Data reading method and device, electronic equipment, storage medium and product

By performing security assessment of user fetch requests and dynamically generating blocking rules, the security risks of dynamic changes in the database are solved, and efficient and secure data reading and transmission are achieved.

CN120296793APending Publication Date: 2025-07-11CHINA MOBILE GROUP ZHEJIANG +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510455138.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing data reading technology has failed to effectively solve the security risks of dynamic changes in the database and has not involved data security assessment of the database itself, resulting in the failure to generate targeted blocking rules.

Method used

By obtaining the user's number fetch request, analyzing the request information and inputting it to the database security evaluation model for security evaluation, dynamically generate blocking rules, determining whether to block requests based on the security evaluation results, returning user data, and distributing data according to historical request preferences.

Benefits of technology

It improves the security and flexibility of database data reading, effectively prevents the security risks of dynamic changes, and ensures the security of data transmission and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296793A_ABST
    Figure CN120296793A_ABST
Patent Text Reader

Abstract

The invention provides a data reading method and device, electronic equipment, a storage medium and a product. The method comprises the following steps: analyzing a user access request to obtain request information; acquiring database information in the main database, inputting the database information into the database security evaluation model to obtain a security evaluation result, dynamically generating a blocking rule based on the security evaluation result, comparing the blocking rule with the request information to determine whether a blocking cause exists, if the blocking cause exists, stopping the access request, and if the blocking cause exists, stopping the access request. If the blocking cause does not exist, requesting a main database based on the access request; and returning the data in the main database requested based on the access request to the user. In the process, the data of the database is subjected to security evaluation; and the blocking rule is dynamically generated from the perspective of database security protection, so that the security and flexibility of data reading are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data reading, and particularly to a data reading method, device, electronic device, storage medium and product. Background Art

[0002] A database is a key component for storing and managing data. Data reading is one of the most basic functions in database operations, which allows users to retrieve stored information from the database. With the growth of business requirements and the development of technology, it becomes particularly important to read data efficiently and accurately.

[0003] In the existing data reading technology, corresponding blocking rules are generated according to the type of known request data to block non-compliant request data, but it does not involve the data security assessment of the database itself, nor is it generating blocking rules from the perspective of database security protection, and it fails to solve the security hidden trouble problems brought by the dynamically changing database risks. Summary of the Invention

[0004] The present invention provides a data reading method, device, electronic device, storage medium and product, which are used to solve the defects in the existing technology that corresponding blocking rules are generated according to the type of known request data to block non-compliant request data, but it does not involve the data security assessment of the database itself, nor is it generating blocking rules from the perspective of database security protection, and it fails to solve the security hidden trouble problems brought by the dynamically changing database risks.

[0005] The present invention provides a data reading method, including the following steps: Obtain the data fetching request of the user, and parse the data fetching request to obtain request information; Obtain the database information in the main database, input the database information into the database security assessment model for security assessment, obtain the security assessment result output by the database security assessment model, and dynamically generate a blocking rule based on the security assessment result. Compare the blocking rule with the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request; if there is no blocking reason, request the main database based on the data fetching request; Return the data in the main database requested based on the data fetching request to the user.

[0006] According to the data reading method provided by the present invention, the returning the data in the main database requested based on the data fetching request to the user includes: Parse the data fetching request to obtain the identifier of the requester; Based on the identifier of the requester, determine the historical request preference of the organization to which the requester belongs; Return the data in the main database requested based on the fetch request to the user according to the historical request preferences.

[0007] According to a data reading method provided by the present invention, the security assessment results include high-sensitive data leakage risk assessment results, data tampering risk assessment results, attack vulnerability risk assessment results, and data network risk assessment results; The dynamically generating blocking rules based on the security assessment results includes: Dynamically generate respective corresponding blocking rules based on the high-sensitive data leakage risk assessment results, the data tampering risk assessment results, the attack vulnerability risk assessment results, and the data network risk assessment results.

[0008] According to a data reading method provided by the present invention, the database security assessment model includes a first feature extraction branch, a second feature extraction branch, a fusion module, a linear layer, and a classification assessment module; The first feature extraction branch is used to extract the first features of the database information; The second feature extraction branch is used to extract high-dimensional features from the database information, and after channel equalization of the high-dimensional features, a first equalized feature and a second equalized feature are obtained. The first equalized feature is convolved in the local attention channel to obtain local features, the second equalized feature is convolved in the global attention channel to obtain global features, and the local features and the global features are fused to obtain second features; The fusion module is used to fuse the first feature and the second feature to obtain a fused feature; The linear layer is used to obtain extraction features based on the fused features; The classification assessment module is used to obtain the security assessment results based on the extraction features.

[0009] According to a data reading method provided by the present invention, the local attention channel includes three first convolutional layers, a second convolutional layer, and a third convolutional layer connected in series in sequence. The convolutional kernels of the first convolutional layer, the second convolutional layer, and the third convolutional layer are different. Among them, the first convolutional layer, the second convolutional layer, and the third convolutional layer are all connected to a local convolutional module; The convolving the first equalized feature in the local attention channel to obtain local features includes: Input the first equalized feature into the first convolutional layer to obtain a first-scale feature, and input the first-scale feature into the corresponding local convolutional module to obtain a first-scale local feature; Input the first-scale feature into a second convolutional layer to obtain a second-scale feature, and input the second-scale feature into a corresponding local convolutional module to obtain a second-scale local feature; Input the second-scale feature into the third convolutional layer to obtain a third-scale feature, and input the third-scale feature into a corresponding local convolutional module to obtain a third-scale local feature; Based on the first-scale local feature, the second-scale local feature, and the third-scale local feature, obtain the local feature.

[0010] According to a data reading method provided by the present invention, the obtaining the global feature by performing convolution on the second evenly-divided feature in the global attention channel includes: Perform window multi-head attention calculation and sliding window multi-head attention calculation on the second evenly-divided feature to obtain the global feature.

[0011] According to a data reading method provided by the present invention, the returning the data in the main database requested based on the data fetching request to the user according to the historical request preference includes: According to the historical request preference, take the data in the main database requested based on the data fetching request as a data fetching result, and divide the data fetching result into a first part of data and a second part of data; Send an acquisition token to the user, where the acquisition token includes the first part of data, a decryption token, a combination method, and a query token; Receive the query token, where the query token is returned by the user after receiving the acquisition token; Obtain an encryption number, encrypt the second part of data based on the encryption rule corresponding to the encryption number to obtain a target data, and send the target data to the user, so that the user decrypts the target data based on the decryption token to obtain the second part of data, and combines the first part of data and the second part of data based on the combination method to obtain the data fetching result.

[0012] According to a data reading method provided by the present invention, the database information includes at least two of database metadata, access logs, network information, performance metrics, security configurations, sensitive data identifiers, and system configurations.

[0013] The present invention also provides a data reading device, including the following units: An acquisition unit, configured to acquire a data fetching request of a user, and parse the data fetching request to obtain request information; A comparison unit, configured to obtain database information in the main database, input the database information into a database security assessment model for security assessment, obtain a security assessment result output by the database security assessment model, and dynamically generate a blocking rule based on the security assessment result, compare the blocking rule with the request information to determine whether there is a blocking reason, if there is a blocking reason, stop the data fetching request, and if there is no blocking reason, request the main database based on the data fetching request; A return unit, configured to return the data in the main database requested based on the data fetching request to the user.

[0014] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the data reading method as described in any one of the above is implemented.

[0015] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the data reading method as described in any one of the above is implemented.

[0016] The present invention further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the data reading method as described in any one of the above is implemented.

[0017] The data reading method, device, electronic device, storage medium and product provided by the present invention, on the one hand, input the database information into a database security assessment model for security assessment to obtain a security assessment result, which can evaluate the security of the data in the database itself; on the other hand, dynamically generate a blocking rule based on the security assessment result, which dynamically generates a blocking rule from the perspective of database security protection, improving the security and flexibility of data reading, thereby solving the security hidden trouble problem brought by the dynamically changing database risk. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0019] Figure 1 is one of the flow schematic diagrams of the data reading method provided by the present invention.

[0020] Figure 2 is the structural schematic diagram of the database security assessment model provided by the present invention.

[0021] Figure 3 It is a schematic diagram of the local attention channel provided by the present invention.

[0022] Figure 4 It is a schematic flowchart of step 130 in the data reading method provided by the present invention.

[0023] Figure 5 It is the second schematic flowchart of the data reading method provided by the present invention.

[0024] Figure 6 It is a schematic structural diagram of the data reading device provided by the present invention.

[0025] Figure 7 It is a schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners

[0026] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.

[0027] The terms "first", "second", etc. in the present invention are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order different from those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category.

[0028] Figure 1 It is the first schematic flowchart of the data reading method provided by the present invention. As Figure 1 shown, the method includes step 110, step 120 and step 130.

[0029] Step 110: Obtain the data fetching request of the user and parse the data fetching request to obtain request information.

[0030] Specifically, the data fetching request of the user can be obtained. The data fetching request refers to a request instruction initiated by the user to the system in a certain way (such as interface operation, program call, etc.) for obtaining specific data. It carries the user's demand information for data and is a form of data interaction between the user and the system.

[0031] It should be noted that the data retrieval request records the requester identifier and the request information. Here, the request information corresponds to the data that the current user needs to query, including one or more of query conditions, data attributes, data volume, and data formats. The embodiments of the present invention do not make specific limitations thereto.

[0032] Correspondingly, after obtaining the user's data retrieval request, the data retrieval request can be parsed to obtain the requester identifier and the request information.

[0033] Here is an example of the composition of the data retrieval request. The data retrieval request is that "marketing personnel at the prefecture-level city need to obtain a list of target user numbers for a specific customer group". Correspondingly, the requester identifier is: specific marketing personnel and the prefecture-level city device identifier; the request information is: a list of target user numbers for a specific customer group.

[0034] Step 120: Obtain the database information in the main database, input the database information into the database security assessment model for security assessment, obtain the security assessment result output by the database security assessment model, and dynamically generate a blocking rule based on the security assessment result. Compare the blocking rule with the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data retrieval request; if there is no blocking reason, request the main database based on the data retrieval request.

[0035] Specifically, obtain the database information in the main database. Among them, the database information includes at least two of database metadata, access logs, network information, performance metrics, security configurations, sensitive data identifiers, and system configurations.

[0036] Among them, the database metadata includes the database version and data type; the access log includes access records, operation logs, failed attempts, and audit logs; the network information includes network traffic, port status, IP address (Internet Protocol Address), and firewall information; the performance metrics include CPU (Central Processing Unit) usage rate, memory usage, disk space, and I / O load (Input / Output Load); the security configuration includes an authentication mechanism and encryption settings; the sensitive data identifier includes data classification, data label, data location, and data access permission; the system configuration includes the operating system version, system configuration files, etc. The embodiments of the present invention do not make specific limitations thereto.

[0037] Then, input the database information into the database security assessment model for security assessment to obtain the security assessment results output by the database security assessment model. The security assessment results include the high-sensitive data leakage risk assessment result, the data tampering risk assessment result, the attack vulnerability risk assessment result, and the data network risk assessment result.

[0038] Furthermore, blocking rules can be dynamically generated based on the security assessment results. Compare the blocking rules with the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request. If there is no blocking reason, request the main database based on the data fetching request.

[0039] Among them, the blocking rules dynamically generated based on the security assessment results are as follows: I. Regarding the high-sensitive data leakage risk assessment result, compare the blocking rules with the request information to determine whether there is a blocking reason. The blocking rules focus on detecting and preventing any queries that access sensitive data. The specific blocking rules are as follows: Block any SELECT statements on tables containing sensitive information; Restrict direct queries on sensitive fields, such as passwords, credit card numbers, etc.; Detect and prevent bulk export operations of sensitive data; If a query involves sensitive data but does not have the necessary permission tags or authentication, reject the query.

[0040] II. Regarding the data tampering risk assessment result, compare the blocking rules with the request information to determine whether there is a blocking reason. The blocking rules focus on preventing unauthorized data modification. The specific blocking rules are as follows: For UPDATE and DELETE statements, check whether there is appropriate authorization; Check the scope of modified data to avoid large-scale data modification; Modification operations on sensitive tables require an additional approval process; Check the differences before and after modifying the data to ensure data consistency and integrity.

[0041] III. Regarding the attack vulnerability risk assessment result, compare the blocking rules with the request information to determine whether there is a blocking reason: The blocking rules focus on identifying and preventing possible SQL injection attacks. The specific blocking rules are as follows: Clean and verify all incoming parameters to ensure they conform to the expected format; Check for special characters in SQL statements to prevent SQL injection caused by string concatenation; Use pre-compiled statements (parameterized queries) to reduce the injection risk; For complex queries, perform syntax tree analysis to ensure the legality of SQL statements.

[0042] IV. Regarding the data network risk assessment results, compare the blocking rules with the request information to determine whether there are any blocking reasons: The blocking rules focus on monitoring and preventing database access requests from untrusted sources. The specific blocking rules are as follows: Only allow database connections from IP addresses in the whitelist; limit the concurrency of each connection to prevent resource exhaustion; for database access requests on non-standard ports, conduct strict authentication; monitor abnormal behaviors, such as a large number of failed login attempts within a short period of time.

[0043] Step 130: Return the data in the primary database requested based on the data fetching request to the user.

[0044] Specifically, return the data in the primary database requested based on the data fetching request to the user.

[0045] The method provided by the embodiments of the present invention obtains the data fetching request of the user, parses the data fetching request to obtain the request information, then obtains the database information in the primary database, inputs the database information into the database security assessment model for security assessment to obtain the security assessment result, dynamically generates blocking rules based on the security assessment result, compares the blocking rules with the request information to determine whether there are any blocking reasons. If there are blocking reasons, stop the data fetching request; if there are no blocking reasons, request the primary database based on the data fetching request. Finally, return the data in the primary database requested based on the data fetching request to the user. On the one hand, inputting the database information into the database security assessment model for security assessment to obtain the security assessment result can evaluate the security of the data in the database itself; on the other hand, dynamically generating blocking rules based on the security assessment result is to dynamically generate blocking rules from the perspective of database security protection, improving the security and flexibility of data reading, thereby solving the security hidden problems brought by the dynamically changing database risks.

[0046] Based on the above embodiments, step 130 includes: Step 131: Parse the data fetching request to obtain the requester identifier. Step 132: Based on the requester identifier, determine the historical request preferences of the organization to which the requester belongs. Step 133: According to the historical request preferences, return the data in the primary database requested based on the data fetching request to the user.

[0047] Specifically, parse the data fetching request to obtain the requester identifier. The requester identifier corresponds to the source information of the request end of the current user, including request user identity information or request device information (including address and device terminal identifier, etc.). The embodiments of the present invention do not make specific limitations on this.

[0048] Since the requester identifier obtained in the embodiments of the present invention corresponds to the source information of the requester side of the current user, the organization to which the current requester belongs can be identified based on the requester identifier, and the historical request preferences of the current organization can be obtained.

[0049] Specifically, the embodiments of the present invention link the organization personnel management database and establish a historical preference database for different organizations. Among them, the organization personnel management database records the information of the organizations and the internal personnel of the organizations that have the permission to access the current main database. The historical preference database records the historical data extraction preferences of different organizations and is updated in real time according to the data extraction preferences of users.

[0050] It should be noted that the embodiments of the present invention manage the behaviors of users in units of organizations because different organizations have different preference habits for data extraction. The historical data extraction preferences referred to in the embodiments of the present invention include data formats and data display forms, etc. For example, the historical request preference of the marketing personnel organization is: PDF report, displayed in icon form; the historical request preference of the customer service personnel organization is: Excel file, displayed in text summary form, and so on.

[0051] After obtaining the requester identifier, identify the requester identifier or the request device information to obtain the identity of the requesting user, and retrieve the organization to which the current requesting user belongs from the organization personnel management database, and then retrieve the historical request preferences recorded in the historical preference database according to the organization. Of course, if the organization to which it belongs is identified, a blank organization is established for the current user and a blank historical request preference is established.

[0052] Furthermore, based on the historical request preferences, the data in the main database requested based on the data extraction request can be returned to the user.

[0053] It can be understood that the data requested in the main database is returned to the user according to the historical request preferences of the user. Since different users belong to organizations with different historical request preferences, the data can be provided to the users with different historical request preferences according to the characteristics of different users to achieve multi-type data requests.

[0054] Based on the above embodiments, the security assessment results include high-sensitive data leakage risk assessment results, data tampering risk assessment results, attack vulnerability risk assessment results, and data network risk assessment results; The dynamically generating blocking rules based on the security assessment results in step 120 includes: Based on the high-sensitive data leakage risk assessment results, the data tampering risk assessment results, the attack vulnerability risk assessment results, and the data network risk assessment results, dynamically generate the corresponding blocking rules respectively.

[0055] Specifically, different from traditional static blocking rules, the embodiments of the present invention provide a way to provide dynamic blocking rules according to the real-time dynamic database situation of the database, so as to maximize the data security of the database.

[0056] The security assessment results include high-sensitive data leakage risk assessment results, data tampering risk assessment results, attack vulnerability risk assessment results, and data network risk assessment results.

[0057] I. High-sensitive data leakage risk: High-sensitive data faces the risk of unauthorized access or leakage. Regarding the high-sensitive data leakage risk, it can be distinguished by identifying and locating high-sensitive data in the database and monitoring the database access logs to obtain abnormal access or leakage of high-sensitive data.

[0058] II. Data tampering risk: The data in the database is changed by an unauthorized third party. Regarding the data tampering risk, it can be verified by identifying the data signature of the database or using checksums for data integrity, and monitoring the database access logs to find suspicious modification operations.

[0059] III. Attack vulnerability risk: The database has security vulnerabilities that may be attacked by third-party illegal persons. Regarding the attack vulnerability risk, it can be analyzed by analyzing the network traffic and access logs of the database to identify potential or damaged attack vulnerabilities.

[0060] IV. Data network risk: There is a risk that the data in the network environment where the database is located may be decrypted or tampered with. Regarding the data network risk, it can be analyzed by analyzing the network traffic and network logs of the database to determine whether there is an environmental risk in the current network environment.

[0061] Furthermore, based on the high-sensitive data leakage risk assessment results, data tampering risk assessment results, attack vulnerability risk assessment results, and data network risk assessment results, respective corresponding blocking rules are dynamically generated.

[0062] The method provided by the embodiments of the present invention dynamically generates respective corresponding blocking rules based on the high-sensitive data leakage risk assessment results, data tampering risk assessment results, attack vulnerability risk assessment results, and data network risk assessment results, so that the system can immediately identify and block potential threat behaviors according to the real-time risk assessment results, such as unauthorized data access, data tampering, or attack attempts.

[0063] Based on the above embodiments, the database security assessment model includes a first feature extraction branch, a second feature extraction branch, a fusion module, a linear layer, and a classification assessment module; The first feature extraction branch is used to extract the first features of the database information; The second feature extraction branch is used to extract high-dimensional features from the database information, and after equally dividing the channels of the high-dimensional features, a first equally divided feature and a second equally divided feature are obtained. The first equally divided feature is convolved in the local attention channel to obtain a local feature, the second equally divided feature is convolved in the global attention channel to obtain a global feature, and the local feature and the global feature are fused to obtain a second feature; The fusion module is used to fuse the first feature and the second feature to obtain a fused feature; The linear layer is used to obtain an extracted feature based on the fused feature; The classification and evaluation module is used to obtain the security evaluation result based on the extracted feature.

[0064] Specifically, Figure 2 is a schematic structural diagram of the database security evaluation model provided by the present invention. As Figure 2 shown, the database security evaluation model includes a first feature extraction branch, a second feature extraction branch, a fusion module, a linear layer, and a classification and evaluation module. In addition, the database security evaluation model further includes a feature construction module, and the feature construction module is used to process the data in the database information at consecutive time points collected to obtain a feature vector corresponding to each time point.

[0065] Specifically, the database version and data type in the database metadata at each time point are one-hot encoded to obtain database metadata features, the number of failed attempts in the access log is numerically standardized, the access records, operation logs, and audit logs are one-hot encoded to obtain access log features, and the network traffic in the network information is converted into the inflow and outflow volume per minute and numerically standardized. The port status is converted into binary features, the IP address is converted into location features, and the firewall information is one-hot encoded to obtain network information features; the utilization rate, memory usage, disk space, and I / O load in the performance metrics are directly converted into performance metric features; the security configuration is one-hot encoded to obtain security configuration features; the sensitive data identifier is also one-hot encoded to obtain sensitive data identifier features; the system configuration files in the system configuration are converted into binary features, and other information is one-hot encoded to obtain system configuration features. The above all converted features are integrated to obtain the database features at the current time point, and the database features at each time point in a fixed time window are concatenated to obtain a feature vector (if there are missing features, they are filled with default values or interpolated).

[0066] Among them, the first feature extraction branch, the second feature extraction branch, the fusion module, and the linear layer belong to the feature extraction module. The first feature extraction branch is used to extract the first feature of the database information. The first feature extraction branch includes a linear layer and an activation function. The linear layer here can use the Linear function, and the activation layer here can use the GELU (Gaussian Error Linear Unit) activation function, or the Softmax activation function, or the ReLU (Rectified Linear Units) activation function. The embodiments of the present invention do not make specific limitations on this.

[0067] The second feature branch may include a linear layer, an activation function, a local attention channel, and a global attention channel. The second feature extraction branch is used to extract the high-dimensional features in the database information, and after channel averaging the high-dimensional features, the first averaged feature and the second averaged feature are obtained. The first averaged feature is convolved in the local attention channel to obtain a local feature, and the second averaged feature is convolved in the global attention channel to obtain a global feature. The local feature and the global feature are fused to obtain the second feature. The fusion module is used to fuse the first feature and the second feature to obtain a fused feature, and the linear layer is used to obtain an extracted feature based on the fused feature.

[0068] The classification and evaluation module is used to perform a classification head prediction on the extracted feature to obtain one of the four security evaluation results and the corresponding confidence level.

[0069] In summary, the feature vector of the same database information is input into the first feature extraction branch and processed by a linear layer and an activation function to obtain the first feature, and input into the second feature extraction branch and processed by a linear layer and an activation function to obtain high-dimensional features. The high-dimensional features are channel-averaged to obtain the first averaged feature and the second averaged feature. The first averaged feature is convolved in the local attention channel to obtain a local feature, and the second averaged feature is convolved in the global attention channel to obtain a global feature. The global feature and the local feature are combined to obtain the second feature. The first feature and the second feature are fused and then processed by a linear layer to obtain the extracted feature.

[0070] It should be noted that the database security evaluation model can achieve the effect of more accurately capturing important security features in the database through the combination of the local attention channel and the global attention channel.

[0071] Based on the above embodiments, the local attention channel includes three first convolutional layers, a second convolutional layer, and a third convolutional layer connected in series in sequence. The convolutional kernels of the first convolutional layer, the second convolutional layer, and the third convolutional layer are different. Among them, the first convolutional layer, the second convolutional layer, and the third convolutional layer are all connected to a local convolutional module; Performing convolution on the first equalization feature in the local attention channel to obtain a local feature includes: Inputting the first equalization feature into the first convolutional layer to obtain a first-scale feature, and inputting the first-scale feature into a corresponding local convolutional module to obtain a first-scale local feature; Inputting the first-scale feature into the second convolutional layer to obtain a second-scale feature, and inputting the second-scale feature into a corresponding local convolutional module to obtain a second-scale local feature; Inputting the second-scale feature into the third convolutional layer to obtain a third-scale feature, and inputting the third-scale feature into a corresponding local convolutional module to obtain a third-scale local feature; Based on the first-scale local feature, the second-scale local feature, and the third-scale local feature, the local feature is obtained.

[0072] Specifically, Figure 3 is a schematic diagram of the local attention channel provided by the present invention, as Figure 3 shown, the local attention channel includes three convolutional layers with different convolutional kernels connected in series in sequence, where each convolutional layer is connected to a local convolutional module. The first equalization feature is input into the convolutional layer to obtain scale features of different scales, and the local feature of each scale is input into the corresponding local convolutional module to obtain a scale local feature. The three scale local features are concatenated to obtain the local feature.

[0073] In each local convolutional module, after the scale feature passes through a depthwise separable convolution (reducing the number of parameters and maintaining the computational efficiency), an element-wise multiplication operation is performed with the same-scale feature (performing a Hadamard product with the original scale feature for feature enhancement and suppressing irrelevant features). The multiplied feature passes through an adaptive pooling operation and a convolutional layer to generate a dynamic weight. The dynamic weight and a static learning parameter of the same size (obtained through training) are added and then added in the same dimension to obtain a local convolutional kernel (adaptively assigning weights to different regions of the feature map to improve the flexibility and expressiveness of the model). The scale feature is input into the local convolutional kernel to output the corresponding scale local feature.

[0074] The relevant calculation formula in the local convolutional module is: Wherein, represents the multiplied feature, represents the scale feature, represents the scale local feature, represents the dynamic weight, represents the activation function, represents the depthwise separable convolution, represents the operation on Perform Adaptive pooling operation of size, Indicates a convolution operation, Indicates the Hadamard product, Indicates with As the convolution kernel convolution operation, Indicates static learning parameters.

[0075] Based on the above embodiments, the obtaining the global feature by performing convolution on the second equally divided feature in the global attention channel includes: Performing window multi-head attention calculation and sliding window multi-head attention calculation on the second equally divided feature to obtain the global feature.

[0076] Specifically, the global attention channel of the embodiments of the present invention includes multiple attention modules, and each attention module performs sliding window multi-head attention calculation on the features input thereto, and the formula for the sliding window multi-head attention calculation is as follows: Wherein, Indicates the global feature, Indicates the feature input to the current attention module, Indicates a multi-layer perceptron, Indicates a normalization operation, Indicates window multi-head attention calculation, Indicates sliding window multi-head attention calculation.

[0077] Based on the above embodiments, step 130 includes: Step 141, according to the historical request preference, using the data in the main database requested based on the data fetching request as the data fetching result, and dividing the data fetching result into first part data and second part data; Step 142, sending a secret order acquisition instruction to the user, the secret order acquisition instruction including the first part data, a decryption secret order, a combination method, and a query token; Step 143, receiving the query token, the query token being returned by the user after receiving the secret order acquisition instruction; Step 144, obtaining an encryption number, encrypting the second part of the data based on the encryption rule corresponding to the encryption number to obtain target data, and sending the target data to the user, so that the user decrypts the target data based on the decryption secret order to obtain the second part of the data, and combines the first part of the data and the second part of the data based on the combination method to obtain the data fetching result.

[0078] Specifically, Figure 4 Is a schematic flow chart of step 130 in the data reading method provided by the present invention, asFigure 4 As shown, in order to improve the security of the data fetching process, the present invention preferably provides a data fetching method. Different from the traditional data fetching method that directly distributes the fetched data results to the requesting end (user), the data distribution module of the present invention adopts a step-by-step encryption and distribution strategy to ensure the security of the data and distributes the fetched data results.

[0079] Specifically, according to the historical request preferences, the data in the main database requested based on the data fetching request is used as the fetched data results, and the fetched data results are divided into a first part of data and a second part of data.

[0080] Then, an access token is sent to the user (requesting end), where the access token includes the first part of data, a decryption token, a combination method, and a query token.

[0081] Next, the query token sent by the user is received. The query token is returned by the user after receiving the access token.

[0082] Furthermore, an encryption number is obtained. Based on the encryption rule corresponding to the encryption number, the second part of data is encrypted to obtain the target data, and the target data is sent to the user so that the user decrypts the target data based on the decryption token to obtain the second part of data, and combines the first part of data and the second part of data based on the combination method to obtain the fetched data results.

[0083] The method provided by the embodiment of the present invention distributes the data in a step-by-step manner during the data fetching process. By combining the sending of the access token and the query token, the data is divided into two parts, encrypted, and distributed to the requesting end, ensuring the security of the data during transmission. Even if the data is intercepted or leaked during transmission, the attacker cannot obtain the complete data content because the complete combination of the data depends on the decryption token held by the receiving party, which greatly improves the security of data distribution.

[0084] Based on any of the above embodiments, Figure 5 is the second flow schematic diagram of the data reading method provided by the present invention. As Figure 5 shown, the method includes: In the first step, the data fetching request of the user is obtained, and the requester identification and request information are parsed from the data fetching request.

[0085] In the second step, obtain the database information in the main database, input the database information into the database security assessment model for security assessment, and obtain the security assessment results output by the database security assessment model. The security assessment results include the high-sensitive data leakage risk assessment result, the data tampering risk assessment result, the attack vulnerability risk assessment result, and the data network risk assessment result. Then, based on the high-sensitive data leakage risk assessment result, the data tampering risk assessment result, the attack vulnerability risk assessment result, and the data network risk assessment result, dynamically generate their respective corresponding blocking rules. Finally, based on the security assessment results, dynamically generate blocking rules, compare the blocking rules with the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request. If there is no blocking reason, request the main database based on the data fetching request.

[0086] In the third step, based on the requester identifier, determine the historical request preferences of the organization to which the requester belongs.

[0087] In the fourth step, according to the historical request preferences, use the data in the main database requested based on the data fetching request as the data fetching result, and divide the data fetching result into the first part of data and the second part of data.

[0088] In the fifth step, send a secret order acquisition to the user. The secret order acquisition includes the first part of data, the decryption secret order, the combination method, and the query token.

[0089] In the sixth step, receive the query token. The query token is returned by the user after receiving the secret order acquisition.

[0090] In the seventh step, obtain the encryption number. Based on the encryption rule corresponding to the encryption number, encrypt the second part of data to obtain the target data, and send the target data to the user so that the user can decrypt the target data based on the decryption secret order to obtain the second part of data, and combine the first part of data and the second part of data based on the combination method to obtain the data fetching result.

[0091] Here, the database security assessment model includes a first feature extraction branch, a second feature extraction branch, a fusion module, a linear layer, and a classification assessment module; the first feature extraction branch is used to extract the first feature of the database information; the second feature extraction branch is used to extract the high-dimensional features in the database information, and after evenly dividing the channels of the high-dimensional features, obtain the first evenly divided feature and the second evenly divided feature. Convolve the first evenly divided feature in the local attention channel to obtain the local feature, perform window multi-head attention calculation and sliding window multi-head attention calculation on the second evenly divided feature to obtain the global feature, and fuse the local feature and the global feature to obtain the second feature. The fusion module is used to fuse the first feature and the second feature to obtain the fusion feature; the linear layer is used to obtain the extracted feature based on the fusion feature; the classification assessment module is used to obtain the security assessment result based on the extracted feature.

[0092] The method provided by the embodiments of the present invention: 1. Compared with the prior art, the database security assessment model in the present invention can more accurately capture important security features in the database by combining local attention channels and global attention channels; can automatically adjust the model to adapt to different database environments by combining dynamic weights and static learnable parameters; can lightweight the self-attention matrix through axial chunking and aggregation operations, can enhance the security assessment ability while keeping the model lightweight, and further achieve the effect of dynamically generating the security assessment results of the database.

[0093] 2. Compared with the prior art, the method of fine classification of database security risks and dynamic generation of blocking rules in the present invention can effectively prevent various types of security threats; can achieve the dual effects of improving user experience and data security by using the historical preferences of users to provide customized services.

[0094] 3. Compared with the prior art, the strategy of encrypting and distributing data in two parts in the present invention can achieve the effect that even if the data is intercepted, it cannot be completely interpreted; can achieve the effect of ensuring the integrity and confidentiality of data during the data transmission process by combining the issued access token and query token.

[0095] The technical solution of the present invention can significantly enhance the security of the operator in data processing, which is conducive to improving customer trust, promoting user retention and attracting new users. Especially for a large amount of user-sensitive data, including personal information, call records, etc., features such as the security assessment model and step-by-step encryption and distribution strategy in the present application proposal can effectively protect the sensitive data in the main database from unauthorized access and potential data leakage risks. Of course, it can also improve the data security of the database itself. In the current environment where data security has become the focus of attention of enterprises and individuals, this is a very important feature for operators, which helps to enhance the brand image and market competitiveness.

[0096] The technical solution of the present invention can greatly improve the operation efficiency of mobile operators. Through automated and intelligent data management processes, the dynamic blocking request and intelligent preference matching functions in the proposal can achieve rapid response to user requests and personalized services, thereby improving the efficiency of the overall business process, saving costs, and providing a smoother service experience for users. This plays an important role in improving customer satisfaction and increasing revenue.

[0097] The technical solution of the present invention can help operators better comply with increasingly strict data protection regulations. The dynamic security assessment and data isolation measures in the proposal ensure that data processing activities meet legal requirements and reduce the risk of violations. This not only avoids potential high fines but also enables operators to establish a responsible corporate image, enhance the trust of partners, expand international business opportunities, and ultimately bring greater market share and development space.

[0098] Example application scenario 1: The present invention can be applied to the scenario where local marketing personnel need to carry out targeted marketing activities for a certain labeled customer group. After submitting a demand work order, they obtain a list of target customer numbers from the data mart (target database) to carry out marketing activities.

[0099] At this time, the working process of the present invention is as follows: The marketing personnel submit a demand work order as a data retrieval request [including request information (a list of numbers for a specific customer group) and request source (the identity information and device information of the marketing personnel)]. The system learns from the request source of the marketing personnel that the historical request preference of the current marketing department is: data in the form of PDF-formatted chart information; it retrieves the database information of the main database in real time and performs an evaluation using the database security assessment model, obtaining a security assessment result of: high-sensitive data risk, and generating a dynamic blocking rule for high-sensitive data risk (prohibiting access to sensitive data of a specific customer group). After comparing the data retrieval request, it is found that it matches the blocking rule, so the current data retrieval request is blocked.

[0100] Example application scenario 2: The present invention can be applied to the scenario where customer service personnel feedback that a batch of number lists have abnormal consumption to query relevant transaction, bill, and other data in the market application.

[0101] At this time, the working process of the present invention is as follows: The customer service personnel submit a demand work order as a data retrieval request [requesting to query data (transaction records and bill information of a specific number list), request source (the identity information and device information of the customer service personnel)]. The system learns from the request source of the customer service personnel that the historical request preference of the department to which the current customer service personnel belong is: data in the form of an EXCEL-formatted text summary; it retrieves the database information of the main database in real time and performs an evaluation using the database security assessment model, obtaining a security assessment result of: no risk, so the data retrieval request is not blocked; it provides the corresponding data retrieval result based on the historical request preference, and then gives the data retrieval result to the corresponding customer service personnel according to the data security distribution rule provided in the embodiment of the present invention.

[0102] Next, the data reading device provided by the present invention will be described. The data reading device described below can be correspondingly referred to the data reading method described above.

[0103] Based on any of the above embodiments, the present invention provides a data reading device,Figure 6 is a schematic structural diagram of the data reading device provided by the present invention. As Figure 6 shown, the device includes: An acquisition unit 610, configured to acquire a data fetching request of a user, and parse the data fetching request to obtain request information; A comparison unit 620, configured to acquire database information in a main database, input the database information into a database security evaluation model for security evaluation, obtain a security evaluation result output by the database security evaluation model, and dynamically generate a blocking rule based on the security evaluation result, compare the blocking rule and the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request; if there is no blocking reason, request the main database based on the data fetching request; A return unit 630, configured to return the data in the main database requested based on the data fetching request to the user.

[0104] The device provided by the embodiment of the present invention acquires a data fetching request of a user, parses the data fetching request to obtain a requester identifier and request information, then acquires database information in a main database, inputs the database information into a database security evaluation model for security evaluation, obtains a security evaluation result, and dynamically generates a blocking rule based on the security evaluation result, compares the blocking rule and the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request; if there is no blocking reason, request the main database based on the data fetching request. Finally, return the data in the main database requested based on the data fetching request to the user. On the one hand, inputting the database information into the database security evaluation model for security evaluation to obtain a security evaluation result can perform a security evaluation on the data of the database itself; on the other hand, dynamically generating a blocking rule based on the security evaluation result dynamically generates a blocking rule from the perspective of database security protection, improving the security and flexibility of data reading, and thus solving the security hidden danger problem brought by the dynamically changing database risk.

[0105] Based on any of the above embodiments, the return unit 630 is specifically configured to: Parse the data fetching request to obtain a requester identifier; Determine the historical request preference of the organization to which the requester belongs based on the requester identifier; Return the data in the main database requested based on the data fetching request to the user according to the historical request preference.

[0106] Based on any of the above embodiments, the security evaluation result includes a high-sensitive data leakage risk evaluation result, a data tampering risk evaluation result, an attack vulnerability risk evaluation result, and a data network risk evaluation result; The comparison unit 620 is specifically configured to: Based on the high - sensitive data leakage risk assessment result, the data tampering risk assessment result, the attack vulnerability risk assessment result, and the data network risk assessment result, blocking rules corresponding to each are dynamically generated.

[0107] Based on any of the above embodiments, the database security assessment model includes a first feature extraction branch, a second feature extraction branch, a fusion module, a linear layer, and a classification assessment module; The first feature extraction branch is used to extract the first features of the database information; The second feature extraction branch is used to extract high - dimensional features from the database information, and after equally dividing the channels of the high - dimensional features, a first equally - divided feature and a second equally - divided feature are obtained. The first equally - divided feature is convolved in the local attention channel to obtain local features, the second equally - divided feature is convolved in the global attention channel to obtain global features, and the local features and the global features are fused to obtain second features; The fusion module is used to fuse the first feature and the second feature to obtain a fused feature; The linear layer is used to obtain extracted features based on the fused feature; The classification assessment module is used to obtain the security assessment result based on the extracted features.

[0108] Based on any of the above embodiments, the local attention channel includes three first convolutional layers, a second convolutional layer, and a third convolutional layer connected in series in sequence. The convolutional kernels of the first convolutional layer, the second convolutional layer, and the third convolutional layer are different. Among them, the first convolutional layer, the second convolutional layer, and the third convolutional layer are all connected to a local convolutional module; The step of convolving the first equally - divided feature in the local attention channel to obtain local features includes: Inputting the first equally - divided feature into the first convolutional layer to obtain a first - scale feature, and inputting the first - scale feature into the corresponding local convolutional module to obtain a first - scale local feature; Inputting the first - scale feature into the second convolutional layer to obtain a second - scale feature, and inputting the second - scale feature into the corresponding local convolutional module to obtain a second - scale local feature; Inputting the second - scale feature into the third convolutional layer to obtain a third - scale feature, and inputting the third - scale feature into the corresponding local convolutional module to obtain a third - scale local feature; Based on the first - scale local feature, the second - scale local feature, and the third - scale local feature, the local features are obtained.

[0109] Based on any of the above embodiments, the second feature extraction branch is specifically configured to: Perform window multi-head attention calculation and sliding window multi-head attention calculation on the second evenly divided feature to obtain the global feature.

[0110] Based on any of the above embodiments, the return unit 630 is specifically configured to: According to the historical request preference, use the data in the main database requested based on the data fetching request as the data fetching result, and divide the data fetching result into a first part of data and a second part of data; Send a fetching secret order to the user, where the fetching secret order includes the first part of data, a decryption secret order, a combination method, and a query token; Receive the query token, where the query token is returned by the user after receiving the fetching secret order; Obtain an encryption number, encrypt the second part of data based on the encryption rule corresponding to the encryption number to obtain target data, and send the target data to the user, so that the user decrypts the target data based on the decryption secret order to obtain the second part of data, and combines the first part of data and the second part of data based on the combination method to obtain the data fetching result.

[0111] Based on any of the above embodiments, the database information includes at least two of database metadata, access logs, network information, performance metrics, security configurations, sensitive data identifiers, and system configurations.

[0112] Figure 7 It is a schematic structural diagram of an electronic device provided by the present invention. As Figure 7 shown, the electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 complete mutual communication through the communication bus 740. The processor 710 can call the logical instructions in the memory 730 to execute a data reading method, which includes: obtaining a data fetching request of a user, parsing the data fetching request to obtain request information; obtaining database information in the main database, inputting the database information into a database security evaluation model for security evaluation to obtain a security evaluation result output by the database security evaluation model, and dynamically generating a blocking rule based on the security evaluation result, comparing the blocking rule and the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request. If there is no blocking reason, request the main database based on the data fetching request; return the data in the main database requested based on the data fetching request to the user.

[0113] In addition, when the logical instructions in the above-mentioned memory 730 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0114] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data reading method provided by the above-mentioned various methods. The method includes: obtaining a data fetching request of a user, parsing the data fetching request to obtain request information; obtaining database information in a main database, inputting the database information into a database security evaluation model for security evaluation, obtaining a security evaluation result output by the database security evaluation model, and dynamically generating a blocking rule based on the security evaluation result, comparing the blocking rule and the request information to determine whether there is a blocking reason. If there is a blocking reason, the data fetching request is stopped. If there is no blocking reason, the main database is requested based on the data fetching request; returning the data in the main database requested based on the data fetching request to the user.

[0115] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the data reading method provided by the above-mentioned various methods. The method includes: obtaining a data fetching request of a user, parsing the data fetching request to obtain request information; obtaining database information in a main database, inputting the database information into a database security evaluation model for security evaluation, obtaining a security evaluation result output by the database security evaluation model, and dynamically generating a blocking rule based on the security evaluation result, comparing the blocking rule and the request information to determine whether there is a blocking reason. If there is a blocking reason, the data fetching request is stopped. If there is no blocking reason, the main database is requested based on the data fetching request; returning the data in the main database requested based on the data fetching request to the user.

[0116] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.

[0117] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0118] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data reading method, characterized in that, Including: Obtain the data fetching request of the user, and parse the data fetching request to obtain request information; Obtain database information in the main database, input the database information into the database security assessment model for security assessment, obtain the security assessment result output by the database security assessment model, and dynamically generate a blocking rule based on the security assessment result. Compare the blocking rule with the request information to determine whether there is a blocking reason. If there is a blocking reason, stop the data fetching request; if there is no blocking reason, request the main database based on the data fetching request; Return the data in the main database requested based on the data fetching request to the user.

2. The data reading method according to claim 1, wherein The returning the data in the main database requested based on the data fetching request to the user includes: Parse the data fetching request to obtain the identifier of the requester; Based on the identifier of the requester, determine the historical request preference of the organization to which the requester belongs; According to the historical request preference, return the data in the main database requested based on the data fetching request to the user.

3. The data reading method according to claim 1, wherein, The security assessment result includes a high-sensitive data leakage risk assessment result, a data tampering risk assessment result, an attack vulnerability risk assessment result, and a data network risk assessment result; The dynamically generating a blocking rule based on the security assessment result includes: Dynamically generate respective corresponding blocking rules based on the high-sensitive data leakage risk assessment result, the data tampering risk assessment result, the attack vulnerability risk assessment result, and the data network risk assessment result.

4. The data reading method according to claim 1, characterized in that The database security assessment model includes a first feature extraction branch, a second feature extraction branch, a fusion module, a linear layer, and a classification assessment module; The first feature extraction branch is used to extract the first feature of the database information; The second feature extraction branch is used to extract the high-dimensional feature in the database information, and after evenly dividing the channels of the high-dimensional feature, obtain a first evenly divided feature and a second evenly divided feature. Convolve the first evenly divided feature in the local attention channel to obtain a local feature, convolve the second evenly divided feature in the global attention channel to obtain a global feature, and fuse the local feature and the global feature to obtain a second feature; The fusion module is used to fuse the first feature and the second feature to obtain a fused feature; The linear layer is used to obtain an extracted feature based on the fused feature; The classification assessment module is used to obtain the security assessment result based on the extracted feature.

5. The data reading method according to claim 4, wherein The local attention channel includes three first convolutional layers, a second convolutional layer, and a third convolutional layer connected in series in sequence. The convolutional kernels of the first convolutional layer, the second convolutional layer, and the third convolutional layer are different. Among them, the first convolutional layer, the second convolutional layer, and the third convolutional layer are all connected to a local convolutional module; The convolving the first evenly divided feature in the local attention channel to obtain a local feature includes: Input the first evenly divided feature into the first convolutional layer to obtain a first-scale feature, and input the first-scale feature into the corresponding local convolutional module to obtain a first-scale local feature; Input the first-scale feature into the second convolutional layer to obtain a second-scale feature, and input the second-scale feature into the corresponding local convolutional module to obtain a second-scale local feature; Input the second-scale feature into the third convolutional layer to obtain a third-scale feature, and input the third-scale feature into the corresponding local convolutional module to obtain a third-scale local feature; Obtain the local feature based on the first-scale local feature, the second-scale local feature, and the third-scale local feature.

6. The data reading method according to claim 4, wherein The step of convolving the second evenly-divided feature in the global attention channel to obtain a global feature includes: Perform window multi-head attention calculation and sliding window multi-head attention calculation on the second evenly-divided feature to obtain the global feature.

7. The data reading method according to any one of claims 1 to 6, characterized in that, The step of returning the data in the primary database requested based on the data fetching request to the user according to the historical request preference includes: According to the historical request preference, use the data in the primary database requested based on the data fetching request as the data fetching result, and divide the data fetching result into a first part of data and a second part of data; Send an acquisition token to the user, where the acquisition token includes the first part of data, a decryption token, a combination method, and a query token; Receive the query token, where the query token is returned by the user after receiving the acquisition token; Obtain an encryption number, encrypt the second part of data based on the encryption rule corresponding to the encryption number to obtain target data, and send the target data to the user, so that the user decrypts the target data based on the decryption token to obtain the second part of data, and combines the first part of data and the second part of data based on the combination method to obtain the data fetching result.

8. The data reading method according to any one of claims 1 to 6, characterized in that The database information includes at least two of database metadata, access logs, network information, performance metrics, security configurations, sensitive data identifiers, and system configurations.

9. A data reading device, characterized in that, It includes: An acquisition unit, configured to acquire a data fetching request of a user, and parse the data fetching request to obtain request information; A comparison unit, configured to acquire database information in the primary database, input the database information into a database security evaluation model for security evaluation to obtain a security evaluation result output by the database security evaluation model, dynamically generate a blocking rule based on the security evaluation result, compare the blocking rule and the request information to determine whether there is a blocking reason, if there is a blocking reason, stop the data fetching request, and if there is no blocking reason, request the primary database based on the data fetching request; A return unit, configured to return the data in the primary database requested based on the data fetching request to the user.

10. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the data reading method according to any one of claims 1 to 8.

11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the data reading method according to any one of claims 1 to 8.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the data reading method according to any one of claims 1 to 8.