is used to adopt a load balancing strategy to ensure balanced resource consumption of different privacy protection layers.
10. The database security system supporting multiple privacy protection schemes according to any one of claims 7 to 9, characterized in that: The privacy protection layer includes a privacy protection algorithm and an engine thereof, and the privacy protection algorithm includes at least one or more of a deterministic encryption algorithm, an order-preserving encryption algorithm, and an order-revealing encryption algorithm.
Citation Information
Patent Citations
Database audit method and device
CN105260378A
Database protocol analysis and encapsulation method and system
CN115269695A
Database access permission determination method and device, electronic equipment and storage medium
CN116896474A
Extensible database transparent encryption device and method
CN116915387A
Cloud migration for legacy on-premises process code
US20230089662A1