Database data processing method and device based on large model and storage medium
Through the large model, the execution plan of database operation statements is determined and encrypted, and the security problem of data communication between the application side and the database is solved, and secure communication without direct encryption between the application side and the database is realized, which improves efficiency and security.
Patent Information
- Application Number
- CN202510417945.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, the security of data communication between the application side and the database is difficult to ensure, especially when the configuration of the encryption and decryption algorithm needs to be modified, the application side is highly invasive, and the security of the integrated database storage and encryption and decryption scheme is questionable.
The execution plan of the database operation statement is determined through a large model, and when there is a field to be encrypted, it is encrypted, a second execution plan is generated, provided to the target database for processing, receiving the response result and determining the processing result, so as to realize the encryption process is completed in the encryption gateway.
No encryption processing is required for application and databases, ensuring data communication security, reducing computing pressure and centrally managing encryption and decryption operations, improving efficiency and security.
Smart Images

Figure CN120378140A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence technology, and in particular to the fields of cloud computing, cloud services, databases, data security, large models, etc. In particular, it relates to a method, device, and storage medium for processing database data based on a large model. Background Art
[0002] In modern software systems, the application side and the database are two crucial components. The application side interacts with the database through database operation statements to perform operations such as creating, reading, updating, and deleting data. During the communication process between the application side and the database, it is very important to ensure the security of data communication between the application side and the database side. Summary of the Invention
[0003] The present disclosure provides a method, device, and storage medium for processing database data based on a large model.
[0004] According to one aspect of the present disclosure, there is provided a method for processing database data based on a large model, which is applied to a first encryption gateway. The method includes: obtaining a database operation statement sent by an application side to a target database; determining a first execution plan of the database operation statement according to a large model; encrypting the field value of a field to be encrypted in the first execution plan to obtain a second execution plan when it is determined that there is a field to be encrypted in the first execution plan; providing the second execution plan to the target database and receiving a first response result returned by the target database for the second execution plan; determining a processing result of the database operation statement according to the first response result and providing the processing result to the application side.
[0005] According to another aspect of the present disclosure, there is provided a device for processing database data based on a large model, which is applied to a first encryption gateway. The device includes: an obtaining module for obtaining a database operation statement sent by an application side to a target database; a determining module for determining a first execution plan of the database operation statement according to a large model; an encrypting module for encrypting the field value of a field to be encrypted in the first execution plan to obtain a second execution plan when it is determined that there is a field to be encrypted in the first execution plan; a communication module for providing the second execution plan to the target database and receiving a first response result returned by the target database for the second execution plan; a processing module for determining a processing result of the database operation statement according to the first response result and providing the processing result to the application side.
[0006] According to another aspect of the present disclosure, there is provided an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the database data processing method based on a large model proposed by the present disclosure.
[0007] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the database data processing method based on a large model proposed by the present disclosure.
[0008] According to another aspect of the present disclosure, there is provided a computer program product including a computer program, which when executed by a processor, implements the database data processing method based on a large model proposed by the present disclosure.
[0009] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0011] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure;
[0012] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure;
[0013] Figure 3 is a schematic diagram according to the third embodiment of the present disclosure;
[0014] Figure 4 is a schematic diagram according to the fourth embodiment of the present disclosure;
[0015] Figure 5 is a schematic diagram according to the fifth embodiment of the present disclosure;
[0016] Figure 6 is a block diagram of an electronic device for implementing the database data processing method based on a large model of the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted in the following description for clarity and conciseness.
[0018] In the related art, during the process of communication between the application side and the database, usually the application side encrypts the data, or the database encrypts the data. However, in the solution of encrypting data on the application side, when the encryption and decryption algorithm configuration needs to be modified, the application side needs to configure the change, which has a greater intrusion on the application side; in the way of encrypting data in the database, this solution is actually a solution integrating storage and encryption algorithms. For example, the database provides encryption and decryption functions. If the storage service is controlled, the data encryption and decryption are actually controlled, and the security is in doubt. Therefore, how to ensure the security of data communication between the application side and the database side in a convenient way is a technical problem that needs to be solved urgently at present.
[0019] In view of the above problems, the present disclosure proposes a method, device and storage medium for processing database data based on a large model. The solution proposes the following technical concept: obtaining a database operation statement sent by the application side to the target database, determining a first execution plan of the database operation statement through the large model, and encrypting the field value of the field to be encrypted in the first execution plan when it is determined that there is a field to be encrypted in the first execution plan to obtain a second execution plan, providing the second execution plan to the target database, and receiving a first response result returned by the target database for the second execution plan; determining the processing result of the database operation statement according to the first response result and providing the processing result to the application side. Thus, by determining the execution plan of the database operation statement through the first encryption gateway and encrypting the fields to be encrypted in the execution plan and then providing them to the target database for processing, it is possible to ensure the security of data communication between the application side and the database without the need for the application side and the database to perform encryption processing.
[0020] Figure 1 It is a schematic diagram according to the first embodiment of the present disclosure. It should be noted that the method for processing database data based on a large model in the embodiments of the present disclosure can be applied to a device for processing database data based on a large model. The device can be a first encryption gateway, or can be configured in the first encryption gateway. The first encryption gateway in this embodiment can be configured in an electronic device.
[0021] Among them, the electronic device can be any device with computing capabilities, such as a personal computer (PC for short), a mobile terminal, a server, etc. The mobile terminal can be, for example, a vehicle-mounted device, a mobile phone, a tablet computer, a personal digital assistant, a wearable device, a smart speaker, a server, a server cluster, and other hardware devices with various operating systems, touch screens, and / or display screens.
[0022] It should be noted that in the following embodiments, the data processing device of the database based on the large model is taken as an example of the first encryption gateway for description.
[0023] As Figure 1 shown, the database data processing method based on the large model may include the following steps:
[0024] Step 101, obtain the database operation statement sent by the application end to the target database.
[0025] Among them, the target database refers to the database that the application end can access.
[0026] In this embodiment, the application end can insert or update data into the target database through the database operation statement, etc.
[0027] In some embodiments, when the above target database supports Structured Query Language (SQL), SQL can be used to write the database operation statement. Among them, the database operation statement written using the SQL language can be called an SQL statement.
[0028] Among them, the application end refers to the terminal where the application that can communicate with the target database is located.
[0029] Step 102, determine the first execution plan of the database operation statement according to the large model.
[0030] In this embodiment, a corresponding prompt word can be generated according to the database operation statement. Among them, the prompt word is used to instruct the large model to generate the first execution plan of the database operation statement. The prompt word is input into the large model to obtain the first execution plan of the database operation statement. Thus, by prompting the large model with the prompt word, the large model can be made to understand based on the prompt word, so as to more accurately obtain the first execution plan of the database operation statement.
[0031] In some other embodiments, to make the generated first execution plan adapt to the characteristics of the target database, the characteristics of the target database are obtained; a prompt is generated according to the characteristics of the target database and the database operation statement, and the prompt is used to instruct the large model to generate an execution plan for the database operation statement according to the characteristics of the target database. The prompt is input into the large model to obtain an execution plan for the database operation statement. Thus, the generated first execution plan can adapt to the characteristics of the target database, which helps to optimize the query processing process and improve the efficiency of subsequent operations.
[0032] Step 103, in the case where it is determined that there are fields to be encrypted in the first execution plan, encrypt the field values of the fields to be encrypted in the first execution plan to obtain a second execution plan.
[0033] In some embodiments, for each field in the first execution plan, the field in the first execution plan can be matched with a preset field. If the field matches the preset field, it is determined that the field is a field to be encrypted.
[0034] In some other embodiments, it can be determined whether the first execution plan includes a preset field. If the preset field is included, it is determined that there are fields to be encrypted in the first execution plan.
[0035] For example, if the preset field is an address field, it can be determined whether there is an address field in the first execution plan. If there is an address field, it is determined that there are fields to be encrypted in the first execution plan, and the field to be encrypted is the address field.
[0036] Step 104, provide the second execution plan to the target database and receive a first response result returned by the target database for the second execution plan.
[0037] In this embodiment, the target database executes the second execution plan to obtain a first response result of the second execution plan and provides the first response result to the first encryption gateway.
[0038] Step 105, determine the processing result of the database operation statement according to the first response result and provide the processing result to the application side.
[0039] In some embodiments, the first response result can be directly used as the processing result of the database operation statement.
[0040] For example, if the database operation statement is used to write data into the target database, correspondingly, a second execution plan for the database operation statement can be determined. After the target database successfully stores the corresponding data in the second execution plan, it can return a first response result indicating successful data writing to the first encryption gateway. Correspondingly, the first encryption gateway can use the first response result as the processing result of the database operation statement and provide the processing result to the application side.
[0041] In some other embodiments, preset processing may be performed on the first response result, and the first response result after the preset processing is used as the processing result of the database operation statement. For example, the preset processing may be format conversion.
[0042] In the method for processing database data based on a large model according to the embodiments of the present disclosure, a database operation statement sent by an application end to a target database is obtained, and a first execution plan of the database operation statement is determined through the large model. When it is determined that there are fields to be encrypted in the first execution plan, the field values of the fields to be encrypted in the first execution plan are encrypted to obtain a second execution plan, and the second execution plan is provided to the target database, and a first response result returned by the target database for the second execution plan is received; the processing result of the database operation statement is determined according to the first response result, and the processing result is provided to the application end. Thus, by determining the execution plan of the database operation statement through the first encryption gateway and encrypting the fields to be encrypted in the execution plan and then providing them to the target database for processing, it is possible to ensure the security of data communication between the application end and the database without the need for the application end and the database to perform encryption processing.
[0043] In some embodiments, if the field values of the fields to be encrypted of multiple object identifiers need to be encrypted, that is, when there is a large amount of data to be encrypted, in order to obtain the second execution plan as soon as possible and improve the efficiency of the application end to obtain the processing result of the database operation statement, multiple second encryption gateways that can be combined with the first encryption gateway can be used to obtain the ciphertext field values of the fields to be encrypted of multiple first object identifiers. To clearly understand this process, the following Figure 2 An exemplary description is given of a possible implementation manner of obtaining the ciphertext field values of the fields to be encrypted of multiple first object identifiers through multiple second encryption gateways.
[0044] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure.
[0045] As Figure 2 shown, the method may further include the following steps:
[0046] Step 201, obtain a database operation statement sent by an application end to a target database.
[0047] Step 202, determine a first execution plan of the database operation statement according to the large model.
[0048] It should be noted that for the specific implementation manners of step 201 and step 202, reference may be made to the relevant descriptions in other embodiments, and details are not described herein again.
[0049] Step 203, when it is determined that there are fields to be encrypted in the first execution plan and the fields to be encrypted correspond to multiple first object identifiers, determine the first total quantity of the multiple first object identifiers.
[0050] Step 204, when the first total quantity is greater than the first preset quantity threshold, obtain the ciphertext field values of the fields to be encrypted of the multiple first object identifiers through multiple second encryption gateways, where the ciphertext field values are obtained by encrypting the field values of the fields to be encrypted of the first object identifiers.
[0051] Among them, the first object identifier is used to uniquely identify an object. For example, if the object is a commodity, the first object identifier can be a commodity identifier. Another example is that if the object is a user, the first object identifier can be the user's account.
[0052] In some embodiments, a possible implementation manner of the above step 204 is as follows: when the first total quantity is greater than the first preset quantity threshold, group the multiple first object identifiers to obtain multiple first identifier groups; generate encryption tasks corresponding to the multiple first identifier groups respectively, where the encryption tasks are used to indicate encrypting the field values of the fields to be encrypted of the first object identifiers in the corresponding first identifier groups; provide the multiple encryption tasks to the multiple second encryption gateways respectively, and receive the first task execution results returned by each second encryption gateway for the corresponding encryption task, where the first task execution results include: the ciphertext field values of the fields to be encrypted of the first object identifiers in the corresponding first identifier groups. Thus, task management is implemented through the first encryption gateway, and the corresponding encryption tasks are executed by the multiple second encryption gateways respectively, so that when the first encryption gateway implements task management, the ciphertext field values of the fields to be encrypted of each object identifier in the first execution plan can be obtained accurately and quickly.
[0053] Among them, the first preset quantity threshold is a quantity threshold preset according to actual requirements, and the embodiment does not specifically limit the value of the first preset quantity threshold.
[0054] In some embodiments, the multiple first object identifiers can be grouped according to a preset grouping strategy to obtain multiple first identifier groups. For example, the preset grouping strategy can be to group the multiple first object identifiers based on the geographical location corresponding to the first object identifiers, where the first object identifiers in the same geographical location are assigned to the same group. Another example is that the preset grouping strategy can be to group the first object identifiers in a way that every 10 object identifiers form a group.
[0055] Among them, in this embodiment, each second encryption gateway corresponds to an encryption task.
[0056] In some other embodiments, when the first total quantity is less than or equal to the first preset quantity threshold, the field values of the fields to be encrypted of multiple first object identifiers are encrypted respectively to obtain the ciphertext field values of the fields to be encrypted of the multiple object identifiers. Thus, when there is less data to be encrypted, the first gateway can be used to encrypt the field values of the fields to be encrypted of multiple first object identifiers, improving the security of data encryption.
[0057] It can be understood that in some scenarios, to ensure the security of data communication, different encryption algorithms may be set for different databases. Correspondingly, to accurately encrypt the field values of the fields to be encrypted, when the first total quantity is less than or equal to the first preset quantity threshold, the encryption algorithm corresponding to the target database can be obtained, and according to the encryption algorithm of the target database, the field values of the fields to be encrypted of multiple first object identifiers are encrypted respectively to obtain the ciphertext field values of the fields to be encrypted of the multiple object identifiers. Thus, combined with the encryption algorithm corresponding to the target database, the field values of the fields to be encrypted of the corresponding object identifiers are accurately encrypted, improving the security of data encryption.
[0058] Step 205: Replace the field values of the fields to be encrypted of each first object identifier in the first execution plan with the corresponding ciphertext field values to obtain a second execution plan.
[0059] Step 206: Provide the second execution plan to the target database and receive the first response result returned by the target database for the second execution plan.
[0060] Step 207: Determine the processing result of the database operation statement according to the first response result and provide the processing result to the application side.
[0061] It should be noted that for the specific implementation manners of steps 205 to 207, reference can be made to the relevant descriptions in other embodiments, which will not be elaborated here.
[0062] In this embodiment, when it is determined that there are fields to be encrypted in the first execution plan and the fields to be encrypted correspond to multiple first object identifiers, the total quantity of the multiple first object identifiers is determined. When the first total quantity is greater than the first preset quantity threshold, multiple second encryption gateways are used to determine the ciphertext field values of the fields to be encrypted of the multiple first object identifiers, which can improve the efficiency of obtaining the ciphertext field values of the fields to be encrypted of the multiple first objects, thereby improving the efficiency of obtaining the second execution plan and helping to improve the efficiency of the application side in obtaining the processing result of the database operation statement.
[0063] It can be understood that in some scenarios, when there are no fields to be encrypted in the first execution plan, in order to clearly understand the processing process proposed by this solution when it is determined that there are no fields to be encrypted in the first execution plan, the following is combined with Figure 3 to give an exemplary description of this process.
[0064] As Figure 3 shown, it may include:
[0065] Step 301, obtain the database operation statement sent by the application end to the target database.
[0066] Step 302, determine the first execution plan of the database operation statement according to the large model.
[0067] It should be noted that for the specific implementation manners of Step 301 and Step 302, reference can be made to the relevant descriptions in other embodiments, which will not be elaborated here.
[0068] Step 303, provide the first execution plan to the target database.
[0069] Step 304, receive the second response result returned by the target database for the first execution plan.
[0070] Step 305, when there are fields to be decrypted in the second response result, decrypt the field values of the fields to be decrypted in the second response result to obtain the decryption result.
[0071] In some embodiments, for each field in the second response result, the field can be matched with a preset field. If the field matches the preset field, it is determined that there are fields to be decrypted in the second response result, and the field is determined as the field to be decrypted.
[0072] In some embodiments, a possible implementation manner of the above Step 305 is as follows: when there are fields to be decrypted in the second response result and the fields to be decrypted correspond to multiple second object identifiers, determine the second total quantity of the multiple second object identifiers; when the second total quantity is greater than the second preset quantity threshold, obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers through multiple third encryption gateways, where the plaintext field values are obtained by decrypting the field values of the fields to be decrypted of the second object identifiers; replace the field values of the fields to be decrypted of each second object identifier in the second response result with the corresponding plaintext field values to obtain the decryption result. Thus, when there is a large amount of data to be decrypted, decrypting the field values of the fields to be decrypted of multiple second object identifiers through multiple third encryption gateways can improve the efficiency of obtaining the plaintext field values of the fields to be decrypted of multiple second object identifiers.
[0073] In some embodiments, a possible implementation of obtaining the plaintext field values of the fields to be decrypted of multiple second object identifiers through multiple third encryption gateways is as follows: when the second total quantity is greater than the second preset quantity threshold, group multiple second object identifier groups to obtain multiple second identifier groups; generate decryption tasks corresponding to each of the multiple second identifier groups, where the decryption task is used to indicate decrypting the field values of the fields to be decrypted of the second object identifiers in the corresponding second identifier group; provide the multiple decryption tasks to the multiple third encryption gateways respectively, and receive the second task execution results returned by each third encryption gateway for the corresponding decryption task, where the second execution result includes: the plaintext field values of the fields to be decrypted of the second object identifiers in the corresponding second identifier group. Thus, the first encryption gateway determines the decryption tasks to be executed by the multiple third encryption gateways, and the multiple third encryption gateways classify and execute the corresponding decryption tasks, so that when the first encryption gateway realizes task management, it can accurately and quickly obtain the plaintext field values of the fields to be decrypted of each object identifier in the second response result, improving the efficiency of obtaining the plaintext field values of the fields to be decrypted of each object identifier in the second response result.
[0074] In some embodiments, each third encryption gateway corresponds to one decryption task. That is to say, the decryption tasks corresponding to different third encryption gateways are different.
[0075] Among them, the second preset quantity threshold is a quantity threshold preset according to actual needs, and the embodiment does not specifically limit the value of the second preset quantity threshold.
[0076] It should be noted that the first preset quantity threshold and the second preset quantity threshold in the present disclosure may be the same or different, and the embodiment does not specifically limit this.
[0077] In some other embodiments, when the second total quantity is less than or equal to the second preset quantity threshold, decrypt the field values of the fields to be decrypted of the multiple second object identifiers respectively to obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers. Thus, when the data to be decrypted is less, the first encryption gateway can decrypt the field values of the decrypted fields of the second object identifiers by itself, improving the security of data decryption.
[0078] In some embodiments, in some scenarios, to further improve data security, the encryption algorithms corresponding to different databases are usually different. When the second total quantity is less than or equal to the second preset quantity threshold, the decryption algorithm of the target database can be obtained, and based on the decryption algorithm, the field values of the fields to be decrypted of multiple second object identifiers are respectively decrypted to obtain the plaintext field values of the fields to be decrypted of multiple second object identifiers. Thus, in combination with the decryption algorithm corresponding to the target database, the decryption of the field values of the fields to be decrypted of multiple second object identifiers is accurately realized.
[0079] Among them, it should be noted that the decryption algorithm corresponding to the target database is determined based on the encryption algorithm corresponding to the target database.
[0080] Among them, the field to be decrypted is the field that needs to be decrypted. For example, the field to be decrypted can be an address field, etc.
[0081] Step 306, determine the processing result of the database operation statement according to the decryption result, and provide the processing result to the application side.
[0082] In some embodiments, after obtaining the decryption result, it can be determined whether the plaintext field value of the field to be decrypted meets the filtering condition in the database operation statement, and the processing result of the database operation statement is generated according to the plaintext field value that meets the filtering condition.
[0083] For example, the filtering condition in the database operation statement is: the address including the specified keyword from the target database. Suppose the decryption result determined based on the database operation statement includes multiple decrypted address information. According to the filtering condition, the multiple address information in the decryption result can be filtered to obtain the target address information including the specified keyword, and the processing result of the database operation statement is generated according to the target address information.
[0084] Among them, it should be noted that when the second response result does not have a field to be decrypted, the processing result of the database operation statement can be determined according to the second response result, and the processing result is provided to the application side.
[0085] In this embodiment, when it is determined that there are no fields to be encrypted in the first execution plan corresponding to the database operation statement, the second response result of the first execution plan is obtained through the target database. When there are fields to be decrypted in the second response result, the field values of the fields to be decrypted in the second response result are decrypted to obtain a decryption result, and the processing result of the database operation statement is determined according to the decryption result, and the processing result is provided to the application side. Thus, there is no need for the application side and the database to perform decryption processing, enabling the first encryption gateway to decrypt the communication data between the application side and the database, sharing the computing pressure of both communication parties, and centrally managing the encryption and decryption operations, which helps to unify the management of the encryption and decryption processes and improve efficiency and security.
[0086] The following is an example for illustration. Figure 4 It is a schematic diagram according to the fourth embodiment of the present disclosure. It should be noted that in this embodiment, an example of inserting data into the target database through a database operation statement is used for exemplary description. In Figure 4 it may include the following steps:
[0087] Step 401, the first encryption gateway intercepts the database operation statement sent by the application side to the target database.
[0088] Step 402, the first encryption gateway inputs the database operation statement into the large model to obtain the first execution plan of the database operation statement.
[0089] Step 403, the first encryption gateway encrypts the field values of the fields to be encrypted in the first execution plan through the encryption algorithm of the target database to obtain the second execution plan.
[0090] It should be noted that the encryption algorithm of the target database can be set according to actual needs, and this embodiment does not specifically limit the encryption algorithm of the target database.
[0091] Step 404, the first encryption gateway writes the ciphertext field values of the fields to be encrypted in the second execution plan into the target database.
[0092] Step 405, receive the response result returned by the target database.
[0093] In this embodiment, the ciphertext field values in the second execution plan can be written into the target database through the interface of the target database.
[0094] It should be noted that the target database in this embodiment can be various types of databases. For example, the target database can be a database other than mysql, oracle, and postgres, and this embodiment does not specifically limit the target database.
[0095] Step 406, the first encryption gateway determines the processing result of the database operation statement based on the response result and provides the processing result to the application side.
[0096] In this embodiment, the first encryption gateway encrypts the fields to be encrypted, enabling the gateway to have an encryption function. The target database does not need to perform data encryption, separating encryption and storage, which helps improve data security.
[0097] To implement the above embodiment, the present disclosure also provides a database data processing device based on a large model.
[0098] Figure 5 It is a schematic diagram according to the fifth embodiment of the present disclosure. It should be noted that the database data processing device based on the large model in this embodiment is applied to the first encryption gateway.
[0099] As Figure 5 shown, the database data processing device 50 based on the large model may include: an acquisition module 501, a determination module 502, an encryption module 503, a communication module 504, and a processing module 505, where:
[0100] The acquisition module 501 is configured to acquire the database operation statement sent by the application side to the target database.
[0101] The determination module 502 is configured to determine the first execution plan of the database operation statement according to the large model.
[0102] The encryption module 503 is configured to encrypt the field value of the field to be encrypted in the first execution plan to obtain a second execution plan when it is determined that there is a field to be encrypted in the first execution plan.
[0103] The communication module 504 is configured to provide the second execution plan to the target database and receive the first response result returned by the target database for the second execution plan.
[0104] The processing module 505 is configured to determine the processing result of the database operation statement according to the first response result and provide the processing result to the application side.
[0105] As a possible implementation manner of the embodiment of the present disclosure, the encryption module 503 includes:
[0106] The first determination unit is configured to determine the first total number of multiple first object identifiers when it is determined that there is a field to be encrypted in the first execution plan and the field to be encrypted corresponds to multiple first object identifiers;
[0107] The first encryption unit is configured to, when the first total quantity is greater than the first preset quantity threshold, obtain the ciphertext field values of the fields to be encrypted of multiple first object identifiers through multiple second encryption gateways, where the ciphertext field values are obtained by encrypting the field values of the fields to be encrypted of the first object identifiers;
[0108] The first replacement unit is configured to replace the field values of the fields to be encrypted of each first object identifier in the first execution plan with the corresponding ciphertext field values to obtain a second execution plan.
[0109] As a possible implementation manner of the embodiments of the present disclosure, the first encryption unit is specifically configured to: when the first total quantity is greater than the first preset quantity threshold, group multiple first object identifiers to obtain multiple first identifier groups; generate encryption tasks corresponding to the multiple first identifier groups respectively, where the encryption tasks are used to indicate encrypting the field values of the fields to be encrypted of the first object identifiers in the corresponding first identifier groups; provide the multiple encryption tasks to the multiple second encryption gateways respectively, and receive the first task execution results returned by each second encryption gateway for the corresponding encryption task, where the first task execution results include: the ciphertext field values of the fields to be encrypted of the first object identifiers in the corresponding first identifier groups.
[0110] As a possible implementation manner of the embodiments of the present disclosure, the encryption module further includes: a second encryption unit configured to, when the first total quantity is less than or equal to the first preset quantity threshold, encrypt the field values of the fields to be encrypted of the multiple first object identifiers respectively to obtain the ciphertext field values of the fields to be encrypted of the multiple object identifiers.
[0111] As a possible implementation manner of the embodiments of the present disclosure, the second encryption unit is specifically configured to: when the first total quantity is less than or equal to the first preset quantity threshold, obtain the encryption algorithm corresponding to the target database; encrypt the field values of the fields to be encrypted of the multiple first object identifiers respectively according to the encryption algorithm to obtain the ciphertext field values of the fields to be encrypted of the multiple object identifiers.
[0112] As a possible implementation manner of the embodiments of the present disclosure, the apparatus may further include:
[0113] A providing module configured to, when it is determined that there is no field to be encrypted in the first execution plan, provide the first execution plan to the target database;
[0114] A receiving module configured to receive a second response result returned by the target database for the first execution plan;
[0115] A decryption module configured to, when there is a field to be decrypted in the second response result, decrypt the field value of the field to be decrypted in the second response result to obtain a decryption result;
[0116] A result processing module, configured to determine a processing result of a database operation statement according to a decryption result, and provide the processing result to an application side.
[0117] As a possible implementation manner of an embodiment of the present disclosure, the decryption module includes:
[0118] A second determination unit, configured to determine a second total quantity of multiple second object identifiers when there are fields to be decrypted in a second response result and the fields to be decrypted correspond to multiple second object identifiers;
[0119] A first decryption unit, configured to obtain a plaintext field value of a field to be decrypted of multiple second object identifiers through multiple third encryption gateways when the second total quantity is greater than a second preset quantity threshold, where the plaintext field value is obtained by decrypting a field value of the field to be decrypted of the second object identifier;
[0120] A second replacement unit, configured to replace the field value of the field to be decrypted of each second object identifier in the second response result with the corresponding plaintext field value to obtain a decryption result.
[0121] As a possible implementation manner of an embodiment of the present disclosure, the first decryption unit is specifically configured to: when the second total quantity is greater than a second preset quantity threshold, group multiple second object identifier groups to obtain multiple second identifier groups; generate decryption tasks corresponding to the multiple second identifier groups respectively, where the decryption tasks are used to indicate decrypting the field value of the field to be decrypted of the second object identifier in the corresponding second identifier group; provide the multiple decryption tasks to the multiple third encryption gateways respectively, and receive second task execution results returned by each third encryption gateway for the corresponding decryption task, where the second execution result includes: the plaintext field value of the field to be decrypted of the second object identifier in the corresponding second identifier group.
[0122] As a possible implementation manner of an embodiment of the present disclosure, the decryption module further includes: a second decryption unit, configured to: when the second total quantity is less than or equal to a second preset quantity threshold, decrypt the field values of the fields to be decrypted of the multiple second object identifiers respectively to obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers.
[0123] As a possible implementation manner of an embodiment of the present disclosure, the second decryption unit is specifically configured to: when the second total quantity is less than or equal to a second preset quantity threshold, obtain a decryption algorithm for a target database; and decrypt the field values of the fields to be decrypted of the multiple second object identifiers respectively according to the decryption algorithm to obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers.
[0124] As a possible implementation manner of an embodiment of the present disclosure, the determining module 502 is specifically configured to: generate a corresponding prompt word according to a database operation statement, where the prompt word is used to instruct a large model to generate an execution plan of the database operation statement; input the prompt word into the large model to obtain a first execution plan of the database operation statement.
[0125] As a possible implementation manner of an embodiment of the present disclosure, generating a corresponding prompt word according to a database operation statement includes: obtaining the characteristics of a target database; generating a prompt word according to the characteristics of the target database and the database operation statement, where the prompt word is used to instruct the large model to generate an execution plan of the database operation statement according to the characteristics of the target database.
[0126] It should be noted that the foregoing explanation of the embodiment of the method for processing database data based on a large model also applies to the apparatus for processing database data based on a large model in this embodiment, and details are not described herein again.
[0127] In the apparatus for processing database data based on a large model according to an embodiment of the present disclosure, a database operation statement sent by an application end to a target database is obtained, and a first execution plan of the database operation statement is determined through a large model. In the case where there is a field to be encrypted in the determined first execution plan, the field value of the field to be encrypted in the first execution plan is encrypted to obtain a second execution plan, and the second execution plan is provided to the target database, and a first response result returned by the target database for the second execution plan is received; a processing result of the database operation statement is determined according to the first response result, and the processing result is provided to the application end. Thus, by determining the execution plan of the database operation statement through the first encryption gateway and encrypting the field to be encrypted in the execution plan and then providing it to the target database for processing, it is possible to ensure the security of data communication between the application end and the database without the need for the application end and the database to perform encryption processing.
[0128] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information involved are all carried out on the premise of obtaining the user's consent, and all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0129] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0130] Figure 6It is a block diagram of an electronic device for implementing the database data processing method based on a large model according to an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementations of the present disclosure described and / or claimed herein.
[0131] As Figure 6 shown, the electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0132] Multiple components in the electronic device 600 are connected to the I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, an optical disk, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows the electronic device 600 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0133] The computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 executes the various methods and processes described above, such as the method for processing database data based on a large model. For example, in some embodiments, the method for processing database data based on a large model can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded into the RAM 603 and executed by the computing unit 601, one or more steps of the method for processing database data based on a large model described above can be executed. Alternatively, in other embodiments, the computing unit 601 can be configured to execute the method for processing database data based on a large model in any other suitable manner (e.g., by means of firmware).
[0134] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0135] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0136] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0137] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0138] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0139] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The relationship between the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server incorporating a blockchain.
[0140] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution disclosed in this disclosure can be achieved, and no limitations are imposed herein.
[0141] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. A method for processing database data based on a large model, which is applied to a first encryption gateway. The method includes: Obtaining a database operation statement sent by an application end to a target database; Determining a first execution plan for the database operation statement according to the large model; When it is determined that there are fields to be encrypted in the first execution plan, encrypting the field values of the fields to be encrypted in the first execution plan to obtain a second execution plan; Providing the second execution plan to the target database and receiving a first response result returned by the target database for the second execution plan; Determining the processing result of the database operation statement according to the first response result and providing the processing result to the application end.
2. The method according to claim 1, wherein, The step of, when it is determined that there are fields to be encrypted in the first execution plan, encrypting the field values of the fields to be encrypted in the first execution plan to obtain a second execution plan includes: When it is determined that there are fields to be encrypted in the first execution plan and the fields to be encrypted correspond to multiple first object identifiers, determining a first total quantity of the multiple first object identifiers; When the first total quantity is greater than a first preset quantity threshold, obtaining ciphertext field values of the fields to be encrypted of the multiple first object identifiers through multiple second encryption gateways, where the ciphertext field values are obtained by encrypting the field values of the fields to be encrypted of the first object identifiers; Replacing the field values of the fields to be encrypted of each of the first object identifiers in the first execution plan with the corresponding ciphertext field values to obtain the second execution plan.
3. The method according to claim 2, wherein The step of, when the first total quantity is greater than a first preset quantity threshold, obtaining ciphertext field values of the fields to be encrypted of the multiple first object identifiers through multiple second encryption gateways includes: When the first total quantity is greater than a first preset quantity threshold, grouping the multiple first object identifiers to obtain multiple first identifier groups; Generating encryption tasks corresponding to the multiple first identifier groups respectively, where the encryption tasks are used to indicate encrypting the field values of the fields to be encrypted of the first object identifiers in the corresponding first identifier groups; Providing the multiple encryption tasks to multiple second encryption gateways respectively and receiving first task execution results returned by each of the second encryption gateways for the corresponding encryption tasks, where the first task execution results include: the ciphertext field values of the fields to be encrypted of the first object identifiers in the corresponding first identifier groups.
4. The method according to claim 2, wherein, The method further includes: When the first total quantity is less than or equal to the first preset quantity threshold, encrypting the field values of the fields to be encrypted of the multiple first object identifiers respectively to obtain ciphertext field values of the fields to be encrypted of the multiple object identifiers.
5. The method according to claim 4, wherein, The step of, when the first total quantity is less than or equal to the first preset quantity threshold, encrypting the field values of the fields to be encrypted of the multiple first object identifiers respectively to obtain ciphertext field values of the fields to be encrypted of the multiple object identifiers includes: When the first total quantity is less than or equal to the first preset quantity threshold, obtaining an encryption algorithm corresponding to the target database; According to the encryption algorithm, encrypt the field values of the fields to be encrypted of multiple first object identifiers respectively to obtain the ciphertext field values of the fields to be encrypted of the multiple object identifiers.
6. The method according to claim 1, wherein, The method further includes: When it is determined that there is no field to be encrypted in the first execution plan, provide the first execution plan to the target database; Receive a second response result returned by the target database for the first execution plan; When there is a field to be decrypted in the second response result, decrypt the field value of the field to be decrypted in the second response result to obtain a decryption result; Determine the processing result of the database operation statement according to the decryption result and provide the processing result to the application side.
7. The method according to claim 6, wherein When there is a field to be decrypted in the second response result, decrypt the field value of the field to be decrypted in the second response result to obtain a decryption result, including: When there is a field to be decrypted in the second response result and the field to be decrypted corresponds to multiple second object identifiers, determine the second total quantity of the multiple second object identifiers; When the second total quantity is greater than a second preset quantity threshold, obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers through multiple third encryption gateways, where the plaintext field values are obtained by decrypting the field values of the fields to be decrypted of the second object identifiers; Replace the field values of the fields to be decrypted of each of the second object identifiers in the second response result with the corresponding plaintext field values to obtain the decryption result.
8. The method according to claim 7, wherein When the second total quantity is greater than a second preset quantity threshold, obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers through multiple third encryption gateways, including: When the second total quantity is greater than a second preset quantity threshold, group the multiple second object identifier groups to obtain multiple second identifier groups; Generate decryption tasks corresponding to the multiple second identifier groups respectively, where the decryption tasks are used to indicate decrypting the field values of the fields to be decrypted of the second object identifiers in the corresponding second identifier group; Provide the multiple decryption tasks to multiple third encryption gateways respectively and receive second task execution results returned by each of the third encryption gateways for the corresponding decryption tasks, where the second execution results include: the plaintext field values of the fields to be decrypted of the second object identifiers in the corresponding second identifier group.
9. The method according to claim 7, wherein The method further includes: When the second total quantity is less than or equal to the second preset quantity threshold, decrypt the field values of the fields to be decrypted of the multiple second object identifiers respectively to obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers.
10. The method according to claim 9, wherein, When the second total quantity is less than or equal to the second preset quantity threshold, decrypt the field values of the fields to be decrypted of the multiple second object identifiers respectively to obtain the plaintext field values of the fields to be decrypted of the multiple second object identifiers, including: When the second total quantity is less than or equal to the second preset quantity threshold, obtain the decryption algorithm of the target database; According to the decryption algorithm, decrypt the field values of the fields to be decrypted of multiple second object identifiers respectively, and obtain the plaintext field values of the fields to be decrypted of multiple second object identifiers.
11. The method according to any one of claims 1-10, wherein, The determining, according to the large model, the first execution plan of the database operation statement includes: Generating a corresponding prompt word according to the database operation statement, where the prompt word is used to instruct the large model to generate an execution plan of the database operation statement; Inputting the prompt word into the large model to obtain the first execution plan of the database operation statement.
12. The method according to claim 11, wherein, The generating, according to the database operation statement, a corresponding prompt word includes: Obtaining the characteristics of the target database; Generating the prompt word according to the characteristics of the target database and the database operation statement, where the prompt word is used to instruct the large model to generate an execution plan of the database operation statement according to the characteristics of the target database.
13. A database data processing device based on a large model, applied to a first encryption gateway, the device includes: An obtaining module, configured to obtain a database operation statement sent by an application end to a target database; A determining module, configured to determine a first execution plan of the database operation statement according to a large model; An encryption module, configured to encrypt the field value of a field to be encrypted in the first execution plan to obtain a second execution plan when it is determined that there is a field to be encrypted in the first execution plan; A communication module, configured to provide the second execution plan to the target database and receive a first response result returned by the target database for the second execution plan; A processing module, configured to determine a processing result of the database operation statement according to the first response result and provide the processing result to the application end.
14. An electronic device, including: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1 to 12.
15. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 12.
16. A computer program product, including a computer program, where the computer program implements the method according to any one of claims 1 to 12 when executed by a processor.