Database data storage encryption method and device

Through the reverse proxy, the database encryption gateway is deployed and the encryption and decryption function is defined, and the column-level encryption granularity and newly added secret columns are used to solve the limitations and performance problems of database data storage encryption in the existing technology, achieving flexible data security protection.

CN120372640AInactive Publication Date: 2025-07-25BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510408030.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-25
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing database data storage encryption technology has limitations, great performance impact, and cannot directly solve problems such as encryption of stock sensitive data and limited support field types, resulting in poor practical application results.

Method used

Deploy the database encryption gateway through a reverse proxy, define the encryption and decryption function, adopt column-level encryption granularity, add newly cryptographic column storage data, and parse and rewritten SQL statements between the business system and the database to realize the encryption and decryption operations of data.

Benefits of technology

Compatible with different types of data fields, reduce the impact on business system performance, support differentiated encryption protection, prevent data from being illegally obtained during storage, and meet the data security needs of multiple scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372640A_ABST
    Figure CN120372640A_ABST
Patent Text Reader

Abstract

The invention discloses a database data storage encryption method and device, and belongs to the technical field of data storage encryption. According to the method, an encryption and decryption function is defined on a database, and an encryption gateway is deployed by using a reverse proxy technology, so that analysis and rewriting of a service access database message are realized. And for the SQL statement of the matching strategy, an encryption function is applied during data writing, and a decryption function is applied during data reading, so that encryption storage and decryption access of the data are ensured. Besides, column-level data encryption is supported, encrypted data are stored in a mode of newly adding columns, and decrypted data are restored to original column data when necessary, so that the device can be compatible with various types of data fields and encryption algorithms, and is suitable for database environments with different complexities and scales.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data storage encryption, and particularly relates to a method and device for encrypting database data storage. Background Art

[0002] Currently, the existing implementation schemes using gateway encryption mainly include two types: front proxy gateway in-application encryption and rear proxy database encryption gateway. However, these two schemes have significant defects:

[0003] Front proxy gateway in-application encryption: Adaptation is required for the application programming language and framework, generally only supporting the application system environment developed in the Java language, with great limitations; data is encrypted first and then written into the database, which has a great impact on the performance of business scenarios with dynamically written data volumes; it cannot directly solve the encryption problem of the existing sensitive data in the database; it does not support data access from the database operation and maintenance terminal and dynamic encryption and decryption of data read and write operations; the supported field types are limited, and the length and field type of the encrypted data change, resulting in some fields being unable to be encrypted;

[0004] Rear proxy database encryption gateway: It has a great impact on the performance of business scenarios with dynamically written data volumes, and there will be transmission failures and data loss when the data volume is large or the parsing times out, and it cannot directly process the encryption of existing sensitive data, and the supported field types are limited, etc.;

[0005] These significant defects severely limit the application effect of the existing encryption technology in actual data security protection. Summary of the Invention

[0006] The purpose of the present invention is to overcome the deficiencies of the prior art, and provide a method and device for encrypting database data storage to solve the problems proposed in the above background art.

[0007] The purpose of the present invention can be achieved by the following technical solutions: A method for encrypting database data storage includes the following steps:

[0008] Step S1, design a database encryption gateway: Deploy a database encryption gateway between the service and the database through the reverse proxy method;

[0009] Step S2, define encryption and decryption functions: Define encryption and decryption functions on the database for encrypting and decrypting data;

[0010] Among them, the encryption and decryption functions accept the original data or encrypted data and the key as parameters, and return the encrypted data or the decrypted original data;

[0011] Step S3: Implement column-level data encryption: Support column data encryption granularity; for columns that need to be encrypted, use the method of adding new columns, store the encrypted data in the newly added encrypted columns, and delete the original column data at the same time;

[0012] When the service accesses the data in this column, the encryption gateway maps the access request to the encrypted column; when decrypting the configuration for this table or column, the encryption gateway decrypts the data in the encrypted column and puts it into the original column data, and deletes the encrypted column;

[0013] Step S4: Encrypt the table data in the database, including: adding the target database, schema scanning, configuring the encryption policy, creating encryption and decryption functions, and performing data encryption operations.

[0014] Preferably, in step S1, use the database encryption gateway to parse and process the messages for the service to access the database, including:

[0015] All access requests for the service to access the database are first sent to the encryption gateway. When an access request arrives, the encryption gateway captures the basic structure of the access request to determine the source and target of the access request; among them, the message for the service to access the database refers to the access request for the service to access the database;

[0016] For messages containing SQL statements, the encryption gateway identifies and extracts the SQL statements in the message according to the predefined format or protocol.

[0017] Preferably, in step S2, judge whether the extracted SQL statement needs to be rewritten according to the preconfigured encryption policy;

[0018] When performing a data write operation, the encryption gateway rewrites the SQL statement that matches the policy to make it carry an encryption function, so as to store the encrypted data in the database;

[0019] When performing a data read operation, the encryption gateway rewrites the SQL statement that matches the policy to make it carry a decryption function, so as to decrypt the encrypted data when reading the data.

[0020] Preferably, in step S3, the process of supporting column data encryption granularity when implementing data encryption includes:

[0021] Create a newly added encrypted column in the table where the data needs to be encrypted;

[0022] Use encryption and decryption functions to encrypt the data in the original column, store the encrypted data in the newly added encrypted column, and delete the data in the original column;

[0023] When the business logic accesses the original column data, map the access request to the newly added encrypted column by modifying the database query statement;

[0024] When decrypting and configuring a table or column, encrypted data is retrieved from the newly added column and decryption operations are performed; among them, the same encryption and decryption algorithms and keys as those in the encryption process are used in the decryption process;

[0025] The decrypted data is placed into the original column data, and the newly added encrypted column is deleted.

[0026] Preferably, in step S4, encrypting the table data in the database includes:

[0027] Adding a target database: adding the target database to be encrypted to the database encryption gateway;

[0028] Schema scanning: using the encryption gateway to perform schema scanning on the target database to obtain the list and attribute information of databases, tables, and fields;

[0029] Configuring an encryption policy: configuring and selecting the tables and column data to be encrypted, as well as the encryption algorithm and key to be used according to actual requirements;

[0030] Creating encryption and decryption functions: connecting to the database based on the encryption gateway and creating predefined encryption and decryption functions on the database;

[0031] Performing data encryption operations: performing operations to update the original table data or copy the table and migrate the data according to the actual data model to achieve encrypted storage of the data.

[0032] Preferably, the updating of the original table data includes: creating a new encrypted column on the original table, and writing the encrypted data into the encrypted column by calling the encryption function through the UPDATE statement.

[0033] Preferably, the copying of the table and migrating the data includes: creating a temporary new table, adding corresponding encrypted columns, and directly writing the encrypted data into the corresponding columns of the temporary new table; after successful encryption, changing the name of the temporary new table to the original table name and deleting the original table.

[0034] To solve the above problems, the present invention also provides a database data storage encryption device, including:

[0035] A database encryption gateway module, deployed in a reverse proxy manner, for parsing the message of the service accessing the database, rewriting the SQL statements that match the policy, and realizing encryption during data writing and decryption during data reading;

[0036] An encryption and decryption function module, defining encryption and decryption functions on the database, for performing encryption and decryption operations on the data;

[0037] A schema scanning module, for performing schema scanning on the target database to obtain the list and attribute information of databases, tables, and fields;

[0038] An encryption policy configuration module, used to configure and select the tables and column data to be encrypted, as well as the encryption algorithm and key to be used;

[0039] A data encryption operation module, which performs operations such as updating the original table data or copying the table and migrating the data according to the actual data model to achieve encrypted storage of data.

[0040] Compared with the existing solutions, the beneficial effects achieved by the present invention are as follows:

[0041] The present invention stores encrypted data by adding new columns, can be compatible with different types of data fields and encryption algorithms, realizes field-based storage encryption, and does not require large-scale modification of the structure of the original database and the application program.

[0042] The present invention supports the encryption granularity of column data, can perform differential encryption protection according to the sensitivity of different data, and meets the data security requirements in different scenarios.

[0043] The present invention deploys the encryption gateway through the reverse proxy method, separates the encryption and decryption operations from the business system, and reduces the impact on the performance of the business system; at the same time, two data encryption operation schemes can be selected according to the actual situation to further optimize the performance of the data encryption process.

[0044] The present invention stores encrypted data by adding new columns, deletes the original column data, and restores the data to the original column only during decryption, which can effectively prevent the data from being illegally obtained during the storage process. Description of the Drawings

[0045] The following further describes the present invention with reference to the accompanying drawings.

[0046] Figure 1 It is a flowchart of a method for encrypting database data storage proposed by the present invention.

[0047] Figure 2 It is a module structure diagram of a device for encrypting database data storage proposed by the present invention. Detailed Embodiments

[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.

[0049] Embodiment 1, as Figure 1 shown, the present invention is a method for encrypting database data storage, including the following steps:

[0050] Step S1, design a database encryption gateway: deploy the database encryption gateway between the business and the database through the reverse proxy method;

[0051] Step S2, Define encryption and decryption functions: Define encryption and decryption functions on the database for encrypting and decrypting data;

[0052] Among them, the encryption and decryption functions accept the original data or encrypted data and the key as parameters, and return the encrypted data or the decrypted original data;

[0053] Step S3, Implement column-level data encryption: Support column data encryption granularity; For columns that need to be encrypted, use the method of adding new columns to store the encrypted data in the newly added encrypted column after encryption, and at the same time delete the original column data;

[0054] When the service accesses the data in this column, the encryption gateway maps the access request to the encrypted column; When decrypting the configuration for this table or column, the encryption gateway decrypts the data in the encrypted column and puts it into the original column data, and deletes the encrypted column;

[0055] Step S4, Encrypt the table data in the database, including: adding the target database, schema scanning, configuring the encryption policy, creating encryption and decryption functions, and performing data encryption operations.

[0056] It should be noted that in Step S1, the database encryption gateway is used to parse and process the messages of the service accessing the database, including:

[0057] All access requests from the service to the database are first sent to the encryption gateway. When an access request arrives, the encryption gateway captures the basic structure of the access request, including but not limited to the source address, destination address, and port number, to determine the source and target of the access request; Among them, the message of the service accessing the database refers to the access request of the service accessing the database;

[0058] For messages containing SQL statements, the encryption gateway identifies and extracts the SQL statements in the message according to the predefined protocol; Exemplarily, in a database access request based on JDBC, the encryption gateway extracts the executed SQL statement from specific fields of the JDBC protocol.

[0059] It should be noted that in Step S2, it is judged whether the extracted SQL statement needs to be rewritten according to the pre-configured encryption policy; Among them, the encryption policy is the encryption and decryption function configured according to the actual encryption requirements;

[0060] When performing a data write operation, the encryption gateway rewrites the SQL statement that matches the policy to make it carry the encryption function, so as to encrypt the data and store it in the database;

[0061] When performing a data reading operation, the encryption gateway rewrites the SQL statements that match the policy to append a decryption function, so as to decrypt the encrypted data when reading the data;

[0062] Among them, the encryption function uses a symmetric encryption function or an asymmetric encryption function;

[0063] It should be noted that in step S3, the process of supporting the encryption granularity of column data when implementing data encryption includes:

[0064] Create a new encrypted column in the table where data needs to be encrypted;

[0065] Use the encryption and decryption functions to encrypt the data in the original column, store the encrypted data in the new encrypted column, and delete the data in the original column;

[0066] When the business logic accesses the data in the original column, map the access request to the new encrypted column by modifying the database query statement;

[0067] When decrypting the configuration of the table or column, retrieve the encrypted data from the new column and perform a decryption operation; among them, the decryption process uses the same encryption and decryption algorithms and keys as the encryption process;

[0068] Put the decrypted data into the original column data and delete the new encrypted column;

[0069] Exemplarily, taking the encryption of the name column as an example:

[0070] Create a new column: Create a new column name1 in the original table. The data type of this column is binary, and its length can be compatible with the length of the encrypted data;

[0071] Encrypted data storage: Use the encryption function funenc() to encrypt the original data in the name column, and store the encrypted data in the name1 column; set the original data in the name column to null;

[0072] Business access mapping: When the business system accesses the data in the name column, the encryption gateway maps the access request to the name1 column and reads the encrypted data from the name1 column;

[0073] Decryption configuration processing: When decrypting the configuration of this table or column, the encryption gateway uses the decryption function fundec() to decrypt the encrypted data in the name1 column, and stores the decrypted data in the original name column, and then deletes the name1 column;

[0074] It should be noted that in step S4, the encryption process for the table data in the database includes:

[0075] Add target database: Add the target database to be encrypted on the database encryption gateway;

[0076] Schema scanning: Use the encryption gateway to perform schema scanning on the target database to obtain the list and attribute information of databases, tables, and fields;

[0077] Configure encryption policy: According to actual requirements, configure and select the table and column data to be encrypted, as well as the encryption algorithm and key to be used;

[0078] Create encryption and decryption functions: Connect to the database based on the encryption gateway and create predefined encryption and decryption functions on the database;

[0079] Execute data encryption operation: According to the actual data model, execute the operation of updating the original table data or copying the table and migrating the data to achieve encrypted storage of the data;

[0080] Among them, the update of the original table data includes:

[0081] Create a new encrypted column on the original table, and call the encryption function through the UPDATE statement to encrypt the data and write it into the encrypted column; for example, update A'funenc() calls the encryption function to encrypt the data and write it in;

[0082] The copying of the table and migrating the data includes: Create a temporary new table, add the corresponding encrypted column, and directly write the encrypted data into the corresponding column of the temporary new table; after successful encryption, change the name of the temporary new table to the original table name and delete the original table.

[0083] Example 2, as Figure 2 shown, the present invention is a device for encrypting database data storage, including:

[0084] Database encryption gateway module, deployed through reverse proxy, used to parse the messages accessing the database in the service, rewrite the SQL statements that match the policy, and achieve encryption during data writing and decryption during data reading;

[0085] Encryption and decryption function module, define encryption and decryption functions on the database, used to perform encryption and decryption operations on the data;

[0086] Schema scanning module, used to perform schema scanning on the target database to obtain the list and attribute information of databases, tables, and fields;

[0087] Encryption policy configuration module, used to configure and select the table and column data to be encrypted, as well as the encryption algorithm and key to be used;

[0088] Data encryption operation module, according to the actual data model, execute the operation of updating the original table data or copying the table and migrating the data to achieve encrypted storage of the data.

[0089] In several embodiments provided by the present invention, it should be understood that the disclosed system can be implemented in other ways. For example, the above-described invention embodiments are merely illustrative. For example, the division of modules is only a logical function division, and there can be other division methods in actual implementation.

[0090] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0091] In addition, in each embodiment of the present invention, the functional modules can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a combination of hardware and software functional modules.

[0092] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.

[0093] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for encrypting database data storage, characterized in that, It includes the following steps: Step S1, design a database encryption gateway: Deploy the database encryption gateway between the service and the database in the way of reverse proxy; Step S2, define encryption and decryption functions: Define encryption and decryption functions on the database for encrypting and decrypting data; Among them, the encryption and decryption functions accept the original data or encrypted data and the key as parameters and return the encrypted data or the decrypted original data; Step S3, implement column-level data encryption: Support the encryption granularity of column data; For the columns that need to be encrypted, adopt the way of adding new columns, store the encrypted data in the newly added encrypted columns, and delete the original column data at the same time; When the service accesses the data of this column, the encryption gateway maps the access request to the encrypted column; When decrypting the configuration of this table or column, the encryption gateway decrypts the data in the encrypted column and puts it into the original column data, and deletes the encrypted column; Step S4, perform encryption processing on the table data in the database, including: adding the target database, schema scanning, configuring the encryption policy, creating encryption and decryption functions, and performing data encryption operations.

2. The method for encrypting database data storage according to claim 1, characterized in that, In step S1, use the database encryption gateway to parse and process the messages of the service accessing the database, including: All access requests of the service accessing the database are first sent to the encryption gateway. When an access request arrives, the encryption gateway captures the basic structure of the access request to determine the source and target of the access request; Among them, the message of the service accessing the database refers to the access request of the service accessing the database; For the message containing the SQL statement, the encryption gateway identifies and extracts the SQL statement in the message according to the predefined format or protocol.

3. A method for encrypting database data storage according to claim 2, characterized in that, In step S2, judge whether the extracted SQL statement needs to be rewritten according to the pre-configured encryption policy; When performing the data writing operation, the encryption gateway rewrites the SQL statement that matches the policy to make it carry the encryption function, so as to store the encrypted data in the database; When performing the data reading operation, the encryption gateway rewrites the SQL statement that matches the policy to make it carry the decryption function, so as to decrypt the encrypted data when reading the data.

4. A method for encrypting database data storage according to claim 3, characterized in that, In step S3, the process of supporting the encryption granularity of column data when implementing data encryption includes: Create a newly added encrypted column in the table that needs to encrypt data; Use the encryption and decryption functions to encrypt the data in the original column, store the encrypted data in the newly added encrypted column, and delete the data in the original column; When the business logic accesses the data of the original column, map the access request to the newly added encrypted column by modifying the database query statement; When decrypting the configuration of the table or column, take out the encrypted data from the newly added column and perform decryption operations; Among them, the decryption process uses the same encryption and decryption algorithm and key as the encryption process; Put the decrypted data into the original column data and delete the newly added encrypted column.

5. A method for encrypting database data storage according to claim 4, characterized in that, In step S4, perform encryption processing on the table data in the database, including: Add the target database: Add the target database that needs to be encrypted on the database encryption gateway; Schema scanning: Use the encryption gateway to perform schema scanning on the target database to obtain the list and attribute information of the library, table, and fields; Configure the encryption policy: According to actual requirements, configure and select the tables, column data to be encrypted, as well as the encryption algorithm and key to be used; Create encryption and decryption functions: Connect to the database based on the encryption gateway and create predefined encryption and decryption functions on the database; Execute data encryption operations: According to the actual data model, execute operations to update the original table data or copy the table and migrate the data to achieve encrypted storage of the data.

6. A method for encrypting database data storage according to claim 5, characterized in that, The above-mentioned update of the original table data includes: creating a new encrypted column on the original table, and calling the encryption function through the UPDATE statement to encrypt the data and write it into the encrypted column.

7. A method for encrypting database data storage according to claim 5, characterized in that, The above-mentioned copying of the table and migrating the data includes: creating a temporary new table, adding corresponding encrypted columns, encrypting the data and directly writing it into the corresponding columns of the temporary new table; after successful encryption, changing the name of the temporary new table to the original table name and deleting the original table.

8. An apparatus for encrypting database data storage, applying a method for encrypting database data storage according to any one of claims 1-7, characterized in that, Including: Database encryption gateway module, deployed in the way of reverse proxy, used to parse the messages of business access to the database, rewrite the SQL statements that match the policy, and achieve encryption during data writing and decryption during data reading; Encryption and decryption function module, defining encryption and decryption functions on the database, used to perform encryption and decryption operations on the data; Architecture scanning module, used to scan the architecture of the target database to obtain the list and attribute information of the database, tables, and fields; Encryption policy configuration module, used to configure and select the tables, column data to be encrypted, as well as the encryption algorithm and key to be used; Data encryption operation module, according to the actual data model, execute operations to update the original table data or copy the table and migrate the data to achieve encrypted storage of the data.

Citation Information

Patent Citations

  • Field-level database encryption device

    CN102855448A

  • Database encryption method and device, equipment and medium

    CN117113422A

  • Non-intrusive data information security management method and device

    CN119357988A

  • Database Encryption to Provide Write Protection

    US20160292427A1