Database quantum encryption method based on bypass deployment
The bypass proxy gateway generates encryption keys and key pairs, identify and encrypt sensitive fields, solves the performance problems caused by imprecise encryption in the prior art, and realizes the secure and efficient processing of database privacy data.
Patent Information
- Application Number
- CN202510540644.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-18
AI Technical Summary
The existing database encryption technology cannot be refined and encrypted, resulting in high performance overhead and reducing database read and write performance during data processing, affecting the efficiency of the business system.
The encryption key is generated through the bypass proxy gateway, and independent key pairs are assigned to different power grid data access users, and sensitive fields are identified and encrypted when data is written, and encryption query and decryption are performed during query.
It realizes secure and efficient encryption of private data, reduces the risk of data leakage, and improves the processing performance and security of the database.
Smart Images

Figure CN120342716A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encrypted communication, and particularly to a database quantum encryption method based on bypass deployment. Background Art
[0002] In the digital wave, data has become one of the most core assets of enterprises and organizations. From a vast amount of user identity information, transaction records to business secrets related to the survival of enterprises, various types of data are stored in databases. However, the data security situation is not optimistic. Data leakage incidents occur frequently, bringing heavy blows to all parties. For example, a well-known e-commerce platform was once hacked, resulting in the theft of sensitive data such as the names, addresses, contact information, and payment information of millions of users. This not only damaged the rights and interests of users, but also put the e-commerce platform in a difficult situation of facing huge compensation, customer loss, and serious damage to its brand image. According to statistics by authoritative institutions, the number of data leakage incidents has been on the rise in recent years, and the average economic loss caused by each data leakage is as high as millions of dollars. Data security has become a key issue that enterprises and organizations urgently need to solve.
[0003] To address the data security challenges, traditional database encryption technologies have emerged. However, these technologies have many limitations. The existing technologies have insufficiently fine-grained encryption. Most traditional encryption methods encrypt the entire database or the entire table, and cannot encrypt specific fields separately. This leads to the situation that in practical applications, even if only some fields involve sensitive information, a large amount of irrelevant data will be encrypted and decrypted together, greatly increasing the performance overhead of the system. In addition, during the data encryption and decryption processes, traditional encryption methods will significantly reduce the read and write performance of the database, especially when dealing with large-scale data, the performance degradation is more obvious, seriously affecting the normal operation efficiency of the business system. Therefore, a database quantum encryption method based on bypass deployment is needed. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a database quantum encryption method based on bypass deployment, which can encrypt privacy data safely and efficiently.
[0005] To achieve the above purpose, the embodiments of the present invention provide a database quantum encryption method based on bypass deployment, and the encryption method includes:
[0006] A bypass proxy gateway generates an encryption key and assigns independent key pairs to different grid data access users;
[0007] Encrypt the privacy data in the new grid data record according to the encryption key and add it to the database;
[0008] Identify the privacy data in the query request according to the query request initiated by the user;
[0009] Encapsulate the identified privacy data through encryption, and perform an encrypted query in the database based on the encrypted privacy data;
[0010] Obtain the result of the encrypted query, decrypt the result of the encrypted query with the key pair in the allocated key pair, and return the decrypted result to the authorized user.
[0011] Optionally, encrypt the privacy data in the new power grid data record according to the encryption key and add it to the database, including:
[0012] The application system initiates an INSERT SQL request to add the new power grid data to the database;
[0013] Parse the INSERT SQL request, and intercept the INSERT SQL request when an INSERT statement is detected;
[0014] Parse the INSERT statement in the INSERT SQL request to extract the table name, field list, and value list;
[0015] Perform sensitive word recognition on the extracted table name, field list, and value list to obtain the sensitive fields belonging to the privacy user;
[0016] Encrypt the sensitive fields through the encryption key.
[0017] Optionally, perform sensitive word recognition on the extracted table name, field list, and value list to obtain the sensitive fields belonging to the privacy user, including:
[0018] Obtain the table name, field list, and value list, and perform a matching search in the predefined sensitive word rule library;
[0019] When a keyword is matched in the sensitive word rule library, extract the corresponding value of the field name in the table name, field list, and value list that matches the keyword;
[0020] Perform data format verification according to the corresponding value of the extracted field name;
[0021] When the verification passes, the corresponding value of the field name is marked as a sensitive field;
[0022] When the verification fails, the corresponding value of the field name is regarded as ordinary data.
[0023] Optionally, perform data format verification according to the extracted corresponding value, including:
[0024] Obtain the field name and the corresponding value of the field name;
[0025] Determine the sensitive type of the field name;
[0026] When it is determined that the field name is a mobile phone number, determine whether the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3 - 9, and there are a total of 11 digits;
[0027] When the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3 - 9, and there are a total of 11 digits, determine that the corresponding value of the field name is a sensitive field;
[0028] When it is determined that the field name is an ID number, determine whether the corresponding value of the field name conforms to the rule of the GB11643 - 1999 standard;
[0029] When the corresponding value of the field name conforms to the rule of the GB11643 - 1999 standard, determine that the corresponding value of the field name is a sensitive field;
[0030] When it is determined that the field name is an email, determine whether the corresponding value of the field name conforms to the rule of the RFC5322 standard;
[0031] When the corresponding value of the field name conforms to the rule of the RFC5322 standard, determine that the corresponding value of the field name is a sensitive field.
[0032] Optionally, encrypt the sensitive field with an encryption key, including:
[0033] Obtain the sensitive field;
[0034] Convert the numbers in the sensitive field to binary, construct a polynomial based on the numbers converted to binary, and the numbers converted to binary are the coefficients of the polynomial;
[0035] Scale the polynomial according to the specification of the Kyber algorithm to obtain a message that meets the requirements;
[0036] Calculate the ciphertext according to the obtained key through formula (1):
[0037]
[0038] Where u, v are ciphertexts, e1 is a randomly generated error vector, r is a random polynomial vector, e2 is an error polynomial, A, t are public keys, and m represents the message.
[0039] Optionally, encrypt the privacy data in the new power grid data record with an encryption key and add it to the database, including:
[0040] Obtain the encrypted sensitive field;
[0041] Combine the encrypted sensitive field with ordinary data to generate a rewritten INSERT statement;
[0042] Send the rewritten INSERT statement to the database to ensure that the sensitive field is stored in an encrypted form.
[0043] Optionally, encrypt and encapsulate the identified privacy data, and perform an encrypted query in the database according to the encrypted and encapsulated privacy data, including:
[0044] Obtain the privacy data in the encrypted query request;
[0045] Encapsulate the privacy field value corresponding to the privacy data in the encrypted query request into an SQL query to generate a rewritten SELECT statement;
[0046] Send the rewritten SELECT statement to the database;
[0047] According to the rewritten SELECT statement, parse the SQL expression, query the corresponding data records in the database, and then return the encrypted data records that meet the conditions.
[0048] Optionally, the sensitive fields include voltage, current, and user information.
[0049] Through the above technical solution, a database quantum encryption method based on bypass deployment provided by the present invention generates an encryption key through a bypass proxy gateway, and can allocate independent key pairs to different grid data access users, so that different grid data access users can decrypt the encrypted information separately according to the allocated keys. Encrypt the privacy data in the new grid data record according to the encryption key and add it to the database, so that the database can be continuously updated. According to the query request initiated by the user, the privacy data in the query request can be identified, and then the identified privacy data can be encrypted and encapsulated, and an encrypted query can be performed in the database according to the encrypted and encapsulated privacy data. Obtain the result of the encrypted query, and then decrypt the result of the encrypted query with the key in the allocated key pair, and return the decrypted result to the user. The present invention can encrypt privacy data safely and efficiently.
[0050] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent specific implementation part. Brief Description of the Drawings
[0051] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention, and constitute a part of the specification. Together with the following specific embodiments, they are used to explain the embodiments of the present invention, but do not constitute a limitation to the embodiments of the present invention. In the accompanying drawings:
[0052] Figure 1 is a flowchart of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0053] Figure 2 is a first flowchart of identifying sensitive fields of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0054] Figure 3 is a second flowchart of identifying sensitive fields of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0055] Figure 4 is a third flowchart of identifying sensitive fields of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0056] Figure 5 is a first flowchart of encryption processing of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0057] Figure 6 is a second flowchart of encryption processing of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0058] Figure 7 is a flowchart of encrypted query of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention;
[0059] Figure 8 is a schematic diagram of the practical application of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention. Specific Embodiments
[0060] The following will describe in detail the specific embodiments of the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the embodiments of the present invention, and are not used to limit the embodiments of the present invention.
[0061] In the embodiments of the present application, certain industry-existing solutions such as software, components, models, etc. may be mentioned. They should be considered exemplary. The purpose is only to illustrate the feasibility in the implementation of the technical solutions of the present application, but it does not mean that the applicant has already or necessarily used this solution.
[0062] Figure 1 It is a flowchart of a database quantum encryption method based on bypass deployment according to an embodiment of the present invention. In the present invention, the process of this encryption method may include:
[0063] In step S1, the bypass proxy gateway generates an encryption key and assigns independent key pairs to different power grid data access users.
[0064] In step S2, the privacy data in the new power grid data record is encrypted according to the encryption key and added to the database.
[0065] In step S3, according to the query request initiated by the user, the query request is identified for privacy data.
[0066] In step S4, the identified privacy data is encrypted and encapsulated, and an encrypted query is performed in the database according to the encrypted and encapsulated privacy data.
[0067] In step S5, the result of the encrypted query is obtained, the result of the encrypted query is decrypted by the key in the assigned key pair, and the decrypted result is returned to the authorized user.
[0068] In the present invention, the bypass proxy gateway generates an encryption key and can assign independent key pairs to different power grid data access users, so that different power grid data access users can decrypt the encrypted information separately according to the assigned key. The privacy data in the new power grid data record is encrypted according to the encryption key and added to the database, so that the database can be continuously updated. According to the query request initiated by the user, the query request can be identified for privacy data, then the identified privacy data can be encrypted and encapsulated, and an encrypted query can be performed in the database according to the encrypted and encapsulated privacy data. The result of the encrypted query is obtained, then the result of the encrypted query can be decrypted by the key in the assigned key pair, and the decrypted result can be returned to the user. The present invention can perform secure and efficient encryption for privacy data.
[0069] In an embodiment of the present invention, as Figure 2 shown, the first process of identifying sensitive fields may include:
[0070] In step S6, the application system initiates an INSERT SQL request to add new power grid data to the database.
[0071] In step S7, the INSERT SQL request is parsed, and when an INSERT statement is detected, the INSERT SQL request is intercepted.
[0072] In step S8, the INSERT statement in the INSERT SQL request is parsed to extract the table name, field list and value list.
[0073] In step S9, sensitive words are identified on the extracted table names, field lists, and value lists to obtain sensitive fields belonging to the privacy user.
[0074] In step S10, the sensitive fields are encrypted using an encryption key.
[0075] In the present invention, when updating the database, the application system can initiate an INSERT SQL request so that new power grid data can be added to the database. The present invention can deploy a proxy gateway to achieve real-time monitoring and interception of traffic messages between the system or operation and maintenance end and the database. When the INSERT SQL request is parsed and an INSERT statement is detected, the INSERT SQL request can be intercepted. After the INSERT SQL request is intercepted, the INSERT statement in the INSERT SQL request can be parsed to extract the table name, field list and value list. The process is to extract the table name: INTO\s+(\w+) or UPDATE\s+(\w+); match to indicate users. Extract field name: $([\w,\s]+)$; match the field names as name, phone, and further split into name, phone. Extract field values: VALUES\s*$([^)]+)$, the matched field values are '张三', '13800138000', further split into '张三', and '13800138000'.
[0076] After the extraction is completed, the extracted table name, field list and value list can be used to identify sensitive words, so as to obtain sensitive fields belonging to the privacy user. After obtaining the sensitive fields, the obtained sensitive fields can be encrypted using the encryption key.
[0077] Compared with traditional database security solutions, most of which rely only on firewalls or simple access control policies, it is difficult to effectively intercept complex and changeable SQL attacks. The proxy gateway in the present invention has a deep analysis function, which can monitor and identify potential attack behaviors in real time, such as SQL injection, unauthorized access, etc. Only requests that have been strictly verified can reach the database, which greatly reduces the risk of data leakage and builds a solid defense line for database security.
[0078] Different from some solutions that only perform static encryption during the data storage phase, the present invention focuses on data security during the dynamic writing process. Through advanced automatic recognition technology, sensitive fields in SQL statements are accurately located and immediately encrypted. This process ensures that personal and enterprise privacy data remains encrypted throughout the process of writing to the database. Even in the event of a data breach, since the data is encrypted, attackers cannot obtain the real information, thus achieving deep protection of privacy data.
[0079] In an embodiment of the present invention, as Figure 3 shown, the second process of identifying sensitive fields may include:
[0080] In step S11, obtain the table name, field list, and value list, and match and search in the predefined sensitive word rule library.
[0081] In step S12, when a keyword is matched in the sensitive word rule library, extract the corresponding value of the field name in the table name, field list, and value list that match the keyword.
[0082] In step S13, perform data format verification based on the corresponding value of the extracted field name.
[0083] In step S14, when the verification passes, the corresponding value of the field name is marked as a sensitive field.
[0084] In step S15, when the verification fails, the corresponding value of the field name is regarded as ordinary data.
[0085] In the present invention, when identifying sensitive fields, the obtained table name, field list, and value list can be matched and searched in the predefined sensitive word rule library. When a keyword (such as phone) is matched in the sensitive word rule library, the corresponding data verification rule can be triggered, that is, the corresponding value of the field name in the table name, field list, and value list that match the keyword can be extracted. After the corresponding value is extracted, data format verification can be performed based on the corresponding value of the extracted field name. When the verification passes, the corresponding value of the field name can be marked as a sensitive field. When the verification fails, the corresponding value of the field name can be regarded as ordinary data. In the present invention, the keyword can refer to the corresponding word or phrase, such as phone, id, email.
[0086] In an embodiment of the present invention, as Figure 4 shown, the third process of identifying sensitive fields may include:
[0087] In step S16, obtain the field name and the corresponding value of the field name.
[0088] In step S17, determine the sensitive type of the field name.
[0089] In step S18, when it is determined that the field name is the mobile phone number, it is determined whether the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3 - 9, and there are a total of 11 digits.
[0090] In step S19, when the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3 - 9, and there are a total of 11 digits, it is determined that the corresponding value of the field name is a sensitive field.
[0091] In step S20, when it is determined that the field name is the ID number, it is determined whether the corresponding value of the field name conforms to the rule of the GB11643 - 1999 standard.
[0092] In step S21, when the corresponding value of the field name conforms to the rule of the GB11643 - 1999 standard, it is determined that the corresponding value of the field name is a sensitive field.
[0093] In step S22, when it is determined that the field name is the email, it is determined whether the corresponding value of the field name conforms to the rule of the RFC5322 standard.
[0094] In step S23, when the corresponding value of the field name conforms to the rule of the RFC5322 standard, it is determined that the corresponding value of the field name is a sensitive field.
[0095] In the present invention, when validating the data format of the extracted corresponding values, the field name and the corresponding value of the field name can be obtained first, and this corresponding value is the value to be validated. After obtaining the field name and the corresponding value, its type can be determined according to the field name. This type can be a mobile phone number, an ID card number, and an email address. When it is determined that the type of the field name is a mobile phone number, it can be determined whether the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3-9, and there are a total of eleven digits. If this rule is met, it can be determined that the corresponding value of the field name is a sensitive field. When it is determined that the type of the field name is an ID card number, it can be determined whether the corresponding value of the field name conforms to the rule of the GB11643-1999 standard. If this rule is met, it can be determined that the corresponding value of the field name is a sensitive field. When it is determined that the type of the field name is an email address, it can be determined whether the corresponding value of the field name conforms to the rule of the RFC5322 standard. If the rule is met, it can be determined that the corresponding value of the field name is a sensitive field. If the above rules are not met, it can be determined that the corresponding value of the field name is not a sensitive field, but an ordinary field, and no special encryption processing is required. A specific implementation example is as follows: The proxy gateway parses the INSERT statement and extracts the following information: table name: power_data; field list: device_id, voltage, current, user_id; value list: 13, 20.5, 10.2, '001'; According to the predefined sensitive field rule library, the field names in the parsed SQL are matched with the sensitive field names in the rule library. For example, if voltage and current are defined as sensitive fields for power data and user_id is defined as a sensitive field for user information in the rule library, and these fields are parsed in the SQL statement, then the data of these fields is encrypted.
[0096] In an embodiment of the present invention, as Figure 5 shown, the first process of the encryption process may include:
[0097] In step S24, obtain sensitive fields.
[0098] In step S25, convert the numbers in the sensitive fields into binary, construct a polynomial based on the numbers converted into binary, and the numbers converted into binary are the coefficients of the polynomial.
[0099] In step S26, scale the polynomial according to the specifications of the Kyber algorithm to obtain a message that meets the requirements.
[0100] In step S27, calculate the ciphertext according to the obtained secret key through formula (1):
[0101]
[0102] Among them, u and v are ciphertexts, e1 is a randomly generated error vector, r is a random polynomial vector, e2 is an error polynomial, A and t are public keys, and m represents a message.
[0103] In the present invention, when encrypting sensitive fields, the sensitive fields can be obtained first, and then the numbers in the sensitive fields can be converted into binary. According to the numbers converted into binary, polynomials can be constructed, and the numbers converted into binary can be the coefficients of the polynomials. After being converted into polynomials, according to the specifications of the Kyber algorithm, the polynomials can be scaled to obtain a message that meets the requirements. The message can be plaintext, and then the plaintext can be converted into ciphertext. In the process of converting into ciphertext, the secret key can be obtained first, and then the ciphertext can be calculated according to the obtained secret key through formula (1). During the data transmission process, the data is transmitted through ciphertext, so the problem of data leakage will not occur.
[0104] In an embodiment of the present invention, as Figure 6 shown, the second process of the encryption process may include:
[0105] In step S28, the encrypted sensitive fields are obtained.
[0106] In step S29, the encrypted sensitive fields are combined with ordinary data to generate a rewritten INSERT statement.
[0107] In step S30, the rewritten INSERT statement is sent to the database to ensure that the sensitive fields are stored in an encrypted form.
[0108] In the present invention, after obtaining the encrypted sensitive fields, the encrypted sensitive fields and non-sensitive fields, that is, ordinary data, can be combined to generate a rewritten INSERT statement. After generating the rewritten INSERT statement, the proxy gateway can send the rewritten INSERT statement to the database for execution, so as to ensure that the sensitive fields are stored in an encrypted form.
[0109] In an embodiment of the present invention, as Figure 7 shown, the process of encrypted query may include:
[0110] In step S31, the private data in the encrypted query request is obtained.
[0111] In step S32, the privacy field values corresponding to the private data in the encrypted query request are encapsulated into the SQL query to generate a rewritten SELECT statement.
[0112] In step S33, the rewritten SELECT statement is sent to the database.
[0113] In step S34, according to the rewritten SELECT statement, the SQL expression is parsed, and the corresponding data records are queried in the database, and then the encrypted data records that meet the conditions are returned.
[0114] In the present invention, when performing an encrypted query, the proxy gateway can receive the private data in the encrypted query request, and then can encapsulate the privacy field value corresponding to the private data in the encrypted query request into the SQL query, so as to generate a rewritten SELECE statement. After generating the rewritten SELECE statement, the rewritten SELECE statement can be sent to the database. The database can parse the SQL expression according to the rewritten SELECE statement, and can query the corresponding data records in the database, and then can return the encrypted data records that meet the conditions. The proxy gateway can receive the encrypted data records returned by the database, and then can use the corresponding decryption key to decrypt the encryption result, including the encrypted value "0x162A…e8" of the privacy field "name". The decrypted data records can be returned to the authorized user, for example, decrypting "0x162A…e8" to "zhangsan".
[0115] In the present invention, the sensitive fields may include voltage, current, and user information.
[0116] On the other hand, the present invention also provides a database quantum encryption system based on bypass deployment. The encryption system includes: a database, a data user, and a proxy gateway. The database is a functional extension based on a traditional relational database, and realizes the encrypted storage of sensitive data. The database can perform retrieval processing at the cryptographic level for user query requests from the privacy SQL engine. It integrates encryption and decryption functions based on the Kyber algorithm, supports the encrypted storage of data and the decryption operation of encrypted data during query, thereby ensuring the security of data during storage and retrieval. Data users are divided into two categories: data providers and data users. They interact with the private data of the database through the standard SQL language without directly participating in the encryption process of the private data. This design makes the encryption management and processing of private data transparent to users, that is, users can complete data operations without knowing the encryption details. The proxy gateway is responsible for syntax analysis and reconstruction of SQL operations initiated by users, including operations such as INSERT and SELECT. It forwards these operations to the database system to perform corresponding data operations. The proxy gateway is also responsible for independently generating quantum keys based on the post-quantum cryptography Kyber for each field involved in the encryption requirement, ensuring the confidentiality and security of data during storage and processing, and effectively resisting attacks from future quantum computers, such as Figure 8As shown, when the data user interacts with the proxy gateway or database, it is transmitted through the network and the interaction actions are completed through the switch. This encryption method can be applied to industries such as power, aviation, and chemistry.
[0117] Through the above technical solution, a database quantum encryption method based on bypass deployment provided by the present invention generates an encryption key and can assign independent key pairs to different power grid data access users, so that different power grid data access users can decrypt the encrypted information separately according to the assigned key. Encrypt the privacy data in the new power grid data record according to the encryption key and add it to the database, so that the database can be continuously updated. According to the query request initiated by the user, the privacy data in the query request can be identified, and then the identified privacy data can be encrypted and encapsulated, and an encrypted query can be performed in the database according to the encrypted and encapsulated privacy data. Obtain the result of the encrypted query, and then decrypt the result of the encrypted query with the key in the assigned key pair, and return the decrypted result to the user. The present invention can perform secure and efficient encryption for privacy data.
[0118] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0119] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0120] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions in the process Figure 1one or more processes and / or blocks Figure 1 the functions specified in one or more blocks.
[0121] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 one or more processes and / or blocks Figure 1 or more processes and / or the functions specified in one or more blocks.
[0122] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0123] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0124] Computer-readable media include permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media do not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0125] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, commodity or device comprising the element.
[0126] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A database quantum encryption method based on bypass deployment, characterized in that, The encryption method includes: The bypass proxy gateway generates an encryption key and assigns an independent key pair to different grid data access users; Encrypt the privacy data in the new grid data record according to the encryption key and add it to the database; According to the query request initiated by the user, identify the privacy data in the query request; Encapsulate the identified privacy data, and perform an encrypted query in the database according to the encrypted and encapsulated privacy data; Obtain the result of the encrypted query, decrypt the result of the encrypted query through the key in the assigned key pair, and return the decrypted result to the authorized user.
2. The encryption method according to claim 1, wherein Encrypt the privacy data in the new grid data record according to the encryption key and add it to the database, including: The application system initiates an INSERT SQL request to add new grid data to the database; Parse the INSERT SQL request, and intercept the INSERT SQL request when an INSERT statement is detected; Parse the INSERT statement in the INSERT SQL request to extract the table name, field list, and value list; Identify sensitive words in the extracted table name, field list, and value list to obtain sensitive fields belonging to privacy users; Encrypt the sensitive fields through the encryption key.
3. The encryption method according to claim 2, wherein Identify sensitive words in the extracted table name, field list, and value list to obtain sensitive fields belonging to privacy users, including: Obtain the table name, field list, and value list, and match and search in the predefined sensitive word rule library; When a keyword is matched in the sensitive word rule library, extract the corresponding value of the field name in the table name, field list, and value list that matches the keyword; Perform data format verification according to the extracted corresponding value of the field name; When the verification passes, the corresponding value of the field name is marked as a sensitive field; When the verification fails, the corresponding value of the field name is regarded as ordinary data.
4. The encryption method according to claim 3, wherein Perform data format verification according to the extracted corresponding value, including: Obtain the field name and the corresponding value of the field name; Judge the sensitive type of the field name; When it is determined that the field name is a mobile phone number, determine whether the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3-9, and there are 11 digits in total; When the corresponding value of the field name conforms to the rule that the first digit is 1, the second digit is 3-9, and there are 11 digits in total, determine that the corresponding value of the field name is a sensitive field; When it is determined that the field name is an ID card number, determine whether the corresponding value of the field name conforms to the rule of the GB11643-1999 standard; When the corresponding value of the field name conforms to the rule of the GB11643-1999 standard, determine that the corresponding value of the field name is a sensitive field; When it is determined that the field name is an email, determine whether the corresponding value of the field name conforms to the rule of the RFC5322 standard; When the corresponding value of the field name conforms to the rule of the RFC5322 standard, determine that the corresponding value of the field name is a sensitive field.
5. The encryption method according to claim 2, wherein Encrypting the sensitive fields with an encryption key includes: Obtaining the sensitive fields; Converting the numbers in the sensitive fields into binary, constructing a polynomial based on the numbers converted into binary, and the numbers converted into binary are the coefficients of the polynomial; Scaling the polynomial according to the specifications of the Kyber algorithm to obtain a compliant message; Calculating the ciphertext according to the obtained key through formula (1): where u and v are ciphertexts, e1 is a randomly generated error vector, r is a random polynomial vector, e2 is an error polynomial, A and t are public keys, and m represents the message.
6. The encryption method according to claim 3, characterized in that, Encrypting the privacy data in the new power grid data record according to the encryption key and adding it to the database, including: Obtaining the encrypted sensitive fields; Combining the encrypted sensitive fields with the ordinary data to generate a rewritten INSERT statement; Sending the rewritten INSERT statement to the database to ensure that the sensitive fields are stored in an encrypted form.
7. The encryption method according to claim 6, wherein Encapsulating and encrypting the identified privacy data, and performing an encrypted query in the database according to the encapsulated and encrypted privacy data, including: Obtaining the privacy data in the encrypted query request; Encapsulating the privacy field values corresponding to the privacy data in the encrypted query request into the SQL query to generate a rewritten SELECT statement; Sending the rewritten SELECT statement to the database; Parsing the SQL expression according to the rewritten SELECT statement, querying the corresponding data records in the database, and then returning the encrypted data records that meet the conditions.
8. The encryption method according to claim 2, wherein The sensitive fields include voltage, current, and user information.