Method for executing security policy by SQL engine and SQL engine

By obtaining different types of security policies in the SQL engine to configure the corresponding software sources, the problem that SQL engine must rely on the data security policies provided by a certain software in the existing technology is solved, and a more flexible data security system and a higher user experience is achieved.

CN120162341APending Publication Date: 2025-06-17HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410095005.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-01-23
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In the prior art, when using data security policies, SQL engines must rely on a certain software (for example, Apache Ranger), which leads to a relatively rigid data security system and reduces the user experience.

Method used

Provides a method for SQL engines to execute security policies. By obtaining different types of security policies to configure their respective software sources, the SQL engine allows SQL engines to flexibly use data security policies provided by different software to avoid strong binding relationships with one software.

Benefits of technology

This makes the data security system more flexible, improves the user experience, and ensures the security and privacy of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162341A_ABST
    Figure CN120162341A_ABST
Patent Text Reader

Abstract

The invention provides a method for executing a security policy by an SQL (Structured Query Language) engine, the method is applied to a database system, the database system comprises a database and at least one SQL engine, the at least one SQL engine is used for obtaining data stored in the database according to an SQL statement, and the method comprises the following steps: the SQL engine obtains first configuration information, the first configuration information is used for indicating different types of security policies executed on the SQL engine to configure at least one software source respectively corresponding to the different types of security policies, and the at least one software source respectively corresponding to the different types of security policies is not completely the same; according to the first configuration information, the SQL engine protects the security and / or privacy of the data stored in the database by executing corresponding security policies provided by different software sources indicated in the first configuration information. According to the method, a data security system can be relatively flexible, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application with the application number 202311733024.3, titled "Method for Using SQL Engine, Computing Device", filed with the China National Intellectual Property Administration on December 15, 2023, the entire content of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of databases, and more particularly, to a method for a Structured Query Language (SQL) engine to execute security policies, an SQL engine, and a computing device. Background Art

[0003] Currently, for enterprise-level applications, ensuring data security and privacy is of utmost importance. The engine in a database system (e.g., an SQL engine), as the underlying computing engine of the data stack, must ensure that data can only be accessed by authorized personnel to avoid data leakage and abuse. Specifically, by configuring data security policies for the SQL engine, the SQL engine can protect the security and privacy of data according to the configured data security policies.

[0004] In related technical solutions, for an SQL engine, if the SQL engine uses a certain software that provides data security policies (e.g., Apache Ranger), then multiple data security policies configured on the SQL engine must rely on this software (e.g., Apache Ranger). This makes the current data security system rather rigid and reduces the user experience.

[0005] In view of this, how to make the data security system more flexible to improve the user experience has become an urgent technical problem to be solved. Summary of the Invention

[0006] This application provides a method for an SQL engine to execute security policies, which can make the data security system more flexible and improve the user experience.

[0007] In a first aspect, a method for a SQL engine to execute security policies is provided. This method is applied to a database system, which includes a database and at least one SQL engine. The at least one SQL engine is used to obtain the data stored in the database according to SQL statements. The method includes: each of the SQL engines separately obtains first configuration information, which is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, and the at least one software source corresponding to each of the different types of security policies is not completely the same; each of the SQL engines protects the security and / or privacy of the data stored in the database by executing the corresponding security policies provided by the different software sources indicated in the first configuration information.

[0008] In the above technical solution, the SQL engine can flexibly use the data security policies provided by different software, avoid the strong binding relationship between all types of data security policies on the SQL engine and one software, make the data security system more flexible, and improve the user experience.

[0009] In combination with the first aspect, in some implementation manners of the first aspect, each of the SQL engines obtains the first configuration information through at least one of the following: the interface of each of the SQL engines, a configuration file, or a visual configuration interface.

[0010] In combination with the first aspect, in some implementation manners of the first aspect, the different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include a first software and a second software. Each of the SQL engines determines that the SQL engine passes the security check of the first type of security policy when passing the verification of the first type of security policy provided by the first software and the second software respectively.

[0011] In the above technical solution, multiple security protections can take effect simultaneously, so as to better protect the security and / or privacy of the data.

[0012] In combination with the first aspect, in some implementation manners of the first aspect, the method further includes: each of the SQL engines separately obtains second configuration information, which is used to configure the SQL engine to execute some or all of the different types of security policies; each of the SQL engines separately executes some or all of the different types of security policies according to the received second configuration information.

[0013] In the above technical solution, the SQL engine can flexibly use some or all of multiple types of security policies, make the data security system more flexible, and improve the user experience.

[0014] In combination with the first aspect, in some implementations of the first aspect, the different types of security policies include at least two of the following: security policies for data access permission control, security policies for data desensitization, and security policies for data row-level filtering.

[0015] In combination with the first aspect, in some implementations of the first aspect, the software sources include: Ranger, Hive Meta Store (HMS), and Hive Access Control List (ACL).

[0016] In combination with the first aspect, in some implementations of the first aspect, the method is applied to a cloud management platform, which is used to manage the infrastructure that provides cloud services. The infrastructure includes at least one cloud data center, and each cloud data center is provided with at least one server, and the SQL engine runs on the at least one server.

[0017] In a second aspect, a SQL engine is provided. The SQL engine is located in a database system, and the database system also includes a database. The SQL engine is used to obtain the data stored in the database according to an SQL statement. The SQL engine includes: an acquisition module and a processing module. Among them, the acquisition module is used to obtain first configuration information, and the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine. The at least one software source corresponding to each of the different types of security policies is not completely the same; the processing module is used to protect the security and / or privacy of the data stored in the database by executing the corresponding security policies provided by the different software sources indicated in the first configuration information according to the first configuration information.

[0018] In combination with the second aspect, in some implementations of the second aspect, the acquisition module is specifically used to obtain the first configuration information in at least one of the following ways: the interface of the SQL engine, a configuration file, or a visual configuration interface.

[0019] In combination with the second aspect, in some implementations of the second aspect, the different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include a first software and a second software. The processing module is specifically used to: when passing the verification of the first type of security policies provided by the first software and the second software respectively, determine that the SQL engine passes the security verification of the first type of security policy.

[0020] In combination with the second aspect, in some implementations of the second aspect, the obtaining module is further configured to obtain second configuration information for configuring the SQL engine to execute some or all of the security policies of different types; the processing module is further configured to execute some or all of the security policies of different types according to the second configuration information.

[0021] In combination with the second aspect, in some implementations of the second aspect, the different types of security policies include at least two of the following: security policies for data access permission control, security policies for data masking, and security policies for data row-level filtering.

[0022] In combination with the second aspect, in some implementations of the second aspect, the software sources include: Apache Ranger, Hive Metadata Store HMS, and Hive Access Control List ACL.

[0023] In combination with the second aspect, in some implementations of the second aspect, the SQL engine runs in at least one server, the at least one server is located in at least one cloud data center, and the at least one server is an infrastructure for providing cloud services managed by a cloud management platform.

[0024] It should be understood that for the beneficial effects in the second aspect and various implementations of the second aspect, please refer to the beneficial effects in the first aspect and various implementations of the first aspect, which will not be elaborated here.

[0025] In a third aspect, a database system is provided, which includes a database and at least one SQL engine provided as in the second aspect and any one of the implementations of the second aspect. The at least one SQL engine is configured to obtain the data stored in the database according to an SQL statement.

[0026] In a fourth aspect, a computing device is provided, which includes a processor and a memory. Optionally, an input / output interface is further included. The processor is configured to control the input / output interface to send and receive information, the memory is configured to store a computer program, and the processor is configured to call and run the computer program from the memory, so as to execute the method in the first aspect or any possible implementation of the first aspect.

[0027] Optionally, the processor may be a general-purpose processor, which can be implemented by hardware or by software. When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor may be a general-purpose processor, which is implemented by reading the software code stored in the memory. The memory may be integrated in the processor or may exist independently outside the processor.

[0028] In a fifth aspect, a computing device cluster is provided, including at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method in the first aspect or any possible implementation manner of the first aspect.

[0029] In a sixth aspect, a chip is provided, and the chip obtains and executes instructions to implement the method in the above-mentioned first aspect and any implementation manner of the first aspect.

[0030] Optionally, as an implementation manner, the chip includes a processor and a data interface, and the processor reads instructions stored on a memory through the data interface and executes the method in the above-mentioned first aspect and any implementation manner of the first aspect.

[0031] Optionally, as an implementation manner, the chip may further include a memory, and instructions are stored in the memory. The processor is configured to execute the instructions stored on the memory, and when the instructions are executed, the processor is configured to execute the method in the first aspect and any implementation manner of the first aspect.

[0032] In a seventh aspect, a computer program product including instructions is provided. When the instructions are run on a computing device, the computing device is caused to execute the method in the above-mentioned first aspect and any implementation manner of the first aspect.

[0033] In an eighth aspect, a computer program product including instructions is provided. When the instructions are run on a computing device cluster, the computing device cluster is caused to execute the method in the above-mentioned first aspect and any implementation manner of the first aspect.

[0034] In a ninth aspect, a computer-readable storage medium is provided, including computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method in the above-mentioned first aspect and any implementation manner of the first aspect.

[0035] As an example, these computer-readable storages include, but are not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM), and hard drive.

[0036] Optionally, as an implementation manner, the above storage medium may specifically be a non-volatile storage medium.

[0037] In a tenth aspect, a computer-readable storage medium is provided, including computer program instructions. When the computer program instructions are executed by a cluster of computing devices, the cluster of computing devices executes the methods in the first aspect and any implementation manner of the first aspect as described above.

[0038] As an example, these computer-readable storages include, but are not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM), and hard drive.

[0039] Optionally, as an implementation manner, the above storage medium may specifically be a non-volatile storage medium. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 is a schematic block diagram of a cloud scenario applicable to an embodiment of the present application.

[0041] Figure 2 is a schematic flowchart of a method for a SQL engine to execute a security policy provided by an embodiment of the present application.

[0042] Figure 3 is the correspondence between multiple data security policies of a SQL engine and the sources of the security policies provided by an embodiment of the present application.

[0043] Figure 4 is a schematic block diagram of the software sources corresponding to different categories of data security policies configured for a SQL engine provided by an embodiment of the present application.

[0044] Figure 5 is a schematic flowchart of a process for a SQL engine to execute a security policy provided by an embodiment of the present application.

[0045] Figure 6 is a schematic block diagram of a SQL engine 600 provided by an embodiment of the present application.

[0046] Figure 7 is a schematic block diagram of a database system 700 provided by an embodiment of the present application.

[0047] Figure 8 is a schematic architecture diagram of a computing device 1500 provided by an embodiment of the present application.

[0048] Figure 9It is a schematic diagram of the architecture of a computing device cluster provided by an embodiment of the present application.

[0049] Figure 10 It is a schematic diagram showing the connection between computing devices 1500A and 1500B via a network provided by an embodiment of the present application. Detailed implementation manners

[0050] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.

[0051] The present application will present various aspects, embodiments or features around a system including multiple devices, components, modules, etc. It should be understood and clear that each system may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. In addition, combinations of these solutions can also be used.

[0052] In addition, in the embodiments of the present application, words such as "exemplary" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "exemplary" is intended to present concepts in a specific manner.

[0053] In the embodiments of the present application, "corresponding" and "corresponding" can sometimes be used interchangeably. It should be noted that when not emphasizing their differences, the meanings they convey are the same.

[0054] The business scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art can know that with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0055] The reference to "one embodiment" or "some embodiments" etc. described in this specification means that specific features, structures or characteristics described in conjunction with the embodiment are included in one or more embodiments of the present application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments" etc. appearing in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0056] In this application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the relationship between related objects and indicates that three relationships can exist. For example, A and / or B can mean: including the case where A exists alone, the case where A and B exist simultaneously, and the case where B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. "At least one (item)" or similar expressions refer to any combination of these items, including any combination of single item(s) or plural item(s). For example, at least one (item) of a, b, or c can mean: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0057] For ease of description, the concepts involved in the embodiments of this application will be explained below.

[0058] 1. Structured Query Language (SQL) engine

[0059] The SQL engine is a software component used to process SQL queries and is one of the core components of a database management system (DBMS).

[0060] The main functions of the SQL engine are introduced below.

[0061] 1) Parse the SQL statement: Convert the SQL statement into an internal representation, i.e., a parse tree.

[0062] 2) Optimize the query plan: Optimize the parse tree to generate an efficient query execution plan.

[0063] 3) Execute the query plan: Execute the query according to the query plan and retrieve the results from the data stored in the database.

[0064] 4) Return the result: Return the query result to the client application.

[0065] Several common SQL engines are listed below.

[0066] 1) The Hive engine is a data warehouse tool based on Hadoop used for data extraction, transformation, and loading, which is a mechanism for storing, querying, and analyzing large-scale data stored in Hadoop.

[0067] 2) The Spark engine is a fast and general-purpose computing engine designed specifically for large-scale data processing.

[0068] 3) The Presto engine is an open-source distributed SQL query engine launched by Facebook. It can support data scales from GB to PB and is mainly applied to scenarios with second-level queries.

[0069] 4) The Trino engine is an analysis engine designed for OLAP for efficient distributed query of large amounts of data. The Trino engine and the Presto engine belong to two branches of the same open-source ecosystem.

[0070] 2. Data security

[0071] Data security is used to protect the security and privacy of the data stored in the database, avoiding data leakage and / or data abuse, etc. Specifically, data security can be divided into data security at the engine layer and data security at the storage layer.

[0072] Data security at the engine layer mainly protects the security and privacy of the data stored in the database through the SQL engine executing data security policies.

[0073] The following introduces several common data security policies.

[0074] 1) Security policies of data access permission control

[0075] Security policies of data access permission control define the permissions for data access. The dimensions of this definition are generally: data source / database / table / column (from large to small).

[0076] 2) Security policies of data masking

[0077] Security policies of data masking generally define corresponding data masking policies (which can be implemented by specific functions) for a specific user to access specific columns of a specific table, so as to achieve different people seeing different contents of the same data and making sensitive data invisible to low-privilege users.

[0078] It should be understood that data desensitization is a technical means to protect personal privacy. Its main purpose is to keep sensitive information confidential while ensuring the usability and effectiveness of data, so as to avoid the security risks brought by data leakage. Through data desensitization, partial information of sensitive data can be hidden or changed, thereby reducing the risk of data leakage and protecting personal privacy and data security. The implementation of data desensitization needs to follow two principles: one is to retain meaningful information for the desensitized application as much as possible; the other is to prevent hackers from cracking to the greatest extent. Data desensitization can be divided into static data desensitization and dynamic data desensitization. Static data desensitization means that after desensitizing the sensitive information in the original data, it is provided to relevant personnel for use. This can ensure that sensitive information will not be leaked when using the data. Dynamic data desensitization is to perform real-time desensitization processing on sensitive information during data transmission to ensure that sensitive information will not be obtained by unauthorized personnel during the transmission process.

[0079] 3) Security policies of the data row-level filtering (row level filter) type

[0080] Security policies of the data row-level filtering type refer to screening each row of data during data processing and only retaining the data rows that meet specific conditions, thereby controlling users to only access specific data rows of the data table.

[0081] 3. Software providing data security policies

[0082] Software providing data security policies can also be called the source of data security policies. It is used to provide the above-mentioned data security policies to the SQL engine. The types of data security policies provided by different software can be the same or different.

[0083] The following introduces several common software providing data security policies.

[0084] 1) Apache Ranger

[0085] Apache Ranger can also be simply referred to as Ranger. Apache Ranger is an open-source component related to Hadoop security, and it provides a very comprehensive data security management framework.

[0086] The functions related to Apache Ranger security are very rich, and the control strength is finer. Specifically, Apache Ranger provides the following three types of different data security policies for the SQL engine: security policies of the data access permission control type, security policies of the data desensitization type, and security policies of the data row-level filtering type.

[0087] 2) Hive Metadata Warehouse (Hive metastore, HMS)

[0088] The Hive metadata warehouse is the place where metadata in Hive is stored. Hive is a data warehouse tool based on Hadoop that can map structured data files into a database table and provide SQL-like query functions. The metadata of Hive includes descriptions of information such as tables, databases, partitions, and buckets, and this information is stored in the metastore database.

[0089] In Hive, the metadata is stored in a relational database management system (RDBMS), such as MySQL, Derby, etc. Hive natively uses Derby to store metadata, and the metadata service is provided by MetaStore, which is responsible for managing client access to the metadata. The Hive metadata warehouse can be stored on the Hadoop Distributed File System (HDFS) and associated with the data and metadata in the data warehouse.

[0090] In Hive, the management of metadata is relatively independent of the management of data and can be accessed and operated through the metadata service. Through the Hive metadata warehouse, it is convenient to manage and maintain metadata information such as tables, databases, partitions, and buckets in Hive, ensuring data integrity and consistency.

[0091] 3) Hive Access Permission List (ACL)

[0092] Currently, for enterprise-level applications, ensuring data security and privacy is extremely important. The engine in the database system (e.g., the SQL engine), as the underlying computing engine of the data stack, must ensure that data can only be accessed by authorized personnel to avoid data leakage and abuse. Specifically, by configuring data security policies for the SQL engine, the SQL engine can protect the security and privacy of data according to the configured data security policies.

[0093] In related technical solutions, for an SQL engine, if the SQL engine uses a software that provides data security policies (for example, Apache Ranger), then multiple data security policies configured on the SQL engine must rely on this software (for example, Apache Ranger). That is, if the security policy for data access permission control used by the SQL engine is provided by Apache Ranger, then other security policies, such as data masking security policies and data row-level filtering security policies, also need to be provided by Apache Ranger. This results in a strong binding between the security policies in the SQL engine and a certain software (the software that provides data security policies), making the current data security system relatively rigid. The SQL engine cannot flexibly use data security policies provided by different software, reducing the user experience.

[0094] In view of this, an embodiment of the present application provides a method for an SQL engine to execute security policies. This method enables the SQL engine to flexibly use data security policies provided by different software, avoids the strong binding relationship between all types of data security policies on the SQL engine and a single software, makes the data security system more flexible, and improves the user experience.

[0095] In a possible implementation, the method provided by the embodiment of the present application can be applied to the scenario of cloud services. For ease of description, the scenario of cloud services will be described in detail below in combination with Figure 1 ,

[0096] Figure 1 is a schematic block diagram of a cloud scenario applicable to the embodiment of the present application. As Figure 1 shown, this cloud scenario may include: a cloud management platform 110, the Internet 120, and a client 130.

[0097] As Figure 1 shown, the cloud management platform 110 is used to manage the infrastructure that provides multiple cloud services. The infrastructure includes multiple cloud data centers, each cloud data center includes multiple servers, and each server includes cloud service resources respectively, providing corresponding cloud services for tenants.

[0098] Specifically, an SQL engine runs on the servers in the cloud data center, and the method provided by the embodiment of the present application is executed by this SQL engine.

[0099] The cloud management platform 110 can be located in a cloud data center, which can provide access interfaces (such as interfaces or application program interfaces (APIs)). Tenants can operate the client 130 to remotely access the access interface to register cloud accounts and passwords on the cloud management platform 110 and log in to the cloud management platform 110. After the cloud management platform 110 successfully authenticates the cloud accounts and passwords, the tenants can further pay on the cloud management platform 110 to select and purchase virtual machines of specific specifications (processors, memory, disks). After the successful payment and purchase, the cloud management platform 110 provides the remote login account password of the purchased virtual machine, and the client 130 can remotely log in to the virtual machine and install and run the tenants' applications in the virtual machine. Therefore, tenants can create, manage, log in to, and operate virtual machines in the cloud data center through the cloud management platform 110. Among them, virtual machines can also be called elastic compute services (ECS), elastic instances (with different names in different cloud service providers).

[0100] It should be understood that the tenants of cloud services can be individuals, enterprises, schools, hospitals, administrative organs, etc.

[0101] The functions of the cloud management platform 110 include but are not limited to user consoles, computing management services, network management services, storage management services, authentication services, and image management services. The user console provides an interface or API to interact with tenants. The computing management service is used to manage the servers running virtual machines and containers, as well as bare metal servers. The network management service is used to manage network services (such as gateways, firewalls, etc.). The storage management service is used to manage storage services (such as data bucket services). The authentication service is used to manage the account passwords of tenants. The image management service is used to manage virtual machine images. Tenants can use the client 130 to log in to the cloud management platform 110 through the Internet 120 to manage the rented cloud services.

[0102] First, in combination with Figure 2 , a method for an SQL engine to execute security policies provided by an embodiment of the present application will be described in detail. It should be understood that Figure 2 the examples are only for helping those skilled in the art to understand the embodiments of the present application, rather than limiting the embodiments of the application to Figure 2 the specific values or specific scenarios shown in the examples. Those skilled in the art can obviously make various equivalent modifications or changes according to Figure 2 the following examples given, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0103] Figure 2 is a schematic flowchart of a method for an SQL engine to execute security policies provided by an embodiment of the present application. As shown in Figure 2As shown, the method may include steps 210-220, which will be described in detail below respectively.

[0104] In one example, the method is applied to a database system, which includes a database and at least one SQL engine. The at least one SQL engine is used to obtain the data stored in the database according to SQL statements.

[0105] Step 210: The SQL engine obtains configuration information, which is used to configure the corresponding source software for each type of data security policy respectively.

[0106] In the embodiments of the present application, each SQL engine may be allowed to freely define different acquisition sources for various data security policies used or consumed by it. That is, the corresponding acquisition sources for each type of data security policy can be configured respectively.

[0107] It should be understood that each type of data security policy may correspond to one acquisition source, or may also correspond to multiple acquisition sources. The present application does not make specific limitations on this.

[0108] It should also be understood that the acquisition sources corresponding to different types of data security policies may include the same acquisition source, or may not include the same acquisition source. The present application does not make specific limitations on this.

[0109] The above acquisition source may also be referred to as a data security policy source, which can be understood as the software that provides data security policies. The software that provides data security policies may include but is not limited to: Apache Ranger, HMS, Hive ACL, etc.

[0110] It should be noted that in addition to deploying the SQL engines required for business, the user also needs to deploy more than one type of software that provides data security policies.

[0111] The above various data security policies may include but are not limited to: security policies for data access permission control, security policies for data masking, security policies for data row-level filtering, etc.

[0112] Optionally, in the embodiments of the present application, each SQL engine may also be allowed to freely define whether to enable some or all of the above various data security policies.

[0113] In one possible implementation, the administrator can configure different acquisition sources for various data security policies used by each SQL engine. There are various implementation methods for this configuration, and the embodiments of the present application do not make specific limitations on this. Several possible implementation methods are introduced below.

[0114] 1. The administrator configures different acquisition sources of various data security policies used by the SQL engine through the interface of the SQL engine.

[0115] Specifically, the administrator configures different acquisition sources of various data security policies used by the SQL engine through the application programming interface (API) of the SQL engine.

[0116] For example, if the SQL engine is located on the client side, the SQL engine can be configured through this implementation method.

[0117] 2. The administrator configures different acquisition sources of various data security policies used by the SQL engine through a configuration file or a visual interface.

[0118] For example, if the SQL engine is located on the server side, the SQL engine can be configured through this implementation method.

[0119] For example, as Figure 3 shown, the acquisition source configured by the administrator for the security policy of data access permission control (which can also be simply referred to as the access configuration item) is Security Policy Source 1, the acquisition sources configured for the security policy of data masking (which can also be simply referred to as the masking configuration item) are Security Policy Source 2 and Security Policy Source 3, and the acquisition source configured for the security policy of data row-level filtering (which can also be simply referred to as the rowlevelfilter configuration item) is Security Policy Source 3.

[0120] In the embodiment of the present application, it is assumed that the above-mentioned Security Policy Source 1 is HMS, Security Policy Source 2 is Apache Ranger, and Security Policy Source 3 is other software. As Figure 4 shown, through the security policy configuration interface of the SQL engine, the acquisition source configured for the security policy of data access permission control (which can also be simply referred to as the access configuration item) is HMS, the acquisition sources configured for the security policy of data masking (which can also be simply referred to as the masking configuration item) are Apache Ranger and other software, and the acquisition source configured for the security policy of data row-level filtering (which can also be simply referred to as the rowlevelfilter configuration item) is other software.

[0121] That is to say, the security policy of data access permission control used by the SQL engine is the security policy of data access permission control provided by HMS, the security policy of data masking used is the security policy of data masking provided by Apache Ranger and other software, and the security policy of data row-level filtering used is the security policy of data row-level filtering provided by other software.

[0122] Taking the example of an administrator configuring the SQL engine through a configuration file, this article will illustrate the specific implementation of the configuration file in combination with Figure 4 to give an example of the specific implementation of the configuration file.

[0123] In a possible implementation, taking the Spark SQL engine as an example, the following parameters can be added and saved in the Spark system startup configuration file:

[0124] spark.ranger.plugin.authorization.enable=fslse;

[0125] spark.HMS.plugin.access.enable=true;

[0126] spark.rangerandothers.plugin.masking.enable=true;

[0127] spark.others.plugin.row_level_filter.enable=true;

[0128] Among them, "spark.ranger.plugin.authorization.enable=fslse" is used to set the data security policy provided by Ranger to be disabled; "spark.HMS.plugin.access.enable=true" is used to set the security policy for enabling data access permission control provided by HMS (abbreviated as access); "spark.rangerandothers.plugin.masking.enable=true" is used to set the security policy for enabling data masking provided by Ranger and other software (abbreviated as masking); "spark.others.plugin.rowlevelfilter.enable=true" is used to set the security policy for enabling data row-level filtering provided by other software (abbreviated as rowlevelfilter).

[0129] It should be understood that in the above implementation, it is assumed that all data security policies in the SQL engine use those provided by Ranger. Therefore, it is necessary to first set the data security policy provided by Ranger to be disabled, and then set the data security policies provided by different sources to be enabled.

[0130] Since there are two ways to submit SQL tasks in Spark, users can choose to configure the above parameters at the following three different locations.

[0131] 1) The JDBC server of Spark;

[0132] 2) The local conf file of the Spark client;

[0133] 3) The command-line parameters of Spark.

[0134] It should be noted that the above is an example with the SQL engine being Spark, and it is applicable to other SQL engines.

[0135] In another possible implementation, taking the SQL engine Presto as an example, the following parameters can be added and saved in the system startup configuration file of Presto:

[0136] security.access.source=HMS;

[0137] security.masking.source=Ranger / others;

[0138] security.row_level_filter.source=others;

[0139] Among them, "security.access.source=HMS" means to set the security policy for enabling the data access permission control class provided by HMS (abbreviated as access); "security.masking.source=Ranger / others" means to set the security policy for enabling the data masking class provided by Ranger and other software (abbreviated as masking); "security.row_level_filter.source=others" means to set the security policy for enabling the data row-level filtering class provided by other software (abbreviated as rowlevelfilter).

[0140] It should be noted that the above is an example with the SQL engine being Presto, and it is applicable to other SQL engines.

[0141] Step 220: The SQL engine executes the data security policies provided by the corresponding software sources to protect the security and / or privacy of the data stored in the database.

[0142] In the embodiments of the present application, after obtaining the above configuration information, the SQL engine can enable a data security policy based on the configuration information to protect the security and / or privacy of the data stored in the database.

[0143] In one implementation, for a security policy of data access permission control, the SQL engine can execute the security policy of data access permission control to perform a security check on the user's permission to access the database before obtaining data from the database according to the SQL statement, so as to protect the security of the data stored in the database.

[0144] In another implementation, for a security policy of data masking or data row-level filtering, the SQL engine can execute the security policy of data masking or data row-level filtering to mask or perform row-level filtering on the data stored in the database after obtaining data from the database according to the SQL statement, so as to protect the privacy of the data stored in the database.

[0145] In the embodiments of the present application, since each type of data security policy can come from one software, or can also come from two or more software. For the same type of data security policy provided by two or more software, in the execution process of the SQL engine, it is necessary to support enabling the same type of data security policy provided by these two or more software to take effect simultaneously, that is, it is necessary to determine whether the security check of the same type of data security policy provided by these two or more software can be passed. In this way, multiple security protections can take effect simultaneously, so as to better protect the security and / or privacy of the data.

[0146] For example, taking the above security policy of data masking as an example, this security policy includes both the security policy of data masking provided by ApacheRanger and the security policy of data masking provided by other software. As Figure 5 shown, when the SQL engine executes the security policy of data masking, it is necessary to determine whether the security check of the security policy of data masking provided by ApacheRanger can be passed, and also determine whether the security check of the security policy of data masking provided by other software can be passed.

[0147] In one case, in Figure 5 , if for the security policy of data masking, the SQL engine passes both the security check of the security policy of data masking provided by ApacheRanger and the security check of the security policy of data masking provided by other software, then it can be understood that the check is successful.

[0148] In another case, inFigure 5 In this case, if the SQL engine passes the security check of the data masking security policy provided by Apache Ranger, but fails to pass the security check of the data masking security policy provided by other software, it can be understood that the check fails.

[0149] In another case, in Figure 5 if the SQL engine passes the security check of the data masking security policy provided by other software, but fails to pass the security check of the data masking security policy provided by Apache Ranger, it can also be understood that the check fails.

[0150] In another case, in Figure 5 if the SQL engine fails to pass the security check of the data masking security policy provided by Apache Ranger and also fails to pass the security check of the data masking security policy provided by other software, it can also be understood that the check fails.

[0151] In the above technical solution, the SQL engine can flexibly use the data security policies provided by different software, avoiding the strong binding relationship between all types of data security policies on the SQL engine and one software, making the data security system more flexible and improving the user experience.

[0152] Above, in combination with Figures 1 to 5 the method provided in the embodiments of the present application has been described in detail. Next, in combination with Figures 6 - 9 the embodiments of the device of the present application will be described in detail. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments. Therefore, for parts not described in detail, reference can be made to the previous method embodiments.

[0153] Figure 6 FIG. is a schematic block diagram of a SQL engine 600 provided by an embodiment of the present application. The SQL engine 600 can be implemented by software, hardware, or a combination of both. The SQL engine 600 provided by the embodiments of the present application can implement the method flow shown in Figure 2 of the embodiments of the present application. The SQL engine 600 includes: an acquisition module 610 and a processing module 620. Among them, the acquisition module 610 is used to acquire first configuration information, and the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, and the at least one software source corresponding to each of the different types of security policies is not completely the same; the processing module 620 is used to protect the security and / or privacy of the data stored in the database by executing the corresponding security policies provided by the different software sources indicated in the first configuration information.

[0154] Optionally, the obtaining module 610 is specifically configured to obtain the first configuration information in at least one of the following ways: the interface of the SQL engine, a configuration file, or a visual configuration interface.

[0155] Optionally, the different types of security policies include the first type of security policy, and the software sources corresponding to the first type of security policy include the first software and the second software. The processing module 620 is specifically configured to determine that the SQL engine passes the security check of the first type of security policy when the checks of the first type of security policies respectively provided by the first software and the second software are passed.

[0156] Optionally, the obtaining module 610 is further configured to obtain second configuration information, where the second configuration information is used to configure the SQL engine to execute some or all of the different types of security policies; the processing module 620 is further configured to execute some or all of the different types of security policies according to the second configuration information.

[0157] Optionally, the different types of security policies include at least two of the following: security policies for data access permission control, security policies for data masking, and security policies for data row-level filtering.

[0158] Optionally, the software sources include: Apache Ranger, Hive Metadata Store HMS, and Hive Access Control List ACL.

[0159] Optionally, the SQL engine 600 runs in at least one server, the at least one server is located in at least one cloud data center, and the at least one server is the infrastructure that provides cloud services managed by a cloud management platform.

[0160] The SQL engine 600 here may be embodied in the form of a functional module. The term "module" here may be implemented in software and / or hardware forms, and no specific limitation is made thereto.

[0161] For example, the "module" may be a software program, a hardware circuit, or a combination of the two that implements the above functions. Exemplarily, next, taking the obtaining module 610 as an example, the implementation manner of the obtaining module 610 is introduced. Similarly, the implementation manners of other modules, such as the processing module 620, may refer to the implementation manner of the obtaining module 610.

[0162] As an example of the acquisition module 610 as a software functional unit, the acquisition module 610 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the acquisition module 610 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running the code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs.

[0163] Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same virtual private cloud (VPC), or may be distributed in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.

[0164] As an example of the acquisition module 610 as a hardware functional unit, the acquisition module 610 may include at least one computing device, such as a server, etc. Or, the acquisition module 610 may also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0165] The multiple computing devices included in the obtaining module 610 may be distributed in the same region or in different regions. The multiple computing devices included in the obtaining module 610 may be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the obtaining module 610 may be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0166] Therefore, the modules in the examples described in the embodiments of the present application can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0167] It should be noted that: when the SQL engine 600 provided in the above embodiment executes the above method, only the above division of each functional module is used for illustration. In actual application, the above functions can be assigned to different functional modules according to needs, that is, the internal structure of the SQL engine 600 is divided into different functional modules to complete all or part of the functions described above. For example, the obtaining module 610 can be used to execute any step in the above method, and the processing module 620 can be used to execute any step in the above method. The steps to be implemented by the obtaining module 610 and the processing module 620 can be specified according to needs, and all functions of the above SQL engine 600 can be implemented by respectively implementing different steps in the above method through the obtaining module 610 and the processing module 620.

[0168] In addition, the SQL engine 600 provided in the above embodiment and the method embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment in the above text, and details are not described here again.

[0169] Figure 7 A database system 700 provided by an embodiment of the present application includes a database 710 and at least one SQL engine 600. The at least one SQL engine 600 is used to execute the above different types of security policies when obtaining the data stored in the database 710 according to an SQL statement, so as to protect the security and / or privacy of the data stored in the database 710.

[0170] The method provided by the embodiments of the present application can be executed by a computing device, which can also be referred to as a computer system. It includes a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a processing unit, a memory, and a memory control unit, and the functions and structures of this hardware will be described in detail later. The operating system is any one or more computer operating systems that implement business processing through processes. For example, Linux operating system, Unix operating system, Android operating system, iOS operating system, or Windows operating system, etc. The application layer includes application programs such as a browser, an address book, a word processing software, and an instant messaging software. And, optionally, the computer system is a handheld device such as a smart phone, or a terminal device such as a personal computer. The present application is not particularly limited as long as it can implement the method provided by the embodiments of the present application. The execution subject of the method provided by the embodiments of the present application can be a computing device, or a functional module in the computing device that can call and execute a program.

[0171] Next, in conjunction with Figure 8 , a computing device provided by the embodiments of the present application will be described in detail.

[0172] Figure 8 FIG. 9 is a schematic architecture diagram of a computing device 1500 provided by the embodiments of the present application. The computing device 1500 can be a server, a computer, or other devices with computing capabilities. Figure 8 The shown computing device 1500 includes: at least one processor 1510 and a memory 1520.

[0173] It should be understood that the present application does not limit the number of processors and memories in the computing device 1500.

[0174] The processor 1510 executes instructions in the memory 1520, enabling the computing device 1500 to implement the method provided by the present application. Or, the processor 1510 executes instructions in the memory 1520, enabling the computing device 1500 to implement each functional module provided by the present application, thereby implementing the method provided by the present application.

[0175] Optionally, the computing device 1500 further includes a communication interface 1530. The communication interface 1530 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1500 and other devices or communication networks.

[0176] Optionally, the computing device 1500 further includes a system bus 1540, where the processor 1510, the memory 1520, and the communication interface 1530 are respectively connected to the system bus 1540. The processor 1510 can access the memory 1520 through the system bus 1540. For example, the processor 1510 can read and write data or execute code in the memory 1520 through the system bus 1540. The system bus 1540 is a Peripheral Component Interconnect Express (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus 1540 is divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 8 it is only represented by a thick line in the figure, but it does not mean that there is only one bus or one type of bus.

[0177] In a possible implementation, the main function of the processor 1510 is to interpret the instructions (or codes) of a computer program and process the data in computer software. Among them, the instructions of the computer program and the data in the computer software can be stored in the memory 1520 or the cache 1516.

[0178] Optionally, the processor 1510 may be an integrated circuit chip with signal processing capabilities. By way of example and not limitation, the processor 1510 is a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. Among them, the general-purpose processor is a microprocessor, etc. For example, the processor 1510 is a central processing unit (CPU).

[0179] Optionally, each processor 1510 includes at least one processing unit 1512 and a memory control unit 1514.

[0180] Optionally, the processing unit 1512, also known as the core, is the most important component of the processor. The processing unit 1512 is fabricated from a single crystal silicon using a certain manufacturing process. All calculations, command reception, command storage, and data processing of the processor are executed by the core. The processing units independently execute program instructions and utilize the parallel computing ability to accelerate the program running speed. Each processing unit has a fixed logical structure. For example, the processing unit includes logical units such as a level-1 cache, a level-2 cache, an execution unit, an instruction-level unit, and a bus interface.

[0181] As an implementation example, the memory control unit 1514 is used to control the data interaction between the memory 1520 and the processing unit 1512. Specifically, the memory control unit 1514 receives a memory access request from the processing unit 1512 and controls the access to the memory based on this memory access request. By way of example and not limitation, the memory control unit is a device such as a memory management unit (MMU).

[0182] As an implementation example, each memory control unit 1514 addresses the memory 1520 through the system bus. And an arbiter ( Figure 8 not shown in the figure) is configured in the system bus, and this arbiter is responsible for handling and coordinating the competing accesses of multiple processing units 1512.

[0183] As an implementation example, the processing unit 1512 and the memory control unit 1514 are communicatively connected through internal chip connection lines, such as address lines, so as to realize the communication between the processing unit 1512 and the memory control unit 1514.

[0184] Optionally, each processor 1510 further includes a cache 1516, where the cache is a buffer for data exchange (referred to as cache). When the processing unit 1512 wants to read data, it will first look for the required data in the cache. If found, it will be directly executed; if not found, it will look for it in the memory. Since the cache runs much faster than the memory, the role of the cache is to help the processing unit 1512 run faster.

[0185] The memory 1520 can provide a running space for the processes in the computing device 1500. For example, the memory 1520 stores a computer program for generating a process (specifically, the code of the program). After the computer program is run by the processor to generate a process, the processor allocates a corresponding storage space for this process in the memory 1520. Further, the above storage space further includes a text segment, an initialized data segment, an uninitialized data segment, a stack segment, a heap segment, and so on. The memory 1520 stores the data generated during the running of the process in the storage space corresponding to the above process, such as intermediate data, or process data, and so on.

[0186] Optionally, the memory, also known as internal memory, is used to temporarily store the operation data in the processor 1510 and the data exchanged with external memories such as hard disks. As long as the computer is running, the processor 1510 will transfer the data to be operated to the memory for operation, and after the operation is completed, the processing unit 1512 will then transfer the result.

[0187] By way of example and not limitation, the memory 1520 is a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory is a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory is a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM). It should be noted that the memory 1520 of the systems and methods described herein is intended to include but not be limited to these and any other suitable types of memories.

[0188] The structure of the computing device 1500 listed above is only for illustrative purposes, and the present application is not limited thereto. The computing device 1500 in the embodiments of the present application includes various hardware in a computer system in the prior art. For example, the computing device 1500 further includes other memories in addition to the memory 1520, such as disk memories, etc. Those skilled in the art should understand that the computing device 1500 may further include other devices necessary for normal operation. At the same time, according to specific needs, those skilled in the art should understand that the above-mentioned computing device 1500 may further include hardware devices for implementing other additional functions. In addition, those skilled in the art should understand that the above-mentioned computing device 1500 may also only include the devices necessary for implementing the embodiments of the present application, and do not have to include Figure 8 all the devices shown in

[0189] The embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone, etc.

[0190] As Figure 9 shown, the computing device cluster includes at least one computing device 1500. Instructions for executing the above method may be stored in the same manner in the memory 1520 of one or more computing devices 1500 in the computing device cluster.

[0191] In some possible implementation manners, the memory 1520 in one or more computing devices 1500 in the computing device cluster may also store partial instructions for executing the above method respectively. In other words, a combination of one or more computing devices 1500 may jointly execute the instructions of the above method.

[0192] It should be noted that the memories 1520 in different computing devices 1500 in the computing device cluster may store different instructions, which are respectively used to execute partial functions of the above SQL engine. That is, the instructions stored in the memories 1520 in different computing devices 1500 may implement the functions of one or more modules in the above SQL engine.

[0193] In some possible implementation manners, one or more computing devices in the computing device cluster may be connected through a network. Among them, the network may be a wide area network or a local area network, etc. Figure 10 shows a possible implementation manner. As Figure 10 shown, two computing devices 1500A and 1500B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device.

[0194] It should be understood that Figure 10The functions of the computing device 1500A shown can also be completed by multiple computing devices 1500. Similarly, the functions of the computing device 1500B can also be completed by multiple computing devices 1500.

[0195] In this embodiment, a computer program product including instructions is also provided. The computer program product can be software or a program product including instructions that can run on a computing device or be stored in any available medium. When it runs on a computing device, it causes the computing device to execute the method provided above, or causes the computing device to implement the functions of the SQL engine provided above.

[0196] In this embodiment, a computer-readable storage medium is also provided. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center including one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive), etc. The computer-readable storage medium includes instructions that, when executed on a computing device, cause the computing device to execute the method provided above.

[0197] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0198] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0199] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0200] In several embodiments provided by the present application, it should be understood that the disclosed systems, SQL engines, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0201] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0202] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0203] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0204] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for executing a security policy using a structured query language SQL engine, characterized in that: The method is applied to a database system, the database system includes a database and at least one SQL engine, the at least one SQL engine is used to obtain data stored in the database according to an SQL statement, and the method includes: Each of the SQL engines obtains first configuration information respectively, where the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, and the at least one software source corresponding to each of the different types of security policies is not completely the same; Each of the SQL engines protects the security and / or privacy of the data stored in the database according to the first configuration information by executing corresponding security policies provided by different software sources indicated in the first configuration information.

2. The method according to claim 1, characterized in that: Each of the SQL engines obtains the first configuration information, including: Each of the SQL engines obtains the first configuration information in at least one of the following ways: an interface, a configuration file, or a visual configuration interface of each of the SQL engines.

3. The method according to claim 1 or 2, characterized in that: The different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include first software and second software. Each of the SQL engines protects the security and / or privacy of the data stored in the database according to the first configuration information by executing corresponding security policies provided by different software sources indicated in the first configuration information, including: When each of the SQL engines passes the verification of the first type of security policy provided by the first software and the second software respectively, it is determined that the SQL engine passes the security verification of the first type of security policy.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Each of the SQL engines obtains second configuration information respectively, where the second configuration information is used to configure the SQL engine to execute part of or all of the different types of security policies; Each of the SQL engines executes part of or all of the different types of security policies according to the second configuration information received by the SQL engine.

5. The method according to any one of claims 1 to 4, characterized in that The different types of security policies include at least two of the following: security policies of data access permission control type, security policies of data desensitization type, and security policies of data row-level filtering type.

6. The method according to any one of claims 1 to 5, characterized in that The software sources include: Apache Ranger, Hive metadata warehouse HMS, and Hive access permission list ACL.

7. The method according to any one of claims 1 to 6, characterized in that The method is applied to a cloud management platform, which is used to manage an infrastructure for providing cloud services. The infrastructure includes at least one cloud data center, each of which is provided with at least one server, and the SQL engine runs in the at least one server.

8. A structured query language SQL engine, characterized in that: The SQL engine is located in a database system, and the database system also includes a database. The SQL engine is used to obtain data stored in the database according to an SQL statement. The SQL engine includes: an acquisition module, configured to acquire first configuration information, wherein the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, wherein the at least one software source corresponding to each of the different types of security policies is not completely the same; A processing module is used to protect the security and / or privacy of the data stored in the database according to the first configuration information by executing corresponding security policies provided by different software sources indicated in the first configuration information.

9. The SQL engine according to claim 8, characterized in that: The acquisition module is specifically used for: The first configuration information is obtained by at least one of the following methods: an interface, a configuration file, or a visual configuration interface of the SQL engine.

10. The SQL engine according to claim 8 or 9, characterized in that: The different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include first software and second software. The processing module is specifically used for: In the case of passing the verification of the first type of security policy respectively provided by the first software and the second software, it is determined that the SQL engine passes the security verification of the first type of security policy.

11. The SQL engine according to any one of claims 8 to 10, characterized in that: The acquisition module is further used to acquire second configuration information, where the second configuration information is used to configure the SQL engine to execute some or all of the different types of security policies; The processing module is further configured to execute part or all of the different types of security policies according to the second configuration information.

12. The SQL engine according to any one of claims 8 to 11, characterized in that: The different types of security policies include at least two of the following: security policies of data access permission control type, security policies of data desensitization type, and security policies of data row-level filtering type.

13. The SQL engine according to any one of claims 8 to 12, characterized in that: The software sources include: Apache Ranger, Hive metadata repository HMS, and Hive access permission list ACL.

14. The SQL engine according to any one of claims 8 to 13, characterized in that: The SQL engine runs in at least one server, the at least one server is located in at least one cloud data center, and the at least one server is an infrastructure for providing cloud services managed by a cloud management platform.

15. A database system, characterized in that: The database system comprises a database and at least one SQL engine according to any one of claims 8 to 14, wherein the at least one SQL engine is used to obtain data stored in the database according to an SQL statement.

16. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 7.

17. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster is caused to perform the method according to any one of claims 1 to 7.

18. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method as claimed in any one of claims 1 to 7.

Citation Information

Cited By

  • Method for SQL engine to execute security policy, and SQL engine

    WO2025123968A1