Database global transparent storage encryption method
By configuring storage encryption options in the database, creating two-level keys, and encrypting and decrypting files using CTR encryption mode, the shortcomings of the existing technology in protecting data storage are solved, efficient encryption and decryption of database files are achieved, and data security and system compatibility are guaranteed.
Patent Information
- Application Number
- CN202510223028.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-20
AI Technical Summary
Existing database security measures are not sufficient to protect data storage, and it is difficult to effectively reduce the security threats faced by data.
Provides a database full-domain transparent storage encryption method, which creates two-level keys by configuring storage encryption options, and uses CTR encryption mode to efficiently encrypt and decrypt files, and performs key rotation tasks regularly.
It realizes efficient random encryption and decryption access to database files, effectively reducing the impact of encryption and decryption on database performance, and ensuring data security and system compatibility.
Smart Images

Figure CN120180465A_ABST
Abstract
Description
Technical Field
[0001] The present invention discloses a database global transparent storage encryption method, which relates to the technical field of database security. Background Art
[0002] In today's digital age, data has become an extremely important asset. As a key facility for storing data, databases contain a large amount of sensitive information, such as users' personal identity information, financial data, and enterprises' trade secrets.
[0003] With the development of network technology, the security threats faced by data are increasing day by day. Existing database security measures, such as access control and firewalls, can protect data security to a certain extent, but the protection at the data storage level is still insufficient. Summary of the Invention
[0004] In view of the problems of the prior art, the present invention provides a database global transparent storage encryption method to achieve efficient random encryption and decryption access to files and effectively reduce the impact of encryption and decryption on database performance.
[0005] The specific solution proposed by the present invention is as follows:
[0006] The present invention provides a database global transparent storage encryption method, including:
[0007] Configure the storage encryption options of the database. The storage encryption options include the directory path to be encrypted, the path of the specified key, the current encryption algorithm, and the key rotation period;
[0008] Perform encryption management on the files in the corresponding directory of the database according to the configured storage encryption options:
[0009] Create two-level keys. The first level is the user key, and the second level is the database system key. Randomly generate the database system key according to the user key and the encryption algorithm, assign a KeyID for the key of each file stored in the database, and perform index lookup on the database system key according to the KeyID. Encrypt the files in the corresponding directory of the database with the database system key.
[0010] Manage the key information of the encrypted files. The key information includes two files, namely: the registration file, which is used to record the encryption parameters of each file, and the encryption parameters include the keyID; the key data file, which is used to save all key-related information, and encrypt the key data file using the CTR encryption mode.
[0011] Regularly perform the key rotation task on the encrypted files according to the storage encryption options.
[0012] Further, the step of encrypting the key data file by using the CTR encryption mode in the database global transparent storage encryption method includes:
[0013] Determine whether the key data file exists. If it exists, obtain the corresponding keyID from the registration file, obtain the database system key according to the keyID, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file; if it does not exist, obtain the current key information, record the registration file, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file.
[0014] Further, the step of calling the CTR stream encryption class interface to encrypt the key data file in the database global transparent storage encryption method includes:
[0015] When determining whether the key data file exists, if it does not exist, use the CTR stream encryption creation class to randomly generate nonce and counter, instantiate the CTR stream encryption class with nonce and counter as parameters, and call the CTR stream encryption class interface to encrypt the key data file by using the instantiated CTR stream encryption class;
[0016] If it exists, pass in the parameter string and parse to obtain nonce and counter, instantiate the CTR stream encryption class with nonce and counter as parameters, and call the CTR stream encryption class interface to encrypt the key data file by using the instantiated CTR stream encryption class.
[0017] Further, the step of periodically performing a key rotation task on the encrypted file according to the storage encryption option in the database global transparent storage encryption method includes:
[0018] Obtain the user key of the encrypted file, determine whether there is a corresponding database system key for the user key. If so, calculate the difference between the current time and the generation time of the database system key, determine whether the difference is greater than the rotation period. If it is greater, randomly generate a new database system key and keyID according to the user key and the encryption algorithm, return the new database system key and perform key rotation.
[0019] The present invention also provides a database global transparent storage encryption device, including an encryption start management module, a key management module, and a data file encryption module.
[0020] The encryption start management module configures the storage encryption options of the database. The storage encryption options include the directory path to be encrypted, the path of the specified key, the current encryption algorithm, and the key rotation period.
[0021] The key management module performs encryption management on the files in the corresponding directory of the database according to the configured storage encryption options:
[0022] Create two - level keys. The first - level is the user key, and the second - level is the database system key. Randomly generate the database system key according to the user key and the encryption algorithm. Assign a KeyID of the key to each file stored in the database. The database system key can be indexed and searched according to the KeyID. Use the database system key to encrypt the files in the corresponding directory of the database.
[0023] Manage the key information of the encrypted files. The key information includes two files, namely: the registration file, which is used to record the encryption parameters of each file, and the encryption parameters include the keyID; the key data file, which is used to save all key - related information. The data file encryption module encrypts the key data file using the CTR encryption mode.
[0024] The key management module periodically performs a key rotation task on the encrypted files according to the stored encryption options.
[0025] Furthermore, the data file encryption module of the described database global transparent storage encryption device encrypts the key data file using the CTR encryption mode, including:
[0026] Judge whether the key data file exists. If it exists, obtain the corresponding keyID from the registration file, obtain the database system key according to the keyID, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file; if it does not exist, obtain the current key information, record the registration file, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file.
[0027] Furthermore, the data file encryption module of the described database global transparent storage encryption device calls the CTR stream encryption class interface to encrypt the key data file, including:
[0028] When judging whether the key data file exists, if it does not exist, randomly generate a nonce and a counter using the CTR stream encryption creation class, instantiate the CTR stream encryption class using the nonce and the counter as parameters, and call the CTR stream encryption class interface to encrypt the key data file using the instantiated CTR stream encryption class;
[0029] If it exists, pass in the parameter string and parse to obtain the nonce and the counter, instantiate the CTR stream encryption class using the nonce and the counter as parameters, and call the CTR stream encryption class interface to encrypt the key data file using the instantiated CTR stream encryption class.
[0030] Further, the key management module of the database global transparent storage encryption device regularly performs key rotation tasks on the encrypted files according to the storage encryption options, including: obtaining the user key of the encrypted file, determining whether there is a database system key corresponding to the user key, if so, calculating the difference between the current time and the generation time of the database system key, determining whether the difference is greater than the rotation period, if greater, randomly generating a new database system key and keyID according to the user key and the encryption algorithm, returning the new database system key and performing key rotation.
[0031] The advantages of the present invention are:
[0032] It supports automatic transparent encryption of all files in the database, effectively ensuring the compatibility of the database system, data security, and meeting compliance requirements.
[0033] Two-level keys are designed. The change of the user key does not require modification of historical encrypted data, and it supports regular rotation of the system key.
[0034] Efficient encryption of data is achieved through CTR encryption, supporting random reading and writing of files, and the impact of encryption and decryption on the performance of the database system is relatively small. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 It is a schematic diagram of the key rotation processing flow of the method of the present invention.
[0036] Figure 2 It is a schematic diagram of the read / write process of the encrypted data file of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] CTR (Counter) is a working mode of block cipher, mainly used for encrypting a large amount of data.
[0038] There is a counter in CTR encryption, and this counter generates a continuous value sequence. Its basic principle is to generate a key stream by encrypting the counter, and then perform an exclusive OR operation between the key stream and the plaintext data to obtain the ciphertext. For example, assume there is an 8-bit counter with an initial value of 00000000, and the value of the counter increases after each encryption (such as becoming 00000001, etc.). The continuously changing counter value is encrypted by an encryption algorithm (such as AES) to generate different key stream segments.
[0039] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, so that those skilled in the art can better understand the present invention and be able to implement it, but the embodiments given are not intended to limit the present invention.
[0040] Embodiment 1
[0041] The present invention provides a database global transparent storage encryption method, including:
[0042] Step 1: Configure the storage encryption options of the database. The storage encryption options include the directory path to be encrypted, the path of the specified key, the current encryption algorithm, and the key rotation period.
[0043] Among them, the directory path path to be encrypted is the storage location of the database.
[0044] For the path of the specified key, if there is a previous key path, it only needs to be clearly specified when the key needs to be replaced.
[0045] cipher and old-cipher are the current encryption algorithm and the previous encryption algorithm respectively. Such as SM4, AES, etc. old-cipher is only specified for the previous configuration when the encryption algorithm needs to be replaced.
[0046] For the key rotation period rotation-period, if not specified, the default period is 7 days.
[0047] Step 2: Perform encryption management on the files in the corresponding directory of the database according to the configured storage encryption options:
[0048] Step 21: Create two-level keys. The first level is the user key, and the second level is the database system key. Randomly generate the database system key according to the user key and the encryption algorithm, assign a KeyID for the key of each file stored in the database, and the database system key can be indexed and searched according to the KeyID. Encrypt the files in the corresponding directory of the database with the database system key. There are also benefits to the two-level management of keys. That is, when the user key is changed, there is no need to modify a large number of historical files in the database. Only the metadata information file needs to be rewritten. These meta-files have less content and have little impact on the system.
[0049] Manage the key information of the encrypted files. The key information includes two files, namely: the registration file, which is used to record the encryption parameters of each file, and the encryption parameters include keyID; the key data file, which is used to save all key-related information, and encrypt the key data file using the CTR encryption mode. The encryption of the key data file using the CTR encryption mode includes:
[0050] Judge whether the key data file exists. If it exists, obtain the corresponding keyID from the registration file, obtain the database system key according to the keyID, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file; if it does not exist, obtain the current key information, record the registration file, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file.
[0051] Among them, the calling of the CTR stream encryption class interface to encrypt the key data file includes:
[0052] When determining whether the key data file exists, if it does not exist, use the CTR stream encryption creation class to randomly generate nonce and counter, instantiate the CTR stream encryption class with nonce and counter as parameters, and call the CTR stream encryption class interface to encrypt the key data file using the instantiated CTR stream encryption class;
[0053] If it exists, pass in the parameter string and parse to obtain nonce and counter, instantiate the CTR stream encryption class with nonce and counter as parameters, and call the CTR stream encryption class interface to encrypt the key data file using the instantiated CTR stream encryption class.
[0054] Step 22: Regularly perform a key rotation task on the encrypted file according to the storage encryption option, including: obtaining the user key of the encrypted file, determining whether there is a database system key corresponding to the user key. If so, calculate the difference between the current time and the generation time of the database system key, determine whether the difference is greater than the rotation period. If it is greater, randomly generate a new database system key and keyID according to the user key and the encryption algorithm, return the new database system key and perform key rotation.
[0055] Embodiment 2
[0056] The present invention also provides a database global transparent storage encryption device, including an encryption startup management module, a key management module, and a data file encryption module.
[0057] The encryption startup management module configures the storage encryption option of the database. The storage encryption option includes the directory path to be encrypted, the path of the specified key, the current encryption algorithm, and the key rotation period.
[0058] The key management module performs encryption management on the files in the corresponding directory of the database according to the configured storage encryption option:
[0059] Create two-level keys. The first level is the user key, and the second level is the database system key. Randomly generate the database system key according to the user key and the encryption algorithm, assign a key KeyID to each file stored in the database, and the database system key can be indexed and searched according to the KeyID. Encrypt the files in the corresponding directory of the database using the database system key.
[0060] Manage the key information of the encrypted file. The key information includes two files, namely: a registration file for recording the encryption parameters of each file, where the encryption parameters include keyID; and a key data file for storing all key-related information. The data file encryption module encrypts the key data file using the CTR encryption mode.
[0061] The key management module periodically performs a key rotation task on the encrypted file according to the stored encryption options.
[0062] For the content such as information interaction and execution process among the modules in the above device, since it is based on the same concept as the method embodiment of the present invention, the specific content can be referred to the description in the method embodiment of the present invention and will not be elaborated here.
[0063] Similarly, the device of the present invention supports automatic transparent encryption of the global files in the database, effectively ensuring the compatibility of the database system, data security, and meeting compliance requirements. It designs two levels of keys. The change of the user key does not require modification of the historical encrypted data and supports the periodic rotation of the system key. It realizes efficient encryption of data through CTR encryption, supports random reading and writing of files, and has less impact on the performance of the database system during encryption and decryption.
[0064] It should be noted that not all steps and modules in the above processes and device structures are necessary. Some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted according to needs. The system structure described in the above embodiments can be a physical structure or a logical structure. That is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities respectively, or some components in multiple independent devices may be jointly implemented.
[0065] The above embodiments are only preferred embodiments given to fully illustrate the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or transformations made by those skilled in the art on the basis of the present invention are within the protection scope of the present invention. The protection scope of the present invention is subject to the claims.
Claims
1. A database global transparent storage encryption method, characterized by include: Configure the storage encryption options of the database, which include the directory path to be encrypted, the path to the specified key, the current encryption algorithm, and the key rotation period. Encrypt and manage the files in the corresponding directory of the database according to the configured storage encryption options: Create two levels of keys, the first level is the user key, the second level is the database system key. The database system key is randomly generated based on the user key and the encryption algorithm, and the key ID is assigned to each file stored in the database. The database system key can be indexed and searched based on the KeyID, and the database system key is used to encrypt the files in the corresponding directory of the database. Manage the key information of encrypted files. The key information includes two files: a registration file, which is used to record the encryption parameters of each file, including keyID; a key data file, which is used to save all key-related information. The key data file is encrypted using the CTR encryption mode. Periodically perform key rotation tasks on encrypted files according to the storage encryption options.
2. According to claim 1, a database global transparent storage encryption method is characterized by: The method of encrypting the key data file using the CTR encryption mode includes: Determine whether the key data file exists. If so, obtain the corresponding keyID from the registration file, obtain the database system key according to the keyID, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file; if it does not exist, obtain the current key information, record the registration file, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file.
3. A database global transparent storage encryption method according to claim 2, characterized in that The calling of the CTR stream encryption class interface to encrypt the key data file includes: When judging whether the key data file exists, if it does not exist, the CTR stream encryption creation class is used to randomly generate nonce and counter, and the CTR stream encryption class is instantiated using nonce and counter as parameters, and the CTR stream encryption class interface is called to encrypt the key data file using the instantiated CTR stream encryption class; If it exists, the parameter string is passed in and parsed to obtain nonce and counter, and the CTR stream encryption class is instantiated using nonce and counter as parameters. The CTR stream encryption class interface is called to encrypt the key data file using the instantiated CTR stream encryption class.
4. A database global transparent storage encryption method according to claim 1, characterized in that The periodic key rotation task for the encrypted file according to the storage encryption option includes: Get the user key of the encrypted file, determine whether there is a database system key corresponding to the user key, if so, calculate the difference between the current time and the time when the database system key was generated, determine whether the difference is greater than the rotation period, if greater, randomly generate a new database system key and keyID based on the user key and encryption algorithm, return the new database system key and perform key rotation.
5. A database global transparent storage encryption device, characterized in that It includes encryption startup management module, key management module and data file encryption module. The encrypted startup management module configures the storage encryption options of the database, which include the directory path to be encrypted, the path of the specified key, the current encryption algorithm, and the key rotation period; The key management module encrypts and manages the files in the corresponding directory of the database according to the configured storage encryption options: Create two levels of keys, the first level is the user key, the second level is the database system key. The database system key is randomly generated based on the user key and the encryption algorithm, and the key ID is assigned to each file stored in the database. The database system key can be indexed and searched based on the KeyID, and the database system key is used to encrypt the files in the corresponding directory of the database. Manage the key information of encrypted files. The key information includes two files: a registration file, which is used to record the encryption parameters of each file, including keyID; a key data file, which is used to save all key-related information. The data file encryption module uses the CTR encryption mode to encrypt the key data file. The key management module periodically performs key rotation tasks on encrypted files according to the storage encryption options.
6. A database global transparent storage encryption device according to claim 5, characterized in that The data file encryption module encrypts the key data file using the CTR encryption mode, including: Determine whether the key data file exists. If so, obtain the corresponding keyID from the registration file, obtain the database system key according to the keyID, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file; if it does not exist, obtain the current key information, record the registration file, initialize the CTR stream encryption class, and call the CTR stream encryption class interface to encrypt the key data file.
7. A database global transparent storage encryption device according to claim 6, characterized in that The data file encryption module calls the CTR stream encryption class interface to encrypt the key data file, including: When judging whether the key data file exists, if it does not exist, the CTR stream encryption creation class is used to randomly generate nonce and counter, and the CTR stream encryption class is instantiated using nonce and counter as parameters, and the CTR stream encryption class interface is called to encrypt the key data file using the instantiated CTR stream encryption class; If it exists, the parameter string is passed in and parsed to obtain nonce and counter, and the CTR stream encryption class is instantiated using nonce and counter as parameters. The CTR stream encryption class interface is called to encrypt the key data file using the instantiated CTR stream encryption class.
8. The database global transparent storage encryption device according to claim 6, characterized in that The key management module periodically performs a key rotation task on the encrypted file according to the storage encryption option, including: obtaining the user key of the encrypted file, determining whether there is a database system key corresponding to the user key, if yes, calculating the difference between the current time and the database system key generation time, determining whether the difference is greater than the rotation period, if greater, randomly generating a new database system key and keyID according to the user key and the encryption algorithm, returning the new database system key and performing key rotation.