AI-based database composite query method
Through multi-level permission verification and LLM large model-driven keyword extraction and SQL generation, the problem of lax access permission control in AI-generated SQL queries is solved, the security and controllability of data queries are achieved, and dynamic data subject management is supported.
Patent Information
- Application Number
- CN202510670276.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-09-16
AI Technical Summary
In the existing technology, SQL queries generated by artificial intelligence do not strictly control user access rights, resulting in uncontrollable output data and the risk of unauthorized access to data.
A multi-level permission verification mechanism is adopted to extract keywords and generate SQL statements through the LLM large model. Combined with data subjects and user permission configuration, compound queries are performed to ensure data security and controllability.
It implements multi-level verification of output data, reduces the risk of sensitive information leakage, improves the security and controllability of data query, supports dynamic data subject management, and has strong scalability.
Smart Images

Figure CN120653662A_ABST
Abstract
Claims
1. A database compound query method based on AI, characterized in that: Includes preliminary configuration steps and usage query steps; The preliminary configuration steps include keyword query configuration, data subject query configuration and user authority configuration; The query step includes: Step 1: Get the natural language description of the current user input and generate an HTTP request; Step 2: Extract keyword phrases from the input natural language description using the LLM model. Simultaneously, verify the HTTP request to see if there are any data topics available for querying. If no such data topics exist, terminate the query. If so, obtain a list of such data topics. Step 3: Perform intent recognition on the natural language description in the HTTP request. If no intent is recognized, the query ends. If an intent is recognized, the most appropriate data topic is selected from the data topic list obtained in Step 2 based on the recognized intent and used as the query data topic. Step 4: Obtain detailed data of the query data subject and the three data items within the query data subject that are most similar to the natural language description in the HTTP request; then input the detailed data of the query data subject and the three most similar data items into the LLM model as prompt words for generating SQL, and the LLM model outputs the SQL statement; Step 5: Combine the SQL statement obtained in step 4 with the keyword combination obtained in step 1 to perform a compound query and obtain the output result; Step 6: Reply to the user based on the output result obtained in step 5 and the natural language description input by the user.
2. The AI-based database compound query method according to claim 1, characterized in that: The keyword query setting includes the input parameter open field setting and the output parameter field setting; the data subject query configuration includes the following configuration content: subject name, subject description, question example SQL, configuration association table within the subject, table permission setting, and setting output content restrictions for each table; user permission configuration is to set specific permission rules based on the user's identity information.
3. The AI-based database compound query method according to claim 1, characterized in that: In step 4, the query data details information includes the DDL of the accessible table, the dictionary value description, the problem example SQL, and the outer join table.
4. The AI-based database compound query method according to claim 1, characterized in that: The compound query in step 5 is specifically as follows: Match the keyword group to the input parameter field. If a match is found, obtain the queryable output data corresponding to the input parameter field. Then match and verify the queryable output data with the output parameter field, and return the verified output data as the keyword output data. Execute SQL statements, obtain execution results, filter according to user permission rules, and obtain SQL output data; Finally, the keyword output data is merged with the SQL output data to obtain the output result.