Database transparent encryption method and device, equipment and storage medium

By creating encrypted tablespaces in the database and performing chunking processing and key generation, the universality and data integrity of database encryption technology are solved, and the universality and data confidentiality of transparent encryption are achieved, which is suitable for any file system database.

CN120337291APending Publication Date: 2025-07-18CHENGDU WEISHITONG INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510474013.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing database encryption technology lacks universality and is difficult to ensure the confidentiality and integrity of data. Especially in transparent data encryption, the database requires specific capabilities and interfaces.

Method used

The target table space is created based on the preset encryption algorithm, and the data is transparently encrypted through block processing and key generation mechanisms, including generating table space keys, file master keys, file verification keys and file encryption keys to ensure the confidentiality and integrity of the data.

Benefits of technology

It realizes transparent encryption with the same effect as transparent encryption of data. It is suitable for any file system-based database, ensuring data confidentiality and integrity, not affecting database functions, and does not require the database to have specific encryption capabilities or interfaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337291A_ABST
    Figure CN120337291A_ABST
Patent Text Reader

Abstract

The invention discloses a database transparent encryption method and device, equipment and a storage medium, and relates to the technical field of information security, and the method comprises the steps: creating a target table space, and generating a table space key corresponding to the target table space; wherein the target table space is an encrypted table space encrypted based on a preset encryption algorithm; migrating the target plaintext table to the target table space, and performing block processing on plaintext data corresponding to the target plaintext table based on a preset block condition to obtain a plurality of plaintext blocks; determining a ciphertext of a file master key corresponding to the plaintext data according to the table space key, and respectively generating a file verification key and a file encryption key based on the file master key; and determining a target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculating a target verification value of the target ciphertext block according to the file verification key so as to determine a target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block and the target verification value. According to the invention, data transparent encryption with universality can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a method, device, equipment and storage medium for database transparent encryption. Background Art

[0002] As the core carrier of data assets, if a database has a data leakage, it may cause serious social harm and economic losses. Database encryption is the last line of defense for data security. Database encryption mainly includes technologies such as application transparent encryption, front-end proxy encryption, back-end proxy encryption, data transparent encryption, and file transparent encryption. Transparent data encryption has high performance, but it is not universal, and the database needs to have the ability of data transparent encryption and open the data transparent encryption interface. In addition, limited by the database, it is difficult to ensure the integrity of ciphertext data.

[0003] In summary, how to achieve universal data transparent encryption and ensure the confidentiality and integrity of data is a technical problem that needs to be solved urgently at present. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a method, device, equipment and storage medium for database transparent encryption, which can achieve universal data transparent encryption and ensure the confidentiality and integrity of data. The specific solutions are as follows:

[0005] In the first aspect, the present application provides a method for database transparent encryption, including:

[0006] Create a target tablespace and generate a tablespace key corresponding to the target tablespace; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm;

[0007] Migrate the target plaintext table to the target tablespace, and perform block processing on the plaintext data corresponding to the target plaintext table based on preset block conditions to obtain a number of plaintext blocks;

[0008] Determine the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and generate a file check key and a file encryption key respectively based on the file master key;

[0009] Determine the target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculate the target check value of the target ciphertext block according to the file check key, so as to determine the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block and the target check value.

[0010] Optionally, the generating the tablespace key corresponding to the target tablespace includes:

[0011] Generate the tablespace key corresponding to the target tablespace and the tablespace key identifier corresponding to the tablespace key based on the database encryption management system, and generate a target instruction corresponding to the target tablespace; wherein, the target instruction includes a preset encryption algorithm identifier, a preset verification algorithm identifier, and the tablespace key.

[0012] Correspondingly, after generating the tablespace key corresponding to the target tablespace, it further includes:

[0013] Create a directory corresponding to the target tablespace according to the target instruction, and mount the directory to a preset user space file system, so as to monitor the preset file read and write operations in the database by using the preset user space file system.

[0014] Optionally, the block processing of the plaintext data corresponding to the target plaintext table based on the preset block condition includes:

[0015] Determine the preset block condition based on the preset data page size corresponding to the current database, so as to perform block processing on the plaintext data corresponding to the target plaintext table based on the preset block condition.

[0016] Optionally, the determining the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and generating a file verification key and a file encryption key based on the file master key respectively includes:

[0017] Generate the file master key and security parameters corresponding to the plaintext data, and perform encryption processing on the file master key based on the tablespace key to obtain the ciphertext corresponding to the file master key;

[0018] Generate the file verification key based on the file master key and the preset verification algorithm identifier, and generate the file encryption key based on the file master key and the preset encryption algorithm identifier.

[0019] Optionally, the determining the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block, and the target verification value includes:

[0020] Determine the first file header of the target encrypted file based on the ciphertext;

[0021] Calculate the file verification value corresponding to the first file header based on the file verification key, and determine the second file header of the target encrypted file based on the first file header and the file verification value;

[0022] Determine the file body of the target encrypted file according to the target ciphertext block and the target verification value, and determine the target encrypted file corresponding to the plaintext data based on the file body and the second file header.

[0023] Optionally, determining the first file header of the target encrypted file based on the ciphertext includes:

[0024] Determine the memory occupancy of the plaintext data and determine the data block size of the plaintext block;

[0025] Determine the first file header of the target encrypted file based on the memory occupancy, the data block size, the tablespace key identifier, the ciphertext, the preset encryption algorithm identifier, the preset verification algorithm identifier, and the security parameter.

[0026] Optionally, the database transparent encryption method further includes:

[0027] Parse the file header to be verified of the target encrypted file to obtain a corresponding parsing result, and determine the file master key corresponding to the target encrypted file based on the parsing result;

[0028] Generate the file verification key based on the file master key and the parsing result, and determine the first verification value of the file header to be verified based on the file verification key and the parsing result;

[0029] If it is determined that the first verification value is consistent with the file verification value in the file header to be verified, then determine the second verification value of the ciphertext block to be verified of the target encrypted file based on the file verification key and the parsing result;

[0030] If it is determined that the second verification value is consistent with the target verification value of the ciphertext block to be verified, then generate the file encryption key based on the file master key and the parsing result, and determine the corresponding plaintext data based on the file encryption key and the target encrypted file.

[0031] In a second aspect, the present application provides a database transparent encryption device, including:

[0032] A target tablespace creation module, configured to create a target tablespace and generate a tablespace key corresponding to the target tablespace; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm;

[0033] A plaintext block acquisition module, configured to migrate a target plaintext table to the target tablespace, and perform a chunking process on the plaintext data corresponding to the target plaintext table based on preset chunking conditions to obtain a plurality of plaintext blocks;

[0034] A ciphertext determination module, configured to determine the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and generate a file verification key and a file encryption key respectively based on the file master key;

[0035] A target encrypted file determination module, configured to determine a target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculate a target check value of the target ciphertext block according to the file check key, so as to determine a target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block, and the target check value.

[0036] In a third aspect, the present application provides an electronic device, including:

[0037] A memory, configured to store a computer program;

[0038] A processor, configured to execute the computer program to implement the foregoing database transparent encryption method.

[0039] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the foregoing database transparent encryption method is implemented.

[0040] In the present application, first, a target tablespace is created, and a tablespace key corresponding to the target tablespace is generated; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm; then, a target plaintext table is migrated to the target tablespace, and the plaintext data corresponding to the target plaintext table is block-processed based on a preset block condition to obtain a plurality of plaintext blocks; then, a ciphertext of a file master key corresponding to the plaintext data is determined according to the tablespace key, and a file check key and a file encryption key are respectively generated based on the file master key; finally, a target ciphertext block corresponding to the plaintext block is determined based on the file encryption key, and a target check value of the target ciphertext block is calculated according to the file check key, so as to determine a target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block, and the target check value. As can be seen from the above, the present application can achieve the same effect as the data transparent encryption technology. The encryption and decryption processes are completely transparent to the application, and the functions of the database after encryption are not lost at all. It is not limited to the data type, does not affect statement parsing and optimization, and does not affect database management and use. At the same time, the present application is more universal than the data transparent encryption technology, is applicable to any file system-based database, does not require the database to have the data transparent encryption ability, and does not require the database to open the TDE interface (Transparent Data Encryption). In addition, in the present application, the plaintext data corresponding to the target plaintext table is divided into a combination of multiple ciphertext blocks and check values, which can not only ensure the confidentiality of the data during the database storage process, but also ensure the integrity of the data. Description of the Drawings

[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.

[0042] Figure 1 It is a system architecture diagram of a database transparent encryption solution provided by this application;

[0043] Figure 2 It is a flowchart of a database transparent encryption method provided by this application;

[0044] Figure 3 It is a flowchart of a specific database transparent encryption method provided by this application;

[0045] Figure 4 It is a schematic structural diagram of a database transparent encryption device provided by this application;

[0046] Figure 5 It is a structural diagram of an electronic device provided by this application. Specific embodiments

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0048] As the core carrier of data assets, if a database leaks data, it may cause serious social harm and economic losses. Database encryption is the last line of defense for data security. Database encryption mainly includes technologies such as application transparent encryption, front-end proxy encryption, back-end proxy encryption, data transparent encryption, and file transparent encryption. Transparent data encryption has high performance, but it is not universal, and the database needs to have the ability of data transparent encryption and open data transparent encryption interfaces. In addition, limited by the database, it is difficult to ensure the integrity of ciphertext data. Therefore, this application provides a database transparent encryption solution that can achieve universal data transparent encryption and ensure the confidentiality and integrity of data.

[0049] In the database transparent encryption solution of this application, the system framework adopted can be specifically referred to Figure 1As shown in the figure, it may specifically include: a database user space, a database kernel space, and a database storage space. Among them, the database user space contains a database encryption management system and a database encryption service. The database encryption management system is used for policy management and key management. The database encryption service is built with a security password module and provides transparent encryption functions for the database tablespace through the FUSE (Filesystem in Userspace) framework provided by the Linux system. The database kernel space uses FUSE technology to monitor the read and write behaviors of the database on data files in real time, and calls the callback function registered in the user space to perform block encryption and ciphertext integrity protection on the written data, and perform decryption and ciphertext integrity verification on the read data. The database storage space securely stores the database encrypted files in a block encryption and block verification manner. The database encrypted file consists of two parts: a file header and a file body. The file header is used to define and store file attributes, including information such as plaintext size, block size, encryption algorithm identifier, verification algorithm identifier, tablespace key identifier, file master key, security parameters, and file verification value. The file body adopts a block encryption and verification structure, dividing the database file into several file blocks, and each file block consists of two parts: a ciphertext block and a verification value.

[0050] See Figure 2 As shown in the figure, an embodiment of the present invention discloses a database transparent encryption method, which may include:

[0051] Step S11: Create a target tablespace and generate a tablespace key corresponding to the target tablespace; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm.

[0052] In this embodiment, the target tablespace can be created based on a symmetric encryption algorithm in the database encryption management system.

[0053] It should be noted that generating the tablespace key corresponding to the target tablespace may include: generating the tablespace key corresponding to the target tablespace and the tablespace key identifier corresponding to the tablespace key based on the database encryption management system, and generating the target instruction corresponding to the target tablespace; wherein, the target instruction includes a preset encryption algorithm identifier, a preset verification algorithm identifier, and the tablespace key. Correspondingly, after generating the tablespace key corresponding to the target tablespace, it may further include: creating a directory corresponding to the target tablespace according to the target instruction, and mounting the directory to the preset user space file system, so as to monitor the preset file read and write operations in the database by using the preset user space file system. Specifically, when the database encryption management system creates a target tablespace, a tablespace key and the corresponding tablespace key identifier are generated synchronously, and then a target instruction for creating the target tablespace is sent to the database encryption service. The target instruction includes a preset encryption algorithm identifier, a preset verification algorithm identifier, and the tablespace key. It can be understood that the tablespace key is randomly generated by the database encryption management service and is encrypted and protected by the encryption public and private key pairs of the security password module built in the database encryption service. After receiving the target instruction, the database encryption service creates the directory to which the target tablespace belongs, mounts the directory to the FUSE file system, and synchronously establishes the binding relationship between the tablespace key identifier and the target tablespace.

[0054] Step S12: Migrate the target plaintext table to the target tablespace, and perform block processing on the plaintext data corresponding to the target plaintext table based on a preset block condition to obtain a number of plaintext blocks.

[0055] In this embodiment, the database encryption management system migrates the plaintext table to the target tablespace. After the kernel driver of the FUSE file system detects a file write operation, it calls the callback function registered in the user space to protect the confidentiality and integrity of the data file of the plaintext table. It can be understood that performing block processing on the plaintext data corresponding to the target plaintext table based on a preset block condition may include: determining the preset block condition based on the preset data page size corresponding to the current database, so as to perform block processing on the plaintext data corresponding to the target plaintext table based on the preset block condition. Specifically, the database encryption service performs block division on the plaintext data to obtain a number of plaintext blocks. In order to reduce fragmentation and unnecessary I / O operations when the database stores and retrieves data, the block size is kept consistent with the data page size of the current database, which may be 4KB or 8KB. It should be noted that when the size of the last block of the plaintext data is less than the preset block size, a padding mechanism needs to be adopted to ensure that the size of each plaintext block is consistent. Common padding methods include padding with zero characters, random characters, or characters in a specific pattern.

[0056] Step S13: Determine the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and generate a file verification key and a file encryption key respectively based on the file master key.

[0057] In this embodiment, the step of determining the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key and generating a file verification key and a file encryption key respectively based on the file master key may include: generating the file master key and security parameters corresponding to the plaintext data, and encrypting the file master key based on the tablespace key to obtain the ciphertext corresponding to the file master key; generating the file verification key based on the file master key and the preset verification algorithm identifier, and generating the file encryption key based on the file master key and the preset encryption algorithm identifier. Specifically, the database encryption service calls the security password module to generate a file master key and security parameters for the database file. The file master key is randomly generated by the security password module built into the database encryption service, and the file master key is encrypted by the tablespace key to obtain the ciphertext corresponding to the file master key. Then, the database encryption service can call the security password module to derive the file verification key according to the file master key and the preset verification algorithm identifier, and derive the file encryption key according to the file master key and the preset encryption algorithm identifier.

[0058] Step S14: Determine the target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculate the target verification value of the target ciphertext block according to the file verification key, so as to determine the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block, and the target verification value.

[0059] In this embodiment, the database encryption service calls the security password module to encrypt the plaintext block with the file encryption key to obtain the target ciphertext block, and calculates the target verification value of the target ciphertext block with the file verification key.

[0060] It should be noted that the determination of the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block, and the target check value may include: determining a first file header of the target encrypted file based on the ciphertext; calculating a file check value corresponding to the first file header based on the file check key, and determining a second file header of the target encrypted file based on the first file header and the file check value; determining a file body of the target encrypted file according to the target ciphertext block and the target check value, and determining the target encrypted file corresponding to the plaintext data based on the file body and the second file header. The determination of the first file header of the target encrypted file based on the ciphertext may include: determining the memory occupancy space of the plaintext data and determining the data block size of the plaintext block; determining the first file header of the target encrypted file based on the memory occupancy space, the data block size, the tablespace key identifier, the ciphertext, the preset encryption algorithm identifier, the preset check algorithm identifier, and the security parameter. Specifically, the database encryption service first determines the memory occupancy space of the plaintext data, that is, the plaintext size, and determines the data block size of the plaintext block, that is, the block size. Then the database encryption service writes the plaintext size, the block size, the tablespace key identifier, the ciphertext corresponding to the file master key, the preset encryption algorithm identifier, the preset check algorithm identifier, and the security parameter into the file header to obtain the first file header. Then the database encryption service calls the security password module to calculate the check value of the first file header using the file check key to obtain the file check value of the first file header, and writes the file check value into the file header to obtain the second file header. The database encryption service writes each target ciphertext block and the target check value corresponding to the target ciphertext block into the file body, and determines the target encrypted file corresponding to the plaintext data according to each file body and the second file header.

[0061] It can be understood that in this embodiment, the file master key is protected by the tablespace key, the file encryption key is derived from the file master key and the preset encryption algorithm identifier, and the file check key is derived from the file master key and the preset check algorithm identifier. The database instance key can also be used to isolate the database instance; the file encryption key and the file check key can be used to protect the confidentiality and integrity of the database storage. And each database file has and only has one file master key to ensure the security of data file storage.

[0062] As can be seen from the above, compared with the existing database encryption methods, this embodiment does not need to support multiple programming languages, does not involve technical issues such as database syntax parsing and ciphertext retrieval, and there is no field expansion problem; it does not change the network structure, does not involve technical issues such as database syntax parsing and ciphertext retrieval, and there is no single point of failure problem; it is applicable to any file system-based database, is not restricted by the database, and does not involve technical issues such as ciphertext indexing and ciphertext fuzzy query; it does not require the database to have the TDE data transparent encryption capability, does not require the database to open the TDE interface, and can solve the problem of ciphertext data integrity; by using the FUSE framework provided by the Linux system, there is no need to repeatedly adapt to the operating system kernel, with low technical complexity and good compatibility. In this way, this embodiment can achieve the same effect as the TDE data transparent encryption method, the encryption and decryption process is completely transparent to the application, the database function has zero loss after encryption, the data type is not limited, the statement parsing and optimization are not affected, and the database management and use are not affected. Moreover, this embodiment is more universal than the data transparent encryption technology, is applicable to any file system-based database, does not require the database to have the data transparent encryption capability, nor does it require the database to open the TDE interface.

[0063] Based on the previous embodiment, it can be known that this application can encrypt plaintext data to obtain a target encrypted file. Next, in this embodiment, decrypting the target encrypted file and verifying the integrity of the plaintext data will be elaborated in detail. Refer to Figure 3 As shown, an embodiment of the present invention further discloses a database transparent encryption method, which may include:

[0064] Step S21, parsing the file header to be verified of the target encrypted file to obtain a corresponding parsing result, and determining the file master key corresponding to the target encrypted file based on the parsing result.

[0065] In this embodiment, the database engine requests to read data from the database file. After the kernel driver of the FUSE file system monitors the file read operation, it calls the callback function registered in the user space to perform integrity verification and block decryption on the data. Specifically, the database encryption service parses the file header to be verified to obtain information such as the plaintext size, block size, tablespace key identifier, ciphertext corresponding to the file master key, preset encryption algorithm identifier, preset verification algorithm identifier, security parameters, and file verification value. The database encryption service pulls the tablespace key from the database encryption management system according to the tablespace key identifier and the encryption public and private keys of the security password module. After that, the database encryption service parses the ciphertext corresponding to the file master key according to the tablespace key to obtain the file master key.

[0066] Step S22, generating a file verification key based on the file master key and the parsing result, and determining a first verification value of the file header to be verified based on the file verification key and the parsing result.

[0067] In this embodiment, the database encryption service imports the tablespace key and the file master key into the secure password module. The database encryption service calls the secure password module to generate a file verification key according to the file master key and the preset verification algorithm identifier. Then, the database encryption service calls the secure password module to calculate the first verification value of the file header to be verified by using the file verification key, and compares it with the file verification value stored in the file header to be verified to verify the integrity of the file header to be verified.

[0068] Step S23: If it is determined that the first verification value is consistent with the file verification value in the file header to be verified, then determine the second verification value of the ciphertext block to be verified of the target encrypted file based on the file verification key and the parsing result.

[0069] It can be understood that if it is determined that the first verification value is consistent with the file verification value in the file header to be verified, it is determined that the file header to be verified is complete. The database encryption service calls the secure password module to calculate the second verification value of the ciphertext block to be verified by using the file verification key, and compares it with the target verification value stored in the corresponding file body in the target encrypted file to verify the integrity of the ciphertext block to be verified.

[0070] Step S24: If it is determined that the second verification value is consistent with the target verification value of the ciphertext block to be verified, then generate a file encryption key based on the file master key and the parsing result, and determine the corresponding plaintext data based on the file encryption key and the target encrypted file.

[0071] It should be noted that if it is determined that the second verification value is consistent with the target verification value of the ciphertext block to be verified, it is determined that the ciphertext block to be verified is complete. The database encryption service calls the secure password module to generate a file encryption key according to the file master key and the preset encryption algorithm identifier. Then, the database encryption service calls the secure password module to decrypt each ciphertext block in the target encrypted file by using the file encryption key to obtain the plaintext data. Finally, the database encryption service returns the plaintext data to the kernel of the FUSE file system, and the kernel of the FUSE file system returns the plaintext database to the calling program.

[0072] As can be seen from the above, in this embodiment, the parsing result corresponding to the file header to be verified is first obtained, and the file master key is determined according to the parsing result; the file verification key is determined by using the file master key; the first verification value of the file header to be verified is generated through the file verification key to verify the integrity and accuracy of the file header to be verified; then the second verification value of the ciphertext block to be verified is generated through the file verification key to verify the integrity and accuracy of the ciphertext block to be verified; when it is verified that the file header to be verified and the ciphertext block to be verified are complete and accurate, the file encryption key is determined by using the file master key, and the plaintext data corresponding to the target encrypted file is determined by using the file encryption key. In this way, this embodiment can perform block verification on the database file to verify the confidentiality and integrity of the data storage process.

[0073] Correspondingly, as shown in Figure 4 this application embodiment also provides a database transparent encryption device, which may include:

[0074] A target tablespace creation module 11, configured to create a target tablespace and generate a tablespace key corresponding to the target tablespace; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm;

[0075] A plaintext block acquisition module 12, configured to migrate the target plaintext table to the target tablespace and perform block processing on the plaintext data corresponding to the target plaintext table based on preset block conditions to obtain a plurality of plaintext blocks;

[0076] A ciphertext determination module 13, configured to determine the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and respectively generate a file verification key and a file encryption key based on the file master key;

[0077] A target encrypted file determination module 14, configured to determine the target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculate the target verification value of the target ciphertext block according to the file verification key, so as to determine the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block and the target verification value.

[0078] As can be seen from the above, in the present application, a target tablespace is first created, and a tablespace key corresponding to the target tablespace is generated; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm; then the target plaintext table is migrated to the target tablespace, and the plaintext data corresponding to the target plaintext table is block-processed based on a preset block condition to obtain a plurality of plaintext blocks; then the ciphertext of the file master key corresponding to the plaintext data is determined according to the tablespace key, and a file verification key and a file encryption key are respectively generated based on the file master key; finally, the target ciphertext block corresponding to the plaintext block is determined based on the file encryption key, and the target verification value of the target ciphertext block is calculated according to the file verification key, so as to determine the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block and the target verification value. As can be seen from the above, the present application can achieve the same effect as the data transparent encryption technology. The encryption and decryption processes are completely transparent to the application, and the database function has zero loss after encryption. It is not limited to data types, does not affect statement parsing and optimization, and does not affect database management and use. At the same time, the present application is more universal than the data transparent encryption technology, is applicable to any database based on the file system, does not require the database to have the data transparent encryption ability, and does not require the database to open the TDE interface. In addition, in the present application, the plaintext data corresponding to the target plaintext table is divided into a combination of multiple ciphertext blocks and verification values, which can not only ensure the confidentiality of data during the database storage process, but also ensure the integrity of the data.

[0079] In some specific embodiments, the target tablespace creation module 11 may include:

[0080] A tablespace key generation unit, configured to generate the tablespace key corresponding to the target tablespace and the tablespace key identifier corresponding to the tablespace key based on a database encryption management system, and generate a target instruction corresponding to the target tablespace; wherein, the target instruction includes a preset encryption algorithm identifier, a preset verification algorithm identifier, and the tablespace key;

[0081] Correspondingly, the database transparent encryption device may further include:

[0082] A directory creation module, configured to create a directory corresponding to the target tablespace according to the target instruction, and mount the directory to a preset user space file system, so as to monitor preset file read and write operations in the database by using the preset user space file system.

[0083] In some specific embodiments, the plaintext block acquisition module 12 may include:

[0084] A plaintext data chunking unit, configured to determine the preset chunking condition based on the preset data page size corresponding to the current database, so as to perform chunking processing on the plaintext data corresponding to the target plaintext table based on the preset chunking condition.

[0085] In some specific embodiments, the ciphertext determination module 13 may include:

[0086] A ciphertext determination unit, configured to generate the file master key and security parameters corresponding to the plaintext data, and encrypt the file master key based on the tablespace key to obtain the ciphertext corresponding to the file master key;

[0087] A file encryption key generation unit, configured to generate the file verification key based on the file master key and the preset verification algorithm identifier, and generate the file encryption key based on the file master key and the preset encryption algorithm identifier.

[0088] In some specific embodiments, the target encrypted file determination module 14 may include:

[0089] A first file header determination sub-module, configured to determine the first file header of the target encrypted file based on the ciphertext;

[0090] A second file header determination sub-module, configured to calculate the file verification value corresponding to the first file header based on the file verification key, and determine the second file header of the target encrypted file based on the first file header and the file verification value;

[0091] A target encrypted file determination sub-module, configured to determine the file body of the target encrypted file according to the target ciphertext block and the target verification value, and determine the target encrypted file corresponding to the plaintext data based on the file body and the second file header.

[0092] In some specific embodiments, the first file header determination sub-module may include:

[0093] A memory occupancy space determination unit, configured to determine the memory occupancy space of the plaintext data and determine the data block size of the plaintext block;

[0094] A first file header determination unit, configured to determine the first file header of the target encrypted file based on the memory occupancy space, the data block size, the tablespace key identifier, the ciphertext, the preset encryption algorithm identifier, the preset verification algorithm identifier, and the security parameters.

[0095] In some specific embodiments, the database transparent encryption device may further include:

[0096] The file master key determination module is configured to parse the file header to be verified of the target encrypted file to obtain a corresponding parsing result, and determine the file master key corresponding to the target encrypted file based on the parsing result;

[0097] The first check value determination module is configured to generate the file check key based on the file master key and the parsing result, and determine the first check value of the file header to be verified based on the file check key and the parsing result;

[0098] The second check value determination module is configured to, if it is determined that the first check value is consistent with the file check value in the file header to be verified, determine the second check value of the ciphertext block to be verified of the target encrypted file based on the file check key and the parsing result;

[0099] The plaintext data determination module is configured to, if it is determined that the second check value is consistent with the target check value of the ciphertext block to be verified, generate the file encryption key based on the file master key and the parsing result, and determine the corresponding plaintext data based on the file encryption key and the target encrypted file.

[0100] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the database transparent encryption method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0101] In this embodiment, the power supply 23 is used to provide a working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.

[0102] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be short-term storage or permanent storage.

[0103] Among them, the operating system 221 is used to manage and control each hardware device and computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the database transparent encryption method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.

[0104] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the database transparent encryption method disclosed above. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0105] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and reference can be made to the method part for relevant details.

[0106] Those skilled in the art can further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0107] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0108] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.

[0109] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this text to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A database transparent encryption method, characterized in that, Including: Create a target tablespace and generate a tablespace key corresponding to the target tablespace; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm; Migrate the target plaintext table to the target tablespace, and perform block processing on the plaintext data corresponding to the target plaintext table based on a preset block condition to obtain a number of plaintext blocks; Determine the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and generate a file verification key and a file encryption key respectively based on the file master key; Determine the target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculate the target verification value of the target ciphertext block according to the file verification key, so as to determine the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block and the target verification value.

2. The database transparent encryption method according to claim 1, characterized in that The generating the tablespace key corresponding to the target tablespace includes: Generate the tablespace key corresponding to the target tablespace and the tablespace key identifier corresponding to the tablespace key based on the database encryption management system, and generate a target instruction corresponding to the target tablespace; wherein, the target instruction includes a preset encryption algorithm identifier, a preset verification algorithm identifier and the tablespace key; Correspondingly, after generating the tablespace key corresponding to the target tablespace, it further includes: Create a directory corresponding to the target tablespace according to the target instruction, and mount the directory to the preset user space file system, so as to monitor the preset file read and write operations in the database by using the preset user space file system.

3. The database transparent encryption method according to claim 1, wherein, The performing block processing on the plaintext data corresponding to the target plaintext table based on a preset block condition includes: Determine the preset block condition based on the preset data page size corresponding to the current database, so as to perform block processing on the plaintext data corresponding to the target plaintext table based on the preset block condition.

4. The database transparent encryption method according to claim 2, wherein The determining the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and generating a file verification key and a file encryption key respectively based on the file master key includes: Generate the file master key and security parameters corresponding to the plaintext data, and perform encryption processing on the file master key based on the tablespace key to obtain the ciphertext corresponding to the file master key; Generate the file verification key based on the file master key and the preset verification algorithm identifier, and generate the file encryption key based on the file master key and the preset encryption algorithm identifier.

5. The database transparent encryption method according to claim 4, wherein, The determining the target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block and the target verification value includes: Determine the first file header of the target encrypted file based on the ciphertext; Calculate the file verification value corresponding to the first file header based on the file verification key, and determine the second file header of the target encrypted file based on the first file header and the file verification value; Determine the file body of the target encrypted file according to the target ciphertext block and the target verification value, and determine the target encrypted file corresponding to the plaintext data based on the file body and the second file header.

6. The database transparent encryption method according to claim 5, wherein Determining a first file header of the target encrypted file based on the ciphertext includes: Determining the memory occupancy of the plaintext data and determining the data block size of the plaintext block; Determining the first file header of the target encrypted file based on the memory occupancy, the data block size, the tablespace key identifier, the ciphertext, the preset encryption algorithm identifier, the preset verification algorithm identifier, and the security parameters.

7. The database transparent encryption method according to any one of claims 1 to 6, characterized in that, It further includes: Parsing the file header to be verified of the target encrypted file to obtain a corresponding parsing result, and determining the file master key corresponding to the target encrypted file based on the parsing result; Generating a file verification key based on the file master key and the parsing result, and determining a first verification value of the file header to be verified based on the file verification key and the parsing result; If it is determined that the first verification value is consistent with the file verification value in the file header to be verified, then determining a second verification value of the ciphertext block to be verified of the target encrypted file based on the file verification key and the parsing result; If it is determined that the second verification value is consistent with the target verification value of the ciphertext block to be verified, then generating a file encryption key based on the file master key and the parsing result, and determining the corresponding plaintext data based on the file encryption key and the target encrypted file.

8. A database transparent encryption device, characterized in that, It includes: A target tablespace creation module for creating a target tablespace and generating a tablespace key corresponding to the target tablespace; wherein, the target tablespace is an encrypted tablespace encrypted based on a preset encryption algorithm; A plaintext block acquisition module for migrating a target plaintext table to the target tablespace and performing block processing on the plaintext data corresponding to the target plaintext table based on preset block conditions to obtain a plurality of plaintext blocks; A ciphertext determination module for determining the ciphertext of the file master key corresponding to the plaintext data according to the tablespace key, and respectively generating a file verification key and a file encryption key based on the file master key; A target encrypted file determination module for determining a target ciphertext block corresponding to the plaintext block based on the file encryption key, and calculating a target verification value of the target ciphertext block according to the file verification key, so as to determine a target encrypted file corresponding to the plaintext data based on the ciphertext, the target ciphertext block, and the target verification value.

9. An electronic device, characterized in that, The electronic device includes a processor and a memory; wherein, the memory is used for storing a computer program, and the computer program is loaded and executed by the processor to implement the database transparent encryption method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, For saving a computer program, the computer program, when executed by a processor, implements the database transparent encryption method according to any one of claims 1 to 7.