Authorization method and device, storage medium and electronic equipment
By receiving the authorization request and obtaining the first target credential of the database instance, the problem of the data security center authorizing multiple times on each database asset is solved, and the efficiency of sensitive data identification is improved.
Patent Information
- Application Number
- CN202311777054.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
When a user needs a data security center to identify sensitive data for database assets, he can only authorize credentials to the data security center on the authorization page corresponding to each database asset, resulting in a relatively low efficiency in identifying sensitive data.
By receiving an authorization request initiated by the target object, obtaining the first target credentials of multiple database instances based on the authorization identifier, determining whether the data security center has the permission to access multiple database instances, avoiding credential authorization on the authorization page corresponding to each database asset.
It improves the authorization efficiency of the data security center, and thus improves the efficiency of sensitive data identification.
Smart Images

Figure CN120197204A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to an authorization method and device, a storage medium, and an electronic device. Background Art
[0002] When using the data security center, users need to authorize the data security center to access the user's cloud product resources. Generally, database resources need to be accessed through a connection string, user name, and password. Users need to host their usernames and passwords on the data security center side. The data security center assembles the connection string and connects to the user database through the username and password to access the data and identify sensitive data. In the prior art, it is necessary to authorize the data security center with credentials on the authorization page corresponding to each database asset. This method seriously affects the efficiency of identifying sensitive data in the database.
[0003] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0004] The embodiments of the present application provide an authorization method and device, a storage medium and an electronic device to at least solve the technical problem that when a user needs the data security center to identify sensitive data of a database asset, the user can only perform credential authorization on the data security center separately on the authorization page corresponding to each database asset, resulting in relatively low efficiency in sensitive data identification.
[0005] According to one aspect of an embodiment of the present application, an authorization method is provided, which is applied to a data security center, comprising: receiving an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center; obtaining a first target credential of multiple database instances based on the authorization identifier, wherein the first target credential is used to determine whether the data security center has permission to access the multiple database instances.
[0006] Further, obtaining the first target credentials of multiple database instances based on the authorization identifier includes: determining the authorization method for authorizing access to the data security center based on the authorization identifier, wherein the authorization method is one of the following: a first authorization method, a second authorization method and a third authorization method, the first authorization method is an authorization method when the target object provides credentials, the second authorization method is an authorization method when the target object does not provide credentials, and the third authorization method is an authorization method when the target object provides credentials and the correspondence between the credentials and the database instance; obtaining the first target credentials of multiple database instances based on the authorization method.
[0007] Further, if the authorization method is the first authorization method, the first target credentials for obtaining multiple database instances according to the authorization method include: receiving the first credentials input by the target object through the credential management interface in the data security center, where the first credentials at least include a first account number and password information corresponding to the first account number; establishing a first associated authorization relationship between the first credentials and the multiple database instances; and obtaining the first target credentials according to the first associated authorization relationship and the first credentials.
[0008] Further, if the authorization method is the first authorization method, the first target credentials for obtaining multiple database instances according to the authorization method include: receiving a credential association request for the databases in the multiple database instances through the asset management interface in the data security center, where the credential association request at least includes second credentials corresponding to the multiple database instances, and the second credentials at least include a second account number and password information corresponding to the second account number; establishing a second associated authorization relationship between the databases in the multiple database instances and the second credentials according to the credential association request; and obtaining the first target credentials according to the second associated authorization relationship and the second credentials.
[0009] Further, if the authorization method is the second authorization method, the first target credentials for obtaining multiple database instances according to the authorization method include: establishing a third account number and password information corresponding to the third account number, where the access privilege of the third account number is read-only access; determining third credentials according to the third account number and the password information corresponding to the third account number; establishing a third associated authorization relationship between the third credentials and the multiple database instances; and obtaining the first target credentials according to the third associated authorization relationship and the third credentials.
[0010] Further, if the authorization method is the third authorization method, the first target credentials for obtaining multiple database instances according to the authorization method include: receiving an authorization form input by the target object, where the authorization form at least includes identification information of the database instances in the multiple database instances, fourth credentials, and a correspondence between the identification information and the fourth credentials; identifying the authorization form to obtain the identification information and the fourth credentials; establishing a fourth associated authorization relationship between the fourth credentials and the multiple database instances according to the identification information and the correspondence; and obtaining the first target credentials according to the fourth associated authorization relationship and the fourth credentials.
[0011] Further, after obtaining the first target credentials of multiple database instances based on the authorization identifier, the method further includes: when receiving a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object, accessing the target database instance according to the sensitive data identification request; identifying sensitive data in the database of the target database instance to obtain an identification result.
[0012] Further, when receiving a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object, the accessing the target database instance according to the sensitive data identification request includes: determining a second target credential of the target database instance from the first target credentials according to the sensitive data identification request; accessing the target database instance according to the second target credential.
[0013] Further, the accessing the target database instance according to the second target credential includes: determining a target server of the database in the target database instance; establishing a reverse access network with the target server, and obtaining an access address and an access port of the database in the target database instance according to the reverse access network; establishing a mapped access address and a mapped access port according to the access address and the access port; accessing the mapped access address and the mapped access port according to the second target credential to access the target database instance.
[0014] Further, before receiving an authorization request initiated by a target object, the method further includes: scanning database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning database assets corresponding to the target object according to a trigger instruction of the target object to obtain the list of database instances.
[0015] According to another aspect of the embodiments of the present application, there is also provided an authorization device, including: a receiving unit, configured to receive an authorization request initiated by a target object, where at least an authorization identifier is included in the authorization request, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center; an obtaining unit, configured to obtain first target credentials of multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the right to access the multiple database instances.
[0016] Further, the obtaining unit includes: a first determination subunit, configured to determine an authorization method for accessing the data security center according to the authorization identifier, where the authorization method is one of the following: a first authorization method, a second authorization method, and a third authorization method. The first authorization method is an authorization method when the target object provides a credential. The second authorization method is an authorization method when the target object does not provide a credential. The third authorization method is an authorization method when the target object provides a credential and the corresponding relationship between the credential and the database instance. An obtaining subunit, configured to obtain first target credentials of multiple database instances according to the authorization method.
[0017] Further, if the authorization method is the first authorization method, the obtaining subunit includes: a first receiving module, configured to receive a first credential input by the target object through a credential management interface in the data security center, where the first credential at least includes a first account number and password information corresponding to the first account number; a first establishing module, configured to establish a first associated authorization relationship between the first credential and the multiple database instances; a first obtaining module, configured to obtain the first target credential according to the first associated authorization relationship and the first credential.
[0018] Further, if the authorization method is the first authorization method, the obtaining subunit includes: a second receiving module, configured to receive a credential association request for a database in the multiple database instances through an asset management interface in the data security center, where the credential association request at least includes a second credential corresponding to the multiple database instances, and the second credential at least includes a second account number and password information corresponding to the second account number; a second establishing module, configured to establish a second associated authorization relationship between the database in the multiple database instances and the second credential according to the credential association request; a second obtaining module, configured to obtain the first target credential according to the second associated authorization relationship and the second credential.
[0019] Further, if the authorization method is the second authorization method, the obtaining subunit includes: a third establishing module, configured to establish a third account number and password information corresponding to the third account number, where the access permission of the third account number is read-only access; a first determining module, configured to determine a third credential according to the third account number and the password information corresponding to the third account number; a fourth establishing module, configured to establish a third associated authorization relationship between the third credential and the multiple database instances; a third obtaining module, configured to obtain the first target credential according to the third associated authorization relationship and the third credential.
[0020] Further, if the authorization method is the third authorization method, the obtaining subunit includes: a third receiving module, configured to receive an authorization form input by the target object, where the authorization form at least includes identification information of a database instance among the multiple database instances, a fourth credential, and a correspondence relationship between the identification information and the fourth credential; an identification module, configured to identify the authorization form to obtain the identification information and the fourth credential; a fifth establishing module, configured to establish a fourth associated authorization relationship between the fourth credential and the multiple database instances according to the identification information and the correspondence relationship; and a fourth obtaining module, configured to obtain the first target credential according to the fourth associated authorization relationship and the fourth credential.
[0021] Further, the apparatus further includes: an access unit, configured to, after obtaining the first target credential of the multiple database instances according to the authorization identifier, when receiving a sensitive data identification request initiated by the target object for a target database instance among the multiple database instances, access the target database instance according to the sensitive data identification request; and an identification unit, configured to perform sensitive data identification on the databases in the target database instance to obtain an identification result.
[0022] Further, the access unit includes: a second determining subunit, configured to determine a second target credential of the target database instance from the first target credential according to the sensitive data identification request; and an access subunit, configured to access the target database instance according to the second target credential.
[0023] Further, the access subunit includes: a second determining module, configured to determine a target server of the database in the target database instance; a sixth establishing module, configured to establish a reverse access network with the target server and obtain an access address and an access port of the database in the target database instance according to the reverse access network; a sixth establishing module, configured to establish a mapped access address and a mapped access port according to the access address and the access port; and an access module, configured to access the mapped access address and the mapped access port according to the second target credential to access the target database instance.
[0024] Further, the apparatus further includes: a first scanning unit, configured to scan database assets corresponding to the target object according to a preset time period to obtain a database instance list before receiving an authorization request initiated by the target object; or a second scanning unit, configured to scan the database assets corresponding to the target object according to a trigger instruction of the target object to obtain the database instance list.
[0025] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a program, wherein when the program runs, it controls the device where the storage medium is located to execute the authorization method described in any one of the above.
[0026] According to another aspect of the embodiments of the present invention, there is also provided an electronic device including a memory storing an executable program and a processor for running the program, wherein when the program runs, it executes the authorization method described in any one of the above.
[0027] In the embodiments of the present application, by receiving an authorization request initiated by a target object, where the authorization request at least includes an authorization identifier for indicating an authorization method for authorizing access to the data security center, and obtaining first target credentials of multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the right to access the multiple database instances, and the database instances in the multiple database instances at least include one database, the technical problem that when a user needs the data security center to identify sensitive data of database assets, they can only perform credential authorization on the data security center on the authorization page corresponding to each database asset respectively, resulting in relatively low efficiency of sensitive data identification is solved. In this solution, the data security center receives the authorization request initiated by the target object, and then, according to the authorization identifier, determines the adopted authorization method. The data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of needing to perform credential authorization on the data security center on the authorization page corresponding to each database asset, improving the authorization efficiency for the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0029] Figure 1 is a schematic diagram of a computer terminal provided according to Embodiment 1 of the present application;
[0030] Figure 2 is a flowchart of an authorization method provided according to Embodiment 1 of the present invention;
[0031] Figure 3 is an authorization schematic provided according to Embodiment 1 of the present invention Figure 1 ;
[0032] Figure 4 is an authorization schematic provided according to Embodiment 1 of the present invention Figure 2 ;
[0033] Figure 5 is the authorization schematic diagram provided according to Embodiment 1 of the present invention Figure 3 ;
[0034] Figure 6 is the authorization schematic diagram provided according to Embodiment 1 of the present invention Figure 4 ;
[0035] Figure 7 is the authorization schematic diagram provided according to Embodiment 1 of the present invention Figure 5 ;
[0036] Figure 8 is the flowchart of the optional authorization method provided according to Embodiment 1 of the present invention Figure 1 ;
[0037] Figure 9 is the flowchart of the optional authorization method provided according to Embodiment 1 of the present invention Figure 2 ;
[0038] Figure 10 is the schematic diagram of the authorization device provided according to Embodiment 2 of the present invention;
[0039] Figure 11 is the schematic diagram of the computer terminal provided according to Embodiment 3 of the present invention. Detailed implementation manners
[0040] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0041] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0042] First, some nouns or terms that appear in the process of describing the embodiments of the present application are applicable to the following explanations:
[0043] Credential: A credential, evidence, refers to the username and password for accessing an asset, and the server hosts it in the form of a credential.
[0044] Instance: In computer language, an "instance" is what a "class" becomes after instantiation. A "class" is static and does not occupy process memory, while an "instance" has dynamic memory. In a database, it represents a collection of some programs. A database instance consists of a series of background processes and the memory blocks allocated by the system for these processes. An instance of a cloud server is an independent computing unit virtualized from cloud computing resources, referring to a real host that can be used by users.
[0045] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards in the relevant regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0046] Embodiment 1
[0047] According to the embodiments of the present application, a method for authorization is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0048] The method embodiment provided by the first embodiment of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the authorization method is shown. As Figure 1 shown, the computer terminal (or mobile device) 10 may include a processor set 102 (the processor set 102 may include, but is not limited to, a processing device such as a microprocessor MCU (Microcontroller Unit) or a programmable logic device FPGA (Field Programmable Gate Array), and the processor set 102 may include a processor set. Figure 1102a, 102b, ……, 102n are used to illustrate), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 The structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown in, or have a different configuration from Figure 1 shown.
[0049] It should be noted that the above one or more processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" in this document. The data processing circuit can be embodied in whole or in part as software, hardware, firmware, or any other combination. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is used for processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0050] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage devices corresponding to the authorization method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, the above-mentioned authorization method is implemented. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and their combinations.
[0051] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 may be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0052] The display can be, for example, a touch-screen liquid crystal display, which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0053] Under the above operating environment, the present application provides an authorization method as Figure 2 shown. Figure 2 It is a flowchart of the authorization method provided by Embodiment 1 of the present application. The method includes:
[0054] Step S201, receiving an authorization request initiated by a target object, where the authorization request at least includes an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center.
[0055] Optionally, the data security center receives an authorization request initiated by a user (i.e., the above target object). It should be noted that the authorization request of the user needs to include an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center. For example, the authorization method can be credential authorization, and the credential is provided by the user.
[0056] Step S202, obtaining first target credentials of multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the permission to access the multiple database instances, and the database instances in the multiple database instances at least include one database.
[0057] Optionally, the data security center obtains the first target credentials of the user's multiple database instances according to the above authorization identifier. It should be noted that the data security center obtains the permission to access the multiple database instances based on the first target credentials. It should be noted that there are multiple databases in the database instances of the multiple database instances.
[0058] In summary, the data security center receives an authorization request initiated by a target object. Then, based on the authorization identifier, it determines the authorization method to be adopted. The data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of having to perform credential authorization for the data security center on the authorization page corresponding to each database asset, improving the authorization efficiency for the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.
[0059] In an optional example, before receiving the authorization request initiated by the target object, the method further includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to a trigger instruction of the target object to obtain a list of database instances.
[0060] Optionally, the data security center scans the database assets of the user according to a preset time period or a trigger instruction of the user to obtain a list of database instances of the user, so as to verify whether the database instances are actually existent when the user initiates an authorization request later.
[0061] Optionally, after receiving the authorization request initiated by the target object, in order to ensure information security, the identity information and permission information of the target object are verified. And if the authorization request further includes asset information to be authorized, that is, database instances, the authenticity of the database instances can also be verified.
[0062] In summary, the data security center receives an authorization request initiated by a target object. Then, based on the authorization identifier, it determines the authorization method to be adopted. The data security center obtains the first credentials of multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of having to perform credential authorization for the data security center on the authorization page corresponding to each database asset, improving the authorization efficiency for the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.
[0063] To improve the flexibility of authorizing the data security center, in the authorization method provided in Embodiment 1 of the present application, obtaining the first target credentials of multiple database instances according to the authorization identifier includes: determining the authorization method for accessing and authorizing the data security center according to the authorization identifier, where the authorization method is one of the following: the first authorization method, the second authorization method, and the third authorization method. The first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, and the third authorization method is the authorization method when the target object provides credentials and the corresponding relationship between the credentials and the database instances; obtaining the first target credentials of multiple database instances according to the authorization method.
[0064] Optionally, determine the authorization method for accessing the data security center based on the authorization identifier. It should be noted that the authorization methods include the first authorization method, the second authorization method, and the third authorization method. The first authorization method is the authorization method when the target object provides credentials, which can also be called the authorization method of credential authorization. The second authorization method is the authorization method when the target object does not provide credentials, which can also be called the one-key authorization method. The third authorization method is the authorization method when the target object provides credentials and the corresponding relationship between the credentials and the database instance, which can also be called the import authorization method.
[0065] After determining the authorization method, the data security center obtains the first target credentials of multiple database instances according to the authorization method.
[0066] By authorizing the data security center through the above-mentioned first authorization method, second authorization method, and third authorization method, the flexibility and efficiency of authorization are improved.
[0067] When the authorization method is the first authorization method, that is, the authorization method of credential authorization, it can be divided into two ways for authorization: 1) The credential management side performs associated authorization and cancellation of association of assets. 2) On the asset center side, centered on the asset, perform association of existing credentials or create new credential associations.
[0068] For the credential management side, in the authorization method provided in the first embodiment of the present application, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, where the first credentials at least include the first account and the password information corresponding to the first account; establishing a first associated authorization relationship between the first credentials and multiple database instances; and obtaining the first target credentials based on the first associated authorization relationship and the first credentials.
[0069] Optionally, receive the first credentials input by the target object through the credential management interface in the data security center. For example, Figure 3 is the authorization schematic diagram provided in the first embodiment of the present invention Figure 1 As Figure 3 shown, the user can add the above-mentioned first credentials in the credential management interface according to the product type of the database to be authorized, and the credentials can be used for subsequent authorization of assets of the corresponding asset type.
[0070] Then associate the credentials with the actual assets, that is, establish a first associated authorization relationship between the first credentials and multiple database instances. For example, Figure 4 is the authorization schematic diagram provided in the first embodiment of the present invention Figure 2 As Figure 4As shown, data assets corresponding to the asset type are added under the first credential. It should be noted that the credential can be directly associated with the database instance or directly associated with the database in the database instance.
[0071] It should be noted that in the credential management interface, the associated relationship between the credential and the associated database or database instance can also be disassembled.
[0072] It should be noted that after receiving the user input credential, in order to protect the security of the data, the credential needs to be encrypted. For example, first encrypt the credential through the AES (Advanced Encryption Standard) algorithm to obtain the encrypted credential, and then perform secondary encryption on the encrypted credential through the KMS (Key Management Service) algorithm. Finally, the ciphertext data of the credential is obtained.
[0073] Finally, based on the first associated authorization relationship and the first credential, the first target credential is obtained.
[0074] For the asset center side, in the authorization method provided in the first embodiment of this application, obtaining the first target credential of multiple database instances according to the authorization method includes: receiving, through the asset management interface in the data security center, a credential association request for the databases in multiple database instances, where the credential association request at least includes a second credential corresponding to multiple database instances, and the second credential at least includes a second account and password information corresponding to the second account; establishing a second associated authorization relationship between the databases in multiple database instances and the second credential according to the credential association request; and obtaining the first target credential according to the second associated authorization relationship and the second credential.
[0075] Optionally, the user can initiate a credential association request for the databases in multiple database instances through the asset management interface in the data security center. It should be noted that single or batch database credential associations can be performed in the asset management interface.
[0076] Establish a second associated authorization relationship between the databases in multiple database instances and the second credential according to the above-mentioned credential association request. It should be noted that when establishing the associated relationship, a new credential can also be selected, and then an associated authorization is established between the newly created credential and the database. For example, Figure 5 is the authorization schematic diagram provided in the first embodiment of the present invention Figure 3 as Figure 5 shown, select existing credentials and new credentials for the database assets to be authorized.
[0077] Finally, the data security center obtains the above-mentioned first target credential according to the second associated authorization relationship and the second credential.
[0078] Through the above authorization method, the data security center can quickly obtain the credentials provided by the user, thereby achieving the effect of improving the efficiency of sensitive data identification.
[0079] If the authorization method is the second authorization method, in the authorization method provided in the first embodiment of the present application, obtaining the first target credentials of multiple database instances according to the authorization method includes: establishing a third account and the password information corresponding to the third account, where the access permission of the third account is read-only access; determining the third credential according to the third account and the password information corresponding to the third account; establishing a third associated authorization relationship between the third credential and multiple database instances; and obtaining the first target credential according to the third associated authorization relationship and the third credential.
[0080] Optionally, if the user does not provide credentials and it is the second authorization method, that is, one-key authorization, the data security center will directly create a third account and the password information corresponding to the third account. It should be noted that the third account is a read-only account, that is, it is given the minimum permission to read and access the specified database. Then establish a third associated authorization relationship between the third credential and multiple database instances. For example, Figure 6 is the authorization schematic provided in the first embodiment of the present invention Figure 4 , as Figure 6 shown, perform one-key authorization on the selected database instances. It should be noted that one-key authorization can be performed on single or multiple database instances, or on only one database in a single database instance.
[0081] It should be noted that the third account and the password information corresponding to the third account will establish an associated authorization relationship with the databases in the database instance, and during this period, the user is not allowed to initiate the one-key authorization process for the database instance again.
[0082] Finally, obtain the first target credential according to the third associated authorization relationship and the third credential.
[0083] Through the above second authorization method, the access authorization to the data security center can be quickly completed without the user providing credentials.
[0084] If the authorization method is the third authorization method, in the authorization method provided in the first embodiment of the present application, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving an authorization form input by the target object, where the authorization form at least includes the identification information of the database instances in multiple database instances, the fourth credential, and the corresponding relationship between the identification information and the fourth credential; identifying the authorization form to obtain the identification information and the fourth credential; establishing a fourth associated authorization relationship between the fourth credential and multiple database instances according to the identification information and the corresponding relationship; and obtaining the first target credential according to the fourth associated authorization relationship and the fourth credential.
[0085] Optionally, the data security center can also obtain the access permission to the database through a third authorization method. The user can obtain the account password template file, that is, the above-mentioned authorization template form, through the data security center. Figure 7 It is an authorization schematic diagram provided by Embodiment 1 of the present invention. Figure 5 , such as Figure 7 shown. Then, the user adds the account password in the account password template file and imports the file to complete the authorization.
[0086] The data security center will obtain the identification information and the fourth credential according to the uploaded authorization form, and then establish a fourth associated authorization relationship between the fourth credential and multiple database instances, and then obtain the above-mentioned first target credential.
[0087] Optionally, if there is a database asset in the authorization form that does not have a corresponding credential, it can be directly processed through one-key authorization (that is, the above-mentioned second authorization method).
[0088] Optionally, since the user authorizes the data security center to access the database, it is generally used for sensitive data identification. To prevent the impact on the performance of the user instance, when performing asset authorization, the user can optionally enable or disable the function of "immediately scanning sensitive data".
[0089] In an alternative embodiment, after the above-mentioned data center obtains the first target credential of the above-mentioned multiple database instances, in the authorization method provided by Embodiment 1 of the present application, the following steps are further included: when receiving a sensitive data identification request initiated by a target object for a target database instance among multiple database instances, accessing the target database instance according to the sensitive data identification request, and performing sensitive data identification on the database in the target database instance to obtain an identification result.
[0090] Optionally, after the data security center obtains the above-mentioned first target credential, if it receives a sensitive data identification request from the user for a target database instance among multiple database instances, it directly accesses the database under the target database instance according to the credential of the target database instance, and performs sensitive data identification on the database in the target database instance to obtain an identification result. By accessing the database through the credential of the target database instance, the technical effect of improving data security is achieved.
[0091] To improve the security of data, in the authorization method provided by Embodiment 1 of the present application, when receiving a sensitive data identification request initiated by a target object for a target database instance among multiple database instances, accessing the target database instance according to the sensitive data identification request includes: determining the second target credential of the target database instance from the first target credential according to the sensitive data identification request; accessing the target database instance according to the second target credential.
[0092] Accessing a target database instance based on a second target credential includes: determining a target server of a database in the target database instance; establishing a reverse access network with the target server, and obtaining an access address and an access port of the database in the target database instance based on the reverse access network; establishing a mapped access address and a mapped access port based on the access address and the access port; and accessing the mapped access address and the mapped access port based on the second target credential to access the target database instance.
[0093] Optionally, when the data security center receives a sensitive data identification request initiated by a user, a second target credential of the target database instance is determined from the above-mentioned first target credentials.
[0094] Then, determine the target server of the database in the target database instance, establish a reverse access network between the data security center and the target server, obtain the access address and the access port of the database in the target database instance, and map them to a mapped access address and a mapped access port. Finally, access the mapped access address and the mapped access port according to the second target credential to achieve the purpose of accessing the target database instance.
[0095] Optionally, Figure 8 is the process of an optional authorization method provided in Embodiment 1 of the present invention Figure 1 , and authorization for the data security center can be completed by using a schematic diagram as Figure 8 shown. Determine the assets to be authorized by the user (including multiple database instances), and then complete the authorization through three methods: credential authorization, one-key authorization, and import authorization. Credential authorization includes obtaining associated credential information and setting a username and password. One-key authorization is for assets with empty account passwords, and the one-key authorization flag can be directly set. Import authorization includes parsing the authorization file imported by the user, generating an authorized asset record, and if there are assets without an account and password, the one-key authorization flag can be set.
[0096] Optionally, Figure 9 is the process of an optional authorization method provided in Embodiment 1 of the present invention Figure 2 , and the method as Figure 9The flowchart shown completes the authorization of the data security center, clarifies the set of assets to be authorized, and performs authorization verification and specification check. The authorization verification and specification check here refer to the verification of user permissions and database assets, and then determines whether there is one-click authorization. If it is one-click authorization, create a read-only account and password, and determine whether there is a cache control requirement. If so, set the cache flag, which refers to establishing an associated authorization relationship between the read-only account and password and the database in the database instance. During this period, the user is not allowed to initiate the one-click authorization process for the database instance again. Finally, the read-only account and password are recorded so that the user's authorized assets can be viewed later.
[0097] If it is not one-click authorization, obtain the credentials entered by the user (ie, account number and account password, etc.), and then associate the credentials with the database instance.
[0098] After the association is completed, the Data Security Center automatically sets up the whitelist and security group, opens the reverse access network, and records the mapped IP and port so that the Data Security Center can subsequently access database assets based on the mapped IP and port.
[0099] Through the above authorization method, a flexible asset authorization access method is provided. Users can choose to use credential authorization, one-click authorization or import authorization to authorize the data security center to access the user's cloud assets. Users do not need to worry about the connection between the cloud service network and the cloud product network, whitelist configuration, etc., and by maintaining credentials, the authorization process is greatly simplified when a large number of databases are accessed using the same account and password. This case also provides a more convenient "one-click" authorization method. Users can complete the authorization access process for a single instance or a single instance library with a single button click.
[0100] In the authorization method provided in the first embodiment of the present application, an authorization request initiated by a target object is received. The authorization request at least includes an authorization identifier, and the authorization identifier is used to indicate the authorization method for authorizing access to the data security center. First target credentials of multiple database instances are obtained according to the authorization identifier. The first target credentials are used to determine whether the data security center has the permission to access the multiple database instances. The database instances in the multiple database instances at least include one database. When a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object is received, the target database instance is accessed according to the sensitive data identification request, and sensitive data in the database of the target database instance is identified to obtain an identification result. This solves the technical problem that when a user needs the data security center to identify sensitive data of database assets, the user can only perform credential authorization on the data security center on the authorization page corresponding to each database asset respectively, resulting in relatively low efficiency of sensitive data identification. In this solution, the data security center directly receives the authorization request initiated by the target object, and then determines the adopted authorization method according to the authorization identifier. The data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of performing credential authorization on the data security center on the authorization page corresponding to each database asset, improving the authorization efficiency of the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.
[0101] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0102] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods of the various embodiments of the present application.
[0103] Embodiment 2
[0104] According to an embodiment of the present application, there is also provided a data processing apparatus for implementing the above authorization method, as Figure 10 shown. The apparatus includes: a receiving unit 1001 and an obtaining unit 1002.
[0105] The receiving unit 1001 is configured to receive an authorization request initiated by a target object. The authorization request at least includes an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center.
[0106] The obtaining unit 1002 is configured to obtain first target credentials of multiple database instances according to the authorization identifier. The first target credentials are used to determine whether the data security center has the right to access the multiple database instances, and the database instances in the multiple database instances include at least one database.
[0107] In the authorization apparatus provided in the second embodiment of the present application, the receiving unit 1001 receives an authorization request initiated by a target object. The authorization request at least includes an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center. The obtaining unit 1002 obtains first target credentials of multiple database instances according to the authorization identifier. The first target credentials are used to determine whether the data security center has the right to access the multiple database instances, and the database instances in the multiple database instances include at least one database. This solves the technical problem that when a user needs the data security center to identify sensitive data of database assets, the user can only perform credential authorization on the data security center on the authorization page corresponding to each database asset respectively, resulting in relatively low efficiency of sensitive data identification. In this solution, the data security center directly receives the authorization request initiated by the target object, and then, according to the authorization identifier, determines the adopted authorization method. The data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of performing credential authorization on the data security center on the authorization page corresponding to each database asset, improving the authorization efficiency of the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.
[0108] Optionally, in the authorization apparatus provided in the second embodiment of the present application, the obtaining unit includes: a first determining subunit, configured to determine an authorization method for authorizing access to the data security center according to the authorization identifier, where the authorization method is one of the following: a first authorization method, a second authorization method, and a third authorization method. The first authorization method is an authorization method when the target object provides credentials. The second authorization method is an authorization method when the target object does not provide credentials. The third authorization method is an authorization method when the target object provides credentials and the corresponding relationship between the credentials and the database instances. An obtaining subunit, configured to obtain first target credentials of multiple database instances according to the authorization method.
[0109] Optionally, in the authorization device provided in the second embodiment of the present application, if the authorization method is the first authorization method, the obtaining subunit includes: a first receiving module, configured to receive a first credential input by a target object through a credential management interface in a data security center, where the first credential at least includes a first account number and password information corresponding to the first account number; a first establishing module, configured to establish a first associated authorization relationship between the first credential and multiple database instances; a first obtaining module, configured to obtain a first target credential according to the first associated authorization relationship and the first credential.
[0110] Optionally, in the authorization device provided in the second embodiment of the present application, if the authorization method is the first authorization method, the obtaining subunit includes: a second receiving module, configured to receive a credential association request for a database in multiple database instances through an asset management interface in the data security center, where the credential association request at least includes a second credential corresponding to the multiple database instances, and the second credential at least includes a second account number and password information corresponding to the second account number; a second establishing module, configured to establish a second associated authorization relationship between the database in the multiple database instances and the second credential according to the credential association request; a second obtaining module, configured to obtain a first target credential according to the second associated authorization relationship and the second credential.
[0111] Optionally, in the authorization device provided in the second embodiment of the present application, if the authorization method is the second authorization method, the obtaining subunit includes: a third establishing module, configured to establish a third account number and password information corresponding to the third account number, where the access right of the third account number is read-only access; a first determining module, configured to determine a third credential according to the third account number and the password information corresponding to the third account number; a fourth establishing module, configured to establish a third associated authorization relationship between the third credential and multiple database instances; a third obtaining module, configured to obtain a first target credential according to the third associated authorization relationship and the third credential.
[0112] Optionally, in the authorization device provided in the second embodiment of the present application, if the authorization method is the third authorization method, the obtaining subunit includes: a third receiving module, configured to receive an authorization form input by a target object, where the authorization form at least includes identification information of a database instance in multiple database instances, a fourth credential, and a corresponding relationship between the identification information and the fourth credential; an identifying module, configured to identify the authorization form to obtain the identification information and the fourth credential; a fifth establishing module, configured to establish a fourth associated authorization relationship between the fourth credential and multiple database instances according to the identification information and the corresponding relationship; a fourth obtaining module, configured to obtain a first target credential according to the fourth associated authorization relationship and the fourth credential.
[0113] Optionally, in the authorization device provided in the second embodiment of the present application, the device further includes: an access unit, configured to, after obtaining first target credentials of multiple database instances according to an authorization identifier, when receiving a sensitive data recognition request initiated by a target object for a target database instance among the multiple database instances, access the target database instance according to the sensitive data recognition request; and an identification unit, configured to perform sensitive data recognition on the databases in the target database instance to obtain an identification result.
[0114] Optionally, in the authorization device provided in the second embodiment of the present application, the access unit includes: a second determination subunit, configured to determine second target credentials of the target database instance from the first target credentials according to the sensitive data recognition request; and an access subunit, configured to access the target database instance according to the second target credentials.
[0115] Optionally, in the authorization device provided in the second embodiment of the present application, the access subunit includes: a second determination module, configured to determine a target server of the database in the target database instance; a sixth establishment module, configured to establish a reverse access network with the target server, and obtain an access address and an access port of the database in the target database instance according to the reverse access network; a sixth establishment module, configured to establish a mapped access address and a mapped access port according to the access address and the access port; and an access module, configured to access the mapped access address and the mapped access port according to the second target credentials to access the target database instance.
[0116] Optionally, in the authorization device provided in the second embodiment of the present application, the device further includes: a first scanning unit, configured to scan database assets corresponding to the target object according to a preset time period to obtain a database instance list before receiving an authorization request initiated by the target object; or a second scanning unit, configured to scan database assets corresponding to the target object according to a trigger instruction of the target object to obtain a database instance list.
[0117] It should be noted here that the above receiving unit 1001 and obtaining unit 1002 correspond to steps S201 to S202 in the first embodiment. The instances and application scenarios implemented by the two units and the corresponding steps are the same, but are not limited to the content disclosed in the first embodiment above. It should be noted that the above modules, as a part of the device, can run in the computer terminal 10 provided in the first embodiment.
[0118] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as the schemes, application scenarios, and implementation processes provided in the first embodiment, but are not limited to the schemes provided in the first embodiment.
[0119] Embodiment 3
[0120] Embodiments of the present application may provide a computer terminal, which may be any computer terminal device in a group of computer terminals. Optionally, in this embodiment, the above computer terminal may also be replaced with a terminal device such as a mobile terminal.
[0121] Optionally, in this embodiment, the above computer terminal may be located in at least one of multiple network devices in a computer network.
[0122] In this embodiment, the above computer terminal may execute program code for the following steps in an authorization method: receiving an authorization request initiated by a target object, where the authorization request at least includes an authorization identifier for indicating an authorization method for authorizing access to a data security center; obtaining first target credentials for multiple database instances based on the authorization identifier, where the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, and the database instances in the multiple database instances at least include one database.
[0123] The above computer terminal may execute program code for the following steps in an authorization method: obtaining first target credentials for multiple database instances based on the authorization identifier includes: determining, based on the authorization identifier, an authorization method for authorizing access to the data security center, where the authorization method is one of the following: a first authorization method, a second authorization method, and a third authorization method. The first authorization method is an authorization method when the target object provides credentials, the second authorization method is an authorization method when the target object does not provide credentials, and the third authorization method is an authorization method when the target object provides credentials and the corresponding relationship between the credentials and the database instances; obtaining first target credentials for multiple database instances based on the authorization method.
[0124] The above computer terminal may execute program code for the following steps in an authorization method: if the authorization method is the first authorization method, obtaining first target credentials for multiple database instances based on the authorization method includes: receiving, through a credential management interface in the data security center, a first credential input by the target object, where the first credential at least includes a first account number and password information corresponding to the first account number; establishing a first associated authorization relationship between the first credential and the multiple database instances; obtaining first target credentials based on the first associated authorization relationship and the first credential.
[0125] The above computer terminal can execute the program code for the following steps in the authorization method: If the authorization method is the first authorization method, obtaining the first target credentials for multiple database instances according to the authorization method includes: receiving, through the asset management interface in the data security center, a credential association request for the databases in the multiple database instances, where the credential association request at least includes second credentials corresponding to the multiple database instances, and the second credentials at least include a second account and password information corresponding to the second account; establishing a second association authorization relationship between the databases in the multiple database instances and the second credentials according to the credential association request; and obtaining the first target credentials according to the second association authorization relationship and the second credentials.
[0126] The above computer terminal can execute the program code for the following steps in the authorization method: If the authorization method is the second authorization method, obtaining the first target credentials for multiple database instances according to the authorization method includes: establishing a third account and password information corresponding to the third account, where the access privilege of the third account is read-only access; determining third credentials according to the third account and the password information corresponding to the third account; establishing a third association authorization relationship between the third credentials and the multiple database instances; and obtaining the first target credentials according to the third association authorization relationship and the third credentials.
[0127] The above computer terminal can execute the program code for the following steps in the authorization method: If the authorization method is the third authorization method, obtaining the first target credentials for multiple database instances according to the authorization method includes: receiving an authorization form input by a target object, where the authorization form at least includes identification information of the database instances in the multiple database instances, fourth credentials, and the corresponding relationship between the identification information and the fourth credentials; identifying the authorization form to obtain the identification information and the fourth credentials; establishing a fourth association authorization relationship between the fourth credentials and the multiple database instances according to the identification information and the corresponding relationship; and obtaining the first target credentials according to the fourth association authorization relationship and the fourth credentials.
[0128] The above computer terminal can execute the program code for the following steps in the authorization method: After obtaining the first target credentials for multiple database instances according to the authorization identifier, the method further includes: in the case of receiving a sensitive data identification request initiated by a target object for a target database instance in the multiple database instances, accessing the target database instance according to the sensitive data identification request; and performing sensitive data identification on the database in the target database instance to obtain an identification result.
[0129] The above computer terminal can execute the program code for the following steps in the authorization method: When receiving a sensitive data recognition request for a target database instance among multiple database instances initiated by a target object, accessing the target database instance according to the sensitive data recognition request includes: determining a second target credential of the target database instance from a first target credential according to the sensitive data recognition request; and accessing the target database instance according to the second target credential.
[0130] The above computer terminal can execute the program code for the following steps in the authorization method: Accessing the target database instance according to the second target credential includes: determining a target server of the database in the target database instance; establishing a reverse access network with the target server, and obtaining an access address and an access port of the database in the target database instance according to the reverse access network; establishing a mapped access address and a mapped access port according to the access address and the access port; and accessing the mapped access address and the mapped access port according to the second target credential to access the target database instance.
[0131] The above computer terminal can execute the program code for the following steps in the authorization method: Before receiving an authorization request initiated by a target object, the method further includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to a trigger instruction of the target object to obtain a list of database instances.
[0132] Optionally, Figure 11 is a structural block diagram of a computer terminal according to an embodiment of the present application. As Figure 11 shown, the computer terminal 10 may include: one or more ( Figure 11 only one is shown in the figure) processors 102, a memory 104. The computing terminal 10 may further include a storage controller for controlling and managing the memory 104 through the storage controller; the computing terminal 10 may further include a peripheral interface for connecting a radio frequency module, an audio module, a display screen, etc. through the peripheral interface.
[0133] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the authorization method and device in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implementing the above authorization method. The memory may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, an enterprise internal network, a local area network, a mobile communication network, and combinations thereof.
[0134] The processor can call the information and application programs stored in the memory through a transmission device to execute the following steps: receiving an authorization request initiated by a target object, where the authorization request at least includes an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center; obtaining first target credentials of multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the permission to access the multiple database instances, and the database instances in the multiple database instances at least include one database.
[0135] Optionally, the above-mentioned processor can also execute the program code of the following steps: obtaining the first target credentials of multiple database instances according to the authorization identifier includes: determining the authorization method for authorizing access to the data security center according to the authorization identifier, where the authorization method is one of the following: the first authorization method, the second authorization method, and the third authorization method. The first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, and the third authorization method is the authorization method when the target object provides credentials and the corresponding relationship between the credentials and the database instances; obtaining the first target credentials of multiple database instances according to the authorization method.
[0136] Optionally, the above-mentioned processor can also execute the program code of the following steps: if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, where the first credentials at least include a first account number and password information corresponding to the first account number; establishing a first associated authorization relationship between the first credentials and the multiple database instances; obtaining the first target credentials according to the first associated authorization relationship and the first credentials.
[0137] Optionally, the above-mentioned processor can also execute the program code of the following steps: if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving a credential association request for the databases in the multiple database instances through the asset management interface in the data security center, where the credential association request at least includes second credentials corresponding to the multiple database instances, and the second credentials at least include a second account number and password information corresponding to the second account number; establishing a second associated authorization relationship between the databases in the multiple database instances and the second credentials according to the credential association request; obtaining the first target credentials according to the second associated authorization relationship and the second credentials.
[0138] Optionally, the above-mentioned processor may also execute the program code of the following steps: If the authorization method is the second authorization method, obtaining the first target credentials for multiple database instances according to the authorization method includes: establishing a third account and the password information corresponding to the third account, where the access permission of the third account is read-only access; determining the third credentials according to the third account and the password information corresponding to the third account; establishing a third associated authorization relationship between the third credentials and multiple database instances; and obtaining the first target credentials according to the third associated authorization relationship and the third credentials.
[0139] Optionally, the above-mentioned processor may also execute the program code of the following steps: If the authorization method is the third authorization method, obtaining the first target credentials for multiple database instances according to the authorization method includes: receiving an authorization form input by a target object, where the authorization form at least includes the identification information of the database instance in multiple database instances, the fourth credentials, and the corresponding relationship between the identification information and the fourth credentials; identifying the authorization form to obtain the identification information and the fourth credentials; establishing a fourth associated authorization relationship between the fourth credentials and multiple database instances according to the identification information and the corresponding relationship; and obtaining the first target credentials according to the fourth associated authorization relationship and the fourth credentials.
[0140] Optionally, the above-mentioned processor may also execute the program code of the following steps: After obtaining the first target credentials for multiple database instances according to the authorization identifier, the method further includes: when receiving a sensitive data identification request initiated by a target object for a target database instance in multiple database instances, accessing the target database instance according to the sensitive data identification request; and performing sensitive data identification on the databases in the target database instance to obtain an identification result.
[0141] Optionally, the above-mentioned processor may also execute the program code of the following steps: When receiving a sensitive data identification request initiated by a target object for a target database instance in multiple database instances, accessing the target database instance according to the sensitive data identification request includes: determining the second target credentials of the target database instance from the first target credentials according to the sensitive data identification request; and accessing the target database instance according to the second target credentials.
[0142] Optionally, the above-mentioned processor may also execute the program code of the following steps: Accessing the target database instance according to the second target credentials includes: determining the target server of the database in the target database instance; establishing a reverse access network with the target server, and obtaining the access address and access port of the database in the target database instance according to the reverse access network; establishing a mapped access address and a mapped access port according to the access address and the access port; and accessing the mapped access address and the mapped access port according to the second target credentials to access the target database instance.
[0143] Optionally, the above-mentioned processor may also execute the program code of the following steps: Before receiving the authorization request initiated by the target object, the method further includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or, scanning the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.
[0144] Those of ordinary skill in the art can understand that Figure 11 The structure shown is only for illustration, and the computer terminal may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, and a mobile Internet device (Mobile Internet Devices, MID), a PAD and other terminal devices. Figure 11 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components (such as a network interface, a display device, etc.) than those shown in Figure 11 or have a different configuration from that shown in Figure 11 shown.
[0145] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disc, etc.
[0146] Embodiment 4
[0147] The embodiment of the present application further provides a computer-readable storage medium. Optionally, in this embodiment, the above storage medium may be used to save the program code executed by the authorization method provided in the first embodiment above.
[0148] Optionally, in this embodiment, the above storage medium may be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0149] Optionally, in this embodiment, the above storage medium is set to store the program code for executing the following steps: receiving an authorization request initiated by a target object, where the authorization request at least includes an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center; obtaining first target credentials of multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the right to access the multiple database instances, and the database instances in the multiple database instances at least include one database.
[0150] The above storage medium is configured to store program code for performing the following steps: Obtaining first target credentials of multiple database instances based on an authorization identifier includes: determining an authorization method for authorizing access to the data security center based on the authorization identifier, where the authorization method is one of the following: a first authorization method, a second authorization method, and a third authorization method. The first authorization method is an authorization method when providing credentials for a target object, the second authorization method is an authorization method when not providing credentials for the target object, and the third authorization method is an authorization method when providing credentials for the target object and the corresponding relationship between the credentials and the database instances; obtaining the first target credentials of the multiple database instances according to the authorization method.
[0151] The above storage medium is configured to store program code for performing the following steps: If the authorization method is the first authorization method, obtaining the first target credentials of the multiple database instances according to the authorization method includes: receiving, through a credential management interface in the data security center, a first credential input by a target object, where the first credential includes at least a first account number and password information corresponding to the first account number; establishing a first associated authorization relationship between the first credential and the multiple database instances; obtaining the first target credentials based on the first associated authorization relationship and the first credential.
[0152] The above storage medium is configured to store program code for performing the following steps: If the authorization method is the first authorization method, obtaining the first target credentials of the multiple database instances according to the authorization method includes: receiving, through an asset management interface in the data security center, a credential association request for databases in the multiple database instances, where the credential association request includes at least a second credential corresponding to the multiple database instances, and the second credential includes at least a second account number and password information corresponding to the second account number; establishing a second associated authorization relationship between the databases in the multiple database instances and the second credential according to the credential association request; obtaining the first target credentials based on the second associated authorization relationship and the second credential.
[0153] The above storage medium is configured to store program code for performing the following steps: If the authorization method is the second authorization method, obtaining the first target credentials of the multiple database instances according to the authorization method includes: establishing a third account number and password information corresponding to the third account number, where the access right of the third account number is read-only access; determining a third credential based on the third account number and the password information corresponding to the third account number; establishing a third associated authorization relationship between the third credential and the multiple database instances; obtaining the first target credentials based on the third associated authorization relationship and the third credential.
[0154] The above storage medium is configured to store program code for performing the following steps: If the authorization method is the third authorization method, obtaining first target credentials for multiple database instances according to the authorization method includes: receiving an authorization form input by a target object, where the authorization form at least includes identification information of a database instance among multiple database instances, a fourth credential, and a correspondence relationship between the identification information and the fourth credential; identifying the authorization form to obtain the identification information and the fourth credential; establishing a fourth associated authorization relationship between the fourth credential and multiple database instances according to the identification information and the correspondence relationship; and obtaining first target credentials according to the fourth associated authorization relationship and the fourth credential.
[0155] The above storage medium is configured to store program code for performing the following steps: After obtaining first target credentials for multiple database instances according to an authorization identifier, the method further includes: when receiving a sensitive data identification request initiated by a target object for a target database instance among multiple database instances, accessing the target database instance according to the sensitive data identification request; and performing sensitive data identification on the database in the target database instance to obtain an identification result.
[0156] The above storage medium is configured to store program code for performing the following steps: When receiving a sensitive data identification request initiated by a target object for a target database instance among multiple database instances, accessing the target database instance according to the sensitive data identification request includes: determining a second target credential of the target database instance from the first target credentials according to the sensitive data identification request; and accessing the target database instance according to the second target credential.
[0157] The above storage medium is configured to store program code for performing the following steps: Accessing the target database instance according to the second target credential includes: determining a target server of the database in the target database instance; establishing a reverse access network with the target server, and obtaining an access address and an access port of the database in the target database instance according to the reverse access network; establishing a mapped access address and a mapped access port according to the access address and the access port; and accessing the mapped access address and the mapped access port according to the second target credential to access the target database instance.
[0158] The above storage medium is configured to store program code for performing the following steps: Before receiving an authorization request initiated by a target object, the method further includes: scanning database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning database assets corresponding to the target object according to a trigger instruction of the target object to obtain a list of database instances.
[0159] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0160] In the above embodiments of the present application, the descriptions of the respective embodiments each have their own emphasis. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0161] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0162] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0163] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0164] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks or optical discs, and other media that can store program codes.
[0165] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. An authorization method, characterized in that, The authorization method is applied to a data security center and includes: Receiving an authorization request initiated by a target object, where the authorization request includes at least an authorization identifier for indicating an authorization method for accessing the data security center. Obtaining first target credentials for multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the permission to access the multiple database instances, and the database instances in the multiple database instances include at least one database.
2. The method according to claim 1, wherein The obtaining first target credentials for multiple database instances according to the authorization identifier includes: Determining an authorization method for accessing the data security center according to the authorization identifier, where the authorization method is one of the following: a first authorization method, a second authorization method, and a third authorization method. The first authorization method is the authorization method when the target object provides credentials. The second authorization method is the authorization method when the target object does not provide credentials. The third authorization method is the authorization method when the target object provides credentials and the corresponding relationship between the credentials and the database instances. Obtaining first target credentials for multiple database instances according to the authorization method.
3. The method according to claim 2, characterized in that If the authorization method is the first authorization method, the obtaining first target credentials for multiple database instances according to the authorization method includes: Receiving a first credential input by the target object through a credential management interface in the data security center, where the first credential includes at least a first account and password information corresponding to the first account. Establishing a first associated authorization relationship between the first credential and the multiple database instances. Obtaining the first target credentials according to the first associated authorization relationship and the first credential.
4. The method according to claim 2, wherein If the authorization method is the first authorization method, the obtaining first target credentials for multiple database instances according to the authorization method includes: Receiving a credential association request for the databases in the multiple database instances through an asset management interface in the data security center, where the credential association request includes at least a second credential corresponding to the multiple database instances, and the second credential includes at least a second account and password information corresponding to the second account. Establishing a second associated authorization relationship between the databases in the multiple database instances and the second credential according to the credential association request. Obtaining the first target credentials according to the second associated authorization relationship and the second credential.
5. The method according to claim 2, wherein If the authorization method is the second authorization method, the obtaining first target credentials for multiple database instances according to the authorization method includes: Establishing a third account and password information corresponding to the third account, where the access permission of the third account is read-only access. Determining a third credential according to the third account and the password information corresponding to the third account. Establishing a third associated authorization relationship between the third credential and the multiple database instances. Obtaining the first target credentials according to the third associated authorization relationship and the third credential.
6. The method according to claim 2, characterized in that, If the authorization method is the third authorization method, the first target credentials for obtaining multiple database instances according to the authorization method include: Receiving an authorization form input by the target object, where the authorization form at least includes identification information of a database instance in the multiple database instances, a fourth credential, and a correspondence between the identification information and the fourth credential; Identifying the authorization form to obtain the identification information and the fourth credential; Establishing a fourth associated authorization relationship between the fourth credential and the multiple database instances according to the identification information and the correspondence; Obtaining the first target credentials according to the fourth associated authorization relationship and the fourth credential.
7. The method according to claim 1, wherein After obtaining the first target credentials for multiple database instances according to the authorization identifier, the method further includes: When receiving a sensitive data identification request for a target database instance in the multiple database instances initiated by the target object, accessing the target database instance according to the sensitive data identification request; Performing sensitive data identification on the databases in the target database instance to obtain an identification result.
8. The method according to claim 7, characterized in that When receiving a sensitive data identification request for a target database instance in the multiple database instances initiated by the target object, accessing the target database instance according to the sensitive data identification request includes: Determining a second target credential of the target database instance from the first target credentials according to the sensitive data identification request; Accessing the target database instance according to the second target credential.
9. The method according to claim 8, wherein Accessing the target database instance according to the second target credential includes: Determining a target server of the database in the target database instance; Establishing a reverse access network with the target server, and obtaining an access address and an access port of the database in the target database instance according to the reverse access network; Establishing a mapped access address and a mapped access port according to the access address and the access port; Accessing the mapped access address and the mapped access port according to the second target credential to access the target database instance.
10. The method according to claim 1, wherein Before receiving an authorization request initiated by a target object, the method further includes: Scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or, Scanning the database assets corresponding to the target object according to a trigger instruction of the target object to obtain the list of database instances.
11. An authorization device, characterized in that, Including: A receiving unit, configured to receive an authorization request initiated by a target object, where the authorization request at least includes an authorization identifier for indicating an authorization method for authorizing access to a data security center; An obtaining unit, configured to obtain first target credentials for multiple database instances according to the authorization identifier, where the first target credentials are used to determine whether the data security center has the right to access the multiple database instances, and the database instances in the multiple database instances at least include one database.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein when the program runs, it controls the device where the storage medium is located to execute the authorization method described in any one of claims 1 to 10.
13. An electronic device, characterized in that, Comprising: a memory storing an executable program; a processor for running the program, wherein when the program runs, it executes the authorization method described in any one of claims 1 to 10.