Data processing method, application end, security management platform and storage medium
By implementing custom proxy drivers and security plug-ins on the application side, and using the data assets of the security management platform to automatically process data encryption and decryption, the problem of inflexible data security control in the existing technology is solved, and efficient and flexible data security management is achieved.
Patent Information
- Application Number
- CN202510528262.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the existing database management system, data encryption and decryption need to be performed manually, which increases the work burden of developers, is prone to errors, and cannot flexibly configure according to actual needs. In addition, manual operation in big data and cloud computing environments consumes a lot of time and computing resources, which cannot meet users' flexible needs for data security control.
By enabling the connection between custom proxy drivers and multiple data sources on the application side, using custom security plug-ins to obtain data assets from the security management platform, including classified data assets and sensitive data assets, automatically determine the execution permissions of the client and the encryption requirements of the data, and perform encryption or decryption operations through JDBC drivers to achieve automated security management of data.
It realizes flexible control of data security, reduces human intervention, improves system performance, and can configure appropriate encryption and decryption algorithms according to different scenarios to meet data security needs in big data and cloud computing environments.
Smart Images

Figure CN120046196A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer software technology, and particularly to a data processing method, an application end, a security management platform, a storage medium, and a computer program product. Background Art
[0002] Data security control technology is an important branch in the field of information security, mainly focusing on how to protect the integrity, confidentiality, and availability of data, and prevent data from being illegally accessed, tampered with, or leaked. With the development of new technologies such as big data, cloud computing, and the Internet of Things, data security control technology is also constantly evolving. For example, new security strategies and technologies such as zero-trust networks, data privacy protection, and behavior analysis are now being emphasized.
[0003] Currently, in the current database management system, data encryption and decryption usually need to be performed manually. Developers need to explicitly specify which fields need to be encrypted and which encryption algorithm to use. This not only increases the workload of developers but also is prone to errors due to manual operations. For example, in some relational databases such as MySQL and Oracle, although basic data encryption functions are provided, these functions are usually fixed and cannot be flexibly configured according to actual needs. If a developer wants to encrypt a specific field, they must explicitly specify the field when writing SQL statements and also specify the specific encryption algorithm. In this way, additional operations are required every time data is queried or updated. In addition, in the existing database management system, if it is necessary to change the encryption algorithm or add new encrypted fields, a large amount of code often needs to be modified. For example, when using the JDBC interface to interact with the database in the Java language, if the encryption algorithm of a certain field needs to be changed, it may be necessary to modify all SQL statements involving operations on that field, which undoubtedly increases the maintenance workload. Moreover, when processing a large amount of data, manual data encryption and decryption consume a large amount of time and computing resources. Especially in the cloud computing and big data environments, the data volume is huge and distributed across multiple nodes, and manual data security processing will greatly affect the system performance. The above methods cannot meet the flexible requirements of users for data security control. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a data processing method, an application end, a security management platform, a storage medium, and a computer program product to solve the technical defect that data security cannot be flexibly controlled in the prior art.
[0005] To achieve the above object, a first aspect of the present application provides a data processing method, which is applied to an application end. The application end includes a custom proxy driver and multiple data sources. The custom proxy driver includes a custom security plug-in and a JDBC driver. The data processing method includes: When the client successfully connects to the target data source among the multiple data sources, receive the SQL request initiated by the client; Parse the SQL request to obtain the description information of the target data to be written or the target data to be accessed; Obtain the data assets matching the application end from the security management platform through the custom security plug-in. The data assets include classified data assets and sensitive data assets. The classified data assets include all the data of the application end, storage information, and the read and write permissions of each client that supports accessing the application end for each data source among the multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data; the sensitive data assets include the sensitive fields of the application end and the data algorithms for each type of sensitive field. The data algorithms include data encryption algorithms and data decryption algorithms; Based on the classified data assets, determine whether the client has the execution permission to execute the target data for the target data source; When the client has the execution permission, determine whether the target data contains sensitive fields based on the sensitive data assets; When the target data contains sensitive fields, perform an encryption operation or a decryption operation on the sensitive fields using the data algorithms for the sensitive fields; Execute corresponding data writing or data return operations on the target data after the encryption operation or the decryption operation through the JDBC driver.
[0006] In an embodiment of the present application, the data processing method further includes: when the client does not have the execution permission, return the SQL request to the client.
[0007] In an embodiment of the present application, the data processing method further includes: when the target data does not contain sensitive fields, perform corresponding data writing or data return operations on the target data.
[0008] In an embodiment of the present application, executing corresponding data writing or data return operations on the target data after the encryption operation or the decryption operation through the JDBC driver includes: when the description information of the target data to be written is obtained by parsing the SQL request, write the target data after the encryption operation into the target data source through the JDBC driver; when the description information of the target data to be accessed is obtained by parsing the SQL request, return the target data after the decryption operation to the client through the JDBC driver.
[0009] In an embodiment of the present application, the data processing method further includes: extracting data assets matching the application end from the security management platform at a first preset time interval through a custom security plug-in to determine whether the data assets are updated.
[0010] The second aspect of the present application provides an application end, including: A memory configured to store instructions; A processor configured to call instructions from the memory and capable of implementing the above data processing method when executing the instructions.
[0011] The third aspect of the present application provides a data processing method applied to a security management platform. The security management platform interacts with the application end. The application end includes a custom proxy driver and multiple data sources. The custom proxy driver includes a custom security plug-in and a JDBC driver. The data processing method includes: In response to receiving a classified data asset pull request initiated by the custom security plug-in, returning the stored classified data assets to the custom security plug-in, where the classified data assets include all data of the application end, storage information, and read / write permissions of each client supporting access to the application end for each data source among the multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data; the custom proxy driver determines whether the client has the execution permission to execute the target data based on the classified data assets; In response to receiving a sensitive asset pull request initiated by the custom security plug-in, returning the sensitive data assets to the custom security plug-in, where the sensitive data assets include sensitive fields of the application end and data algorithms for each type of sensitive field. The data algorithms include data encryption algorithms and data decryption algorithms; In response to receiving a key request initiated by the custom security plug-in, returning the required key to the custom security plug-in, where the key request is generated by the custom proxy driver according to the data algorithm corresponding to the sensitive field after determining that the client has the execution permission and determining that the target data contains sensitive fields based on the sensitive data assets.
[0012] In an embodiment of the present application, the data processing method further includes: when successfully connected to the application end, assigning an application identifier to the application end; obtaining all data of the application end, storage information, and read / write permissions of each client supporting access to the application end for each data source among the multiple data sources to generate classified data assets for the application end; determining multiple sensitive fields included in all data, defining data algorithms corresponding to each type of sensitive field among the multiple sensitive fields and keys corresponding to each data algorithm; generating sensitive data assets for the application end according to the multiple sensitive fields and the data algorithms corresponding to each type of sensitive field.
[0013] In an embodiment of the present application, the data processing method further includes: obtaining all data of the application side based on a second preset time interval to determine whether all data has been updated and whether sensitive fields included in all data have been updated, where an update includes at least one of addition, modification, or deletion; in the case where it is determined that all data has been updated, obtaining the updated data and the data source corresponding to the updated data to update the classified data assets; in the case where it is determined that the sensitive fields included in all data have been updated, obtaining the updated fields, defining a data algorithm corresponding to the updated fields and a key corresponding to the data algorithm to update the sensitive data assets.
[0014] In an embodiment of the present application, the data processing method further includes: after generating the sensitive data assets for the application side, obtaining the database and data table where each sensitive field is located in the corresponding data source to perform sensitive type marking on the database and data table.
[0015] The fourth aspect of the present application provides a security management platform, including: a memory configured to store instructions; a processor configured to call the instructions from the memory and capable of implementing the above data processing method when executing the instructions.
[0016] The fifth aspect of the present application provides a machine-readable storage medium, on which instructions are stored, and when the instructions are executed by a processor, the processor is configured to implement the above data processing method.
[0017] The sixth aspect of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the above data processing method.
[0018] In the above technical solution, when the connection to the target data source among multiple data sources is successfully established on the client side, the SQL request initiated by the client is received; the SQL request is parsed to obtain the description information of the target data to be written or the target data to be accessed; a custom security plugin is used to obtain the data assets matching the application side from the security management platform, where the data assets include classified data assets and sensitive data assets. The classified data assets include all the data of the application side, storage information, and the read / write permissions of each client that supports accessing the application side for each data source among multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data; the sensitive data assets include the sensitive fields of the application side and the data algorithms for each type of sensitive field, and the data algorithms include data encryption algorithms and data decryption algorithms; based on the classified data assets, it is determined whether the client has the execution permission to execute the target data for the target data source; when the client has the execution permission, based on the sensitive data assets, it is determined whether the target data contains sensitive fields; when the target data contains sensitive fields, the data algorithms for the sensitive fields are used to perform encryption operations or decryption operations on the sensitive fields; the JDBC driver is used to perform corresponding data writing or data return operations on the target data after the encryption operation or decryption operation. By automatically intercepting and perceiving the SQL request, human intervention is reduced, and appropriate encryption and decryption algorithms are configured for different scenarios, thus realizing the flexible requirements for data security control.
[0019] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification. Together with the following specific implementation, they are used to explain the embodiments of the present application, but do not constitute a limitation to the embodiments of the present application. In the accompanying drawings: Figure 1 Schematically shows a schematic diagram of the application environment of a data processing method according to an embodiment of the present application; Figure 2 Schematically shows a schematic diagram of the flow of a data processing method according to an embodiment of the present application; Figure 3 Schematically shows a schematic diagram of the process of data interaction between a custom security plugin and a security management platform according to an embodiment of the present application; Figure 4 Schematically shows a schematic diagram of the process of an application program accessing a relational database through a JDBC driver for processing interaction according to an embodiment of the present application; Figure 5 Schematically shows a schematic diagram of the flow of another data processing method according to an embodiment of the present application; Figure 6 A timing diagram schematically showing a data processing method according to an embodiment of the present application; Figure 7 An internal structure diagram of a computer device schematically showing according to an embodiment of the present application. Detailed implementation manners
[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. It should be understood that the specific implementation manners described herein are only for explaining and illustrating the embodiments of the present application, and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0022] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present application, such descriptions of "first", "second", etc. are only for descriptive purposes, and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments may be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present application.
[0023] The data processing method provided by the present application can be applied to an application environment as Figure 1 shown. Among them, as Figure 1 shown, the application end may refer to a JAVA application program, and the application end includes a custom proxy driver and multiple data sources. The data source may refer to a large database, such as Oracle, MySQL, SQL Server, PostgreSQL, etc. The custom proxy driver includes a custom security plug-in and a JDBC driver. The JDBC driver is a collection of interfaces and classes used to connect to a database in the Java language. The JDBC driver program allows Java application programs to interact with various types of databases such as Oracle, MySQL, SQL Server, and PostgreSQL. The data writing and query initiated by the client to the application program will be automatically recognized and processed through the interception of the custom proxy driver. The security plug-in obtains the data assets configured by the security management platform to verify the SQL requests initiated by the client. If the verification passes, the data corresponding to the SQL request is executed. If the verification fails, the SQL request initiated by the client is returned.
[0024] Figure 2 Schematically shown is a flowchart of a data processing method according to an embodiment of the present application. As Figure 2 shown, an embodiment of the present application provides a method for a data processing method, which can be applied to an application side. The application side includes a custom proxy driver and multiple data sources. The custom proxy driver includes a custom security plug-in and a JDBC driver. The data processing method may include the following steps: Step 201, when the client successfully connects to the target data source among the multiple data sources, receive the SQL request initiated by the client.
[0025] In the embodiment of the present application, it should be noted that the target data source may refer to various types of relational databases that can interact with Java application programs. For example, it may include relational databases such as Oracle, MySQL, SQL Server, and PostgreSQL. The database belongs to a relatively low-level application system. It is relatively troublesome for an application program to directly access the low-level application system. Therefore, for relatively low-level application systems, corresponding drivers will be provided for upper-layer application programs to use. The driver is a bridge between the application program and the underlying system. For relational database drivers, JDBC drivers are usually used. The execution process of an SQL request first requires establishing a connection. When the client wants to initiate an SQL query, the client first needs to establish a connection with the database to verify the user's identity and permissions. Therefore, in this technical solution, when the client successfully connects to the target data source among the multiple data sources, the application side receives the SQL request initiated by the client.
[0026] Step 202, parse the SQL request to obtain the description information of the target data to be written or the target data to be accessed.
[0027] In the embodiment of the present application, it should be noted that after the application side receives the SQL request initiated by the client, it can parse the SQL request. If the SQL request initiated by the client is a query request, then the application side can parse the SQL request to obtain the description information of the target data to be accessed. For example, it can be parsed to obtain the field A in the database table A in database A that needs to be queried. If the SQL request initiated by the client is a write request, then the application side can parse the SQL request to obtain the target data to be written. For example, it can be parsed to obtain the field B.
[0028] Step 203: Obtain data assets matching the application end from the security management platform through a custom security plug-in. The data assets include classified data assets and sensitive data assets. The classified data assets include all the data of the application end, storage information, and the read / write permissions of each client that supports accessing the application end for each data source among multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data. The sensitive data assets include sensitive fields of the application end and data algorithms for each type of sensitive field. The data algorithms include data encryption algorithms and data decryption algorithms.
[0029] In the embodiment of the present application, it should be noted that a security plug-in is integrated based on a custom proxy driver. In this way, the read / write operations of the application end will first be accepted by the proxy driver. When the proxy driver is loaded, it can request data assets related to the application end from the security management platform through the custom security plug-in. Specifically, as Figure 3 shown, a schematic diagram of the data interaction process between the custom security plug-in and the security management platform is provided. As Figure 3 shown, the custom security plug-in can read the business system configuration, obtain keys from the security management platform, obtain data assets of the application end from the security management platform, and cache the obtained data assets to the custom proxy driver. The security management platform stores data assets of the application end. The data assets include classified data assets and sensitive data assets. The classified data assets include all the data of the application end, storage information, and the read / write permissions of each client that supports accessing the application end for each data source among multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data. The sensitive data assets include sensitive fields of the application end and data algorithms for each type of sensitive field. The data algorithms include data encryption algorithms and data decryption algorithms. After the application end parses the SQL initiated by the client, it can obtain data assets matching the application end from the security management platform through the custom security plug-in for subsequent authentication of the client.
[0030] Step 204: Determine whether the client has the execution permission to execute the target data for the target data source based on the classified data assets.
[0031] In the embodiments of the present application, it should be noted that after the custom security plugin obtains the data assets matching the application end from the security management platform, since the classified data assets already store the read and write permissions of the client for each data source, the client can be authenticated through the classified data assets to determine whether the client has the execution permission to execute the target data for the target data source. For example, assume that the client has the query permission for data sources Oracle and MySQL, the write permission for data source SQL Server, and the query and write permissions for data source PostgreSQL. When the target data source is MySQL, if the SQL request initiated by the client is a write request, obviously, the client does not have the execution permission to execute this SQL request. If the SQL request initiated by the client is a query request, obviously, the client has the execution permission to execute this SQL request.
[0032] Step 205, when the client has the execution permission, determine whether the target data contains sensitive fields based on the sensitive data assets.
[0033] In the embodiments of the present application, it should be noted that a sensitive field is a type of sensitive data. Sensitive data may refer to data that may cause serious harm to society or individuals after leakage. Sensitive data is also called private data. Therefore, after the application end determines that the client has the execution permission to execute the target data for the target data source based on the classified data assets, it is necessary to further determine whether the target data contains sensitive fields.
[0034] In the embodiments of the present application, the data processing method further includes: when the client does not have the execution permission, return the SQL request to the client.
[0035] In this embodiment, it should be noted that after the application end determines that the client does not have the execution permission to execute the target data for the target data source based on the classified data assets, it returns the SQL request to the client. For example, assume that the client has the query permission for data sources Oracle and MySQL, the write permission for data source SQL Server, and the query and write permissions for data source PostgreSQL. When the target data source is MySQL, if the SQL request initiated by the client is a write request, obviously, the client does not have the execution permission to execute this SQL request. At this time, the application end can return the SQL request to the client.
[0036] Step 206, when the target data contains sensitive fields, perform an encryption operation or a decryption operation on the sensitive fields using the data algorithm for the sensitive fields.
[0037] In the embodiments of the present application, it should be noted that since the sensitive data assets include sensitive fields at the application end and data algorithms for each sensitive field, and the data algorithms include data encryption algorithms and data decryption algorithms. Therefore, the application end can further determine whether the target data contains sensitive fields through the sensitive data assets. If it is determined that the target data contains sensitive fields, the data algorithms for the sensitive fields can be further used to perform encryption operations or decryption operations on the sensitive fields. Specifically, after determining that the target data contains sensitive fields, the custom security plug-in extracts the key corresponding to the data algorithm of the sensitive field from the security management platform to perform encryption operations or decryption operations on the sensitive fields.
[0038] In the embodiments of the present application, the data processing method further includes: when the target data does not contain sensitive fields, performing corresponding data writing or data returning operations on the target data.
[0039] In this embodiment, it should be noted that if the application end determines that the target data does not contain sensitive fields, it can directly perform corresponding data writing or data returning operations on the target data.
[0040] Step 207, performing corresponding data writing or data returning operations on the target data after performing encryption operations or decryption operations through the JDBC driver.
[0041] In the embodiments of the present application, it should be noted that after the application end uses the data algorithm for the sensitive field to perform encryption operations or decryption operations on the sensitive field in the target data, it can perform corresponding data writing or data returning operations on the target data after performing encryption operations or decryption operations through the IDBC driver.
[0042] As Figure 4 shown, a schematic diagram of the process for an application to access a relational database for processing interactions through a JDBC driver is provided. As Figure 4 shown, the relational database can include Oracle, MySQL, SQL Server, PostgreSQL, etc. The JDBC driver can allow Java applications to interact with various types of databases such as Oracle, MySQL, SQL Server, PostgreSQL, etc. Specifically, the detailed process of using the JDBC driver of Java to access the database is as follows: (1) Loading the driver: First, the database driver needs to be loaded, which is usually completed through the Class.forName() method. For example, if the relational database used is MySQL, then "com.mysql.jdbc.Driver" can be loaded. The code implementation is Class.forName("com.mysql.jdbc.Driver"); (2) Create a connection: After loading the driver, you can use the DriverManager.getConnection() method to create a connection to the database. At this time, you need to provide the database URL, username, and password. Code implementation: Connection conn = DriverManager.getConnection("jdbc:mysql: / / localhost:3306 / mydatabase", "username", "password"); (3) Create a Statement: After having a connection, you need to create a Statement object to execute SQL statements. At this time, you can use the createStatement() method of the Connection object to create it. Code implementation: Statement stmt = conn.createStatement(); (4) Execute SQL: You can use the executeQuery() or executeUpdate() method of the Statement object to execute SQL queries or updates. Code implementation: ResultSet rs = stmt.executeQuery("SELECT * FROM mytable"); (5) Process the result: If the executed statement is a query statement, you will get a ResultSet object, and you can obtain the target data by traversing this result set.
[0043] In the embodiments of the present application, corresponding data writing or data return operations are performed on the target data after performing encryption operations or decryption operations through the JDBC driver, including: in the case of parsing the SQL request to obtain the target data to be written, writing the target data after performing the encryption operation into the target data source through the JDBC driver; in the case of parsing the SQL request to obtain the description information of the target data to be accessed, returning the target data after performing the decryption operation to the client through the JDBC driver.
[0044] In this embodiment, it should be noted that if the SQL request initiated by the client is a write request, the target data encrypted by the JDBC driver is written into the target data source. If the SQL request initiated by the client is a query request, the target data in the target data source is extracted through the JDBC driver, and after performing the decryption operation on the target data, the decrypted target data is returned to the client.
[0045] In an embodiment of the present application, the data processing method further includes: extracting data assets matching the application end from the security management platform at a first preset time interval through a custom security plugin to determine whether the data assets are updated.
[0046] In this embodiment, it should be noted that the first preset time can be set according to actual requirements, and the custom security plugin can periodically and actively pull the data assets of the application end stored in the security management platform. In this way, when the data assets of the application end are updated, the application end can actively obtain the updated data assets through the custom security plugin.
[0047] Through the above technical solution, by automatically intercepting and perceiving SQL requests, human intervention is reduced, and appropriate encryption and decryption algorithms are configured for different scenarios, thus realizing the flexible requirements for data security control.
[0048] Figure 5 Schematically shows a flowchart of another data processing method according to an embodiment of the present application. As Figure 5 shown, an embodiment of the present application provides a data processing method, which can be applied to a security management platform. The security management platform interacts with the application end. The application end includes a custom proxy driver and multiple data sources. The custom proxy driver includes a custom security plugin and a JDBC driver. The data processing method may include the following steps: Step 501, in response to receiving a classified data asset pulling request initiated by the custom security plugin, return the stored classified data assets to the custom security plugin, where the classified data assets include all data of the application end, storage information, and read / write permissions of each client supporting access to the application end for each data source among multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data; the custom proxy driver determines whether the client has the execution permission to execute the target data for the target data source based on the classified data assets; In an embodiment of the present application, it should be noted that the security management platform stores data assets of the application end, and the data assets include classified data assets and sensitive data assets. The classified data assets include all data of the application end, storage information, and read / write permissions of each client supporting access to the application end for each data source among multiple data sources. The storage information includes the storage relationship between each data and the data source storing the each data. The sensitive data assets include sensitive fields of the application end and data algorithms for each type of sensitive field. The data algorithms include data encryption algorithms and data decryption algorithms. Among them, all data may refer to all business data that the application end needs to process.
[0049] When the client successfully connects to the target data source among multiple data sources, the application end receives the SQL request initiated by the client and parses the SQL request. If the SQL request initiated by the client is a query request, the application end can obtain the description information of the target data to be accessed after parsing the SQL request. If the SQL request initiated by the client is a write request, the application end can obtain the target data to be written after parsing the SQL request. After parsing the SQL initiated by the client, the application end can obtain the data assets matching the application end from the security management platform through a custom security plug-in for subsequent authentication of the client. Specifically, the custom security plug-in can first initiate a data asset pull request to the security management platform or only initiate a classified data asset pull request to the security management platform. In response to receiving the classified data asset pull request initiated by the custom security plug-in, the security management platform returns the stored classified data assets to the custom security plug-in. The custom proxy driver determines the read and write permissions of the client based on the classified data assets pulled by the custom security plug-in to determine whether the client has the execution permission to execute the target data for the target data source. For example, assume that the client has query permissions for data sources Oracle and MySQL, write permissions for data source SQL Server, and query and write permissions for data source PostgreSQL. When the target data source is MySQL, if the SQL request initiated by the client is a write request, obviously, the client does not have the execution permission to execute this SQL request. If the SQL request initiated by the client is a query request, obviously, the client has the execution permission to execute this SQL request.
[0050] In the embodiment of the present application, the data processing method further includes: when successfully connected to the application end, allocating an application identifier to the application end; obtaining all the data, storage information of the application end, and the read and write permissions of each client that supports accessing the application end for each data source among multiple data sources to generate classified data assets for the application end; determining multiple sensitive fields included in all the data, defining data algorithms corresponding to each of the multiple sensitive fields and keys corresponding to each data algorithm; and generating sensitive data assets for the application end according to the multiple sensitive fields and the data algorithms corresponding to each sensitive field.
[0051] In this embodiment, it should be noted that to automatically identify sensitive data, it is first necessary to classify and grade the data, set different encryption and decryption methods for different sensitive types, and then label the tags of sensitive information on the fields of the corresponding database tables. After setting, the sensitive data assets of the entire application program will be formed. To achieve this, a platform is required to provide functional support and the precipitation of sensitive data assets. Therefore, this technical solution develops a security management platform to implement, and the platform provides functions such as metadata management, data classification and grading, data standards, desensitization and encryption configuration, sensitive data identification, and unified key management. As Figure 3 shown, for each application end, the security management platform can define data classification and grading, define processing methods for sensitive types, extract business system table information, label the business system tables, and form sensitive data policy assets.
[0052] In this technical solution, according to requirements, the data security level and the sensitive types of the data can be defined first, and the corresponding encryption and decryption methods can be configured for different sensitive types. Then, the metadata information of the database tables of the application program can be extracted and marked with sensitive types, and the sensitive data assets of the management platform are formed, and then provided to the security plug-in driven by the proxy for calling in the form of an interface. At the same time, the management platform also uniformly manages the keys, ensuring that the keys and data are stored separately, with a higher security level. Specifically, when the security management platform is successfully connected to the application end, it can assign an application identifier to the application end. In this way, all subsequent accesses and data assets of the application end will be marked with the corresponding application representation. The security management platform can obtain all the data, storage information of the application end, and the read and write permissions of each client that supports accessing the application end for each data source in multiple data sources to generate classified data assets for the application end. At the same time, determine multiple sensitive fields included in all the data, define data algorithms corresponding to each sensitive field in the multiple sensitive fields and keys corresponding to each data algorithm, and generate sensitive data assets for the application end according to the multiple sensitive fields and the data algorithms corresponding to each sensitive field.
[0053] In the embodiment of this application, the data processing method further includes: obtaining all the data of the application end based on a second preset time interval to determine whether all the data has been updated and whether the sensitive fields included in all the data have been updated, where the update includes at least one of addition, modification, or deletion; in the case of determining that all the data has been updated, obtaining the updated data and the data source corresponding to the updated data to update the classified data assets; in the case of determining that the sensitive fields included in all the data have been updated, obtaining the updated fields, defining a data algorithm corresponding to the updated fields and a key corresponding to the data algorithm to update the sensitive data assets.
[0054] In this embodiment, it should be noted that the second preset time interval can be set according to actual requirements. In this way, the security management platform can regularly extract all the data of the application side to determine whether all the data is updated and whether there are updates to the sensitive fields included in all the data, where the update can include addition, modification, or deletion. If there are updates to all the extracted data, the updated data and the data source information where the updated data is located are further obtained to update the classified data assets. If there are no updates to all the extracted data, there is no need to update the data assets of the application side. If there are updates to the sensitive fields included in all the extracted data, the updated fields are further obtained, and a data algorithm corresponding to the updated fields and a secret key corresponding to the data algorithm are defined to update the sensitive data assets.
[0055] In the embodiment of the present application, the data processing method further includes: after generating the sensitive data assets for the application side, obtaining the database and data table where each sensitive field is located in the corresponding data source to perform sensitive type marking on the database and data table.
[0056] In this embodiment, it should be noted that after the security management platform generates the sensitive data assets for the application side, it is necessary to further obtain the database and data table information where each sensitive field is located in the corresponding data source to perform sensitive type marking on the database and data table.
[0057] Step 502, in response to receiving a sensitive asset pulling request initiated by a custom security plugin, return the sensitive data assets to the custom security plugin, where the sensitive data assets include the sensitive fields of the application side and the data algorithms for each sensitive field, and the data algorithms include a data encryption algorithm and a data decryption algorithm; In the embodiments of the present application, it should be noted that a sensitive field is a type of sensitive data, and sensitive data may refer to data that may cause serious harm to society or individuals after leakage. Sensitive data is also known as privacy data. Therefore, after the application end determines that the client has the execution permission for the target data based on the classified data assets, it is necessary to further determine the sensitive sub-fields of the target data. Therefore, the application end can initiate a request to pull sensitive data assets to the security management platform through a custom security plug-in. In response to receiving the request to pull sensitive data assets initiated by the custom security plug-in, the security management platform returns the stored sensitive data assets to the custom security plug-in. It should be noted that if the custom security plug-in has pulled the data assets of the application end when pulling the classified data assets, then there is no need to initiate a request for sensitive data assets to the security management platform at this time, and the sensitive data assets in the data assets can be directly used. After the custom security plug-in extracts the sensitive data assets from the security management platform, the custom proxy driver can further determine whether the target data contains sensitive fields through the sensitive data assets. If the target data contains sensitive fields, the data algorithm for the sensitive fields can be further used to encrypt or decrypt the sensitive fields. If the target data does not contain sensitive fields, there is no need to encrypt or decrypt the target data.
[0058] Step 503: In response to receiving the key request initiated by the custom security plug-in, return the required key to the custom security plug-in, where the key request is generated according to the data algorithm corresponding to the sensitive field after the custom proxy driver determines that the target data contains sensitive fields based on the sensitive data assets under the condition that the client has the execution permission.
[0059] In the embodiments of the present application, it should be noted that if the custom proxy driver determines through the sensitive data assets that the target data contains sensitive fields, it is necessary to further use the data algorithm for the sensitive fields to encrypt or decrypt the sensitive fields. And the execution of encryption or decryption operations requires corresponding keys. Therefore, the application end needs to initiate a key request to the security management platform through the custom security plug-in. In response to receiving the key request initiated by the custom security plug-in, the security management platform returns the required key to the custom security plug-in, where the key request is generated according to the data algorithm corresponding to the sensitive field after the custom proxy driver determines that the target data contains sensitive fields based on the sensitive data assets under the condition that the client has the execution permission. After the custom security plug-in extracts the required key from the security management platform, the custom proxy driver can use the data algorithm and key for the sensitive fields to encrypt or decrypt the sensitive fields.
[0060] As Figure 6 shown, a timing diagram of a data processing method is provided.
[0061] In an embodiment of the present application, when the client successfully connects to the target data source among multiple data sources, the application end receives the SQL request initiated by the client and parses the SQL request. If the SQL request initiated by the client is a query request, the application end can obtain the description information of the target data to be accessed by parsing the SQL request. If the SQL request initiated by the client is a write request, the application end can obtain the target data to be written by parsing the SQL request. After parsing the SQL initiated by the client, the application end can initiate a data asset pulling request to the security management platform through a custom security plugin. In response to receiving the data asset pulling request initiated by the custom security plugin, the security management platform returns the stored data assets to the custom security plugin.
[0062] The custom proxy driver authenticates the read and write permissions of the client based on the classified data assets pulled by the custom security plugin to determine whether the client has the execution permission to execute the target data for the target data source. If the client does not have the execution permission to execute the target data for the target data source, the application end returns the SQL request to the client. If the client has the execution permission to execute the target data for the target data source, the custom proxy driver further determines whether the target data contains sensitive fields based on the sensitive data assets. If it is determined that the target data does not contain sensitive fields, there is no need to perform encryption or decryption operations on the target data, and the corresponding data write operation or data return operation is performed on the target data through the JDBC driver. If it is determined that the target data contains sensitive fields, a key request is initiated to the security management platform through the custom security plugin, and in response to the key request, the security management platform returns the required key to the custom security plugin.
[0063] The custom proxy driver performs corresponding encryption or decryption operations on the sensitive fields in the target data according to the corresponding data algorithm and key, and then performs the corresponding data write operation or data return operation on the encrypted or decrypted target data through the JDBC driver. If the SQL request is a query request, the target data in the target data source is extracted through the JDBC, and the custom proxy driver performs the corresponding decryption operation on the sensitive fields in the target data according to the corresponding data algorithm and key to return the decrypted target data to the client. If the SQL request is a write request, the custom proxy driver performs the corresponding encryption operation on the sensitive fields in the target data according to the corresponding data algorithm and key, and writes the encrypted target data to the target data source through the JDBC driver.
[0064] This technical solution adopts innovative process design and technological innovation to achieve the goal of data security control based on JDBC proxy drive and security plug-ins. By maintaining the metadata of the application through the security management platform, classifying and grading data based on standards, tagging the data at the application end, and forming sensitive data assets and classified data assets at the application end. Then, a security plug-in is provided and integrated into the application to regularly pull the data assets on the platform. Through the automatic interception and perception function of the program, human intervention is reduced, and the end-to-end data processing strategy is automatically synchronized and processed, realizing the flexible requirements for data security control.
[0065] In the embodiments of this application, it should be noted that embodied intelligence refers to the ability of an intelligent agent to learn and complete tasks through interaction with the physical environment, emphasizing the perception and action of the body in the environment. In an embodied intelligence system, it is usually necessary to process complex sensor data (such as vision, touch, sound, etc.), and make decisions in real time or in resource-constrained environments. Embodied intelligence emphasizes the interaction of the intelligent agent with the environment through physical entities (such as robots, autonomous vehicles, intelligent devices, etc.), and this process requires a large amount of data support. For example, when an intelligent robot perceives the environment and executes tasks, it will continuously collect multi-modal data such as vision, touch, and hearing, and analyze, make decisions and act based on these data to adapt to the complex and changing real environment. Therefore, the development and application of embodied intelligence involve the collection, processing and transmission of a large amount of data, which naturally involves the issues of data security transmission and sensitive data. Specifically, the embodied intelligence system faces the following challenges and requirements in data security transmission: ① Data collection and processing: The embodied intelligence system will collect a large amount of environmental data and multi-modal data during operation. The processing and analysis of these data need to ensure that they are not tampered with or leaked during transmission to ensure the accuracy and reliability of the system.
[0066] ② Security of data transmission: Since the embodied intelligence system usually needs to exchange data with the cloud or other intelligent devices in real time or near real time, the security of the data transmission process is crucial. Any data leakage or tampering may lead to incorrect system decisions or abnormal behaviors, and may even pose risks in the physical world.
[0067] ③ Security of hardware and software: The hardware facilities, software, algorithm models and data systems of the embodied intelligence system may all become potential sources of security risks. Malicious attackers may use the vulnerabilities of various algorithms, hardware, software, and protocols to launch attacks on the embodied intelligence system, endangering user privacy security and even causing substantial harm in the physical world.
[0068] It can be seen that ensuring the security of sensitive data assets during data transmission is crucial for the development and application of embodied intelligence. Therefore, in the actual application process, data authentication, sensitive data assets, and embodied intelligence can be combined to find a balance between efficient intelligent interaction and strict data security. For example, through technologies such as encryption, federated learning, edge computing, and zero-trust architecture, combined with physical-digital fusion protection means, a secure and controllable embodied intelligence system can be achieved. Specifically, for example, end-to-end encryption can be set. When the embodied intelligence device collects data, a lightweight encryption algorithm is used to encrypt sensitive data in real time to ensure transmission and storage security. For example, data masking can be set, and sensitive fields (such as ID numbers and face information) are masked or replaced, leaving only necessary features for the agent to make decisions. Taking a medical robot as an example, patient health data (such as medical records and images) can be encrypted and stored locally, and only authorized doctors can access it through biometric authentication (authentication). Taking an industrial robot as an example, the process parameters and quality inspection data of the production line are encrypted by a security chip to prevent theft, and dynamic access control is set to only allow specific engineers to access the device logs during the maintenance period.
[0069] An embodiment of the present application provides an application end, including: A memory configured to store instructions; A processor configured to call instructions from the memory and capable of implementing the above data processing method when executing the instructions.
[0070] An embodiment of the present application provides a security management platform, including: A memory configured to store instructions; A processor configured to call the instructions from the memory and capable of implementing the above data processing method when executing the instructions.
[0071] An embodiment of the present application provides a machine-readable storage medium, on which instructions are stored, and when the instructions are executed by a processor, the processor is configured to implement the above data processing method.
[0072] An embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the above data processing method.
[0073] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 7As shown in the figure. The computer device includes a processor A01, a network interface A02, a memory (not shown in the figure), and a database (not shown in the figure) connected through a system bus. Among them, the processor A01 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes an internal memory A03 and a non-volatile storage medium A04. The non-volatile storage medium A04 stores an operating system B01, a computer program B02, and a database (not shown in the figure). The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A04. The database of the computer device is used to store data processing method data. The network interface A02 of the computer device is used to communicate with an external terminal through a network connection. When the computer program B02 is executed by the processor A01, it realizes a data processing method.
[0074] Those skilled in the art can understand that Figure 7 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0075] The embodiment of the present application provides a device, which includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it realizes the steps of the data processing method.
[0076] The present application also provides a computer program product, which is suitable for executing a program for initializing the steps of the data processing method when executed on a data processing device.
[0077] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0078] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0079] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0080] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0081] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0082] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0083] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0084] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0085] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A data processing method, characterized in that: Applied to an application end, the application end includes a custom proxy driver and multiple data sources, the custom proxy driver includes a custom security plug-in and a JDBC driver, and the data processing method includes: When the client successfully connects to a target data source among multiple data sources, receiving a SQL request initiated by the client; Parsing the SQL request to obtain description information of the target data to be written or the target data to be accessed; Acquire data assets matching the application end from the security management platform through the custom security plug-in, wherein the data assets include classified data assets and sensitive data assets, the classified data assets include all data of the application end, storage information, and read and write permissions of each client supporting access to the application end for each of the multiple data sources, the storage information includes the storage relationship between each data and the data source storing the data; the sensitive data assets include sensitive fields of the application end and data algorithms for each sensitive field, and the data algorithms include data encryption algorithms and data decryption algorithms; determining, based on the classified data assets, whether the client has execution authority to execute target data on the target data source; In a case where the client has the execution permission, determining whether the target data contains a sensitive field based on the sensitive data asset; In the case where the target data includes a sensitive field, performing an encryption operation or a decryption operation on the sensitive field using a data algorithm for the sensitive field; The JDBC driver performs corresponding data writing or data returning operations on the target data after the encryption or decryption operations are performed.
2. The data processing method according to claim 1, characterized in that: The data processing method further includes: In the case that the client does not have the execution authority, the SQL request is returned to the client.
3. The data processing method according to claim 1, characterized in that: The data processing method further includes: In a case where the target data does not include a sensitive field, a corresponding data writing or data returning operation is performed on the target data.
4. The data processing method according to claim 1, characterized in that: The performing corresponding data writing or data returning operation on the target data after the encryption operation or decryption operation is performed by the JDBC driver, including: When the target data to be written is obtained by parsing the SQL request, the target data after the encryption operation is performed is written into the target data source through the JDBC driver; When the description information of the target data to be accessed is obtained by parsing the SQL request, the target data after the decryption operation is performed is returned to the client through the JDBC driver.
5. The data processing method according to claim 1, characterized in that: The data processing method further includes: The custom security plug-in extracts data assets matching the application end from the security management platform based on a first preset time interval to determine whether the data assets are updated.
6. A data processing method, characterized in that: Applied to a security management platform, the security management platform interacts with an application end, the application end includes a custom proxy driver and multiple data sources, the custom proxy driver includes a custom security plug-in and a JDBC driver, and the data processing method includes: In response to receiving a classification data asset pull request initiated by the custom security plug-in, the stored classification data asset is returned to the custom security plug-in, wherein the classification data asset includes all data of the application end, storage information, and read and write permissions of each client supporting access to the application end for each of the multiple data sources, and the storage information includes the storage relationship between each data and the data source storing the data; the custom proxy driver determines whether the client has the execution permission to execute the target data for the target data source based on the classification data asset; In response to receiving a sensitive asset pull request initiated by the custom security plug-in, returning sensitive data assets to the custom security plug-in, wherein the sensitive data assets include sensitive fields of the application end and data algorithms for each sensitive field, and the data algorithms include data encryption algorithms and data decryption algorithms; In response to receiving a key request initiated by the custom security plug-in, the required key is returned to the custom security plug-in, wherein the key request is generated by the custom proxy driver according to the data algorithm corresponding to the sensitive field after determining that the target data contains sensitive fields based on the sensitive data assets when determining that the client has the execution permission.
7. The data processing method according to claim 6, characterized in that: The data processing method further includes: When the connection with the application end is successful, an application identifier is allocated to the application end; Acquire all data and storage information of the application end and the read and write permissions of each client supporting access to the application end for each of the multiple data sources, so as to generate classified data assets for the application end; Determine multiple sensitive fields included in all the data, and define a data algorithm corresponding to each of the multiple sensitive fields and a key corresponding to each data algorithm; Sensitive data assets for the application end are generated according to the multiple sensitive fields and the data algorithm corresponding to each sensitive field.
8. The data processing method according to claim 7, characterized in that: The data processing method further includes: Acquire all data of the application end based on a second preset time interval to determine whether all the data are updated and whether sensitive fields included in all the data are updated, wherein the update includes at least one of addition, modification or deletion; When it is determined that all the data are updated, acquiring the updated data and the data source corresponding to the updated data to update the classified data asset; When it is determined that there is an update to the sensitive field included in all the data, the updated field is obtained, and a data algorithm corresponding to the updated field and a key corresponding to the data algorithm are defined to update the sensitive data asset.
9. The data processing method according to claim 7, characterized in that: The data processing method further includes: After generating the sensitive data assets for the application end, the database and data table where each sensitive field is located in the corresponding data source are obtained to mark the database and the data table as sensitive types.
10. An application terminal, characterized in that: include: a memory configured to store instructions; A processor is configured to call the instructions from the memory and implement the data processing method according to any one of claims 1 to 5 when executing the instructions.
11. A security management platform, characterized in that: include: a memory configured to store instructions; A processor is configured to call the instructions from the memory and implement the data processing method according to any one of claims 6 to 9 when executing the instructions.
12. A machine-readable storage medium having instructions stored thereon, characterized in that: When the instruction is executed by a processor, the processor is configured to execute the data processing method according to any one of claims 1 to 5 or configured to execute the data processing method according to any one of claims 6 to 9.
13. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the data processing method according to any one of claims 1 to 5 or is configured to execute the data processing method according to any one of claims 6 to 9.
Citation Information
Patent Citations
Data access control method and device
CN111460506A
Key management method and device, electronic equipment and storage medium
CN112988888A
Business data processing method and device, equipment and storage medium
CN117332434A
Data security architecture method based on native PDR model
CN117667970A
Method for intercepting and rewriting SQL (Structured Query Language) statement
CN117763614A