Fully-encrypted database system, data processing method, security control device and equipment
The full-encrypted database system processes encrypted data through a security control module and engine within a trusted area, addressing the complexity and cost issues of existing encrypted database systems by maintaining system integrity and security without kernel modifications.
Patent Information
- Application Number
- CN202410718069.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-15
- Publication Date
- 2025-07-15
AI Technical Summary
Existing encrypted database systems require significant updates and high costs to implement encrypted data processing due to the need for modifications at the SQL operator level, which complicates integration and limits functionality.
A full-encrypted database system with a security control module and data processing engine within a trusted area that processes encrypted data without modifying the database kernel, allowing secure and efficient data handling.
Enables secure data processing without altering the database kernel, reducing implementation costs and maintaining system integrity while ensuring data security and flexibility.
Smart Images

Figure CN120316809A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of databases, and in particular, to a fully homomorphic encrypted database system, a data processing method, a security control device, and a device. Background Art
[0002] With the rapid development of science and technology, people have higher and higher requirements for data usage security, which makes the application of encrypted databases more and more extensive. At present, the encrypted database provides a homomorphic encryption computing interface at the level of Structured Query Language (SQL) operators, and through the above homomorphic encryption computing interface, the database can perform processing operations on encrypted data.
[0003] However, the homomorphic encryption computing interface at the SQL operator level needs to update and adjust or reconfigure the database kernel to implement, which not only has a high complexity, but also increases the transformation cost of the database. Summary of the Invention
[0004] Embodiments of the present invention provide a fully homomorphic encrypted database system, a data processing method, a security control device, and a device, which can stably implement data processing operations without modifying the database kernel, and reduce the transformation cost of the fully homomorphic encrypted database.
[0005] In a first aspect, an embodiment of the present invention provides a fully homomorphic encrypted database system, including:
[0006] A security control module, which is set in the trusted area corresponding to the fully homomorphic encrypted database, is used to obtain a data processing request, decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine for processing; wherein, the data processing request includes sensitive data after encryption processing;
[0007] The data processing engine is communicatively connected to the security control module and is set in the trusted area corresponding to the fully homomorphic encrypted database, and is used to process the decrypted processing request to obtain a data processing result.
[0008] In a second aspect, an embodiment of the present invention provides a data processing method, which is applied to a fully homomorphic encrypted database system. The fully homomorphic encrypted database system includes a security control module and a data processing engine that are communicatively connected, and the security control module and the data processing engine are both located in the trusted area corresponding to the fully homomorphic encrypted database; the method includes:
[0009] The security control module obtains a data processing request, and the data processing request includes sensitive data after encryption processing;
[0010] The security control module decrypts the data processing request to obtain a decrypted processing request, and sends the decrypted processing request to the data processing engine for processing;
[0011] The data processing engine processes the decrypted processing request to obtain a data processing result.
[0012] In a third aspect, an embodiment of the present invention provides an electronic device, including: a memory and a processor; wherein, the memory is used to store one or more computer instructions, and when the one or more computer instructions are executed by the processor, the data processing method in the second aspect above is implemented.
[0013] In a fourth aspect, an embodiment of the present invention provides a computer storage medium for storing a computer program, and when the computer program is executed by a computer, the data processing method in the second aspect above is implemented.
[0014] In a fifth aspect, an embodiment of the present invention provides a computer program product, including: a computer program, when the computer program is executed by a processor of an electronic device, the processor is caused to execute the steps in the data processing method in the second aspect above.
[0015] In a sixth aspect, an embodiment of the present invention provides a data processing method applied to a security control module. The security control module is communicatively connected to a data processing engine, and both the security control module and the data processing engine are located in a trusted area corresponding to a fully encrypted database; the method includes:
[0016] Obtain a data processing request, where the data processing request includes sensitive data that has been encrypted;
[0017] Decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
[0018] In a seventh aspect, an embodiment of the present invention provides a security control device. The security control device is communicatively connected to a data processing engine, and both the security control device and the data processing engine are located in a trusted area corresponding to a fully encrypted database; the security control device includes:
[0019] A second acquisition module for acquiring a data processing request, where the data processing request includes sensitive data that has been encrypted;
[0020] A second processing module, configured to decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
[0021] In a eighth aspect, an embodiment of the present invention provides an electronic device, including: a memory and a processor; wherein, the memory is used to store one or more computer instructions, and when the one or more computer instructions are executed by the processor, the data processing method in the above sixth aspect is implemented.
[0022] In a ninth aspect, an embodiment of the present invention provides a computer storage medium for storing a computer program, and when the computer program is executed by a computer, the data processing method in the above sixth aspect is implemented.
[0023] In a tenth aspect, an embodiment of the present invention provides a computer program product, including: a computer program, when the computer program is executed by a processor of an electronic device, the processor is caused to execute the steps in the data processing method in the above sixth aspect.
[0024] The fully encrypted state database system, data processing method, security control device and equipment provided in this embodiment obtain a data processing request through a security control module. Since the data processing request is a ciphertext processing request, after the security control module obtains the data processing request, the data processing request is decrypted to obtain a decrypted processing request, and the decrypted processing request is sent to a data processing engine for processing. Then, the data processing engine processes the decrypted processing request, thereby effectively realizing the data encryption processing operation based on the fully encrypted state database. Since the security control module is independent of the data processing engine for executing data processing operations, and both the security control module and the data processing engine are located in the trusted area corresponding to the fully encrypted state database, it effectively realizes stable data processing operations without modifying the database kernel, and also reduces the transformation cost of the database, further ensuring the practicability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0026] Figure 1 It is a schematic diagram of the principle of a fully encrypted state database system provided by an embodiment of the present invention;
[0027] Figure 2 Schematic diagram of the structure of a fully encrypted database system provided by an embodiment of the present invention;
[0028] Figure 3 Schematic diagram of the structure of another fully encrypted database system provided by an embodiment of the present invention;
[0029] Figure 4 Flowchart of data processing operations implemented based on the fully encrypted database system provided by an embodiment of the present invention;
[0030] Figure 5 Flow schematic diagram of a data processing method provided by an embodiment of the present invention;
[0031] Figure 6 For Figure 5 Schematic diagram of the structure of an electronic device corresponding to the data processing method shown in the embodiment;
[0032] Figure 7 Flow schematic diagram of another data processing method provided by an embodiment of the present invention;
[0033] Figure 8 Schematic diagram of the structure of a security control device provided by an embodiment of the present invention;
[0034] Figure 9 For Figure 8 Schematic diagram of the structure of an electronic device corresponding to the security control device shown in the embodiment. Detailed implementation manners
[0035] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0036] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. "Plural" generally includes at least two, but does not exclude the case of including at least one.
[0037] It should be understood that the term "and / or" used herein is merely a description of the relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this text generally indicates that the associated objects before and after are in an "or" relationship.
[0038] Depending on the context, the words "if" and "when" as used herein can be interpreted as "when...", "while...", "in response to determining", or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" can be interpreted as "when determined", "in response to determining", "when detecting (stated condition or event)", or "in response to detecting (stated condition or event)".
[0039] It should also be noted that the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a commodity or system comprising a series of elements not only includes those elements but also includes other elements not explicitly listed, or elements inherent to such commodity or system. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of another identical element in the commodity or system comprising the said element.
[0040] In addition, the step timings in the following method embodiments are only examples and not strictly limited.
[0041] Term Definition:
[0042] Trusted Execution Environment: Trusted Execution Environment, abbreviated as TEE, can provide a secure execution environment isolated from the outside world. Through the secure execution environment, the code and data therein can be protected from being leaked or maliciously tampered with. The instance during the operation of TEE is called enclave.
[0043] Remote Attestation: Remote Attestation, abbreviated as RA, is used to prove that the target service runs in a trusted TEE environment and that the function of the target service code conforms to the expectation; a third-party application can use RA to establish an end-to-end authentication channel with the target service and further establish a secure channel.
[0044] Trusted Domain: Trusted Domain, that is, the user needs to trust the services within this domain.
[0045] Full-encryption state security gateway: Secure Gateway, abbreviated as SecureGW, acts on the database connection link and provides additional security functions, such as data encryption and decryption, data authorization and authentication, etc.
[0046] Data Encryption Key: abbreviated as DEK, used to encrypt user data.
[0047] Master Encryption Key: abbreviated as MEK, used to encrypt the data encryption key DEK.
[0048] Transparent Data Encryption: abbreviated as TDE, is a transparent disk encryption and decryption solution that is insensitive to applications. The data is encrypted with the user-specified key before being written to disk and decrypted before being read from disk and loaded into memory. The data stored in memory is in plain text.
[0049] To facilitate the understanding of the implementation principle and implementation effect of the technical solution in this embodiment, the related technologies will be briefly described below:
[0050] The full-encryption state database adopts confidential computing capabilities, so that after the data is encrypted on the user side (client), it only needs to exist in ciphertext form throughout the non-trusted server side, but still supports all database transactions, queries, analyzes, etc. operations. This can not only minimize the potential data security risks easily caused by uncontrollable factors such as personnel and platform management, but also effectively prevent anyone other than the cloud database service (or data owner such as application service) from accessing the user's plaintext data, avoiding cloud data leakage, and at the same time preventing R & D and operation and maintenance from stealing data and being fearless of database account leakage. Customers can fully own the ownership of the data, ensuring: (1) In the process of providing data services, the external cannot obtain the user's plaintext data; (2) Authorized users can normally read and write the data in the database through the existing protocol; (3) Unauthorized users cannot obtain the plaintext data of the protected users.
[0051] At present, the full-encryption state database generally realizes the processing operation of the database on the encrypted data by providing a confidential computing interface at the level of the Structured Query Language (SQL) operator. However, the above method has defects:
[0052] (1) The encrypted SQL operator is different in usage form from the ordinary database, which makes it usually necessary to adapt when the application accesses the database, and the transformation cost on the application side is high;
[0053] (2) The processing ability of the database for encrypted data is limited by the richness of the implementation of encrypted SQL operators, and its functions are only a subset of those of a general database, making it difficult to meet the diverse needs of applications;
[0054] (3) In the implementation of encrypted SQL operators, it is usually necessary to modify the database kernel, which not only has a relatively high complexity of modification but also incurs high engineering costs.
[0055] To solve the above technical problems, this embodiment provides a fully encrypted database system, a data processing method, a security control device, and a device. As shown in the attached Figure 1 figures, the fully encrypted database system may include: a security control module 200 and a data processing engine 300 disposed in the trusted area corresponding to the fully encrypted database. The above security control module 200 is communicatively connected to the client 100, so that users can use the fully encrypted database system through the client 100. In some instances, the data processing engine 300 may be located in the database kernel, and at this time, the database kernel may mainly include a data processing engine 300 for implementing data processing operations.
[0056] Among them, the fully encrypted database system may be implemented as a cloud server or a cloud service platform. The cloud service platform can provide services for the fully encrypted database, which can be specifically implemented by providing external service interfaces. Users call these service interfaces to use the corresponding services. The service interfaces include forms such as Software Development Kits (SDKs) and Application Programming Interfaces (APIs). Or, in terms of physical implementation, the fully encrypted database system can be any device that can provide computing services, respond to data processing requests, and perform processing. For example, it can be a cluster server, a conventional server, a cloud server, a cloud host, a virtual center, etc. The composition of the fully encrypted database system mainly includes a processor, a hard disk, a memory, a system bus, etc., which is similar to a general computer architecture.
[0057] The above-mentioned client 100 can be any computing device with certain data transmission capabilities. Specifically, in implementation, the client 100 can be a mobile phone, a personal computer (PC), a tablet computer, a set application program, etc. In addition, the basic structure of the client 100 can include: at least one processor. The number of processors depends on the configuration and type of the client 100. The client 100 can also include a memory, which can be volatile, such as: Random Access Memory (RAM), or non-volatile, such as Read-Only Memory (ROM), flash memory, etc., or can also include both types. The memory usually stores an operating system (OS), one or more application programs, and can also store program data, etc. In addition to the processing unit and the memory, the client 100 also includes some basic configurations, such as: a network card chip, an IO bus, a display component, and some peripheral devices, etc. Optionally, some peripheral devices can include, for example: a keyboard, a mouse, a stylus, a printer, etc. Other peripheral devices are well known in the art and will not be elaborated here.
[0058] In the above-mentioned embodiment of the present application, the client 100 can be network-connected to the security control module 200, and this network connection can be a wireless or wired network connection. If the client 100 and the security control module 200 are in a communication connection, the network mode of this mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, 5G, 6G, etc.
[0059] In the embodiment of the present application, the client 100 can generate, store, or obtain an original processing request corresponding to the fully encrypted state data system. In order to avoid data leakage and ensure the security of data operations, the original processing request in plaintext can be encrypted to obtain a data processing request. In order to be able to implement data processing operations, the encrypted data processing request can be sent to the fully encrypted state database system, thus effectively realizing the sending of the original processing request in plaintext to the fully encrypted state data system in the form of ciphertext, so that the fully encrypted state data system obtains the encrypted data processing request.
[0060] The security control module 200 is used to obtain a data processing request sent by the client 100. The data processing request may include sensitive data that has been encrypted. Since the security control module 200 is located in the trusted area corresponding to the fully encrypted database, after obtaining the data processing request, the data processing request can be decrypted to obtain a plaintext decryption processing request. In order to stably implement the data processing operation, the plaintext decryption processing request can be sent to the data processing engine 300 for processing.
[0061] The data processing engine 300 is used to obtain the decryption processing request sent by the security control module 200, and then can perform corresponding data processing operations based on the decryption processing request, and obtain a plaintext data processing result, thereby effectively implementing the data processing operation based on the fully encrypted database.
[0062] In the above implementation process, the data processing operation of the fully encrypted database is performed through the security control module and the data processing engine set in the trusted area corresponding to the fully encrypted database. Since the security control module and the data processing engine for performing the data processing operation are independent of each other, the data processing operation can be stably implemented without modifying the database kernel, which not only reduces the transformation cost of the database, but also has a lower complexity of data processing.
[0063] Next, in conjunction with the accompanying drawings, some embodiments of the present invention will be described in detail. Without conflict between the embodiments, the following embodiments and the features in the embodiments can be combined with each other. In addition, the step timings in the following method embodiments are only examples, not strictly limited.
[0064] Figure 2 It is a schematic structural diagram of a fully encrypted database system provided by an embodiment of the present invention; refer to the attached Figure 2 As shown, this embodiment provides a fully encrypted database system, which can stably implement data processing operations without modifying the database kernel. Specifically, the fully encrypted database system may include:
[0065] The security control module 200 is set in the trusted area corresponding to the fully encrypted database, and is used to obtain a data processing request, decrypt the data processing request to obtain a decryption processing request, and send the decryption processing request to the data processing engine 300 for processing; wherein, the data processing request includes sensitive data that has been encrypted.
[0066] The data processing engine 300 is communicatively connected to the security control module 200 and is set in the trusted area corresponding to the fully encrypted database, and is used to process the decryption processing request to obtain a data processing result.
[0067] Among them, the fully encrypted database corresponds to a trusted area, which is an area trusted by users. Services within the trusted area can be trusted by users. Specifically, users can flexibly configure or adjust the services set in the trusted area according to application requirements or setting requirements. To perform stable and secure data processing operations based on the fully encrypted database, the security control module 200 and the data processing engine 300 in the fully encrypted database system can be located in the trusted area corresponding to the fully encrypted database.
[0068] In addition, for the security control module 200 and the data processing engine 300, different deployment methods can be realized in different application scenarios. For example, as shown in the reference appendix Figure 2 shown, the database kernel is located in the trusted area, the data processing engine 300 is located in the database kernel, the security control module 200 is located outside the database kernel and is communicatively connected to the database kernel. At this time, the data located in the database kernel is plaintext data. Or, as shown in the reference appendix Figure 3 shown, the database kernel is located in the trusted area, and both the security control module 200 and the data processing engine 300 are located in the database kernel. The above different deployment methods can be applied to different application scenarios, thus effectively realizing that the security control module 200 and the data processing engine 300 can be flexibly and stably deployed in the trusted area, not only ensuring the security and reliability of data processing, but also improving the flexible reliability of the fully encrypted database system implementation.
[0069] Regarding the layout methods of the security control module 200 and the data processing engine 300 in the above Figure 2 , when a user accesses the data processing engine 300 in the trusted area without passing through the security control module 200, the risk of data leakage in the above scenario cannot be prevented. For example, after the user obtains the login method of the database kernel, the user can directly connect to the data processing engine within the trusted area, and at this time, the data plaintext can always be seen. In view of the above situation, no security isolation technology can prevent internal active leakage. When there is a data leakage situation in the above scenario, post-event accountability operations can be carried out through management means such as database logs and audits, so as to perform corresponding protection or punishment operations on illegal users. For example, the local login method of the user can be disabled.
[0070] Regarding the above Figure 3Regarding the layout of the security control module 200 and the data processing engine 300 in it, since both the security control module 200 and the data processing engine 300 are located in the database kernel, the security control module 200 at this time can prevent most data access operations on the database kernel; however, when the user logs in locally and uses the method of dumping the in-memory data of the running database, the plaintext data stored in the database kernel can be directly viewed, that is, the data leakage risk existing in the above scenario cannot be prevented at this time. When there is a data leakage situation in the above scenario, post-event accountability operations can be carried out through management means such as database and operating system logs and audits, so as to perform corresponding protection or trigger operations on illegal users. For example, the local login method of the user can be disabled.
[0071] Specifically, when the user has a data processing requirement for the fully encrypted database, the security control module 200 in the fully encrypted database system can obtain a data processing request, where the data processing request includes sensitive data that has been encrypted, that is, the data processing request can be encrypted request information. In some instances, the security control module 200 can be communicatively connected to a client. The user generates a plaintext data processing request through the client and encrypts the sensitive data in the plaintext data processing request, so as to obtain an encrypted data processing request. After the client obtains the encrypted data processing request, it can send the encrypted data processing request to the security control module 200, so that the security control module 200 can passively obtain the data processing request.
[0072] In other instances, the security control module 200 can not only passively obtain a data processing request, but also actively obtain a data processing request. At this time, the security control module 200 can be communicatively connected to a preset device, and the preset device can generate a data processing request according to a preset period (for example: device maintenance request, data security check request, etc.), and the data processing request includes encrypted sensitive data. Then the security control module 200 can actively obtain the data processing request through the preset device, so that the security control module 200 can stably obtain the data processing request.
[0073] Since the security control module 200 is located in the trusted area corresponding to the fully encrypted state database, and processing operations can be performed based on the plaintext data processing request in the trusted area. Therefore, after obtaining the ciphertext data processing request, the data processing request can be decrypted. In some instances, decrypting the data processing request to obtain the decrypted processing request may include: obtaining the sensitive data included in the data processing request; determining the decryption key for processing the sensitive data, where the decryption key can be obtained through derivation processing using a random value and the user master key; using the decryption key to decrypt the data processing request to obtain the decrypted processing request, which is the processing request obtained after the decryption processing operation, thus effectively ensuring the stable reliability of analyzing and processing the decrypted processing request.
[0074] In order to be able to implement data processing operations based on the fully encrypted state database, after the security control module 200 obtains the decrypted processing request, the decrypted processing request can be sent to the data processing engine 300 for processing, so that the data processing engine 300 stably obtains the decrypted processing request. Then, the data processing engine 300 can process the decrypted processing request to obtain the data processing result. Since the data processing engine 300 is located in the trusted area corresponding to the fully encrypted state database, it effectively realizes that data processing operations can be stably performed.
[0075] In addition, for the fully encrypted state database system, the data in the fully encrypted state database can exist in plaintext in the memory. To ensure the security and reliability of data processing, the stored data in the fully encrypted state database can be stored on disk. Specifically, the data processing engine 300 can be connected to a storage area. When the storage area is a local storage area, the storage area is directly connected to the data processing engine 300; when the storage area is a cloud storage area, the storage area is network-connected to the data processing engine 300. For the stored data in the fully encrypted state database, the Transparent Data Encryption (TDE) technology can be used to encrypt the stored data in the fully encrypted state database to obtain the encrypted data, and the encrypted data is stored in the storage area, thus ensuring the security and reliability of data processing.
[0076] The fully homomorphic encryption database system provided in this embodiment obtains a data processing request through a security control module. Since the data processing request is a ciphertext processing request, after the security control module obtains the data processing request, the data processing request is decrypted to obtain a decrypted processing request, and the decrypted processing request is sent to a data processing engine for processing. Then, the data processing engine processes the decrypted processing request, thereby effectively implementing data encryption processing operations based on the fully homomorphic encryption database. Since the security control module is independent of the data processing engine for executing data processing operations, and both the security control module and the data processing engine are located in the trusted area corresponding to the fully homomorphic encryption database, stable data processing operations can be effectively implemented without modifying the database kernel, and the transformation cost of the database is reduced. Further, the practicability of the system is ensured, which is beneficial to market promotion and application.
[0077] Based on the above embodiment, referring to the attached Figures 2-3 As shown in the figure, the security control module 200 can not only directly obtain a data processing request through the client, but also obtain a data processing request through the database access module 400. At this time, the system may further include: a database access module 400 communicatively connected to the security control module 200 and the client, and the database access module 400 is configured to: obtain an original processing request through the client; when the original processing request includes sensitive data, encrypt the sensitive data to obtain a data processing request; and send the data processing request to the security control module 200.
[0078] Among them, the database access module 400 can be set between the security control module 200 and the client, or the database access module 400 can be set within the client, that is, the database access module 400 can be integrated with the client, as long as it can enable the client to perform corresponding data processing operations on the fully encrypted database through the database access module 400. Specifically, when the user has a data processing requirement for the fully encrypted database, the client can generate or obtain an original processing request. In some instances, the client generating or obtaining an original processing request may include: displaying a human-computer interaction interface; obtaining an execution operation input by the user on the human-computer interaction interface; generating or obtaining an original processing request based on the execution operation. Or, the original processing request can not only be obtained through human-computer interaction operations, but also through a preset timing task. At this time, in some other instances, the client generating or obtaining an original processing request may include: obtaining a preset timing period; when the time meets the preset timing period, an original processing request can be generated or obtained, thereby effectively ensuring the accuracy and reliability of obtaining the original processing request. Or, the original processing request can be generated through a preset application code logic. Those skilled in the art can flexibly adjust or configure the obtaining method of the original processing request according to specific application scenarios or application requirements, as long as the stability and reliability of obtaining the original processing request can be ensured, which will not be elaborated here.
[0079] Specifically, the original processing request generated by the client is plaintext processing data. In order to implement data processing operations based on the fully encrypted database, the client can send the plaintext original processing request to the database access module 400, so that the database access module 400 can stably obtain the original processing request through the client. Since the original processing request is a plaintext processing request, in order to ensure the security and reliability of data processing, it is possible to first identify whether the original processing request includes sensitive data. Among them, identifying whether the original processing request includes sensitive data may include: obtaining encryption rule information for analyzing and processing the original processing request, and using the encryption rule information to analyze and process the original processing request to identify whether the original processing request includes sensitive data.
[0080] When the original processing request does not include sensitive data, it indicates that the original processing request at this time does not involve the relevant data that needs to be encrypted. At this time, the database access module 400 can directly send the original processing request to the security control module 200 for corresponding data processing operations; when the original processing request includes sensitive data, it indicates that the original processing request at this time involves the relevant data that needs to be encrypted. Therefore, in order to ensure the security and reliability of data processing, after the database access module 400 obtains the original processing request, it can encrypt the sensitive data in the original processing request to obtain a data processing request, which is the ciphertext request information, and the latter can send the data processing request to the security control module 200, effectively ensuring that the security control module 200 can stably obtain the data processing request.
[0081] In addition, the specific implementation method of the encryption processing operation for the sensitive data in the original processing request in this embodiment is not limited. In some instances, the encryption processing operation can be implemented by a preset encryption algorithm or a preset machine learning model. At this time, when the database access module 400 encrypts the sensitive data to obtain a data processing request, the database access module 400 is used to: obtain the preset encryption algorithm or the preset machine learning model for encrypting the sensitive data; use the preset encryption algorithm or the preset machine learning model to encrypt the sensitive data in the original processing request to obtain a data processing request.
[0082] In other instances, not only can the encryption processing operation be implemented by a preset encryption algorithm or a preset machine learning model, but also the sensitive data in the original processing request can be encrypted by a data encryption key. At this time, when the database access module 400 encrypts the sensitive data to obtain a data processing request, the database access module 400 is used to: obtain the main key corresponding to the original processing request and the random value for encrypting the sensitive data; generate a data encryption key based on the main key and the random value; use the data encryption key to encrypt the sensitive data to obtain a data processing request.
[0083] Specifically, when the database access module 400 obtains an original processing request, it can obtain the master key corresponding to the original processing request. In some instances, obtaining the master key corresponding to the original processing request may include: obtaining the mapping relationship between the pre-configured original processing request and the master key. Specifically, there may be a mapping relationship between the master key and the user identity identifier in the original processing request; based on the mapping relationship and the original processing request, obtain the master key corresponding to the original processing request, so that different original processing requests used by different users to implement the same function can correspond to different master keys. Alternatively, the master key corresponding to the original processing request may be stored in a preset area. At this time, by accessing the preset area, the master key corresponding to the original processing request can be obtained, thereby effectively ensuring the accuracy and reliability of obtaining the master key.
[0084] It should be noted that for the master key corresponding to the original processing request, different types of original processing requests may correspond to different master keys. In some instances, when the original processing request is a first type of operation and maintenance request, the master key corresponding to the original processing request is a null value. Among them, the first type of operation and maintenance request is used to implement operation and maintenance operations unrelated to user data. For example, the original processing request may be a system startup request, a system stop request, an instance creation request, etc. The above data may refer to user data stored in the fully encrypted database; when the original processing request is a second type of operation and maintenance request, the master key corresponding to the original processing request is a non-null value, and the non-controlled master keys corresponding to different users may be different. Among them, the second type of operation and maintenance request is used to implement operation and maintenance operations related to user data. For example, the original processing request may be a data write request, a data update request, a data edit request, etc.
[0085] After obtaining the original processing request, in order to accurately perform stable encryption processing operations on the original processing request, the database access module 400 can also obtain a random value for encrypting sensitive data. After obtaining the master key and the random value, the master key and the random value can be analyzed and processed. Specifically, based on the master key and the random value, generating a data encryption key may include: using a preset algorithm or a preset machine learning model to analyze and process the master key and the random value, so as to stably generate a data encryption key. After obtaining the data encryption key, use the data encryption key to encrypt the sensitive data in the original processing request, thereby effectively ensuring the accuracy and reliability of obtaining the data processing request.
[0086] In this embodiment, the database access module obtains the original processing request through the client. When the original processing request includes sensitive data, the database access module can encrypt the sensitive data to obtain a data processing request, and send the data processing request to the security control module, which effectively ensures the accurate and reliable acquisition of the encrypted data processing request and the practicability of the all-encrypted state database system.
[0087] Based on the above embodiment, continue to refer to the attached Figure 2 As shown, after the database access module 400 obtains the original processing request, the database access module 400 can generate a data encryption key based on the master key, use the data encryption key to encrypt the sensitive data, and send the encrypted data processing request to the security control module 200. After the security control module 200 obtains the encrypted data processing request, it needs to perform a decryption operation on the encrypted data processing request. In order to stably perform the decryption operation on the encrypted data processing request, the database access module 400 needs to transmit the master key used for encrypting the original processing request to the security control module 200. In order to stably implement the secure transmission operation of the master key, the database access module 400 in this embodiment is further configured to: obtain the public key for encrypting and transmitting the master key; use the public key to encrypt the master key to obtain the encrypted master key; and send the encrypted master key to the security control module 200, so that the security control module 200 processes the encrypted master key based on the private key corresponding to the public key to obtain the master key, and uses the master key to decrypt the data processing request.
[0088] Specifically, since the master key is information pre-configured by the user for implementing data processing operations, if the master key is transmitted in plaintext in the fully encrypted state database, the risk of data leakage will increase. Therefore, to avoid transmitting the plaintext master key in the fully encrypted state database system, after the database access module 400 obtains the master key corresponding to the original processing request, it can obtain the public key for encrypting and transmitting the master key. In some instances, obtaining the public key for encrypting and transmitting the master key may include: displaying a human-computer interaction interface; obtaining the execution operation input by the user in the human-computer interaction interface; and obtaining the public key for encrypting and transmitting the master key based on the execution operation. Alternatively, the public key can be allocated by the fully encrypted state database system. In this case, obtaining the public key for encrypting and transmitting the master key may include: the database access module 400 generating a public key acquisition request in response to the obtained original processing request; and sending the public key acquisition request to the security control module 200. The security control module 200 responds to the public key acquisition request, obtains the preset allocated public key corresponding to the public key acquisition request, and sends the preset allocated public key to the database access module 400, so that the database access module 400 can stably obtain the public key for encrypting and transmitting the master key.
[0089] To be able to perform the encrypted transmission operation on the master key, after obtaining the public key and the master key, the master key can be encrypted using the public key to obtain the encrypted master key. After obtaining the encrypted master key, the encrypted master key can be sent to the security control module 200, so that the security control module 200 processes the encrypted master key based on the private key corresponding to the public key, obtains the master key, and decrypts the data processing request using the master key, thus realizing the secure transmission operation of the encrypted master key between the database access module 400 and the security control module 200, and further ensuring the security and reliability of data processing.
[0090] Based on the above embodiments, continue to refer to the attached Figures 2-3 As shown, the fully encrypted state database system in this embodiment can not only implement encrypted data processing operations to obtain data processing results, but also can implement secure transmission operations on the data processing results, so that the client can stably view the data processing results. Specifically, the data processing engine 300, the security control module 200, and the database access module 400 in this embodiment are used to perform the following steps:
[0091] The data processing engine 300 is further configured to send the data processing result to the security control module 200 after obtaining the data processing result;
[0092] The security control module 200 is further configured to generate an encryption key when the data processing result includes sensitive data, encrypt the data processing result using the encryption key to obtain an encrypted processing result, and send the encrypted processing result and a random value to the database access module 400, where the encryption key is determined by the random value and the master key corresponding to the data processing request;
[0093] The database access module 400 is configured to decrypt the encrypted processing result based on the random value to obtain a decrypted processing result, and send the decrypted processing result to the client.
[0094] Specifically, after the data processing engine 300 obtains the data processing result, the plaintext data processing result can be sent to the security control module 200. After the security control module 200 obtains the data processing result, it can first identify whether the data processing result includes sensitive data. In some instances, the security control module 200 stores or caches encryption rule information for judging sensitive data. At this time, identifying whether the data processing result includes sensitive data may include: obtaining the encryption rule information stored in the security control module 200, and analyzing and processing the data processing result using the encryption rule information to identify whether the data processing result includes sensitive data.
[0095] When the data processing result does not include sensitive data, the security control module 200 can directly send the data processing result to the database access module 400, so that the database access module 400 can send the data processing result to the client, so that the user can directly view the data processing result through the client. When the data processing result includes sensitive data, to ensure the security and reliability of data processing, the security control module 200 can generate an encryption key for encrypting the sensitive data in the data processing result. The encryption key can be determined by the random value and the master key corresponding to the data processing request. Specifically, the master key can correspond to the user identity identifier in the data processing request. In some instances, the encryption key can be obtained by performing a derivation process on the random value and the master key using a key derivation function (KDF) algorithm or other preset encryption algorithms.
[0096] After obtaining the encryption key, in order to securely transmit the data processing result stably, the encryption key can be used to encrypt the data processing result to obtain an encrypted processing result, and the encrypted processing result and a random value are sent to the database access module 400, where the encryption key is determined by the random value and the master key corresponding to the data processing request. After the database access module 400 obtains the encrypted processing result and the random value, it can perform a decryption operation on the encrypted processing result based on the random value, so as to obtain a decryption processing result. In order to enable the user to view the decrypted processing result in plaintext, after the database access module 400 obtains the decryption processing result, the decryption processing result can be sent to the client.
[0097] In this embodiment, after obtaining the data processing result, the data processing engine 300 can send the data processing result to the security control module 200; when the data processing result includes sensitive data, the security control module 200 can generate an encryption key, and then use the encryption key to encrypt the data processing result to obtain an encrypted processing result, and send the encrypted processing result and a random value to the database access module 400. After the database access module 400 obtains the encrypted processing result, it can decrypt the encrypted processing result based on the random value to obtain a decryption processing result, and send the decryption processing result to the client, thus effectively realizing the stable, secure and reliable transmission operation of the data processing result, and further improving the practicability of the all-encrypted state database system.
[0098] Based on the above embodiment, continue to refer to the appendix Figures 2-3 As shown, after the security control module 200 obtains the data processing request, in order to ensure the security and reliability of data processing, the security control module 200 in this embodiment can also perform a legal identification operation on the user identity of the data processing operation. At this time, the security control module 200 in this embodiment is also used for: obtaining the user identity identifier corresponding to the data processing request; based on the user identity identifier, determining whether the user of the data processing request is an authorized user; when the user is an authorized user, encrypt the data processing request based on the master key corresponding to the user identity identifier, so that the client obtains the data processing result in plaintext that meets the expected requirements; when the user is an unauthorized user, encrypt the data processing request based on the master key that has no corresponding relationship with the user identity identifier, so that the client cannot obtain the data processing result in plaintext that meets the expected requirements.
[0099] Specifically, after the security control module 200 obtains a data processing request, in order to ensure the security and reliability of the data processing operation, the security control module 200 may obtain the user identity identifier corresponding to the data processing request. In some instances, the user identity identifier may be obtained through a preset mapping relationship. At this time, obtaining the user identity identifier corresponding to the data processing request may include: obtaining the preset mapping relationship used to analyze and process the data processing request, and determining the user identity identifier corresponding to the data processing request based on the preset application relationship and the data processing request.
[0100] After obtaining the user identity identifier, it is possible to determine whether the user of the data processing request is an authorized user based on a preset whitelist. Determining whether the user of the data processing request is an authorized user based on the user identity identifier may include: obtaining the preset whitelist used to analyze and process the user of the data processing request, where the preset whitelist includes the standard identity identifiers of multiple authorized users; identifying whether there is a standard identity identifier in the preset whitelist that matches the user identity identifier; when there is a standard identity identifier in the preset whitelist that matches the user identity identifier, determining that the user is an authorized user; when there is no standard identity identifier in the preset whitelist that matches the user identity identifier, determining that the user is an unauthorized user.
[0101] In some other instances, not only can it be determined whether a user is an authorized user through a preset whitelist, but it can also be combined with whether the user has a corresponding master key to determine whether the user is an authorized user. At this time, when the security control module 200 determines whether the user of the data processing request is an authorized user based on the user identity identifier, the security control module 200 is also used to: detect whether the user identity identifier corresponds to a master key; when the user identity identifier does not correspond to a master key, determining that the user is an unauthorized user; when the user identity identifier corresponds to a master key, determining whether the user of the data processing request is an authorized user based on the master key and the registered master key.
[0102] Specifically, after obtaining the user identity identifier, it is possible to use a preset mapping relationship to detect whether the user identity identifier corresponds to a master key. When the user identity identifier does not correspond to a master key, it can be determined that the user is an unauthorized user; when the user identity identifier corresponds to a master key, it can be directly determined that the user is an authorized user. Alternatively, in order to further ensure the accurate and reliable determination of whether the user is an authorized user, when the user identity identifier corresponds to a master key, it is possible to further determine whether the user of the data processing request is an authorized user based on the master key and the registered master key. At this time, based on the master key and the registered master key, determining whether the user of the data processing request is an authorized user may include: obtaining a preset machine learning model or neural network model for analyzing and processing the master key and the registered master key, sending the master key and the registered master key to the preset machine learning model or neural network model, and obtaining the judgment result output by the machine learning model or neural network model, where the judgment result is used to identify whether the user of the data processing request is an authorized user.
[0103] In some other instances, not only can it be determined whether the user is an authorized user through a preset machine learning model or neural network model, but it is also possible to directly perform analysis and calculation on the master key and the registered master key to implement the determination operation of the authorized user. At this time, based on the master key and the registered master key, determining whether the user of the data processing request is an authorized user may include: calculating the master key to obtain a calculated hash value corresponding to the master key, calculating the registered master key to obtain a registered hash value corresponding to the registered master key, analyzing and matching the calculated hash value and the registered hash value. When the calculated hash value matches the registered hash value, it is determined that the user is an authorized user; when the calculated hash value does not match the registered hash value, it is determined that the user is an unauthorized user, thus stably implementing an accurate determination or identification operation of whether the user is an authorized user.
[0104] When it is determined that the user is an authorized user, it means that the user can safely perform data processing operations at this time. Furthermore, the data processing request can be encrypted based on the master key corresponding to the user identity identifier, so that the client can obtain a plaintext data processing result that meets the expected requirements, that is, the user can obtain the desired data processing result. For example: when the data processing request is a request for the user to query the sales volume of a certain product in the past 3 months, through the data processing operation of the fully homomorphic encryption database system, the returned data processing result can be "the sales volume of a certain product in the past 3 months is 1 million pieces".
[0105] When the user is an unauthorized user, it indicates that the user cannot perform data processing operations securely at this time. Therefore, the data processing request can be encrypted based on the master key that has no corresponding relationship with the user identity identifier. Among them, the master key that has no corresponding relationship with the user identity identifier can include any one of the following: a randomly generated master key, a pre-configured default master key, etc. Since the data processing request is not encrypted based on the master key corresponding to the user identity identifier, the security control module 200 cannot correctly decrypt the encrypted data processing result, so that the client cannot obtain the plaintext data processing result that meets the expected requirements through the database access module 400. Even if the client cannot obtain the plaintext data processing result that meets the expected requirements. For example, when the data processing request is a request for the user to query the sales volume of a certain product in the past 3 months, through the data processing operation of the fully homomorphic encryption database system, the returned data processing result can be "the unit price of the product is 17 yuan per piece". Obviously, the data processing result does not correspond to the above data processing request, so that the user cannot complete the preset data processing operation.
[0106] In some other examples, after the user becomes an authorized user, the security control module 200 in this embodiment can determine whether the user has access rights to the data processing request. At this time, the security control module 200 in this embodiment is further configured to: determine the user's access rights based on the user identity identifier; based on the access rights, determine whether the user has access rights to the data corresponding to the data processing request; when having access rights, allow the data processing request to be encrypted based on the master key corresponding to the user identity identifier; when not having access rights, prohibit the data processing request from being encrypted based on the master key corresponding to the user identity identifier.
[0107] For a fully homomorphic encryption database system, different users can be configured with different access rights. For example, user A can have access rights to all data in the fully homomorphic encryption database system, user B can have access rights to some data in the fully homomorphic encryption database system, and user C has no access rights to any data in the fully homomorphic encryption database system. Therefore, when determining that the user is an authorized user, in order to ensure the security and reliability of data processing, after obtaining the user identity identifier, the user's access rights can be determined based on the user identity identifier. Specifically, the user's access rights can be determined based on a preset mapping relationship and the user identity identifier.
[0108] After determining the access rights of the user, it is possible to determine whether the user has access rights to the data corresponding to the data processing request based on the access rights. In some instances, determining whether the user has access rights to the data corresponding to the data processing request based on the access rights may include: obtaining the access right requirements corresponding to the data corresponding to the data processing request; determining whether the access rights meet the access right requirements; when the access rights meet the access right requirements, determining that the user has access rights to the data corresponding to the data processing request; when the access rights do not meet the access right requirements, determining that the user does not have access rights to the data corresponding to the data processing request.
[0109] When the user has access rights to the data corresponding to the data processing request, it indicates that the user is not only a legitimate authorized user at this time, but also has the corresponding data access rights. Furthermore, it is then allowed to encrypt the data processing request based on the master key corresponding to the user identity. Correspondingly, when the user does not have access rights to the data corresponding to the data processing request, it indicates that although the user is a legitimate authorized user at this time, the user does not have the corresponding data access rights. Furthermore, it is possible to prohibit encrypting the data processing request based on the master key corresponding to the user identity, thus effectively ensuring the security and reliability of data processing.
[0110] In this embodiment, the security control module 200 obtains the user identity corresponding to the data processing request; determines whether the user of the data processing request is an authorized user based on the user identity; when the user is an authorized user, encrypts the data processing request based on the master key corresponding to the user identity, so that the client obtains a plaintext data processing result that meets the expected requirements; when the user is an unauthorized user, encrypts the data processing request based on a master key that has no corresponding relationship with the user identity, so that the client cannot obtain a plaintext data processing result that meets the expected requirements. In this way, it effectively realizes allowing authorized users to perform legitimate data processing operations and be able to obtain correct data processing results; prohibiting unauthorized users from performing normal data processing operations, that is, the user cannot obtain correct data processing results, thereby effectively ensuring the security and reliability of the use of the fully encrypted database system.
[0111] Based on any one of the above embodiments, continue to refer to the appendix Figures 2-3As shown, the security control module 200 in this embodiment can not only implement secure and reliable data processing operations, but also manage the ciphertext metadata. At this time, the security control module 200 in this embodiment is further configured to: obtain a data write request corresponding to the ciphertext metadata, where the ciphertext metadata includes at least one of the following for implementing encrypted data processing operations: encryption rule information for identifying sensitive data, user identity verification code, encryption algorithm parameters, and the ciphertext metadata is stored in the metadata database; determine the user signature information corresponding to the data write request; based on the user signature information, identify whether the data write request is a legitimate request; when the data write request is a legitimate request, then allow the ciphertext metadata to be stored in the metadata database based on the data write request; when the data write request is an illegal request, then prohibit the ciphertext metadata from being stored in the metadata database based on the data write request.
[0112] Specifically, when the user calls the fully encrypted database system for data processing operations, the fully encrypted database system can cache, store, and manage the ciphertext metadata for implementing data processing operations, where the ciphertext metadata can include at least one of the following: encryption rule information for identifying sensitive data, user identity verification code, encryption algorithm parameters, and the above management operations can include at least one of the following: write operation of ciphertext metadata, update operation of ciphertext metadata, delete operation of ciphertext metadata, etc. Hereinafter, the write operation of ciphertext metadata is taken as an example of the management operation of ciphertext metadata for illustration:
[0113] When the user has a data write requirement for the ciphertext metadata, the security control module 200 can be made to obtain a data write request corresponding to the ciphertext metadata. After obtaining the data write request, the legitimacy of the data write request can be verified. At this time, the user signature information corresponding to the data write request can be determined first, and then whether the data write request is a legitimate request can be identified based on the user signature information. Specifically, when the user signature information matches the registered signature information corresponding to the data write request, it can be determined that the data write request is a legitimate request; when the user signature information does not match the registered signature information corresponding to the data write request, it can be determined that the data write request is an illegal request.
[0114] When it is determined that the data write request is a legitimate request, it means that a legitimate write operation can be performed on the ciphertext metadata at this time, and then the ciphertext metadata is allowed to be stored in the metadata database based on the data write request; when the data write request is an illegal request, in order to ensure the legitimate storage and management operations of the ciphertext metadata, the ciphertext metadata can be prohibited from being stored in the metadata database based on the data write request.
[0115] In this embodiment, a data write request corresponding to the ciphertext metadata is obtained through the security control module 200, and the user signature information corresponding to the data write request is determined; based on the user signature information, it is identified whether the data write request is a legal request; when the data write request is a legal request, it is allowed to store the ciphertext metadata in the metadata database based on the data write request; when the data write request is an illegal request, it is prohibited to store the ciphertext metadata in the metadata database based on the data write request, thereby effectively realizing the legal write operation on the ciphertext metadata. Similarly, similar implementation methods and implementation processes can be used to implement other management operations on the ciphertext metadata, such as: write operations and read operations on the ciphertext metadata. The above-mentioned write operation may include at least one of the following: write operation, update operation, deletion, etc., and the above-mentioned read operation may include query operation, thereby realizing the legality and integrity protection operations of the ciphertext metadata, further improving the security and reliability of the use of the fully encrypted database system.
[0116] For specific applications, refer to the attached Figures 2-4 As shown, this application embodiment provides a universal fully-secret database system, which may include a database access module, a security control module, and a data processing engine. The database access module is communicatively connected to a client, or the database access module may be arranged in the client, and the security control module is communicatively connected to the database access module and the data processing engine. The above-mentioned security control module and the data processing engine may be located in a trusted area. In some instances, the security control module may be located in a fully-secret database proxy service, that is, the security control module may be implemented in combination with the fully-secret database proxy service, and the fully-secret database proxy service at this time is a trusted node. For the security control module and the data processing engine, in some instances, the data processing engine may be located in the kernel of the fully-secret database, and the security control module may be located outside the kernel of the fully-secret database; or, both the security control module and the data processing engine may be located in the kernel of the fully-secret database.
[0117] Specifically, based on the above-mentioned fully encrypted database system, a data processing operation can be implemented, and the data processing operation can include the following steps:
[0118] Step 1: The user initiates a query request SQL on the client, and the query request SQL is a plaintext request SQL, and then the plaintext request SQL can be sent to the database access module;
[0119] Step 2: After the database access module obtains the plaintext request SQL, it can encrypt the plaintext request SQL to obtain the encrypted SQL, and then send the encrypted ciphertext SQL to the security control module;
[0120] Among them, the security control module plays the role of "data operation control". For database user access, both remote access by ordinary database users (from the application perspective) and local access by operation and maintenance database users (from the operation and maintenance perspective) need to go through the security control module, which can ensure that queries can only see ciphertexts all the time.
[0121] Step 3: After the security control module obtains the ciphertext SQL, it decrypts the ciphertext SQL to obtain the plaintext SQL, and can send the plaintext SQL to the data processing engine (database kernel);
[0122] Specifically, after the security control module obtains the ciphertext SQL, it can decrypt the sensitive data in the ciphertext SQL, so as to restore the plaintext SQL.
[0123] Step 4: After the data processing engine obtains the plaintext SQL, it can perform query calculations based on the plaintext SQL to obtain the data processing result, and then can return the plaintext data processing result to the security control module;
[0124] Step 5: After the security control module obtains the plaintext data processing result, it can obtain the encryption rules pre-configured by the user, and use the encryption rules to determine whether the plaintext data processing result includes sensitive data; if it includes sensitive data, it randomly generates a random value for the local session, dynamically calculates the data encryption key DEK based on the random value, and then can use the data encryption key DEK to encrypt the sensitive data in the data processing result to obtain the ciphertext data result, and send the ciphertext data result to the database access module.
[0125] Among them, dynamically calculating the data encryption key DEK based on the random value can include: obtaining the user master key, and performing dynamic derivation operations on the random value and the user master key based on the KDF algorithm, so as to obtain the data encryption key DEK. Specifically, DEK = KDF(MEK, nonce), where nonce is the random value (such as an 8B random number), MEK is the user master key, KDF is a preset encryption algorithm, and DEK is the data encryption key.
[0126] After obtaining the ciphertext data result, the random value can be sent to the database access module together with the ciphertext data result. Specifically, after obtaining the ciphertext data result and the random value, the random value and the ciphertext data result can be concatenated to obtain a concatenation result, and then the concatenation result can be sent to the database access module. For example: when the nonce is the random value, the DEK is the data key, and the data is the sensitive data, the ciphertext data result can be Enc(DEK, data). The concatenation result of the random value and the ciphertext data result is Cipher, and this Cipher = nonce||Enc(DEK, data). The random value can be concatenated at the packet header position, the packet tail position, or the middle position, etc. of the ciphertext data result. Those skilled in the art can flexibly adjust or configure the concatenation method according to the specific application scenario or application requirements, as long as the concatenation result can be stably generated, which will not be elaborated here.
[0127] It should be noted that for a fully encrypted database system, the fully encrypted database system can have different usage modes, namely the fully encrypted database mode and the ordinary database mode. Specifically, when an encryption rule for identifying sensitive data is configured in the security control module, it is determined that the fully encrypted database system is in the fully encrypted data mode; when an encryption rule for identifying sensitive data is not configured in the security control module, it is determined that the fully encrypted database system is in the ordinary database mode. In specific applications, users can flexibly configure or adjust the encryption rules in the security control module according to application requirements or design requirements, thereby effectively realizing flexible adjustment or configuration of the usage mode of the fully encrypted database system.
[0128] In addition, in order to improve the security and reliability of the fully encrypted database system, the role / account for configuring the encryption rules is independent of the login account of the database. In this way, even if the database account is leaked, it will not affect the management security.
[0129] Step 6: When the database access module obtains the ciphertext data result, decrypt the ciphertext processing result to obtain the plaintext processing result, and send the plaintext processing result to the client.
[0130] Among them, when the ciphertext data result includes multiple query records, the database access module can process the query records one by one and decrypt the ciphertext content therein, so as to obtain the plaintext processing result. Specifically, decrypting the ciphertext content therein can include: obtaining the random value included in the ciphertext data processing result, dynamically calculating the decryption key DEK in the same way, and then using the decryption key DEK for decryption to obtain the plaintext processing result.
[0131] Step 7: For the stored data or cached data in the fully encrypted database system, the transparent data encryption algorithm TDE can be used to encrypt the stored data or cached data in the fully encrypted database system, and the encrypted data can be stored in a preset area. The above-mentioned stored data or cached data can include encryption rules, log files, configuration data, or running data, etc.
[0132] Among them, the data always exists in plain text in the memory of the database kernel (DB Kernel). When it is stored on disk, it can be encrypted in combination with TDE technology to ensure disk storage security. In addition, the fully encrypted database system in this embodiment can implement the management operation of ciphertext metadata. Among them, the ciphertext metadata can include encryption rule information configured by the user, user identity verification codes, algorithm parameters used for encrypting data, etc. The fully encrypted database system can persist the ciphertext metadata information into the internal protection table of the database and provide a unified management function.
[0133] For the internal protection table of the database, integrity protection can be provided, so that any write operation needs to verify that the write operation is signed by a legitimate user. After verification, it is written by the fully encrypted module, and the data in the internal protection table of the database cannot be modified by any user outside the fully encrypted module, effectively ensuring the security and reliability of data storage.
[0134] The fully encrypted database system provided by this application embodiment provides security protection in the form of a bypass security control module, which can be non-intrusive to the database kernel, is easy to implement in engineering, and has universality; moreover, the fully encrypted database system can support all existing SQL operators. Currently, the SQL operators can be directly executed on the fully encrypted database without modification. For example, it supports fuzzy matching queries for plain text SQL, etc. At the same time, this fully encrypted system solution does not require additional modification on the client side. Only a few lines of configuration are required to access, and the existing code does not need to be modified at all. This fully encrypted database system can be compatible with the existing database, and the database can be upgraded to the fully encrypted database without perception, or can be rolled back to the ordinary database without perception, thus ensuring the flexible and reliable use of this fully encrypted database system.
[0135] Specifically, by placing a security control module in front of an existing database instance, the sensitive data specified in the encryption rule in the query result is encrypted using the key provided by the user, and the result is returned to the database access module in ciphertext form. Then, the database access module decrypts the ciphertext result to restore the plaintext result and returns it to the client. Throughout the above process, except for the database kernel and the application client, the query result always exists in ciphertext form and the function application is transparent. As a part of the database service, the security control module ensures that all database accesses pass through it, guaranteeing that neither remote access nor local access can bypass the security check, thereby ensuring the security and reliability of data processing. Additionally, by integrating the security control module into the database kernel, the result encryption is completed before the query result is returned from the kernel, which can reduce or prevent the risk that platform users bypass the security control module for access control by directly connecting to the database kernel through backend login in the local access (from the platform perspective) to obtain the plaintext data. Even database management and operation and maintenance can only see the ciphertext query result, thus ensuring the security and reliability of data usage, further improving the practicality of the system, and facilitating market promotion and application.
[0136] Figure 5 It is a schematic flowchart of a data processing method provided by an embodiment of the present invention; refer to the appendix Figure 5 As shown, this embodiment provides a data processing method. The execution subject of this method is a fully encrypted database system, that is, this data processing method can be applied to a fully encrypted database system. Refer to the appendix Figures 2-4 As shown, the fully encrypted database system may include a security control module and a data processing engine that are communicatively connected. Both the security control module and the data processing engine are located in the trusted area corresponding to the fully encrypted database. Based on the above fully encrypted database system, the data processing method may include:
[0137] Step S501: The security control module obtains a data processing request, where the data processing request includes sensitive data that has been encrypted.
[0138] Step S502: The security control module decrypts the data processing request to obtain a decrypted processing request, and sends the decrypted processing request to the data processing engine for processing.
[0139] Step S503: The data processing engine processes the decrypted processing request to obtain a data processing result.
[0140] In some instances, before the security control module obtains the data processing request, the method further includes: obtaining a user registration request; displaying a user registration page; and in response to the user's execution operation on the user registration page, obtaining user registration information and a registration master key.
[0141] In some examples, the original processing request sent by the client is obtained through the database access module, where the database access module is communicatively connected to the security control module and the client; when the original processing request includes sensitive data, the sensitive data is encrypted through the database access module to obtain a data processing request; and the data processing request is sent to the security control module through the database access module.
[0142] In some examples, encrypting the sensitive data to obtain a data processing request may include: obtaining a master key corresponding to the original processing request and a random value for encrypting the sensitive data; generating a data encryption key based on the master key and the random value; and encrypting the sensitive data with the data encryption key to obtain a data processing request.
[0143] In some examples, when the original processing request is a first type of operation and maintenance request, the master key corresponding to the original processing request is a null value, where the first type of operation and maintenance request is used to implement operation and maintenance operations independent of user data, and the user data is stored in a fully encrypted database;
[0144] When the original processing request is a second type of operation and maintenance request, the master key corresponding to the original processing request is a non-null value, where the second type of operation and maintenance request is used to implement operation and maintenance operations related to user data.
[0145] In some examples, the method in this embodiment may include: obtaining a public key for encrypting and transmitting the master key; encrypting the master key with the public key to obtain an encrypted master key; and sending the encrypted master key to the security control module so that the security control module processes the encrypted master key based on the private key corresponding to the public key to obtain the master key, and decrypts the data processing request with the master key.
[0146] In some examples, after obtaining the data processing result, the method in this embodiment may include: sending the data processing result to the security control module through the data processing engine; when the data processing result includes sensitive data, generating an encryption key through the security control module, encrypting the data processing result with the encryption key to obtain an encrypted processing result, and sending the encrypted processing result and the random value to the database access module, where the encryption key is determined by the random value and the master key corresponding to the data processing request; decrypting the encrypted processing result based on the random value through the database access module to obtain a decrypted processing result, and sending the decrypted processing result to the client.
[0147] In some instances, after obtaining a data processing request, the method in this embodiment may include: obtaining a user identity identifier corresponding to the data processing request through a security control module; determining whether the user of the data processing request is an authorized user based on the user identity identifier; when the user is an authorized user, encrypting the data processing request based on the master key corresponding to the user identity identifier so that the client can obtain a plaintext data processing result that meets the expected requirements; when the user is an unauthorized user, encrypting the data processing request based on a master key that has no corresponding relationship with the user identity identifier so that the client cannot obtain a plaintext data processing result that meets the expected requirements.
[0148] In some instances, determining whether the user of the data processing request is an authorized user based on the user identity identifier may include: detecting whether a master key corresponds to the user identity identifier; when no master key corresponds to the user identity identifier, determining that the user is an unauthorized user; when a master key corresponds to the user identity identifier, determining whether the user of the data processing request is an authorized user based on the master key and the registered master key.
[0149] In some instances, after the user is an authorized user, the method in this embodiment may further include: determining the access permission of the user based on the user identity identifier through the security control module; determining whether the user has access permission to the data corresponding to the data processing request based on the access permission; when having access permission, allowing the data processing request to be encrypted based on the master key corresponding to the user identity identifier; when not having access permission, prohibiting the data processing request from being encrypted based on the master key corresponding to the user identity identifier.
[0150] In some instances, the security control module and the data processing engine are located in the database kernel, and the database kernel is located in the trusted area; or,
[0151] The data processing engine is located in the database kernel, the security control module is located outside the database kernel and is communicatively connected to the database kernel, and the database kernel is located in the trusted area.
[0152] In some examples, the method in this embodiment may include: obtaining a data write request corresponding to ciphertext metadata through a security control module, where the ciphertext metadata includes at least one of the following for implementing encrypted data processing operations: encryption rule information for identifying sensitive data, user identity verification codes, and encryption algorithm parameters, and the ciphertext metadata is stored in a metadata database; determining user signature information corresponding to the data write request; identifying whether the data write request is a legitimate request based on the user signature information; when the data write request is a legitimate request, allowing the ciphertext metadata to be stored in the metadata database based on the data write request; when the data write request is an illegal request, prohibiting the ciphertext metadata from being stored in the metadata database based on the data write request.
[0153] It should be noted that the specific execution steps, step implementation principles, and step implementation effects of the data processing method in this embodiment are similar to those of the full ciphertext database system in the above Figures 1-4 For the specific execution steps, step implementation principles, and step implementation effects, parts not described in detail in this embodiment can be referred to the relevant descriptions of the Figures 1-4 shown embodiments. The execution process and technical effects of this technical solution are referred to the descriptions in the Figures 1-4 shown embodiments and will not be elaborated here.
[0154] In a possible design, Figure 5 the execution subject of the data processing method shown can be implemented as an electronic device. Referring to the attached Figure 6 shown, the execution subject of the data processing method in this embodiment can be implemented as a full ciphertext database system. The full ciphertext database system includes a security control module and a data processing engine connected by communication. Both the security control module and the data processing engine are located in the trusted area corresponding to the full ciphertext database; specifically, the electronic device may include: a first processor 21 and a first memory 22. Among them, the first memory 22 is used to store a program for the corresponding electronic device to execute the data processing method provided in the above Figure 6 shown embodiments, and the first processor 21 is configured to execute the program stored in the first memory 22.
[0155] The program includes one or more computer instructions. When one or more computer instructions are executed by the first processor 21, the following steps can be implemented: the security control module obtains a data processing request, and the data processing request includes sensitive data after encryption processing; the security control module decrypts the data processing request to obtain a decrypted processing request and sends the decrypted processing request to the data processing engine for processing; the data processing engine processes the decrypted processing request to obtain a data processing result.
[0156] Furthermore, the first processor 21 is also used to execute the foregoing Figure 5All or part of the steps in the illustrated embodiments. Among them, the structure of the electronic device may further include a first communication interface 23 for the electronic device to communicate with other devices or communication networks.
[0157] In addition, an embodiment of the present invention provides a computer storage medium for storing computer software instructions used by an electronic device, which includes programs for executing the data processing methods involved in the above Figure 5 illustrated method embodiments.
[0158] In addition, an embodiment of the present invention provides a computer program product, including: a computer program, when the computer program is executed by a processor of an electronic device, causing the processor to execute Figure 5 the data processing method in the illustrated method embodiments.
[0159] Figure 7 is a schematic flowchart of another data processing method provided by an embodiment of the present invention; referring to the appendix Figure 7 As shown, this embodiment provides another data processing method, and the execution subject of this method is a security control module. Referring to the appendix Figures 2-4 As shown, the security control module is communicatively connected to a data processing engine, and both the security control module and the data processing engine are located in the trusted area corresponding to the fully encrypted database. Based on the above security control module, the data processing method may include:
[0160] Step S701: Obtain a data processing request, where the data processing request includes sensitive data after encryption processing;
[0161] Step S702: Decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
[0162] It should be noted that the specific execution steps, step implementation principles, and step implementation effects of the data processing method in this embodiment are similar to those of the specific execution steps, step implementation principles, and step implementation effects of the security control module in the above Figures 1-4 For the parts not described in detail in this embodiment, reference may be made to the relevant descriptions of the Figures 1-4 illustrated embodiments. The execution process and technical effects of this technical solution are referred to the descriptions in the Figures 1-4 illustrated embodiments and will not be elaborated here.
[0163] Figure 8 is a schematic structural diagram of a security control device provided by an embodiment of the present invention; referring to the appendix Figure 8As shown in the figure, this embodiment provides a security control device. The security control device is communicatively connected to a data processing engine, and both the security control device and the data processing engine are located in the trusted area corresponding to the fully encrypted database. The security control device in this embodiment can execute the above-mentioned Figure 7 data processing method shown. Specifically, the security control device may include:
[0164] A second acquisition module 31, configured to acquire a data processing request, where the data processing request includes sensitive data that has been encrypted.
[0165] A second processing module 32, configured to decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
[0166] Figure 8 The device shown can execute Figure 7 the method of the embodiment shown. For parts not described in detail in this embodiment, reference can be made to the relevant descriptions of the Figure 7 embodiment shown. For the execution process and technical effects of this technical solution, refer to the description in the Figure 7 embodiment shown, which will not be elaborated here.
[0167] In a possible design, Figure 8 the structure of the security control device shown can be implemented as an electronic device. As Figure 9 shown, the electronic device may include: a second processor 41 and a second memory 42. Among them, the second memory 42 is used to store a program for the corresponding electronic device to execute the data processing method provided in the Figure 7 embodiment shown, and the second processor 41 is configured to execute the program stored in the second memory 42.
[0168] The program includes one or more computer instructions. When one or more computer instructions are executed by the second processor 41, the following steps can be implemented: acquiring a data processing request, where the data processing request includes sensitive data that has been encrypted; decrypting the data processing request to obtain a decrypted processing request, and sending the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
[0169] Furthermore, the second processor 41 is also used to execute all or part of the steps in the Figure 7 embodiment shown above.
[0170] Among them, the structure of the electronic device may further include a second communication interface 43, configured for the electronic device to communicate with other devices or communication networks.
[0171] In addition, an embodiment of the present invention provides a computer storage medium for storing computer software instructions used by an electronic device, which includes a program for executing the data processing method involved in the method embodiment described above. Figure 7 shown in the method embodiment.
[0172] Furthermore, an embodiment of the present invention provides a computer program product, including: a computer-readable storage medium storing computer instructions, when the computer instructions are executed by one or more processors, causing the one or more processors to execute the steps in the data processing method in the method embodiment described above. Figure 7 shown in the method embodiment.
[0173] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0174] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of adding a necessary general hardware platform, and of course, it can also be implemented by a combination of hardware and software. Based on this understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a computer product. The present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0175] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable devices generate a device for implementing the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0176] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the function specified in one process Figure 1 or process(es) and / or block(s) Figure 1 or block(s) specified in the one or more processes and / or blocks.
[0177] These computer program instructions can also be loaded onto a computer or other programmable device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing steps for implementing the function specified in one process Figure 1 or process(es) and / or block(s) Figure 1 or block(s) specified in the one or more processes and / or blocks.
[0178] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0179] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0180] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0181] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A fully encrypted database system, characterized in that, Including: A security control module, which is set in the trusted area corresponding to the fully encrypted database, is used to obtain a data processing request, decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to the data processing engine for processing; wherein, the data processing request includes sensitive data after encryption processing; The data processing engine, which is communicatively connected to the security control module and is set in the trusted area corresponding to the fully encrypted database, is used to process the decrypted processing request to obtain a data processing result; Wherein, the data processing engine is located in the database kernel, the security control module is located outside the database kernel and is communicatively connected to the database kernel, and the database kernel is located in the trusted area.
2. The system according to claim 1, wherein The system further includes: a database access module communicatively connected to the security control module and the client, and the database access module is used for: Obtaining an original processing request through the client; When the original processing request includes sensitive data, encrypting the sensitive data to obtain a data processing request; Sending the data processing request to the security control module.
3. The system according to claim 2, characterized in that, When the database access module encrypts the sensitive data to obtain a data processing request, the database access module is used for: Obtaining a main key corresponding to the original processing request and a random value for encrypting the sensitive data; Generating a data encryption key based on the main key and the random value; Using the data encryption key to encrypt the sensitive data to obtain a data processing request.
4. The system according to claim 3, wherein When the original processing request is a first type of operation and maintenance request, the main key corresponding to the original processing request is a null value, wherein the first type of operation and maintenance request is used to implement operation and maintenance operations independent of user data, and the user data is stored in the fully encrypted database; When the original processing request is a second type of operation and maintenance request, the main key corresponding to the original processing request is a non-null value, wherein the second type of operation and maintenance request is used to implement operation and maintenance operations related to user data.
5. The system according to claim 3, characterized in that, The database access module is further used for: Obtaining a public key for encrypting and transmitting the main key; Using the public key to encrypt the main key to obtain an encrypted main key; Sending the encrypted main key to the security control module, so that the security control module processes the encrypted main key based on the private key corresponding to the public key to obtain the main key, and uses the main key to decrypt the data processing request.
6. The system according to claim 3, wherein The data processing engine is further used for, after obtaining the data processing result, sending the data processing result to the security control module; The security control module is further configured to generate an encryption key when the data processing result includes sensitive data, encrypt the data processing result using the encryption key to obtain an encrypted processing result, and send the encrypted processing result and the random value to the database access module, where the encryption key is determined by the random value and the master key corresponding to the data processing request; The database access module is configured to decrypt the encrypted processing result based on the random value to obtain a decrypted processing result, and send the decrypted processing result to the client.
7. The system according to claim 1, characterized in that, After the security control module obtains the data processing request, the security control module is further configured to: Obtain the user identity identifier corresponding to the data processing request; Based on the user identity identifier, determine whether the user of the data processing request is an authorized user; When the user is an authorized user, encrypt the data processing request based on the master key corresponding to the user identity identifier, so that the client obtains a plaintext data processing result that meets the expected requirements; When the user is an unauthorized user, encrypt the data processing request based on the master key that has no corresponding relationship with the user identity identifier, so that the client cannot obtain a plaintext data processing result that meets the expected requirements.
8. The system according to claim 7, characterized in that, When the security control module determines whether the user of the data processing request is an authorized user based on the user identity identifier, the security control module is configured to: Detect whether the user identity identifier corresponds to a master key; When the user identity identifier does not correspond to a master key, determine that the user is an unauthorized user; When the user identity identifier corresponds to a master key, determine whether the user of the data processing request is an authorized user based on the master key and the registered master key.
9. The system according to claim 7, wherein After the user is an authorized user, the security control module is further configured to: Determine the access right of the user based on the user identity identifier; Based on the access right, determine whether the user has the access right to the data corresponding to the data processing request; When having the access right, allow encrypting the data processing request based on the master key corresponding to the user identity identifier; When not having the access right, prohibit encrypting the data processing request based on the master key corresponding to the user identity identifier.
10. The system according to any one of claims 1-9, characterized in that, The security control module is further configured to: Obtain a data writing request corresponding to the ciphertext metadata, where the ciphertext metadata includes at least one of the following for implementing the encrypted data processing operation: encryption rule information for identifying sensitive data, user identity verification code, encryption algorithm parameters, and the ciphertext metadata is stored in the metadata database; Determine the user signature information corresponding to the data writing request; Based on the user signature information, identify whether the data writing request is a legal request; When the data writing request is a legal request, allow storing the ciphertext metadata in the metadata database based on the data writing request; When the data writing request is an illegal request, storing the ciphertext metadata in the metadata database based on the data writing request is prohibited.
11. A data processing method, characterized in that Applied to a fully encrypted database system, the fully encrypted database system includes a security control module and a data processing engine that are communicatively connected. Both the security control module and the data processing engine are located in the trusted area corresponding to the fully encrypted database. The data processing engine is located in the database kernel, the security control module is located outside the database kernel and is communicatively connected to the database kernel, and the database kernel is located in the trusted area. The method includes: The security control module obtains a data processing request, and the data processing request includes sensitive data that has been encrypted. The security control module decrypts the data processing request to obtain a decrypted processing request, and sends the decrypted processing request to the data processing engine for processing. The data processing engine processes the decrypted processing request to obtain a data processing result.
12. A data processing method, characterized in that, Applied to a security control module, the security control module is communicatively connected to a data processing engine, and both the security control module and the data processing engine are located in the trusted area corresponding to the fully encrypted database. The data processing engine is located in the database kernel, the security control module is located outside the database kernel and is communicatively connected to the database kernel, and the database kernel is located in the trusted area. The method includes: Obtain a data processing request, where the data processing request includes sensitive data that has been encrypted. Decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
13. A safety control device, characterized in that, The security control device is communicatively connected to a data processing engine, and both the security control device and the data processing engine are located in the trusted area corresponding to the fully encrypted database. The data processing engine is located in the database kernel, the security control module is located outside the database kernel and is communicatively connected to the database kernel, and the database kernel is located in the trusted area. The security control device includes: A second acquisition module, configured to obtain a data processing request, where the data processing request includes sensitive data that has been encrypted. A second processing module, configured to decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
14. An electronic device, characterized in that, Includes: A memory and a processor; wherein, the memory is used to store one or more computer instructions, and when the one or more computer instructions are executed by the processor, the method described in any one of claims 11-12 above is implemented.