Database query method, device, equipment and medium with private protection feature
By introducing private protection features in database queries, generating a set of query blocks carrying protection tags and performing cross-level visibility detection, the problem of insufficient visibility control of traditional CTE in multi-tenant and complex query optimization scenarios is solved, and stricter query isolation and security boundaries are achieved.
Patent Information
- Application Number
- CN202511093635.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-08-06
AI Technical Summary
Traditional CTE visibility rules cannot achieve precise visibility control in multi-tenant database systems, complex query optimization, and analytical query scenarios, resulting in subqueries potentially unauthorized access to sensitive intermediate results or unexpected dependencies of the main query.
The private protection feature is introduced to generate a set of query blocks with protection tags through target keywords, build the target syntax tree structure, and use the hierarchical scope stack structure to perform cross-level visibility detection to ensure that the protected CTE definition block is visible only to other CTE definition blocks under its direct query level.
Significantly improves query isolation capabilities, implements fine-grained visibility control, prevents unauthorized access and unexpected dependencies of subqueries, and meets the strict isolation requirements of multi-layer nested queries.
Smart Images

Figure CN120596504B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of database technology, and in particular to a database query method, device, equipment and medium with private protection characteristics. Background Art
[0002] Structured Query Language (SQL), the core operating language for relational databases, has seen its syntax continue to evolve with the development of database management systems. The Common Table Expression (CTE) feature introduced in SQL Server 2005 provides modular programming capabilities for complex queries through the WITH AS syntax, significantly improving the readability and maintainability of SQL statements.
[0003] CTEs allow developers to create reusable query blocks within a single query execution by defining temporary named result sets. In traditional implementations, CTE visibility follows strict hierarchical scoping rules: the main query can access its own CTEs, and subqueries can see all CTEs defined in the parent query.
[0004] This scope control mechanism demonstrates good applicability in general query scenarios and can meet most business needs. However, in specific business environments, particularly those involving data security isolation and complex query optimization, traditional CTE visibility rules exhibit significant limitations. For example, in multi-tenant database systems, the current mechanism cannot effectively prevent subqueries from unauthorized access to sensitive intermediate results contained in the main query. When optimizing complex queries, it is difficult to avoid unexpected subqueries' dependencies on the main query's intermediate data. In analytical query scenarios that require an independent computing environment, existing rules also fail to meet strict isolation requirements. Summary of the Invention
[0005] In view of this, the object of the present invention is to provide a database query method, apparatus, device and medium with private protection features, which can achieve refined control of CTE effects by introducing private protection features.
[0006] In a first aspect, the present invention provides a database query method with a privacy protection feature, comprising:
[0007] Receive a query statement to be processed; wherein at least one clause in the query statement contains a target keyword;
[0008] Generate a query block set with protection tags based on the query statement and the target keywords within it to construct a target syntax tree structure with protection tags. The CTE definition blocks modified with protection tags in the query block set have a private protection feature, which means that the CTE definition block is visible only to other CTE definition blocks under its direct query level.
[0009] In the process of constructing a semantic tree structure based on a target syntax tree structure, a hierarchical scope stack structure is maintained, and a cross-level visibility check is performed using the hierarchical scope stack structure to obtain a semantic tree structure that passes the cross-level visibility check; wherein the hierarchical scope stack structure includes a plurality of stack frames, the stack frames correspond to stack symbol tables of query blocks included in the query block set, and a flag bit for identifying whether the query block carries a protection flag is set in the stack symbol table;
[0010] Generate the response result corresponding to the query statement according to the semantic tree structure.
[0011] In one embodiment, generating a query block set carrying a guard mark according to a query statement and a target keyword therein to construct a target syntax tree structure carrying the guard mark includes:
[0012] For any clause contained in the query statement, the following operations are performed: the clause is parsed. If it is detected during the parsing operation that the clause contains the target keyword, a query block corresponding to the clause is generated based on the result of the parsing operation, and a protection mark is added to the query block corresponding to the clause;
[0013] Determine the hierarchical reference information between query blocks corresponding to the clauses;
[0014] The target syntax tree structure is constructed based on the hierarchical reference information between query blocks and the protection tags carried by the query blocks.
[0015] In one embodiment, constructing a target syntax tree structure based on hierarchical reference information between query blocks and protection tags carried by the query blocks includes:
[0016] Constructing an initial syntax tree structure based on hierarchical reference information between query blocks; wherein the syntax nodes of the initial syntax tree structure correspond to the query blocks;
[0017] Traverse each syntax node of the initial syntax tree structure. If the syntax node is a syntax node corresponding to a query block carrying a protection mark, bind the protection attribute data to the metadata of the syntax node to obtain a target syntax tree structure carrying the protection mark; wherein the protection attribute data is used to describe that the query block corresponding to the syntax node carries a protection mark.
[0018] In one embodiment, maintaining a hierarchical scope stack structure includes:
[0019] Traverse the syntax nodes of the target syntax tree structure, parse the current syntax node, push the stack symbol table of the query block onto the stack, and continue parsing the next syntax node to maintain the hierarchical scope stack structure.
[0020] In one embodiment, cross-level visibility detection is performed using a hierarchical scope stack structure to obtain a semantic tree structure that passes the cross-level visibility detection, including:
[0021] For the current semantic node in the semantic tree structure, determine the target query block referenced by the query block corresponding to the current semantic node, call the query block visibility algorithm, and use the hierarchical scope stack structure to perform cross-hierarchical visibility detection between the query block corresponding to the current semantic node and the target query block referenced by it;
[0022] In the case of passing the cross-level visibility detection, the target query block referenced by the query block corresponding to the next semantic node is determined to obtain a semantic tree structure that passes the cross-level visibility detection.
[0023] In one embodiment, a query block visibility algorithm is called to perform cross-level visibility detection between a query block corresponding to a semantic node and a target query block referenced by the query block using a hierarchical scope stack structure, including:
[0024] If it is determined based on the hierarchical scope stack structure that the target query block carries a protection tag, then it is determined whether the query block corresponding to the current semantic node is in the direct query level of the target query block;
[0025] If so, it is determined that the cross-level visibility detection passes.
[0026] In one embodiment, the method further comprises:
[0027] If the cross-level visibility check fails, a semantic error warning is generated for the current semantic node.
[0028] In a second aspect, the present invention further provides a database query device with a privacy protection feature, comprising:
[0029] A query receiving module, configured to receive a query statement to be processed, wherein at least one clause in the query statement contains a target keyword;
[0030] A syntax tree construction module is used to generate a query block set carrying protection tags according to the query statement and the target keywords therein, so as to construct a target syntax tree structure carrying protection tags. The CTE definition blocks modified by protection tags in the query block set have a private protection feature, which means that the CTE definition block is visible only to other CTE definition blocks under its direct query level.
[0031] A semantic tree construction module is used to maintain a hierarchical scope stack structure in the process of constructing a semantic tree structure based on a target syntax tree structure, and to use the hierarchical scope stack structure to perform cross-level visibility detection to obtain a semantic tree structure that passes the cross-level visibility detection; wherein the hierarchical scope stack structure includes multiple stack frames, the stack frames correspond to the stack symbol tables of the query blocks included in the query block set, and the stack symbol tables are provided with a flag bit for identifying whether the query block carries a protection flag;
[0032] The query response module is used to generate the response result corresponding to the query statement according to the semantic tree structure.
[0033] In a third aspect, the present invention further provides an electronic device comprising a processor and a memory, wherein the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement any one of the methods provided in the first aspect.
[0034] In a fourth aspect, the present invention further provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement any one of the methods provided in the first aspect.
[0035] The present invention provides a database query method, apparatus, device and medium with a private protection feature, which first receives a query statement to be processed; wherein at least one clause in the query statement contains a target keyword; then, a query block set carrying a protection mark is generated according to the query statement and the target keyword therein to construct a target syntax tree structure carrying the protection mark; wherein, the CTE definition block modified by the protection mark in the query block set has a private protection feature, and the private protection feature is that the CTE definition block is only visible to other CTE definition blocks under its direct query level; then, a semantic tree structure is constructed, and in the process of constructing the semantic tree structure based on the target syntax tree structure, a hierarchical scope stack structure is maintained, and a cross-level visibility check is performed using the hierarchical scope stack structure to obtain a semantic tree structure that passes the cross-level visibility check; wherein, the hierarchical scope stack structure includes multiple stack frames, and the stack frames correspond to the stack symbol tables of the query blocks included in the query block set, and the stack symbol tables are provided with a flag bit for identifying whether the query blocks carry the protection mark; finally, a response result corresponding to the query statement is generated according to the semantic tree structure. The above method introduces a private protection feature in the database, enabling refined control over the effects of CTE definition blocks through target keywords. This makes the CTE definition blocks modified by the protection mark visible only to other CTE definition blocks under the direct query level, significantly improving query isolation capabilities and marking an important evolution of database query optimization technology towards refined permission control.
[0036] Other features and advantages of the present application will be set forth in the descriptions that follow, and in part will be apparent from the description, or can be learned by practice of the application. The purposes and other advantages of the present application will be realized and attained by the structures particularly pointed out in the description, claims and drawings.
[0037] In order to make the above objectives, features and advantages of the present application more apparent, the following will describe a preferred embodiment in detail, and make a clear and complete description with the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or the prior art description. Obviously, the drawings described below are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0039] Figure 1 A flowchart of a database query method with private protection characteristics provided by the embodiment of the present application;
[0040] Figure 2 A technical framework diagram of a database query method with private protection characteristics provided by the embodiment of the present application;
[0041] Figure 3 A structural schematic diagram of a database query device with private protection characteristics provided by the embodiment of the present application;
[0042] Figure 4 A structural schematic diagram of an electronic device provided by the embodiment of the present application. DETAILED DESCRIPTION
[0043] In order to make the objectives, technical solutions and advantages of the embodiments of the present application more apparent, the technical solutions of the present application will be described clearly and completely in combination with the embodiments below. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.
[0044] Currently, the visibility rule of traditional CTE follows a strict hierarchical inheritance mechanism. This traditional design can meet the needs in most scenarios, but it has limitations in specific business environments: when the CTE scopes of the main query and the subquery need to be strictly isolated, the existing mechanism cannot achieve precise visibility control. Typical scenarios include: preventing the subquery from accessing the sensitive intermediate results of the main query in a multi-tenant system; avoiding the subquery from accidentally depending on the intermediate data of the main query during complex query optimization; and the analytical query scenario that needs to build an independent computing environment. Based on this, the present application provides a database query method, device, equipment and medium with a private protection feature, which realizes fine control of the CTE by introducing a private protection feature. The core value of this feature is: (1) Scope isolation: the CTE modified by PROTECT is only visible to the direct query level that defines it; (2) Security boundary: effectively blocking the access path of the subquery to the parent CTE; (3) Flexible combination: support for mixed use with regular CTEs to achieve fine-grained visibility control.
[0045] This feature is particularly suitable for the following application scenarios: scenarios that require the construction of multi-layer nested queries but require strict isolation of data at each level; protecting intermediate results from being accidentally modified by downstream queries in a multi-step calculation process; controlling the exposure range when encapsulating sensitive calculation logic in views or stored procedures.
[0046] In order to facilitate the understanding of the present embodiment, first of all, a database query method with a private protection feature disclosed by the present embodiment is introduced in detail. This method is applied to a database, especially a GBase 8s database. Referring to the flowchart of a database query method with a private protection feature shown in Figure 1 The method mainly includes the following steps S102 to S108:
[0047] Step S102, receiving a query statement to be processed.
[0048] Among them, the query statement is a SQL query statement, and at least one clause in the query statement contains a target keyword, which indicates that the clause is in a protected state, and is used to make the corresponding CTE definition block have a private protection feature subsequently. Exemplarily, the target keyword can be a PROTECT keyword.
[0049] Step S104, generating a query block set carrying a protection mark according to the query statement and the target keyword in it, to build a target syntax tree structure carrying a protection mark.
[0050] The query block set includes multiple query blocks, and the query block types are divided into main query blocks, subquery blocks, and CTE definition blocks. The CTE definition blocks modified by the protection mark in the query block set have private protection characteristics. The private protection characteristic is that the CTE definition block is only visible to other CTE definition blocks under its direct query level. The direct query level can be understood as the level where the CTE is located. The target syntax tree structure includes syntax nodes corresponding to the query blocks. The upper and lower layer relationships between the syntax nodes are used to describe the hierarchical reference relationship between the query blocks. The metadata of the syntax node corresponding to the CTE definition block carrying the protection mark is bound to protection attribute data. The protection attribute data is used to describe that the query block corresponding to the syntax node carries the protection mark.
[0051] In one example, the clauses contained in the query statement can be parsed in sequence, and when parsing the WITH clause, if the target keyword is detected, the protected CTE definition block can be marked with a protection tag, and the protection attribute data of the CTE definition block can be bound to the metadata of its corresponding syntax node, and the target syntax tree structure can be constructed in combination with the hierarchical reference information between query blocks.
[0052] Step S106 , in the process of constructing the semantic tree structure based on the target syntax tree structure, the hierarchical scope stack structure is maintained, and the hierarchical scope stack structure is used to perform cross-hierarchical visibility detection to obtain a semantic tree structure that passes the cross-hierarchical visibility detection.
[0053] Among them, the embodiment of the present invention improves the traditional hierarchical scope stack structure, and the hierarchical scope stack structure includes multiple stack frames, and the stack frames correspond to the stack symbol tables of the query blocks contained in the query block set. The stack symbol table is provided with a mark bit for identifying whether the query block carries a protection mark. On this basis, after determining the target query block referenced by the query block corresponding to the current semantic node, the query block visibility algorithm can be called, and the assignment of the mark in the stack symbol table corresponding to the stack frame in the hierarchical scope stack structure is used to perform cross-level visibility detection between the query block corresponding to the current semantic node and the target query block referenced by it. If the detection fails, a semantic error alarm is issued to prompt the user that the query statement has a cross-level reference. If it passes, the above process is repeated until a semantic tree structure without cross-level references is obtained.
[0054] Step S108: Generate a response result corresponding to the query statement according to the semantic tree structure.
[0055] In one example, the optimizer performs query optimization based on the semantic tree structure, and the executor performs actual calculations according to the constructed execution plan to return the response results corresponding to the query statement.
[0056] The database query method with private protection features provided in an embodiment of the present invention introduces private protection features into the database, and implements refined control over the effects of CTE definition blocks through target keywords, so that CTE definition blocks modified by protection marks are visible only to other CTE definition blocks under their direct query level, significantly improving query isolation capabilities and marking an important evolution of database query optimization technology towards refined permission control.
[0057] See also Figure 2 The technical framework diagram of a database query method with private protection characteristics shown in the figure, the embodiment of the present invention mainly involves the processes of expansion of the hierarchical scope stack structure, enhanced processing in the syntax parsing stage and conflict detection in the semantic verification stage. Among them, the expansion of the hierarchical scope stack structure is to add a flag bit in the stack symbol table for identifying whether the query block carries a protection flag. The enhanced processing in the syntax parsing stage is to identify the clause containing the target keyword in the syntax parsing stage, and pass its protected status to the metadata of the syntax node. The conflict detection in the semantic verification stage is to perform cross-level visibility verification based on the aforementioned expanded hierarchical scope stack structure, enhance the query isolation capability, and avoid cross-level references in the process of constructing the semantic tree structure.
[0058] For ease of understanding, the present invention provides a specific implementation of a database query method with a privacy protection feature:
[0059] Regarding the aforementioned step S102, an embodiment of the present invention provides a specific method for receiving a query statement to be processed. When writing a query statement, the user adds the PROTECT keyword to the clause that needs to be securely isolated. For example:
[0060] with
[0061] protect t1(a) as (select 1),
[0062] t2(b) as (select from t1)
[0063] Select from (
[0064] With t1(a) as (select 3)
[0065] select from t1 )
[0067] union all
[0068] select from t1;
[0069] Where "t1" contains a PROTECT keyword, which is only visible in the immediate query level where it is defined; "t2" references "t1", which is allowed because "t2" belongs to the immediate query level of "t1" (i.e. same level). For the subquery "Select from (With t1(a) as (select 3) select from t1)", the reference is not allowed because it does not belong to the immediate query level of "t1".
[0070] For the foregoing step S104, the embodiment of the present application provides a specific implementation of generating a set of query blocks carrying protection marks according to a query statement and a target keyword in the query statement, to construct a target Abstract Syntax Tree (AST) structure carrying protection marks, including:
[0071] (1) For any clause contained in the query statement, the following operation is performed: parsing the clause, and if it is detected in the parsing operation that the clause contains a target keyword, generating a query block corresponding to the clause according to the result of the parsing operation, and adding a protection mark to the query block corresponding to the clause.
[0072] In a specific implementation, the lexical analysis identifies the symbol table sequence corresponding to the query statement according to the syntax rule, and identifies the structure of the WITJ clause, the structure of the CTE, etc., to generate respective query blocks and stack symbol tables. The query block refers to a relatively independent semantic unit in the SQL query statement, and usually includes: a Top-level SELECT, a Subquery, a Common Table Expression (CTE), a query in a view definition, a nested query in a stored procedure, etc. Each query block has its independent stack symbol table, which records the object name, type, attribute, definition position, etc. defined in the query block. Further, the stack symbol table of the embodiment of the present application is newly added with a is_protected Boolean flag (i.e. the foregoing protection mark), which identifies whether the CTE definition body is limited to the current level access.
[0073] The process of generating the stack identifier is as follows: if the current clause contains a PROTECT keyword, the mark bit in the stack symbol table is assigned, for example, the is_protected Boolean flag is assigned to the mark bit; if the current clause does not contain a PROTECT keyword, the mark bit in the stack symbol table is set to empty.
[0074] (2) Determine the hierarchical reference information between query blocks corresponding to the clauses.
[0075] (1.3) Construct a target syntax tree structure based on the hierarchical reference information between query blocks and the protection tags carried by the query blocks. Specifically: Construct an initial syntax tree structure based on the hierarchical reference information between query blocks. The syntax nodes of the initial syntax tree structure correspond to the query blocks. Traverse each syntax node of the initial syntax tree structure. If the syntax node corresponds to a query block carrying a protection tag, bind the protection attribute data to the metadata of the syntax node to obtain a target syntax tree structure carrying the protection tag. The protection attribute data is used to describe that the query block corresponding to the syntax node carries a protection tag.
[0076] In practical applications, the SQL syntax tree (AST) construction process involves processes such as PROTECT keyword recognition, scope attribute transfer, and nested block detection. PROTECT keyword recognition marks protected CTE definition blocks during WITH clause parsing; scope attribute transfer binds the is_protected attribute (i.e., protection attribute data) to the metadata of the syntax node corresponding to the CTE definition block; and nested block detection establishes a parent-child relationship tree of query blocks through syntax tree traversal, providing a structural foundation for subsequent stack symbol table management.
[0077] The specific implementation process is as follows: When constructing the syntax tree, the is_protected attribute is passed to the metadata of the syntax node corresponding to the CTE definition block. Based on the marked reference hierarchy information and ctename, a parent-child relationship tree between query blocks is constructed, and then the target syntax tree structure with protection mark is obtained.
[0078] For the aforementioned step S106, an embodiment of the present invention provides a specific implementation method of maintaining a hierarchical scope stack structure in the process of constructing a semantic tree structure based on a target syntax tree structure, and using the hierarchical scope stack structure to perform cross-level visibility detection to obtain a semantic tree structure that passes the cross-level visibility detection.
[0079] In one example, the process of maintaining the hierarchical scope stack structure is as follows: traverse the syntax nodes of the target syntax tree structure, parse the current syntax node, push the stack symbol table of the query block onto the stack, and continue to parse the next syntax node to maintain the hierarchical scope stack structure.
[0080] For example, when constructing a hierarchical scope stack structure layer by layer, for example, the outer stack symbol table is constructed first. The outer layer contains the PROTECT keyword. The current CTE definition block symbol table level is 0, and the is_protected Boolean flag is marked for it. During the construction process, it is found that the inner layer references another CTE definition block without the PROTECT keyword. The inner layer CTE definition block label table is constructed again. The current level is 1, and the is_protected Boolean flag is not marked for it, and so on. When constructing the reference table of the CTE definition block, the CTE definition block table is searched hierarchically in the stack symbol table. If a protected CTE definition block is encountered, it can only be seen by the current level.
[0081] Continuing with the above query statement as an example, the level of "t1" is 0 and is protected, and the level of "t2" is 0 and is not protected. When "from t1" references "t1", "t1" is visible to "t2". The with level in the subquery is 1, and the protected "t1" table at level 0 is not visible.
[0082] In one example, cross-level visibility detection is performed using the hierarchical scope stack structure to obtain a semantic tree structure that passes cross-level visibility detection as shown below:
[0083] (a) For the current semantic node in the semantic tree structure, determine the target query block referenced by the query block corresponding to the current semantic node, call the query block visibility algorithm, and use the hierarchical scope stack structure to perform cross-hierarchical visibility detection between the query block corresponding to the current semantic node and the target query block it references.
[0084] Specifically, the logic of the query block visibility algorithm is as follows: if it is determined based on the hierarchical scope stack structure that the target query block carries a protection mark, then it is determined whether the query block corresponding to the current semantic node is in the direct query level of the target query block; if so, it is determined that the cross-level visibility detection has passed; if not, it is determined that the cross-level visibility detection has not passed.
[0085] (b) If the cross-level visibility detection fails, a semantic error warning is generated for the current semantic node.
[0086] (c) When the cross-level visibility detection is passed, continue to determine the target query block referenced by the query block corresponding to the next semantic node to obtain a semantic tree structure that passes the cross-level visibility detection.
[0087] In actual applications, in order to double-check that protected attributes are not illegally accessed, the hierarchy and protected attributes of the referenced CTE definition block are detected when the syntax tree structure is constructed. If a CTE definition block that references a protected attribute is detected, it is necessary to check whether it belongs to the current hierarchy. If not, an error is reported.
[0088] In summary, GBase 8s ensures that the scope of PROTECT is strictly limited to the query block in which it is defined, through symbol table management during the query parsing phase and access control mechanisms in the execution plan. This design maintains compatibility with SQL standards while providing the security isolation capabilities required for enterprise-level applications, marking a significant evolution in database query optimization technology towards refined permission control.
[0089] Based on the above embodiment, the present invention provides a database query device with a private protection feature. Figure 3 The structure diagram of a database query device with private protection characteristics shown in FIG. 1 mainly includes the following parts:
[0090] The query receiving module 302 is configured to receive a query statement to be processed, wherein at least one clause in the query statement contains a target keyword;
[0091] The syntax tree construction module 304 is configured to generate a query block set carrying protection marks according to the query statement and the target keywords therein, so as to construct a target syntax tree structure carrying protection marks. The CTE definition blocks modified with protection marks in the query block set have a private protection feature, which means that the CTE definition block is visible only to other CTE definition blocks under the direct query level.
[0092] A semantic tree construction module 306 is configured to maintain a hierarchical scope stack structure during the process of constructing a semantic tree structure based on a target syntax tree structure, and to perform cross-hierarchical visibility detection using the hierarchical scope stack structure to obtain a semantic tree structure that passes the cross-hierarchical visibility detection. The hierarchical scope stack structure includes a plurality of stack frames, each stack frame corresponding to a stacked symbol table of a query block included in the query block set, and a flag bit is set in the stacked symbol table to indicate whether the query block carries a protection flag.
[0093] The query response module 308 is used to generate a response result corresponding to the query statement according to the semantic tree structure.
[0094] The database query device with private protection features provided by an embodiment of the present invention introduces private protection features into the database, and implements fine-grained control over the effects of CTE definition blocks through target keywords, so that CTE definition blocks modified by protection marks are visible only to other CTE definition blocks under their direct query level, significantly improving query isolation capabilities and marking an important evolution of database query optimization technology towards fine-grained permission control.
[0095] In one embodiment, the syntax tree construction module 304 is specifically configured to:
[0096] For any clause contained in the query statement, the following operations are performed: the clause is parsed. If it is detected during the parsing operation that the clause contains the target keyword, a query block corresponding to the clause is generated based on the result of the parsing operation, and a protection mark is added to the query block corresponding to the clause;
[0097] Determine the hierarchical reference information between query blocks corresponding to the clauses;
[0098] The target syntax tree structure is constructed based on the hierarchical reference information between query blocks and the protection tags carried by the query blocks.
[0099] In one embodiment, the syntax tree construction module 304 is specifically configured to:
[0100] Constructing an initial syntax tree structure based on hierarchical reference information between query blocks; wherein the syntax nodes of the initial syntax tree structure correspond to the query blocks;
[0101] Traverse each syntax node of the initial syntax tree structure. If the syntax node is a syntax node corresponding to a query block carrying a protection mark, bind the protection attribute data to the metadata of the syntax node to obtain a target syntax tree structure carrying the protection mark; wherein the protection attribute data is used to describe that the query block corresponding to the syntax node carries a protection mark.
[0102] In one embodiment, the semantic tree construction module 306 is specifically configured to:
[0103] Traverse the syntax nodes of the target syntax tree structure, parse the current syntax node, push the stack symbol table of the query block onto the stack, and continue parsing the next syntax node to maintain the hierarchical scope stack structure.
[0104] In one embodiment, the semantic tree construction module 306 is specifically configured to:
[0105] For the current semantic node in the semantic tree structure, determine the target query block referenced by the query block corresponding to the current semantic node, call the query block visibility algorithm, and use the hierarchical scope stack structure to perform cross-hierarchical visibility detection between the query block corresponding to the current semantic node and the target query block referenced by it;
[0106] In the case of passing the cross-level visibility detection, the target query block referenced by the query block corresponding to the next semantic node is determined to obtain a semantic tree structure that passes the cross-level visibility detection.
[0107] In one embodiment, the semantic tree construction module 306 is specifically configured to:
[0108] If it is determined based on the hierarchical scope stack structure that the target query block carries a protection tag, then it is determined whether the query block corresponding to the current semantic node is in the direct query level of the target query block;
[0109] If so, it is determined that the cross-level visibility detection passes.
[0110] In one embodiment, the semantic tree construction module 306 is specifically configured to:
[0111] If the cross-level visibility check fails, a semantic error warning is generated for the current semantic node.
[0112] The device provided in the embodiment of the present invention has the same implementation principle and technical effects as those in the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding content in the aforementioned method embodiment.
[0113] An embodiment of the present invention provides an electronic device. Specifically, the electronic device includes a processor and a storage device. The storage device stores a computer program, and when the computer program is executed by the processor, it executes the method described in any one of the above-mentioned embodiments.
[0114] Figure 4 This is a structural diagram of an electronic device provided in an embodiment of the present invention. The electronic device 100 includes: a processor 40, a memory 41, a bus 42 and a communication interface 43. The processor 40, the communication interface 43 and the memory 41 are connected via the bus 42; the processor 40 is used to execute an executable module stored in the memory 41, such as a computer program.
[0115] Memory 41 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device. Communication between the system network element and at least one other network element is achieved through at least one communication interface 43 (which may be wired or wireless), and may utilize the Internet, a wide area network, a local area network, a metropolitan area network, or the like.
[0116] The bus 42 may be an ISA bus, a PCI bus, or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, Figure 4 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0117] Among them, the memory 41 is used to store programs, and the processor 40 executes the program after receiving the execution instruction. The method executed by the device for flow process definition disclosed in any embodiment of the above-mentioned embodiment of the present invention can be applied to the processor 40 or implemented by the processor 40.
[0118] Processor 40 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method may be completed by hardware integrated logic circuits or software instructions in processor 40. The above processor 40 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processing unit (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It may implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present invention may be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory 41 , and the processor 40 reads the information in the memory 41 and completes the steps of the above method in combination with its hardware.
[0119] The computer program product of the readable storage medium provided by the embodiment of the present application comprises a computer readable storage medium storing program codes, and the program codes comprise instructions for executing the method described in the foregoing method embodiments. The specific implementation can be referred to the foregoing method embodiments, and will not be described here.
[0120] When the functions are realized in the form of software function units and sold or used as independent products, the functions can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the technical solutions that essentially contribute to the prior art can be embodied in the form of software products. The computer software product is stored in a storage medium and includes instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0121] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present application, which are used to illustrate the technical solutions of the present application, but not to limit the present application. The protection scope of the present application is not limited to this. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily think of changes to the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some technical features, within the technical range disclosed by the present application. The modifications, changes or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A database query method with privacy protection characteristics, characterized in that: include: Receive a query statement to be processed; wherein at least one clause in the query statement contains a target keyword; A query block set carrying protection marks is generated according to the query statement and the target keyword therein to construct a target syntax tree structure carrying the protection marks; wherein the CTE definition blocks modified by the protection marks in the query block set have a private protection feature, wherein the private protection feature is that the CTE definition blocks are visible only to other CTE definition blocks under the direct query level; In the process of constructing a semantic tree structure based on the target syntax tree structure, a hierarchical scope stack structure is maintained, and a cross-hierarchical visibility check is performed using the hierarchical scope stack structure to obtain the semantic tree structure that passes the cross-hierarchical visibility check; wherein the hierarchical scope stack structure includes a plurality of stack frames, the stack frames correspond to the stack symbol tables of the query blocks included in the query block set, and the stack symbol table is provided with a flag bit for identifying whether the query block carries the protection flag; A response result corresponding to the query statement is generated according to the semantic tree structure.
2. The database query method with privacy protection characteristics according to claim 1, characterized in that: Generating a query block set carrying a guard mark according to the query statement and the target keyword therein to construct a target syntax tree structure carrying the guard mark, including: For any of the clauses included in the query statement, the following operations are performed: parsing the clause, if it is detected during the parsing operation that the clause contains the target keyword, generating a query block corresponding to the clause according to the result of the parsing operation, and adding a protection mark to the query block corresponding to the clause; Determining hierarchical reference information between the query blocks corresponding to the clauses; A target syntax tree structure is constructed based on the hierarchical reference information between the query blocks and the protection tags carried by the query blocks.
3. The database query method with privacy protection characteristics according to claim 2, characterized in that: Constructing a target syntax tree structure based on the hierarchical reference information between the query blocks and the protection flags carried by the query blocks, including: Constructing an initial syntax tree structure based on the hierarchical reference information between the query blocks; wherein the syntax nodes of the initial syntax tree structure correspond to the query blocks; Traverse each syntax node of the initial syntax tree structure, and if the syntax node is a syntax node corresponding to the query block carrying the protection mark, bind the protection attribute data to the metadata of the syntax node to obtain the target syntax tree structure carrying the protection mark; wherein the protection attribute data is used to describe that the query block corresponding to the syntax node carries the protection mark.
4. The database query method with privacy protection characteristics according to claim 1, characterized in that: Maintain the hierarchical scope stack structure, including: Traversing the syntax nodes of the target syntax tree structure, parsing the current syntax node, pushing the stack symbol table of the query block onto the stack, and continuing to parse the next syntax node to maintain the hierarchical scope stack structure.
5. The database query method with privacy protection characteristics according to claim 1, characterized in that: Performing cross-level visibility detection using the hierarchical scope stack structure to obtain the semantic tree structure that passes the cross-level visibility detection includes: For a current semantic node in the semantic tree structure, determining a target query block referenced by a query block corresponding to the current semantic node, calling a query block visibility algorithm, and using the hierarchical scope stack structure to perform cross-hierarchical visibility detection between the query block corresponding to the current semantic node and the target query block referenced by it; In the case of passing the cross-level visibility detection, continue to determine the target query block referenced by the query block corresponding to the next semantic node to obtain the semantic tree structure that passes the cross-level visibility detection.
6. The database query method with privacy protection characteristics according to claim 5, characterized in that: Calling a query block visibility algorithm and utilizing the hierarchical scope stack structure to perform cross-hierarchical visibility detection between the query block corresponding to the semantic node and the target query block referenced by it, including: If it is determined based on the hierarchical scope stack structure that the target query block carries the protection flag, determining whether the query block corresponding to the current semantic node is in the direct query level of the target query block; If so, it is determined that the cross-level visibility detection passes.
7. The database query method with privacy protection characteristics according to claim 5, characterized in that: The method further comprises: If the cross-level visibility detection fails, a semantic error alarm is generated for the current semantic node.
8. A database query device with privacy protection characteristics, characterized in that: include: A query receiving module, configured to receive a query statement to be processed; wherein at least one clause in the query statement contains a target keyword; a syntax tree construction module, configured to generate a query block set carrying protection marks according to the query statement and the target keyword therein, so as to construct a target syntax tree structure carrying the protection marks; wherein the CTE definition blocks modified by the protection marks in the query block set have a private protection feature, wherein the private protection feature is that the CTE definition blocks are visible only to other CTE definition blocks under the direct query level; A semantic tree construction module, configured to maintain a hierarchical scope stack structure during the process of constructing a semantic tree structure based on the target syntax tree structure, and perform cross-hierarchical visibility detection using the hierarchical scope stack structure to obtain the semantic tree structure that passes the cross-hierarchical visibility detection; wherein the hierarchical scope stack structure includes a plurality of stack frames, the stack frames corresponding to the stacked symbol tables of the query blocks included in the query block set, and the stacked symbol tables are provided with a flag bit for identifying whether the query block carries the protection flag; The query response module is used to generate a response result corresponding to the query statement according to the semantic tree structure.
9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Data record access control method and device in hierarchical relationship
CN103198141A
Database variable parameter scope control method, device and equipment
CN115630085A