Method for realizing general data encryption based on service grid

By using sidecar containers and proxy gateways in the service grid, dynamically loading the encryption algorithm plug-in package, and unified management of keys and encryption rules, the problem of decentralized management of keys and encryption rules in the existing technology is solved, seamless access to multiple databases and data encryption in multiple scenarios is achieved, and the flexibility and security of the system are improved.

CN120217418AActive Publication Date: 2025-06-27云筑信息科技(成都)有限公司
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510718925.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-06-27
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

In the prior art, the data encryption scheme has keys and encryption rules scattered in various systems and cannot be centrally managed, resulting in low security standards and poor compatibility, limiting the flexibility of the system, and does not support row-and-column encryption in tables, limited business scenarios, and difficulty in transforming and upgrading old systems and heterogeneous language systems.

Method used

Using a service mesh-based method, intercepts and parses business requests through sidecar containers and proxy gateways, dynamically loads the encryption algorithm plug-in package, unified management of keys and encryption rules, realizes parsing, rewriting and execution of SQL statements, and supports row and column encryption in tables.

Benefits of technology

It realizes centralized management of keys and encryption rules, improves security standards, supports seamless access to multiple databases, realizes data encryption in multiple scenarios, improves system flexibility and scalability, and simplifies system maintenance and upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217418A_ABST
    Figure CN120217418A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, and discloses a method for realizing universal data encryption based on a service grid, which comprises the following steps of: adding a corresponding side vehicle container in a Pod when a first business system is deployed online; when the side vehicle container is started, first configuration information, including target database instance information, an encryption algorithm, a key and an encryption rule, corresponding to the first service system is pulled from the control plane; the side vehicle container adds an iptables rule to the target database instance information; the first service system initiates a first service request; the side vehicle container intercepts the first service request and performs database binary protocol specification analysis on the intercepted first service request to obtain a first SQL statement; and the sidecar container performs SQL analysis, SQL rewriting and SQL execution on the first SQL statement. The technical problems that in the prior art, secret keys and encryption rules are dispersed in all systems and cannot be managed in a centralized mode, and the safety standard is low are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method for implementing universal data encryption based on a service grid. Background Art

[0002] In the context of trusted data security, especially in scenarios such as cloud computing and big data, secure storage of enterprise data is of vital importance. Data encryption has become one of the key means to protect enterprise data and user personal privacy information (ID card, mobile phone number, bank card number, etc.).

[0003] The existing technology implements data encryption based on SDK, specifically based on AOP technology reflection to obtain entity attributes and encrypt and decrypt its fields; based on native JDBC or ORM framework to implement data encryption and decryption; in addition, the entire data file is encrypted. To implement encryption based on the ORM framework, the system needs to be strongly coupled with the encryption SDK, which is difficult to maintain and upgrade, has poor compatibility, and limits the flexibility of the system; keys and encryption rules are scattered in various systems and cannot be centrally managed, the security standard is low, and there is no unified specification, so data cannot be shared; based on the encrypted storage method of data files, the entire file is encrypted, and encryption of rows and columns in the table is not supported, which is not flexible enough and has limited business scenarios; it is difficult to transform and upgrade old systems and systems in heterogeneous languages. Summary of the invention

[0004] The technical problem to be solved by the present invention is to provide a method for implementing universal data encryption based on a service grid, so as to at least solve some of the above technical problems.

[0005] To achieve the above purpose, the technical solution adopted by the present invention is as follows: A method for implementing universal data encryption based on a service grid comprises the following steps: S1. When the first business system is deployed online, add the corresponding sidecar container to the Pod; S2. When the sidecar container is started, it pulls the first configuration information corresponding to the first business system from the control plane. The first configuration information includes: target database instance information, encryption algorithm, key, and encryption rule; S3. The sidecar container adds iptables rules to the target database instance information in the first configuration information; S4. The first business system initiates a first business request; S5. The sidecar container intercepts the first business request according to the iptables rule and performs target database binary protocol specification parsing on the intercepted first business request to obtain a first SQL statement. S6. The sidecar container determines whether the first SQL statement has a library table field encryption operation according to the encryption rules in the first configuration information; if there is a library table field encryption operation, the first SQL statement is SQL parsed, SQL rewritten, and SQL executed according to the encryption rules, encryption algorithm, and key in the first configuration information; otherwise, the first SQL statement is SQL executed.

[0006] Furthermore, the process of performing SQL parsing, SQL rewriting and SQL execution on the first SQL statement includes: SQL parsing: converting the first SQL statement into corresponding first structured data through a parser; SQL rewriting: obtaining the fields to be encrypted in the first structured data according to the encryption rules in the first configuration information; obtaining the encrypted values ​​of the fields to be encrypted by the encryption algorithm; replacing the plaintext values ​​in the first SQL statement with the encrypted values ​​to generate a third SQL statement; SQL execution: parsing the user name, password, driver type, and target database address in the first configuration information, establishing a target database connection through the user name, password, driver type, and target database address, executing the third SQL statement, and processing the corresponding result set; If there are fields in the result set that need to be decrypted, the fields in the result set that need to be decrypted are decrypted according to the corresponding encryption algorithm.

[0007] Furthermore, S1 also includes: SA: For the second business system that cannot install the sidecar container, the sidecar is centrally deployed to form a proxy gateway; When the SB and proxy gateway are started, they obtain the second configuration information corresponding to the second business system from the control plane, where the second configuration information includes: target database instance information, encryption rules, encryption algorithm, and key; SC and the second service system initiate a second service request; The SD and the proxy gateway parse the second service request according to the target database binary protocol specification to obtain a second SQL statement; The SE and the proxy gateway determine whether the second SQL statement has a library table field encryption operation based on the encryption rules in the second configuration information; if there is a library table field encryption operation, the second SQL statement is SQL parsed, SQL rewritten, and SQL executed based on the encryption rules, encryption algorithm, and key in the second configuration information; otherwise, the second SQL statement is SQL executed.

[0008] Furthermore, the process of performing SQL parsing, SQL rewriting and SQL execution on the second SQL statement includes: SQL parsing: converting the second SQL statement into corresponding second structured data through a parser; SQL Rewriting: Obtain the fields to be encrypted in the second structured data according to the encryption rules in the second configuration information; obtain the encrypted values of the fields to be encrypted through an encryption algorithm; replace the plaintext values in the second SQL statement with the encrypted values to generate a fourth SQL statement; SQL Execution: Parse the username, password, driver type, and target database address in the second configuration information, establish a target database connection through the username, password, driver type, and target database address, execute the fourth SQL statement, and process the corresponding result set; If there are fields to be decrypted in the result set, decrypt the fields to be decrypted in the result set according to the corresponding encryption algorithm.

[0009] Furthermore, parse the first SQL statement or the second SQL statement into a first abstract syntax tree or a second abstract syntax tree through a JSqlParser parser.

[0010] Furthermore, S2 also includes: obtaining multiple encryption algorithms from the control plane, each encryption algorithm corresponding to a plugin package, and the sidecar container downloads and dynamically loads the plugin packages corresponding to the encryption algorithms from the control plane.

[0011] Furthermore, the method of dynamic loading is the Java SPI mechanism.

[0012] Furthermore, the encryption algorithms include: MD5, RSA, AES, SM4.

[0013] Furthermore, the target databases include: mysql, db2, oracle, and tidb.

[0014] Furthermore, the second business system includes a first client that can only be deployed on the host, and the first client includes: Go app1, Java app2; the second business system also includes a second client with a database protocol, and the second client includes: dbeaver, mysql CLI, and mysql GUI.

[0015] Compared with the prior art, the present invention has the following beneficial effects: In the present invention, a sidecar container intercepts a first service request of a first service system and parses the intercepted first service request according to the binary protocol specification of a target database to obtain a first SQL statement. Then, based on first configuration information obtained from a control plane, SQL parsing, SQL rewriting, SQL execution are performed, or data encryption and decryption are completed through SQL execution. The present invention also receives a second service request of a second service system through a proxy gateway and parses the second service request according to the binary protocol specification of the target database to obtain a second SQL statement. Then, based on second configuration information obtained from the control plane, SQL parsing, SQL rewriting, SQL execution are performed, or data encryption and decryption are completed through SQL execution. The first configuration information and the second configuration information respectively loaded by the sidecar container and the proxy gateway are uniformly managed and distributed by the control plane, solving the technical problem in the prior art that keys and encryption rules are scattered in each system and cannot be centrally managed, and the security standard is low. In addition, the service can seamlessly access different databases without any modification, realizing data encryption in multiple scenarios.

[0016] In the present invention, multiple encryption algorithms are obtained from the control plane, and each encryption algorithm corresponds to a plugin package. The sidecar container downloads and dynamically loads the plugin package corresponding to the encryption algorithm from the control plane, which can achieve dynamic configuration and good scalability, realizing high availability and scalability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flowchart of the steps of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] TERMINOLOGY EXPLANATION: A Pod is the smallest deployment unit in Kubernetes and can contain one or more containers; Iptables is a tool for configuring firewall rules in the Linux system; SQL is a standard programming language for managing relational databases; A Statement is an object for executing SQL statements; PreparedStatement is a sub-interface of Statement; JSqlParser is a Java library; Java SPI is a service provider interface mechanism that allows third parties to implement or extend the functions of an application; DBA is a platform for managing and monitoring databases; MD5 is a hash function; RSA is an asymmetric encryption algorithm; AES is a symmetric encryption algorithm; SM4 is a domestic symmetric encryption algorithm; Mysql is a popular open-source relational database management system; Db2 is a relational database management system developed by IBM; Oracle is an enterprise-level relational database management system; TiDB is a distributed relational database; Go app1 is a client application written in the Go language; Java app2 is a client application written in the Java language; DBeaver is a multi-database management tool; mysql CLI is the command-line tool for MySQL; mysql GUI is the graphical management tool for MySQL; To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0019] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation or be constructed and operated in a specific orientation, so it should not be construed as a limitation of the present invention. In addition, the terms "first", "second", "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.

[0020] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "installed", "connected", "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; of course, it can also be a mechanical connection or an electrical connection; in addition, it can also be directly connected, or indirectly connected through an intermediate medium, or the internal communication of two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0021] As Figure 1As shown, a method for implementing universal data encryption based on a service grid includes the following steps: S1. When the first business system is deployed online, add the corresponding sidecar container to the Pod; S2. When the sidecar container is started, it pulls the first configuration information corresponding to the first business system from the control plane. The first configuration information includes: target database instance information, encryption algorithm, key, and encryption rule; S3. The sidecar container adds iptables rules to the target database instance information in the first configuration information; S4. The first business system initiates a first business request; S5. The sidecar container intercepts the first business request according to the iptables rule and performs target database binary protocol specification parsing on the intercepted first business request to obtain a first SQL statement. S6. The sidecar container determines whether the first SQL statement has a library table field encryption operation according to the encryption rules in the first configuration information; if there is a library table field encryption operation, the first SQL statement is SQL parsed, SQL rewritten, and SQL executed according to the encryption rules, encryption algorithm, and key in the first configuration information; otherwise, the first SQL statement is SQL executed.

[0022] Encryption algorithms include: MD5, RSA, AES, and SM4.

[0023] The target databases include: mysql, db2, oracle, and tidb.

[0024] In this embodiment, the sidecar container completes the interception of the first business request of the first business system and performs target database binary protocol specification analysis on the intercepted first business request to obtain the first SQL statement, and then performs SQL analysis, SQL rewriting, SQL execution or SQL execution based on the first configuration information obtained from the control plane to complete data encryption and decryption. The first configuration information loaded by the sidecar container is uniformly managed and issued by the control plane, which solves the technical problems in the prior art that keys and encryption rules are scattered in various systems and cannot be centrally managed, and the security standards are low. In addition, the business can complete seamless access to different databases without any modification, realizing data encryption in various scenarios.

[0025] The present invention implements a method for universal data encryption based on a service grid. In one embodiment, the process of performing SQL parsing, SQL rewriting, and SQL execution on a first SQL statement includes: SQL parsing: converting the first SQL statement into corresponding first structured data through a parser; SQL rewriting: obtaining the fields to be encrypted in the first structured data according to the encryption rules in the first configuration information; obtaining the encrypted values ​​of the fields to be encrypted by the encryption algorithm; replacing the plaintext values ​​in the first SQL statement with the encrypted values ​​to generate a third SQL statement; SQL execution: parsing the user name, password, driver type, and target database address in the first configuration information, establishing a target database connection through the user name, password, driver type, and target database address, executing the third SQL statement, and processing the corresponding result set; If there are fields in the result set that need to be decrypted, the fields in the result set that need to be decrypted are decrypted according to the corresponding encryption algorithm.

[0026] In this embodiment, SQL rewriting implements encryption of rows and columns in a table. Compared with the prior art that does not support encryption of rows and columns in a table, this embodiment is more flexible and applicable to a wider range of business scenarios.

[0027] The present invention implements a method for universal data encryption based on a service grid, wherein in one embodiment, S1 further includes: SA: For the second business system that cannot install the sidecar container, the sidecar is centrally deployed to form a proxy gateway; When the SB and proxy gateway are started, they obtain the second configuration information corresponding to the second business system from the control plane, where the second configuration information includes: target database instance information, encryption rules, encryption algorithm, and key; SC and the second service system initiate a second service request; The SD and the proxy gateway parse the second service request according to the target database binary protocol specification to obtain a second SQL statement; The SE and the proxy gateway determine whether the second SQL statement has a library table field encryption operation based on the encryption rules in the second configuration information; if there is a library table field encryption operation, the second SQL statement is SQL parsed, SQL rewritten, and SQL executed based on the encryption rules, encryption algorithm, and key in the second configuration information; otherwise, the second SQL statement is SQL executed.

[0028] Encryption algorithms include: MD5, RSA, AES, and SM4.

[0029] The target databases include: mysql, db2, oracle, and tidb.

[0030] The second business system includes a first client that can only be deployed on the host. The first client includes: Go app1 and Java app2. The second business system also includes a second client with a database protocol. The second client includes: dbeaver, mysql CLI, and mysql GUI. The first client is a client in an enterprise with heterogeneous languages or that cannot be containerized and can only be deployed on the host, solving the technical problem of difficult transformation and upgrade of old systems and systems with heterogeneous languages in the prior art.

[0031] In this embodiment, the proxy gateway receives the second business request of the second business system and parses the second business request according to the binary protocol specification of the target database to obtain the second SQL statement. Then, based on the second configuration information obtained from the control plane, SQL parsing, SQL rewriting, SQL execution, or data encryption and decryption are performed. The second configuration information loaded by the proxy gateway is uniformly managed and distributed by the control plane, solving the technical problem in the prior art that keys and encryption rules are scattered in each system and cannot be centrally managed, and the security standard is low. In addition, the service can seamlessly access different databases without any modification, realizing data encryption in multiple scenarios.

[0032] In one embodiment of the method for realizing general data encryption based on the service mesh of the present invention, the process of performing SQL parsing, SQL rewriting, and SQL execution on the second SQL statement includes: SQL parsing: converting the second SQL statement into the corresponding second structured data through a parser; SQL rewriting: obtaining the fields to be encrypted in the second structured data according to the encryption rules in the second configuration information; obtaining the encrypted values of the fields to be encrypted through an encryption algorithm; replacing the plaintext values in the second SQL statement with the encrypted values to generate the fourth SQL statement; SQL execution: parsing the username, password, driver type, and target database address in the second configuration information, establishing a target database connection through the username, password, driver type, and target database address, executing the fourth SQL statement, and processing the corresponding result set; If there are fields to be decrypted in the result set, decrypt the fields to be decrypted in the result set according to the corresponding encryption algorithm.

[0033] In this embodiment, SQL rewriting realizes encryption of rows and columns in the table. Compared with the prior art that does not support encryption of rows and columns in the table, this embodiment is more flexible and applicable to a wider range of business scenarios.

[0034] Preferably, the first SQL statement or the second SQL statement is parsed into the first abstract syntax tree or the second abstract syntax tree through the JSqlParser parser.

[0035] The method for implementing general data encryption based on a service mesh in the present invention. In one embodiment, S2 further includes: obtaining multiple encryption algorithms from the control plane, where each encryption algorithm corresponds to a plugin package, and the sidecar container downloads and dynamically loads the plugin package corresponding to the encryption algorithm from the control plane. The method for dynamic loading is the Java SPI mechanism.

[0036] In this embodiment, by obtaining multiple encryption algorithms from the control plane, where each encryption algorithm corresponds to a plugin package, and the sidecar container downloads and dynamically loads the plugin package corresponding to the encryption algorithm from the control plane, it is possible to achieve dynamic configuration and good scalability, and realize the high availability and scalability of the system.

[0037] Preferably, the method for dynamic loading is the Java SPI mechanism.

[0038] Finally, it should be noted that: the above embodiments are only relatively preferred embodiments of the present invention to illustrate the technical solutions of the present invention, rather than limiting it, and certainly not limiting the patent scope of the present invention; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention; that is to say, any meaningless changes or polishings made in the main design concept and spirit of the present invention, as long as the technical problems solved are still the same as those of the present invention, should be included in the protection scope of the present invention; in addition, directly or indirectly applying the technical solutions of the present invention to other related technical fields shall also be included in the patent protection scope of the present invention by the same token.

Claims

1. A method for implementing general data encryption based on a service mesh, characterized in that, The steps include: S1. When the first business system is deployed online, add the corresponding sidecar container to the Pod; S2. When the sidecar container is started, it pulls the first configuration information corresponding to the first business system from the control plane. The first configuration information includes: target database instance information, encryption algorithm, key, and encryption rule; S3. The sidecar container adds iptables rules to the target database instance information in the first configuration information; S4. The first business system initiates a first business request; S5. The sidecar container intercepts the first business request according to the iptables rule and performs target database binary protocol specification parsing on the intercepted first business request to obtain a first SQL statement. S6. The sidecar container determines whether the first SQL statement has a library table field encryption operation according to the encryption rules in the first configuration information; if there is a library table field encryption operation, the first SQL statement is SQL parsed, SQL rewritten, and SQL executed according to the encryption rules, encryption algorithm, and key in the first configuration information; otherwise, the first SQL statement is SQL executed.

2. The method for implementing general data encryption based on a service mesh according to claim 1, wherein The process of performing SQL parsing, SQL rewriting, and SQL execution on the first SQL statement includes: SQL parsing: converting the first SQL statement into corresponding first structured data through a parser; SQL rewriting: obtaining the fields to be encrypted in the first structured data according to the encryption rules in the first configuration information; obtaining the encrypted values ​​of the fields to be encrypted by the encryption algorithm; replacing the plaintext values ​​in the first SQL statement with the encrypted values ​​to generate a third SQL statement; SQL execution: parsing the user name, password, driver type, and target database address in the first configuration information, establishing a target database connection through the user name, password, driver type, and target database address, executing the third SQL statement, and processing the corresponding result set; If there are fields in the result set that need to be decrypted, the fields in the result set that need to be decrypted are decrypted according to the corresponding encryption algorithm.

3. A method for implementing general data encryption based on a service mesh according to claim 1, characterized in that, S1 also includes: SA: For the second business system that cannot install the sidecar container, the sidecar is centrally deployed to form a proxy gateway; When the SB and proxy gateway are started, they obtain the second configuration information corresponding to the second business system from the control plane, where the second configuration information includes: target database instance information, encryption rules, encryption algorithm, and key; SC and the second service system initiate a second service request; The SD and the proxy gateway parse the second service request according to the target database binary protocol specification to obtain a second SQL statement; The SE and the proxy gateway determine whether the second SQL statement has a library table field encryption operation based on the encryption rules in the second configuration information; if there is a library table field encryption operation, the second SQL statement is SQL parsed, SQL rewritten, and SQL executed based on the encryption rules, encryption algorithm, and key in the second configuration information; otherwise, the second SQL statement is SQL executed.

4. A method for implementing general data encryption based on a service mesh according to claim 3, characterized in that, The process of performing SQL parsing, SQL rewriting, and SQL execution on the second SQL statement includes: SQL parsing: converting the second SQL statement into corresponding second structured data through a parser; SQL Rewriting: Obtain the fields to be encrypted in the second structured data according to the encryption rules in the second configuration information; obtain the encrypted values of the fields to be encrypted through an encryption algorithm; replace the plaintext values in the second SQL statement with the encrypted values to generate a fourth SQL statement; SQL Execution: Parse the username, password, driver type, and target database address in the second configuration information, establish a target database connection through the username, password, driver type, and target database address, execute the fourth SQL statement, and process the corresponding result set; If there are fields to be decrypted in the result set, decrypt the fields to be decrypted in the result set according to the corresponding encryption algorithm.

5. A method for implementing general data encryption based on a service mesh according to claim 4, characterized in that Parse the first SQL statement or the second SQL statement into a first abstract syntax tree or a second abstract syntax tree through a JSqlParser parser.

6. The method for implementing general data encryption based on a service mesh according to claim 1, wherein, S2 further includes: obtaining multiple encryption algorithms from the control plane, each encryption algorithm corresponding to a plugin package, and the sidecar container downloads and dynamically loads the plugin packages corresponding to the encryption algorithms from the control plane.

7. A method for implementing general data encryption based on a service mesh according to claim 6, characterized in that, The method of dynamic loading is the Java SPI mechanism.

8. A method for implementing general data encryption based on a service mesh according to claim 1 or 3, characterized in that, Encryption algorithms include: MD5, RSA, AES, SM4.

9. A method for implementing general data encryption based on a service mesh according to claim 1 or 3, characterized in that Target databases include: mysql, db2, oracle, and tidb.

10. The method for implementing general data encryption based on a service mesh according to claim 3, wherein The second business system includes a first client that can only be deployed on the host. The first client includes: Go app1, Java app2; the second business system further includes a second client with a database protocol. The second client includes: dbeaver, mysql CLI, and mysql GUI.

Citation Information

Patent Citations

  • Service request interception method and related device

    CN108846065A

  • Systems and methods to run user space network stack inside docker container while bypassing container linux network stack

    CN110366720A

  • Data authority control method and device, electronic equipment and storage medium

    CN116756727A

  • Network access control method based on network side vehicle container

    CN119520040A

  • Input and output validation

    US20090044271A1