SQL (Structured Query Language) statement analysis method, device and equipment based on database transparent encryption

By checking the syntax structure of SQL statements and selecting appropriate encryption and decryption strategies based on their complexity, the problem of low parsing efficiency of complex SQL statements is solved, and efficient database access and data decryption are achieved.

CN119987776APending Publication Date: 2025-05-13AISINO CORPORATION
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311508965.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the transparent database encryption technology, the parsing efficiency of complex SQL statements is low, resulting in slower reading and writing of data in the database driver layer, affecting the access efficiency of the database system.

Method used

By checking the syntax structure of the SQL statement, if it is a simple class, the fields are parsed and transparently encrypted; if it is a complex class, the pre-configured encryption and decryption policy is obtained, the encrypted column fields and keys are parsed according to the policy, and the SQL statement to be executed is generated.

Benefits of technology

It improves the parsing efficiency of SQL statements, reduces the parsing time of complex SQL statements, improves the access efficiency of databases, and obtains plaintext data through decryption results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987776A_ABST
    Figure CN119987776A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of computer security, provides an SQL statement analysis method, device and equipment based on database transparent encryption, and is used for improving the accuracy and efficiency of database access. According to the method, aiming at a simple-class target SQL statement, an encrypted column field is quickly and accurately obtained through field analysis, and transparent encryption is carried out on the encrypted column field; aiming at the complex target SQL statement, an encryption and decryption strategy is pre-configured, the encryption and decryption strategy is in a key-value pair form, a key comprises a database name and a data table name, and a value comprises a column name and a secret key of a data table, so that an encryption column field and a corresponding secret key can be quickly and accurately obtained through the encryption and decryption strategy, and the encryption and decryption efficiency is improved. Therefore, the analysis time of the complex SQL statement is shortened, the analysis accuracy is improved, and after the target SQL statement is executed, the decryption column field in the database query result is decrypted, so that high-efficiency and accurate access to the database is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer security technology, and in particular to a method, device and equipment for parsing SQL statements based on database transparent encryption. Background Art

[0002] When using a universal key, the database transparent encryption technology is transparent to the database system because the encryption and decryption process is transparent to the database system. Therefore, the database system does not need to know or process the encryption and decryption process. It only needs to store and transmit the data in ciphertext form. In this way, there will be no obvious difference in the parsing process of different SQL statements for accessing the database. However, for business scenarios with higher security requirements, sensitive data usually needs to be encrypted, and the SQL statement with one sensitive field and one key has low parsing efficiency, especially for more complex SQL statements. The parsing time will increase significantly, resulting in slower data reading and writing at the database driver layer, which directly affects the access efficiency of the database system. Summary of the invention

[0003] The embodiments of the present application provide a method, apparatus and device for parsing SQL statements based on database transparent encryption, so as to improve the parsing efficiency of SQL statements when metadata is encrypted.

[0004] In a first aspect, an embodiment of the present application provides a SQL statement parsing method based on database transparent encryption, comprising:

[0005] Check the syntax structure of the acquired target SQL statement;

[0006] If the grammatical structure is a simple class, the fields included in the target SQL statement are parsed to obtain encrypted column fields, and after transparently encrypting the encrypted column fields, a SQL statement to be executed is obtained;

[0007] If the grammatical structure is a complex class, then obtain the encryption and decryption strategy pre-configured for the target SQL statement, and obtain the SQL statement to be executed according to the encryption and decryption strategy; wherein the encryption and decryption strategy is in the form of a key-value pair, the key includes the database name and the data table name, and the value includes the column name and the key of the data table;

[0008] Execute the SQL statement to be executed to obtain the database query result;

[0009] If the database query result includes a decryption column field, the decryption column field is decrypted to obtain a decryption result.

[0010] In a second aspect, an embodiment of the present application provides a SQL statement parsing device based on database transparent encryption, comprising:

[0011] A checking module is used to check the grammatical structure of the acquired target SQL statement;

[0012] An encryption module, for parsing the fields included in the target SQL statement to obtain the encrypted column fields, and transparently encrypting the encrypted column fields to obtain the SQL statement to be executed if the grammatical structure is a simple class; and, for obtaining the encryption and decryption strategy pre-configured for the target SQL statement if the grammatical structure is a complex class, and obtaining the SQL statement to be executed according to the encryption and decryption strategy; wherein the encryption and decryption strategy is in the form of a key-value pair, the key includes the database name and the data table name, and the value includes the column name and the key of the data table;

[0013] An execution module is used to execute the SQL statement to be executed and obtain a database query result;

[0014] The decryption module is used to decrypt the decryption column field if the database query result contains the decryption column field to obtain the decryption result.

[0015] Optionally, the encryption module is specifically used for:

[0016] If the encryption and decryption strategy is no encryption, the target SQL statement is used as the SQL statement to be executed;

[0017] If the encryption and decryption strategy is encryption, determine whether the encrypted column field in the target SQL statement is encrypted in the preprocessing stage. If so, use the preprocessed target SQL statement as the SQL statement to be executed. Otherwise, obtain the encrypted column field according to the key-value pair configured in the encryption and decryption strategy, and transparently encrypt the encrypted column field to obtain the SQL statement to be executed.

[0018] Optionally, the decryption module is specifically used for:

[0019] If the number of the decryption column fields is single, directly decrypt the decryption column fields to obtain the decryption result;

[0020] If there are multiple decryption column fields, the multiple decryption column fields are split and then decrypted, and the decrypted fields are concatenated to obtain the decryption result.

[0021] Optionally, the configuration factors of the encryption and decryption strategy include at least one of the following:

[0022] Whether complex SQL statements need to be encrypted or decrypted;

[0023] Whether the database accessed by the complex SQL statement contains encrypted data tables;

[0024] Whether there are encrypted columns in the data table accessed by the complex SQL statement;

[0025] Whether the encrypted column field in the SQL statement of the complex class is a preprocessing parameter;

[0026] Check whether the returned result set corresponding to the SQL statement of the complex class contains a decryption column.

[0027] Optionally, the encryption process of the target SQL statement and the decryption process of the database query result are encapsulated into a plug-in and configured in the target application that accesses the database.

[0028] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor;

[0029] The memory is used to store computer programs;

[0030] The processor is used to implement a SQL statement parsing method based on database transparent encryption when executing the computer program.

[0031] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute a SQL statement parsing method based on database transparent encryption.

[0032] The beneficial effects of the SQL statement parsing method, device and apparatus based on database transparent encryption provided by the embodiments of the present application are as follows:

[0033] The target SQL statement is encrypted from two aspects, simple class and complex class. For the target SQL statement of the simple class, the encrypted column field is obtained through field parsing, and the SQL statement to be executed is obtained after transparent encryption. For the target SQL statement of the complex class, the encryption and decryption strategy is pre-configured, wherein the encryption and decryption strategy is in the form of a key-value pair, the key includes the database name and the data table name, and the value includes the column name and the key of the data table. In this way, the relationship between the encrypted column field and the key in the target SQL statement can be directly obtained through the obtained encryption and decryption strategy, and the SQL statement to be executed can be obtained, thereby reducing the parsing time of the complex SQL statement. Furthermore, after executing the SQL statement to be executed, the plaintext data of the encrypted column field is obtained by decrypting the decrypted column field in the database query result, thereby realizing efficient access to the database.

[0034] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0036] Figure 1 A flow chart of a SQL statement parsing method based on database transparent encryption provided in an embodiment of the present application;

[0037] Figure 2 A flowchart for parsing complex SQL statements provided in an embodiment of the present application;

[0038] Figure 3 A flowchart of a method for decrypting database query results provided in an embodiment of the present application;

[0039] Figure 4 A structural diagram of a SQL statement parsing device based on database transparent encryption provided in an embodiment of the present application;

[0040] Figure 5 A structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0041] In order to make the purpose, technical solutions and advantages of this application clearer, this application will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0042] Based on the exemplary embodiments shown in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application. In addition, although the disclosure in this application is introduced according to one or several exemplary examples, it should be understood that each aspect of these disclosures can also constitute a complete technical solution separately.

[0043] It should be understood that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, for example, they can be implemented according to an order other than those given in the diagrams or descriptions of the embodiments of this application.

[0044] In addition, the terms "include" and "have" and any variations thereof are intended to cover but not exclude inclusion, for example, a product or device comprising a list of components is not necessarily limited to those components expressly listed but may include other components not expressly listed or inherent to such products or devices.

[0045] The term "module" as used in this application refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.

[0046] Database transparent encryption technology is a technology that encrypts data stored in a database while being transparent to the application. In this way, the application can use the data in the database without making any modifications. It is the current mainstream database encryption solution.

[0047] Database transparent encryption technology can be divided into two types: one is metadata encryption technology, also known as column encryption, which encrypts sensitive data fields so that only authorized users can view them; the other is overall encryption technology, which encrypts the entire database.

[0048] Regarding metadata encryption technology, since the time required to parse the column fields that need to be encrypted from different SQL statements is different, when the SQL statement is more complex, the parsing time increases significantly, causing the data reading and writing of the database driver layer to slow down, which directly affects the access efficiency of the database system.

[0049] In view of this, the embodiment of the present application provides a method for parsing SQL statements based on transparent encryption of databases. For simple SQL statements, the fields contained in the SQL statements, such as table name fields, column name fields, etc., can be quickly obtained through a commonly used parser, so as to locate the encrypted column fields, and transparently encrypt the encrypted column fields according to the keys corresponding to the encrypted field columns to obtain the SQL to be executed; for complex SQL statements, it supports configuring specific encryption and decryption strategies for SQL statements, so as to quickly obtain the encrypted column fields and corresponding keys in the SQL statements according to the encryption and decryption strategies, and obtain the SQL statements to be executed, thereby reducing the time and performance loss caused by the parsing of complex SQL statements. Furthermore, after executing the SQL statements to be executed, the plaintext data of the encrypted column fields is obtained by decrypting the decrypted column fields in the database query results, thereby achieving efficient access to the database.

[0050] See also Figure 1 , which is a flow chart of a SQL statement parsing method based on database transparent encryption provided in an embodiment of the present application, mainly comprising the following steps:

[0051] S101: Check the grammatical structure of the acquired target SQL statement.

[0052] In actual business scenarios, the syntax structures of different SQL statements vary and can be classified as easy or difficult. Generally, simple SQL statements are shorter in length and have a single query condition, while complex SQL statements are longer, have multi-level nesting, contain conjunctions, and involve logical judgments.

[0053] For example, "SELECT CustomerName,Address FROM Customers c where c.id='inid'" is a simple SQL statement. Here, "SELECT" represents the keyword for a selection query, "CustomerName" and "Address" represent the two column fields (i.e., column names) for the selection query, "FROM" represents the keyword for the data table source, "Customers" represents the name of the data table for the selection query, "c" represents the abbreviation of Customers, "where" represents the keyword for the selection query condition, and "c.id='inid'" represents the condition content.

[0054] Another example, "SELECT CustomerName,Address,Leavl,Slalnumber fromCustomerName c,Slal s,Deptemant d where c.customerID=s.customerID and d.name=“R & D Department”" is a complex SQL statement that includes multi-table queries and join queries. Here, "SELECT" represents the keyword for a selection query, "CustomerName", "Address", "Leavl", and "Slalnumber" represent the four column fields for the selection query, "FROM" represents the keyword for the data table source, "CustomerName", "Slal", and "Deptemant" represent the names of the three data tables for the selection query, "c", "s", and "d" respectively represent the abbreviations of these three data table names, "where" represents the keyword for the selection query condition, and "c.customerID=s.customerID and d.name=“R & D Department”" represents the condition content.

[0055] Generally, simple SQL statements can usually be accurately parsed for fields using a parser. However, for complex SQL statements, the parser cannot perform field parsing or the parsing results are inaccurate, thus affecting the execution of the SQL statement. Therefore, after obtaining the target SQL statement, it is necessary to check the syntax result of the target SQL statement to determine the field parsing method.

[0056] Since complex SQL statements cannot be parsed by the parser, when a SQL statement with a complex syntax structure is detected, the SQL statement is stored in the configuration table, and professional technicians configure a special encryption and decryption strategy for the SQL statement.

[0057] In one example, the encryption and decryption strategy is to encrypt and decrypt the column fields in the data table. This is because each column in the data table is generally in a fixed data format, such as date, integer, etc., and encryption and decryption of row fields will destroy the integrity of the data, causing the data to be leaked during unauthorized access, and the encrypted operations (such as sorting, grouping, indexing, etc.) will increase the resource overhead of database access.

[0058] In one example, the encryption and decryption strategy in the configuration table is of Map data type, that is, in the form of key-value pairs, denoted as Map<key,value> , where the key contains the database name and the data table name, and the value contains the column name of the data table (that is, the column field in the data table that needs to be encrypted and decrypted) and the key corresponding to the column name. Different columns that need to be encrypted and decrypted have different keys.

[0059] It should be noted that in the SQL statement, only the column fields corresponding to the parameters that need to be encrypted and decrypted need to configure the encryption and decryption strategy, not every parameter needs to be configured with the encryption and decryption strategy.

[0060] In one example, factors considered when configuring an encryption and decryption strategy for a complex SQL statement include at least one of the following:

[0061] (1) Do complex SQL statements need to be encrypted or decrypted?

[0062] For example, in the data table user, the name column is sensitive data. Therefore, for the SQL statement "Select id, name, age from user", the name field in the database query result needs to be decrypted. For the SQL statement "Select count (1) from user where name = 'lining'", the name field of the user table in the query condition where has a comparison expression, and the content of the name field on the right side of the equal sign, liming, needs to be encrypted.

[0063] (2) Whether there is an encrypted data table in the database accessed by the complex SQL statement.

[0064] In one example, a data table containing at least one column of sensitive data is recorded as an encrypted data table.

[0065] (3) Whether there are encrypted columns in the data table accessed by the complex SQL statement.

[0066] In one example, a column containing sensitive data in a data table is recorded as an encrypted column.

[0067] In one example, an SQL statement accessing an encrypted data table having encrypted columns may or may not need to be encrypted or decrypted.

[0068] For example, name in the user table is an encrypted column field. For the SQL statement "Select count(1)from(Select id,name from user where age>10)", since it counts the number of users whose age is greater than 10, encryption and decryption are not required even if an encrypted column exists.

[0069] (4) Whether the encrypted column fields in the complex class SQL statement are preprocessing parameters.

[0070] In one example, a parameter in a data table may be designated as an encrypted column field, so that pre-encryption processing is performed on the designated parameter.

[0071] (5) Whether the return result set corresponding to the complex class SQL statement contains a decryption column.

[0072] In one example, the database query result set returned by JDBC is received using the ResultSet type. When the SQL statement contains encrypted column fields, the database query result corresponding to the SQL statement contains decrypted column fields.

[0073] For example, name in the data table user is an encrypted column field. The name parameter in the database query result returned by the SQL "Select id, name, age from user" needs to be decrypted.

[0074] After configuring the encryption and decryption strategy, complex SQL statements can be parsed using the encryption and decryption strategy.

[0075] In the embodiments of the present application, in actual applications, users can flexibly configure encryption and decryption strategies for unparseable complex SQL statements through the above factors, which is more applicable and suitable for various complex SQL statements.

[0076] S102: When the syntax structure is a simple class, the fields included in the target SQL statement are parsed to obtain the encrypted column fields, and the encrypted column fields are transparently encrypted to obtain the SQL statement to be executed.

[0077] In one example, for a simple SQL statement, a parser based on Antlr4 can quickly and accurately parse out the fields contained in the target SQL statement and locate the encrypted column fields.

[0078] For example, the name column in the target SQL statement Select id, name, age from user is sensitive data that needs to be protected. After the Antlr4-based parser performs field parsing on "Select id, name, age from user", three column fields named id, name, and age and a field named user are obtained, and the encrypted column field is located as name.

[0079] It should be noted that the embodiment of the present application does not impose any restrictive requirements on the number of encrypted column fields in the target SQL statement. It can be one or more, such as the encrypted column fields in Select id, name, age from user are name and age.

[0080] After the encrypted column field is obtained, the encrypted column field is transparently encrypted according to the key corresponding to the encrypted column field, and the original encrypted column field is replaced with the encrypted field to rewrite the SQL statement to obtain the SQL statement to be executed.

[0081] For example, if the encrypted column field in the target SQL statement Select id, name, age from user is name, then the SQL statement to be executed after transparent encryption is Select id, ciphertext, age from user.

[0082] S103: When the grammatical structure is a complex class, an encryption and decryption strategy pre-configured for the target SQL statement is obtained, and the SQL statement to be executed is obtained according to the encryption and decryption strategy.

[0083] Since complex SQL statements cannot be accurately parsed by the parser, professional technicians configure encryption and decryption strategies for complex SQL statements and store them. In this way, when the grammatical structure of the target SQL statement is complex, the encryption and decryption strategy corresponding to the target SQL statement can be obtained, and the field can be parsed according to the obtained encryption and decryption strategy to obtain the SQL statement to be executed.

[0084] See also Figure 2 , which is the field parsing process of complex target SQL statements, mainly includes the following steps:

[0085] S1031: Determine whether the encryption / decryption strategy is encryption, if not, execute S1032, if yes, execute S1033.

[0086] In one example, when the data table accessed by the target SQL statement does not contain sensitive data, there is no need to encrypt and decrypt the column fields, so the configured encryption and decryption strategy is not encrypted, that is, there is no need to encrypt and decrypt the column fields. When the data table accessed by the target SQL statement contains sensitive data, the column fields need to be encrypted and decrypted, so the configured encryption and decryption strategy is encryption.

[0087] S1032: Use the target SQL statement as the SQL statement to be executed.

[0088] When the encryption and decryption strategy corresponding to the target SQL statement is no encryption, there is no need to process the column fields in the target SQL statement. Therefore, the target SQL statement can be directly used as the SQL statement to be executed.

[0089] S1033: Determine whether the encrypted column field in the target SQL statement is encrypted in the preprocessing stage. If so, execute S1034; if not, execute S1035.

[0090] When the encryption and decryption strategy corresponding to the target SQL statement is encryption, it is necessary to handle it in two cases according to whether the encrypted column field is encrypted in the preprocessing stage.

[0091] S1034: Use the preprocessed target SQL statement as the SQL statement to be executed.

[0092] When the encrypted column field in the target SQL statement is encrypted in the preprocessing stage, the preprocessed target SQL statement is used as the SQL statement to be executed.

[0093] For example, the target SQL statement is "INSERT INTO users(id,name,age)VALUES(?,?,?)". The "name" column in the data table is ciphertext, so the corresponding encryption and decryption strategy is to encrypt the column field corresponding to the second parameter. Therefore, in the preprocessing stage, the "name" column field is encrypted to obtain the SQL statement to be executed.

[0094] S1035: Obtain the encrypted column field according to the key-value pair configured in the encryption and decryption strategy, and obtain the SQL statement to be executed after transparently encrypting the encrypted column field.

[0095] When the encrypted column fields in the target SQL statement are not encrypted in the preprocessing stage, the target SQL statement is still the original SQL statement. At this time, the encrypted column fields in the target SQL statement can be determined according to the key-value pairs in the configured encryption and decryption strategy, and the SQL statement to be executed can be obtained after transparent encryption processing according to the corresponding key. Through the key-value pairs in the configured encryption and decryption strategy, the encrypted column fields and the corresponding keys can be quickly obtained, thereby reducing the time loss and performance loss caused by complex SQL statement field parsing and improving the efficiency of database access.

[0096] For example, for the target SQL statement "Select count(1) from user where name = 'lining'", after configuring name in the data table user as an encrypted column field, the content in single quotation marks '' will be encrypted, thereby obtaining the SQL statement to be executed.

[0097] S104: Execute the SQL statement to be executed to obtain the database query result.

[0098] By submitting the SQL statements to be executed after encrypting sensitive data to the database driver layer for execution, the database query results can be obtained, while ensuring the security of data transmission and storage.

[0099] S105: When the database query result includes a decryption column field, the decryption column field is decrypted to obtain a decryption result.

[0100] See also Figure 3 , which is the decryption process of the database query results, mainly includes the following steps:

[0101] S1051: Determine the number of decryption column fields in the database query result. If it is a single number, execute S1052; if it is multiple, execute S1053.

[0102] Since the number of encrypted column fields can be one or more, the number of decrypted column fields can also be one or more, and decryption needs to be performed according to different situations.

[0103] S1052: Directly decrypt the decryption column field to obtain a decryption result.

[0104] When the number of decryption column fields is single, it is only necessary to decrypt the single decryption column field to obtain the decryption result.

[0105] For example, assuming that "name" in "select id, name, age from user" is an encrypted column field, the database query result of the SQL statement contains only one decrypted column field. Therefore, after decrypting the "name" column, the decrypted result is obtained.

[0106] S1053: splitting the multiple decryption column fields and then decrypting them, and concatenating the decrypted fields to obtain a decryption result.

[0107] When there are multiple decryption column fields, it is necessary to decrypt the multiple decryption column fields to obtain the decryption result.

[0108] For example, in the SQL statement "select id,concat(name,'-',age)as info from user", concat is a character concatenation function, and "name" and "age" are both encrypted column fields. The database query result of this SQL statement contains two decrypted column fields. Therefore, the "name" column and the "age" column are decrypted separately and concatenated to obtain the decrypted result.

[0109] In the embodiments of the present application, for simple SQL statements, when there is one key for each column field corresponding to sensitive data, the parser can quickly locate the encrypted column field and the corresponding key, thereby realizing the parsing of simple SQL statements and correctly encrypting and decrypting the corresponding data; and for complex SQL statements, when the parser cannot perform field parsing, the key-value pairs in the configured encryption and decryption strategy can quickly locate the encrypted column field and the corresponding key of sensitive data, thereby reducing the time and performance loss of complex SQL statement parsing and improving the access efficiency of the database. At the same time, whether it is the encryption and decryption process for the column field of simple SQL statements or the encryption and decryption process for the column field of complex SQL statements, both are to change the original transparent encryption and decryption technology logic of the database, which is more friendly to the application programs accessing the database.

[0110] In one example, at the software design level, the encryption process of the target SQL statement in the SQL statement parsing method based on database transparent encryption, as well as the decryption process of the database query result, can be encapsulated into a software plug-in and configured in the target application that accesses the database, thereby improving the efficiency and accuracy of the target application accessing the database.

[0111] Based on the same technical concept, an embodiment of the present application provides a SQL statement parsing device based on database transparent encryption, which can implement the SQL statement parsing method based on database transparent encryption in the above embodiment.

[0112] See also Figure 4 The SQL statement parsing device includes a checking module 401, an encryption module 402, an execution module 403, and a decryption module 404, wherein:

[0113] A checking module 401 is used to check the grammatical structure of the acquired target SQL statement;

[0114] The encryption module 402 is used to parse the fields included in the target SQL statement if the grammatical structure is a simple class, obtain the encrypted column fields, and transparently encrypt the encrypted column fields to obtain the SQL statement to be executed; and if the grammatical structure is a complex class, obtain the encryption and decryption strategy pre-configured for the target SQL statement, and obtain the SQL statement to be executed according to the encryption and decryption strategy; wherein the encryption and decryption strategy is in the form of a key-value pair, the key includes the database name and the data table name, and the value includes the column name and the key of the data table;

[0115] An execution module 403 is used to execute the SQL statement to be executed and obtain a database query result;

[0116] The decryption module 404 is configured to decrypt the decryption column field to obtain a decryption result if the database query result includes a decryption column field.

[0117] Optionally, the encryption module 402 is specifically used for:

[0118] If the encryption and decryption strategy is no encryption, the target SQL statement is used as the SQL statement to be executed;

[0119] If the encryption and decryption strategy is encryption, determine whether the encrypted column field in the target SQL statement is encrypted in the preprocessing stage. If so, use the preprocessed target SQL statement as the SQL statement to be executed. Otherwise, obtain the encrypted column field according to the key-value pair configured in the encryption and decryption strategy, and transparently encrypt the encrypted column field to obtain the SQL statement to be executed.

[0120] Optionally, the decryption module 404 is specifically used for:

[0121] If the number of the decryption column fields is single, directly decrypt the decryption column fields to obtain the decryption result;

[0122] If there are multiple decryption column fields, the multiple decryption column fields are split and then decrypted, and the decrypted fields are concatenated to obtain the decryption result.

[0123] Optionally, the configuration factors of the encryption and decryption strategy include at least one of the following:

[0124] Whether complex SQL statements need to be encrypted or decrypted;

[0125] Whether the database accessed by the complex SQL statement contains encrypted data tables;

[0126] Whether there are encrypted columns in the data table accessed by the complex SQL statement;

[0127] Whether the encrypted column field in the SQL statement of the complex class is a preprocessing parameter;

[0128] Check whether the returned result set corresponding to the SQL statement of the complex class contains a decryption column.

[0129] Optionally, the encryption process of the target SQL statement and the decryption process of the database query result are encapsulated into a plug-in and configured in the target application that accesses the database.

[0130] It should be noted here that the above-mentioned SQL statement parsing device provided in the embodiment of the present application can implement the SQL statement parsing method steps based on database transparent encryption implemented by the above-mentioned method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0131] Based on the same technical concept, an embodiment of the present application provides an electronic device on which an application for accessing a database is installed, and the SQL statement parsing method based on transparent database encryption in the above embodiment can be implemented.

[0132] See also Figure 5 The electronic device includes a processor 501. The processor 501 may also be a controller. The processor 501 is configured to execute Figure 1-Figure 3 The electronic device may also include a memory 502, which is coupled to the processor 501 and stores necessary program instructions and data for the device. The processor 501 is connected to the memory 502, the memory 502 is used to store computer programs, and the processor 501 is used to execute the computer programs stored in the memory 502 to complete the steps of executing the corresponding functions of the above method.

[0133] In the embodiments of the present application, for the concepts, explanations, detailed descriptions and other steps involved in the electronic device and related to the technical solutions provided in the embodiments of the present application, please refer to the descriptions of these contents in the aforementioned methods or other embodiments, which will not be repeated here.

[0134] It should be noted that the processor involved in the above-mentioned embodiments of the present application can be a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The memory may be integrated into the processor or may be separately provided from the processor. The memory may be a volatile memory, such as a random-access memory (RAM); the memory may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or the memory may be any other medium that can be used to carry or store a desired computer program in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may be a combination of the above memories.

[0135] The embodiments of the present application further provide a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the method in the above embodiments.

[0136] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0137] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0138] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0139] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0140] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A SQL statement parsing method based on database transparent encryption, characterized in that: include: Check the syntax structure of the acquired target SQL statement; If the grammatical structure is a simple class, the fields included in the target SQL statement are parsed to obtain encrypted column fields, and after transparently encrypting the encrypted column fields, a SQL statement to be executed is obtained; If the grammatical structure is a complex class, then obtain the encryption and decryption strategy pre-configured for the target SQL statement, and obtain the SQL statement to be executed according to the encryption and decryption strategy; wherein the encryption and decryption strategy is in the form of a key-value pair, the key includes the database name and the data table name, and the value includes the column name and the key of the data table; Execute the SQL statement to be executed to obtain the database query result; If the database query result includes a decryption column field, the decryption column field is decrypted to obtain a decryption result.

2. The method according to claim 1, characterized in that Obtaining the SQL statement to be executed according to the encryption and decryption strategy includes: If the encryption and decryption strategy is no encryption, the target SQL statement is used as the SQL statement to be executed; If the encryption and decryption strategy is encryption, determine whether the encrypted column field in the target SQL statement is encrypted in the preprocessing stage. If so, use the preprocessed target SQL statement as the SQL statement to be executed. Otherwise, obtain the encrypted column field according to the key-value pair configured in the encryption and decryption strategy, and transparently encrypt the encrypted column field to obtain the SQL statement to be executed.

3. The method according to claim 1, characterized in that The decrypting the decryption column field to obtain a decryption result includes: If the number of the decryption column fields is single, directly decrypt the decryption column fields to obtain the decryption result; If there are multiple decryption column fields, the multiple decryption column fields are split and then decrypted, and the decrypted fields are concatenated to obtain the decryption result.

4. The method according to any one of claims 1 to 3, characterized in that The configuration factors of the encryption and decryption strategy include at least one of the following: Whether complex SQL statements need to be encrypted or decrypted; Whether the database accessed by the complex SQL statement contains encrypted data tables; Whether there are encrypted columns in the data table accessed by the complex SQL statement; Whether the encrypted column field in the SQL statement of the complex class is a preprocessing parameter; Check whether the returned result set corresponding to the SQL statement of the complex class contains a decryption column.

5. The method according to any one of claims 1 to 3, characterized in that The encryption process of the target SQL statement and the decryption process of the database query result are encapsulated into a plug-in and configured in the target application that accesses the database.

6. A SQL statement parsing device based on database transparent encryption, characterized in that: include: A checking module is used to check the grammatical structure of the acquired target SQL statement; An encryption module, for parsing the fields included in the target SQL statement to obtain the encrypted column fields, and transparently encrypting the encrypted column fields to obtain the SQL statement to be executed if the grammatical structure is a simple class; and, for obtaining the encryption and decryption strategy pre-configured for the target SQL statement if the grammatical structure is a complex class, and obtaining the SQL statement to be executed according to the encryption and decryption strategy; wherein the encryption and decryption strategy is in the form of a key-value pair, the key includes the database name and the data table name, and the value includes the column name and the key of the data table; An execution module is used to execute the SQL statement to be executed and obtain a database query result; The decryption module is used to decrypt the decryption column field if the database query result contains the decryption column field to obtain the decryption result.

7. The device according to claim 6, characterized in that The encryption module is specifically used for: If the encryption and decryption strategy is no encryption, the target SQL statement is used as the SQL statement to be executed; If the encryption and decryption strategy is encryption, determine whether the encrypted column field in the target SQL statement is encrypted in the preprocessing stage. If so, use the preprocessed target SQL statement as the SQL statement to be executed. Otherwise, obtain the encrypted column field according to the key-value pair configured in the encryption and decryption strategy, and transparently encrypt the encrypted column field to obtain the SQL statement to be executed.

8. The device according to claim 6, characterized in that The decryption module is specifically used for: If the number of the decryption column fields is single, directly decrypt the decryption column fields to obtain the decryption result; If there are multiple decryption column fields, the multiple decryption column fields are split and then decrypted, and the decrypted fields are concatenated to obtain the decryption result.

9. An electronic device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is configured to implement the method according to any one of claims 1 to 5 when executing the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the method according to any one of claims 1 to 5.

Citation Information

Cited By

  • Method for improving count operation efficiency in database whole table encryption scene

    CN121070963A

  • A multi-scene applicable database transparent encryption method

    CN122863583A