Database access method, electronic equipment, storage medium and program product
By receiving the database access request from the client terminal and processing and reorganizing the response message according to the pre-stored masking policy, the problem of excessive workload of public servers when multiple terminals access the public database at the same time is solved, and the security of database access is improved.
Patent Information
- Application Number
- CN202510204713.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-13
AI Technical Summary
When multiple terminals access public databases at the same time, the amount of concurrent data on the public server is too large, which threatens the security of the database. How to reduce the workload of the public server and ensure the security of database access is an urgent issue.
By receiving the database access request sent by the client terminal, the initial response message is obtained, and the masking action is determined according to the pre-stored masking policy, the initial response message is processed and reorganized to generate a target response message, and the target response message is sent to the client terminal. This proxy module is used to configure the database key information permissions and assign different masking policies to different roles.
Through the processing and reorganization of masking policies, the workload of database access requests to public servers is reduced, and the security of database access is improved to prevent illegal access.
Smart Images

Figure CN119988415A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data transmission, and in particular to a database access method, electronic equipment, storage medium and program product. Background Art
[0002] With the continuous development of network technology, the application fields of the Internet are also increasing. In the process of data transmission, web services are installed on multiple terminals. Multiple terminals will access the public database when performing business. If multiple terminals access the public database at the same time, the concurrent data volume of the public server of the public database is too large. In addition, due to the complexity of Internet business, loopholes will be introduced in the data transmission process, resulting in illegal access to the database, affecting the overall data security. Therefore, how to reduce the workload of the public server and ensure the security of database access is an urgent problem to be solved. Summary of the invention
[0003] The purpose of some embodiments of the present application is to provide a database access method, electronic device, storage medium and program product. Through the technical solution of the embodiments of the present application, by receiving a database access request sent by a client terminal, and obtaining an initial response message corresponding to the database access request; according to a pre-stored masking strategy, determining a masking action corresponding to the database access request; wherein the masking strategy at least includes a rule matching mode, a data masking mode and a matching process; according to the masking action, processing the initial response message, and reorganizing the processed message to obtain a target response message corresponding to the database access request, and sending the target response message to the client terminal. In the embodiments of the present application, a proxy module is used to configure the database key information authority, assign different masking strategies to operation and maintenance personnel, merchants, and buyers, and process the obtained response message according to the masking strategy to obtain the target response message, which not only reduces the workload, but also ensures the security of database access.
[0004] In a first aspect, some embodiments of the present application provide a database access method, including:
[0005] Receiving a database access request sent by a client terminal, and obtaining an initial response message corresponding to the database access request;
[0006] Determine a masking action corresponding to the database access request according to a pre-stored masking strategy; wherein the masking strategy at least includes a rule matching mode, a data masking mode and a matching process;
[0007] According to the masking action, the initial response message is processed, and the processed message is reorganized to obtain a target response message corresponding to the database access request, and the target response message is sent to the client terminal.
[0008] Some embodiments of the present application set up a proxy module, which is used to configure the database key information permissions, assign different masking strategies to operation and maintenance personnel, merchants, and buyers, and process the acquisition response message according to the masking strategy to obtain the target response message, which not only reduces the workload but also ensures the security of database access.
[0009] Optionally, determining the masking action corresponding to the database access request according to a pre-stored masking strategy includes:
[0010] The rule matching mode and the matching process are used to match the keywords in the database access request, determine the target matching field corresponding to the keyword, and determine the target data mask mode corresponding to the keyword.
[0011] Optionally, the processing of the initial response message according to the masking action, and reorganizing the processed message to obtain a target response message corresponding to the database access request includes:
[0012] Adopting the target data masking mode, performing masking action processing on the initial response message to obtain processed data;
[0013] The target matching field and the processed data are reorganized to generate a target response message corresponding to the database access request.
[0014] Some embodiments of the present application determine the masking action based on the database request message, modify the response message, separate the protocol and data of the response message, modify the data, and then combine the new data with the protocol to form a new response message, thereby improving the security of database access.
[0015] Optionally, the rule matching mode includes at least one of a complete matching mode, a partial matching mode or a regular expression matching mode; the complete matching mode is used to trigger a masking action when the queried data name is completely consistent when querying the database; the partial matching mode is used to trigger a masking action when the database name is partially matched; the regular expression matching mode is used to match according to a regular expression.
[0016] Optionally, the data masking mode includes at least one of masking, replacement, offset modification and random modification.
[0017] Optionally, the matching process includes at least a first matching at a network layer and a second matching at a service layer.
[0018] Some embodiments of the present application can be set according to the permissions of different terminals by setting the rule matching mode, data masking mode and matching process in the masking strategy. In this way, the coupling degree is small and the operation and maintenance are simple. The policy center configures the masking strategy of the database agent and can uniformly control the access behavior of all roles.
[0019] Optionally, the method further comprises:
[0020] The masking strategy is updated.
[0021] Some embodiments of the present application continuously update the masking strategy through a proxy module. If the strategy has been updated, it is necessary to obtain a new strategy from a strategy center to ensure that after the latest strategy is obtained, the masking action can be determined according to the request message.
[0022] In a second aspect, some embodiments of the present application provide a database access device, including:
[0023] A receiving module, used to receive a database access request sent by a client terminal and obtain an initial response message corresponding to the database access request;
[0024] A matching module, used to determine a masking action corresponding to the database access request according to a pre-stored masking strategy; wherein the masking strategy at least includes a rule matching mode, a data masking mode and a matching process;
[0025] The reassembly module is used to process the initial response message according to the mask action, reassemble the processed message, obtain a target response message corresponding to the database access request, and send the target response message to the client terminal.
[0026] Some embodiments of the present application set up a proxy module, which is used to configure the database key information permissions, assign different masking strategies to operation and maintenance personnel, merchants, and buyers, and process the acquisition response message according to the masking strategy to obtain the target response message, which not only reduces the workload but also ensures the security of database access.
[0027] Optionally, the matching module is used to:
[0028] The rule matching mode and the matching process are used to match the keywords in the database access request, determine the target matching field corresponding to the keyword, and determine the target data mask mode corresponding to the keyword.
[0029] Optionally, the recombination module is used to:
[0030] Adopting the target data masking mode, performing masking action processing on the initial response message to obtain processed data;
[0031] The target matching field and the processed data are reorganized to generate a target response message corresponding to the database access request.
[0032] Some embodiments of the present application determine the masking action based on the database request message, modify the response message, separate the protocol and data of the response message, modify the data, and then combine the new data with the protocol to form a new response message, thereby improving the security of database access.
[0033] Optionally, the rule matching mode includes at least one of a complete matching mode, a partial matching mode or a regular expression matching mode; the complete matching mode is used to trigger a masking action when the queried data name is completely consistent when querying the database; the partial matching mode is used to trigger a masking action when the database name is partially matched; the regular expression matching mode is used to match according to a regular expression.
[0034] Optionally, the data masking mode includes at least one of masking, replacement, offset modification and random modification.
[0035] Optionally, the matching process includes at least a first matching at a network layer and a second matching at a service layer.
[0036] Some embodiments of the present application can be set according to the permissions of different terminals by setting the rule matching mode, data masking mode and matching process in the masking strategy. In this way, the coupling degree is small and the operation and maintenance are simple. The policy center configures the masking strategy of the database agent and can uniformly control the access behavior of all roles.
[0037] Optionally, the matching module is used to:
[0038] The masking strategy is updated.
[0039] Some embodiments of the present application continuously update the masking strategy through a proxy module. If the strategy has been updated, it is necessary to obtain a new strategy from a strategy center to ensure that after the latest strategy is obtained, the masking action can be determined according to the request message.
[0040] In a third aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the database access method as described in any embodiment of the first aspect can be implemented.
[0041] In a fourth aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the database access method as described in any embodiment of the first aspect.
[0042] In a fifth aspect, some embodiments of the present application provide a computer program product, comprising a computer program, wherein the computer program, when executed by a processor, can implement the database access method as described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the drawings required for use in some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0044] Figure 1 A flowchart of a database access method provided in an embodiment of the present application;
[0045] Figure 2 A schematic diagram of the structure of a database access system provided in an embodiment of the present application;
[0046] Figure 3 A flowchart of another database access method provided in an embodiment of the present application;
[0047] Figure 4 A schematic diagram of the structure of a database access device provided in an embodiment of the present application;
[0048] Figure 5 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0049] The technical solutions in some embodiments of the present application will be described below in conjunction with the drawings in some embodiments of the present application.
[0050] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0051] With the continuous development of network technology, the application fields of the Internet are also increasing. In the process of data transmission, web services are installed on multiple terminals. Multiple terminals will access the public database when executing business. If multiple terminals access the public database at the same time, the concurrent data volume of the public server of the public database is too large. Moreover, due to the complexity of Internet business, loopholes will be introduced in the data transmission process, which will lead to illegal access to the database and affect the overall data security. Therefore, how to reduce the workload of the public server and ensure the security of database access is an urgent problem to be solved. In view of this, some embodiments of the present application provide a database access method, which includes receiving a database access request sent by a client terminal and obtaining an initial response message corresponding to the database access request; determining a mask action corresponding to the database access request according to a pre-stored mask strategy; wherein the mask strategy at least includes a rule matching mode, a data mask mode and a matching process; processing the initial response message according to the mask action, and reorganizing the processed message to obtain a target response message corresponding to the database access request, and sending the target response message to the client terminal. In the embodiment of the present application, a proxy module is used to configure the database key information permissions, assign different masking strategies to operation and maintenance personnel, merchants, and buyers, and process the acquired response message according to the masking strategy to obtain the target response message, which not only reduces the workload but also ensures the security of database access.
[0052] The present application embodiment provides a database access system, such as Figure 2 As shown, multiple terminals are respectively connected to the database proxy module, the database proxy module is used to execute the policy, web applications are installed on the terminals respectively, the database proxy module and the database are installed on the same server, and can be installed on different servers, which is not specifically limited here. The database proxy module is used to execute the database return packet key information masking method with structure and content separation, and the database return packet data is processed by the database proxy module and the policy management center, and the key information is masked to prevent its content from being illegally obtained.
[0053] like Figure 1 As shown, an embodiment of the present application provides a database access method, the method comprising:
[0054] S101, receiving a database access request sent by a client terminal, and obtaining an initial response message corresponding to the database access request;
[0055] Specifically, a plurality of client terminals are respectively connected to a public server, on which a database proxy module is installed. The public server receives database access requests sent by the client terminals, and obtains corresponding initial response messages from the database according to the database access requests.
[0056] S102, determining a masking action corresponding to the database access request according to a pre-stored masking strategy; wherein the masking strategy at least includes a rule matching mode, a data masking mode and a matching process;
[0057] Specifically, a masking strategy is stored on a public server, and the masking strategy needs to be continuously updated to ensure that the masking strategy is the latest strategy. The masking strategy includes at least a rule matching mode, a data masking mode and a matching process, and determines the corresponding masking action based on the pre-stored masking strategy and the keywords in the database access request.
[0058] Exemplarily, the masking action at least includes that the rule matching mode adopted is a complete matching mode, the data masking mode is a replacement mode, for example, certain data is replaced with special characters, and the matching process is to perform a rough match first and then a fine match.
[0059] S103. Process the initial response message according to the masking action, reorganize the processed message, obtain a target response message corresponding to the database access request, and send the target response message to the client terminal.
[0060] Specifically, after obtaining the masking action, the public server processes the initial response message, that is, masks the data in the initial response message to ensure the security of database access, and then reorganizes the database fields and the processed message to obtain the target response message, and sends the target response message to the corresponding client terminal.
[0061] like Figure 3 As shown, it specifically includes starting the database proxy module and loading the database masking strategy; when receiving a database access request, determining the masking action according to the database strategy; processing the message returned by the database service according to the masking action, replacing the key information data in the message with invalid data (for example, all + signs) to prevent the key information from being obtained without authorization.
[0062] Exemplarily, if client terminal 1 sends a database access request 1, the database access request 1 includes a terminal identifier 1 and a database name 1 of the client terminal 1, the public server searches the database for a corresponding initial response message based on the terminal identifier 1 and the database name 1 of the client terminal 1 in the database access request 1, and then determines a masking action corresponding to the terminal identifier 1 and the database name 1 based on a pre-stored masking strategy; wherein the masking strategy includes at least a rule matching mode, a data masking mode and a matching process, and according to the masking action, the initial response message is processed, and the processed message is reorganized to obtain a target response message corresponding to the database access request 1, and the target response message is sent to the client terminal 1.
[0063] Some embodiments of the present application set up a proxy module, which is used to configure the database key information permissions, assign different masking strategies to operation and maintenance personnel, merchants, and buyers, and process the acquisition response message according to the masking strategy to obtain the target response message, which not only reduces the workload but also ensures the security of database access.
[0064] Another embodiment of the present application further supplements the database access method provided in the above embodiment.
[0065] Optionally, determining a masking action corresponding to the database access request according to a pre-stored masking strategy includes:
[0066] The rule matching mode and matching process are adopted to match the keywords in the database access request, determine the target matching field corresponding to the keyword, and determine the target data mask mode corresponding to the keyword.
[0067] In the embodiment of the present application, for loading the mask strategy, the database proxy module needs to load the complete mask strategy into the memory when starting. The mask strategy includes three parts: rule matching mode, data mask mode, and strategy content.
[0068] Optionally, the rule matching mode includes at least one of a complete matching mode, a partial matching mode or a regular expression matching mode; the complete matching mode is used to trigger a masking action when the queried data name is completely consistent when querying the database; the partial matching mode is used to trigger a masking action when the database name is partially matched; the regular expression matching mode is used to match according to a regular expression.
[0069] Among them, in the rule matching mode, the complete matching mode refers to triggering the masking action when the queried data name (database name, table name, field name) when querying the database is completely consistent; the partial matching mode triggers the masking action when the data name partially matches, which belongs to fuzzy matching; regular expression matching refers to special matching according to regular expressions.
[0070] Optionally, the data masking mode includes at least one of masking, replacement, offset modification and random modification.
[0071] Among them, the data masking mode includes four methods: masking, replacement, offset modification and random modification. Masking refers to covering with a certain symbol, replacement refers to changing to a uniform fixed value, offset modification refers to a uniform offset of the ASCII value of the character, and random modification refers to a random offset of the ASCII value of the character.
[0072] Optionally, the matching process includes at least a first matching at the network layer and a second matching at the service layer.
[0073] Among them, the policy content, that is, the matching process, first matches the initial information such as the database user name, the client source IP address, and the client segment name, and performs a rough match at the network layer, that is, the first match at the network layer; then matches the database name, table name, and field name, and performs a business layer match, that is, the second match at the business layer. The rule matching method, matching starting point, and matching length correspond to the rule matching mode, and the operation method, operation starting point, and operation length correspond to the data mask mode.
[0074] Some embodiments of the present application can be set according to the permissions of different terminals by setting the rule matching mode, data masking mode and matching process in the masking strategy. In this way, the coupling degree is small and the operation and maintenance are simple. The policy center configures the masking strategy of the database agent and can uniformly control the access behavior of all roles.
[0075] Optionally, the initial response message is processed according to the masking action, and the processed message is reorganized to obtain a target response message corresponding to the database access request, including:
[0076] Adopting the target data masking mode, the initial response message is masked to obtain the processed data;
[0077] The target matching fields and the processed data are reorganized to generate a target response message corresponding to the database access request.
[0078] Specifically, the public server masks the key information in the initial response. Since the database response message corresponds to the format of the request message, the masking action can make corresponding modifications to the response message. However, the response message is a combination of database protocol fields and content. Therefore, it is necessary to separate the protocol fields and content first, then modify the content, and finally combine the protocol fields and new content to form a new response message and return it to the client terminal.
[0079] Some embodiments of the present application determine the masking action based on the database request message, modify the response message, separate the protocol and data of the response message, modify the data, and then combine the new data with the protocol to form a new response message, thereby improving the security of database access.
[0080] Optionally, the method further comprises:
[0081] Updates to the masking strategy.
[0082] Specifically, when the public server receives a database access request sent by a client terminal, it needs to determine in real time whether the masking strategy has been updated. Since the concurrent amount of database access in actual use is very large, in order to minimize the number of times the strategy is loaded, it is necessary to use semaphore synchronization to communicate across processes. The Windows system can use the CreateMux function to achieve this, and the Unix system can use the semget and semctl functions in the SYSTEM V semaphore to achieve this. After using semaphore synchronization, it can be guaranteed that the database proxy module will load the latest strategy only when and only when the masking strategy is updated, so that the maximum operating efficiency can be guaranteed, and the old masking strategy will not be used for data processing. In actual deployment. The masking strategy is updated through the policy center. If the strategy has been updated, it is necessary to obtain a new strategy from the policy center. After ensuring that the latest strategy is obtained, the masking action is determined according to the request message.
[0083] Some embodiments of the present application continuously update the masking strategy through a proxy module. If the strategy has been updated, it is necessary to obtain a new strategy from a strategy center to ensure that after the latest strategy is obtained, the masking action can be determined according to the request message.
[0084] The embodiment of the present application can be applied to the user information confidentiality policy of an online shopping mall, and the specific process is as follows:
[0085] 1. Start the policy center, configure the permissions for key database information, and assign different permission policies to operation and maintenance personnel, merchants, and buyers.
[0086] 2. Start the database agent.
[0087] 3. Start the mall service and backend management service, and the database agent provides data services to the mall service and backend management service.
[0088] The embodiments of the present application focus on the masking of key information of database return packets with separated structure and content. A policy center is used to configure the masking strategy of the database agent to cover all access roles. The masking action is determined according to the database request message, and the reply message is modified. After the protocol and data of the reply message are separated, the data is modified, and the new data is combined with the protocol to form a new reply message. The security level is high and the database is directly protected. The module coupling is small and the operation and maintenance are simple. The policy center configures the masking strategy of the database agent, which can uniformly control the access behavior of all roles.
[0089] It should be noted that each implementable method in this embodiment may be implemented separately, or may be implemented in combination in any combination without conflict, and this application is not limited thereto.
[0090] Another embodiment of the present application provides a database access device, which is used to execute the database access method provided by the above embodiment.
[0091] like Figure 4 4 is a schematic diagram of the structure of a database access device provided in an embodiment of the present application. The database access device includes a receiving module 401, a matching module 402 and a reorganization module 403, wherein:
[0092] The receiving module 401 is used to receive a database access request sent by a client terminal and obtain an initial response message corresponding to the database access request;
[0093] The matching module 402 is used to determine the masking action corresponding to the database access request according to the pre-stored masking strategy; wherein the masking strategy at least includes a rule matching mode, a data masking mode and a matching process;
[0094] The reassembly module 403 is used to process the initial response message according to the mask action, reassemble the processed message, obtain the target response message corresponding to the database access request, and send the target response message to the client terminal.
[0095] Regarding the device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0096] Some embodiments of the present application set up a proxy module, which is used to configure the database key information permissions, assign different masking strategies to operation and maintenance personnel, merchants, and buyers, and process the acquisition response message according to the masking strategy to obtain the target response message, which not only reduces the workload but also ensures the security of database access.
[0097] Another embodiment of the present application further supplements the database access device provided in the above embodiment.
[0098] Optionally, a matching module is used to:
[0099] The rule matching mode and matching process are adopted to match the keywords in the database access request, determine the target matching field corresponding to the keyword, and determine the target data mask mode corresponding to the keyword.
[0100] Optionally, a recombinant module is used to:
[0101] Adopting the target data masking mode, the initial response message is masked to obtain the processed data;
[0102] The target matching fields and the processed data are reorganized to generate a target response message corresponding to the database access request.
[0103] Some embodiments of the present application determine the masking action based on the database request message, modify the response message, separate the protocol and data of the response message, modify the data, and then combine the new data with the protocol to form a new response message, thereby improving the security of database access.
[0104] Optionally, the rule matching mode includes at least one of a complete matching mode, a partial matching mode or a regular expression matching mode; the complete matching mode is used to trigger a masking action when the queried data name is completely consistent when querying the database; the partial matching mode is used to trigger a masking action when the database name is partially matched; the regular expression matching mode is used to match according to a regular expression.
[0105] Optionally, the data masking mode includes at least one of masking, replacement, offset modification and random modification.
[0106] Optionally, the matching process includes at least a first matching at the network layer and a second matching at the service layer.
[0107] Some embodiments of the present application can be set according to the permissions of different terminals by setting the rule matching mode, data masking mode and matching process in the masking strategy. In this way, the coupling degree is small and the operation and maintenance are simple. The policy center configures the masking strategy of the database agent and can uniformly control the access behavior of all roles.
[0108] Optionally, a matching module is used to:
[0109] Updates to the masking strategy.
[0110] Some embodiments of the present application continuously update the masking strategy through a proxy module. If the strategy has been updated, it is necessary to obtain a new strategy from a strategy center to ensure that after the latest strategy is obtained, the masking action can be determined according to the request message.
[0111] Regarding the device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0112] It should be noted that each implementable method in this embodiment may be implemented separately, or may be implemented in combination in any combination without conflict, and this application is not limited thereto.
[0113] The embodiments of the present application also provide a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the operation of the method corresponding to any embodiment of the database access method provided in the above embodiments can be implemented.
[0114] An embodiment of the present application further provides a computer program product, wherein the computer program product includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations of the method corresponding to any embodiment of the database access method provided in the above embodiments.
[0115] like Figure 5 As shown, some embodiments of the present application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored in the memory 510 and executable on the processor 520, wherein the processor 520 can implement a method of any embodiment of the database access method described above when reading the program from the memory 510 through a bus 530 and executing the program.
[0116] Processor 520 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 520 can be a microprocessor.
[0117] The memory 510 may be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 520 of the disclosed embodiment may be used to execute instructions in the memory 510 to implement the method shown above. The memory 510 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.
[0118] The above are only embodiments of the present application and are not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0119] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0120] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
Claims
1. A database access method, characterized in that: The method comprises: Receiving a database access request sent by a client terminal, and obtaining an initial response message corresponding to the database access request; Determine a masking action corresponding to the database access request according to a pre-stored masking strategy; wherein the masking strategy at least includes a rule matching mode, a data masking mode and a matching process; According to the masking action, the initial response message is processed, and the processed message is reorganized to obtain a target response message corresponding to the database access request, and the target response message is sent to the client terminal.
2. The database access method according to claim 1, characterized in that: The determining, according to the pre-stored masking strategy, a masking action corresponding to the database access request comprises: The rule matching mode and the matching process are used to match the keywords in the database access request, determine the target matching field corresponding to the keyword, and determine the target data mask mode corresponding to the keyword.
3. The database access method according to claim 2, characterized in that: The processing of the initial response message according to the masking action and reorganization of the processed message to obtain a target response message corresponding to the database access request includes: Adopting the target data masking mode, performing masking action processing on the initial response message to obtain processed data; The target matching field and the processed data are reorganized to generate a target response message corresponding to the database access request.
4. The database access method according to claim 1, characterized in that: The rule matching mode includes at least one of a complete matching mode, a partial matching mode or a regular expression matching mode; the complete matching mode is used to trigger a masking action when the queried data name is completely consistent when querying the database; the partial matching mode is used to trigger a masking action when the database name is partially matched; the regular expression matching mode is used to match according to a regular expression.
5. The database access method according to claim 1, characterized in that: The data masking mode includes at least one of masking, replacement, offset modification and random modification.
6. The database access method according to claim 1, characterized in that: The matching process includes at least a first matching at the network layer and a second matching at the service layer.
7. The database access method according to claim 1, characterized in that: The method further comprises: The masking strategy is updated.
8. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor can implement the database access method described in any one of claims 1 to 7 when executing the program.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the program, when executed by a processor, can implement the database access method described in any one of claims 1 to 7.
10. A computer program product, comprising a computer program, wherein: When the computer program is executed by a processor, the database access method described in any one of claims 1 to 7 can be implemented.