Distributed database node security communication method and system
By establishing encrypted communication and topological relationships in a distributed database system, the security issue of data transmission from a trusted domain to an untrusted domain is resolved, ensuring that data remains encrypted during transmission and achieving secure data transmission.
Patent Information
- Application Number
- CN202510641214.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-05-19
AI Technical Summary
How to ensure the security of data read in a trusted domain when it is transmitted to an untrusted domain in a distributed database system, especially to prevent data leakage.
By establishing encrypted communication between the data management device in the trusted domain and the storage node in the non-trusted domain, and utilizing topological relationships and encryption policies, data can be ensured to remain encrypted during transmission until it reaches the security gateway for decryption.
It achieves the security of data during transmission in the untrusted domain, ensures that the data in the trusted domain is not leaked when transmitted to the untrusted domain, and improves the security and reliability of data transmission.
Smart Images

Figure CN120675736A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and in particular to a distributed database node secure communication method and system. Background Art
[0002] With the rapid development of information technology and the advent of the big data era, the explosive growth of data volumes has placed higher demands on data storage systems. Traditional centralized database systems face performance bottlenecks and reliability issues when processing large amounts of data. To address these issues, distributed database technology has emerged. This article provides a background introduction to distributed database technology.
[0003] A distributed database is a database system that stores data in multiple physical locations. It connects multiple database nodes through a network to form a logically unified data storage and management system. The main features of a distributed database include: Data distribution: Data is stored in a dispersed manner on different nodes, which can be physically dispersed servers or different storage devices on the same server. Data independence: Each node is independent of each other and can perform data operations and management independently. High availability: Distributed databases usually have failover and data replication mechanisms to ensure data availability and consistency in the event of node failure. Scalability: Distributed databases can easily expand storage capacity and processing power by adding nodes. Performance optimization: Distributed databases can use multiple nodes to process data in parallel to improve data processing efficiency.
[0004] Distributed databases can be categorized into the following types based on how data is distributed and managed: Partitioned databases: Data is divided into multiple parts, each stored on a different node. Replicated databases: Copies of data are stored on multiple nodes, each capable of handling read and write operations. Distributed database systems: Combine the characteristics of partitioning and replication, with data being both partitioned and replicated.
[0005] Distributed databases are usually deployed in trusted domains, which means that the communication between nodes is considered secure and trustworthy. However, for external third-party applications, they are usually considered to be in untrusted domains. Therefore, how to ensure the security of data read in the trusted domain and transferred to the untrusted domain is a current research issue. Summary of the Invention
[0006] The embodiments of the present application provide a distributed database node secure communication method and system to ensure the data security of data read from a trusted domain to a non-trusted domain.
[0007] To achieve the above objectives, this application adopts the following technical solutions: In a first aspect, a distributed database node secure communication method is provided, which is applied to a data management device, wherein the data management device is located in a first trusted domain, and the distributed storage nodes are located in a second trusted domain, and the first trusted domain and the second trusted domain are connected via non-trusted domain communication; the method includes: when it is necessary to analyze at least one type of data, the data management device sends a data acquisition request to N storage nodes in the second trusted domain, and the data acquisition request is used to request the provision of at least one type of data, and the at least one type of data is stored in N storage nodes, where N is an integer greater than 1; the data management device receives data ciphertext information from the second trusted domain; the data management device decrypts the data ciphertext information to obtain at least one type of plaintext data; the data management device analyzes at least one type of plaintext data to obtain a data analysis result.
[0008] Optionally, the data ciphertext information is information encrypted by some of the M storage nodes in the first trusted domain, and the encryption performed by some of the storage nodes is instructed by the data management device, M is an integer greater than N, the M storage nodes include N storage nodes, and the M storage nodes also include MN storage nodes other than the N storage nodes, and the MN storage nodes are used to forward at least one type of data.
[0009] Optionally, in the case where at least one type of data needs to be analyzed, the method also includes: the data management device determines that at least one type of data is distributedly stored in N storage nodes in the second trusted domain; the data management device determines a first topological relationship based on the topological relationship between the storage nodes in the second trusted domain, the storage nodes in the first topological relationship are M storage nodes, the first topological relationship indicates a routing path for sending data stored in the N storage nodes to the security gateway of the first trusted domain through the M storage nodes, the first trusted domain and the second trusted domain are connected through non-trusted domain communication, including: the data management device is connected to the security gateway through non-trusted domain communication; accordingly, the data acquisition request includes data routing information of each of the N storage nodes in the first topological relationship.
[0010] Optionally, for the i-th storage node among N storage nodes, i is any integer from 1 to N. If the i-th storage node has a previous-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes the information of the sending port of the previous-hop storage node; if the i-th storage node has a next-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes the information of the receiving port of the next-hop storage node, or if the i-th storage node does not have a next-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes the receiving port information of the security gateway.
[0011] Optionally, the method further includes: the data management device determines a data encryption policy based on the first topological relationship; accordingly, the data acquisition request further includes the data encryption policy, and the data encryption policy indicates that some storage nodes need to perform encryption.
[0012] Optionally, the first topological relationship is a topological relationship of a tree-like branch structure, a storage node among the M storage nodes that serves as a root node in the tree-like branch structure is connected to the security gateway, the tree-like branch structure includes multiple branches, and N storage nodes are distributed on multiple branches. The data encryption policy indicates that the first type of storage nodes among the M storage nodes need to perform encryption, and the second type of storage nodes among the M storage nodes do not need to perform encryption; wherein, the second type of storage node is a storage node that serves as the root node of at least two branches among the multiple branches, and the first type of storage node is other storage nodes among the M storage nodes except the second type of storage nodes. Any storage node among the M storage nodes is used to determine whether it belongs to the first type of storage node or the second type of storage node based on its own data routing information in the first topological relationship.
[0013] Optionally, the first storage node is any storage node among the N storage nodes; in the case where the first storage node belongs to the partial storage node that performs encryption, if the first storage node has a previous-hop storage node in the first topological relationship, the first storage node is configured to: encrypt the ciphertext or plaintext data received from the previous-hop storage node together with the plaintext data provided by the first storage node itself to obtain the ciphertext data, and send the ciphertext data to the next-hop storage node or security gateway of the first storage node in the first topological relationship; in the case where the first storage node belongs to the partial storage node that performs encryption, if the first storage node does not have a previous-hop storage node in the first topological relationship, the first storage node is configured to: encrypt the plaintext data provided by the first storage node itself to obtain the ciphertext data, and send the ciphertext data to the next-hop storage node or security gateway of the first storage node in the first topological relationship. Full gateway; in the case where the first storage node does not belong to the partial storage nodes that perform encryption, if the first storage node has a previous-hop storage node in the first topological relationship, the first storage node is configured to: package the ciphertext or plaintext data received from the previous-hop storage node and the plaintext data provided by the first storage node itself, and send them to the next-hop storage node or security gateway in the first topological relationship of the first storage node; in the case where the first storage node does not belong to the partial storage nodes that perform encryption, if the first storage node does not have a previous-hop storage node in the first topological relationship, the first storage node is configured to: send the plaintext data provided by the first storage node itself to the next-hop storage node or security gateway in the first topological relationship of the first storage node; wherein the ciphertext or plaintext data belongs to at least one type of data, and the plaintext data provided by the first storage node itself also belongs to at least one type of data.
[0014] Optionally, the second storage node is any storage node among the MN storage nodes; in the case where the second storage node belongs to the part of the storage nodes that perform encryption, the second storage node is configured to: encrypt the ciphertext or plaintext data received from the previous hop storage node again to obtain the ciphertext data, and send the ciphertext data to the next hop storage node or security gateway of the second storage node in the first topology relationship; in the case where the second storage node does not belong to the part of the storage nodes that perform encryption, the second storage node is configured to: package the ciphertext or plaintext data received from the previous hop storage node and send it to the next hop storage node or security gateway of the second storage node in the first topology relationship; wherein, the ciphertext or plaintext data belongs to at least one type of data.
[0015] Optionally, the data management device decrypts the data ciphertext information to obtain at least one type of plaintext data, including: the data management device decrypts the data ciphertext information according to the data encryption policy to obtain at least one type of plaintext data.
[0016] In a second aspect, a distributed database node secure communication system is provided, which includes a data management device, the data management device is located in a first trusted domain, the distributed storage nodes are located in a second trusted domain, and the first trusted domain and the second trusted domain are connected via a non-trusted domain communication; the data management device is configured as follows: when it is necessary to analyze at least one type of data, the data management device sends a data acquisition request to N storage nodes in the second trusted domain, the data acquisition request is used to request the provision of at least one type of data, and the at least one type of data is stored in the N storage nodes; the data management device receives data ciphertext information from the second trusted domain; the data management device decrypts the data ciphertext information to obtain at least one type of plaintext data; the data management device analyzes at least one type of plaintext data to obtain a data analysis result.
[0017] The system described in the second aspect is further configured to execute the method described in the first aspect.
[0018] In a third aspect, an electronic device is provided, comprising: a processor and a memory; the memory is used to store a computer program, and when the processor executes the computer program, the electronic device executes the above-mentioned distributed database node secure communication method.
[0019] In one possible design, the big data-based natural capital statistics device described in the third aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used to enable the big data-based natural capital statistics device described in the third aspect to communicate with other big data-based natural capital statistics devices.
[0020] In a fourth aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer is caused to execute the above-mentioned distributed database node secure communication method.
[0021] In summary, the above method and system have the following technical effects: When a first trusted domain and a second trusted domain are connected via a non-trusted domain communication link, if a data management device in the first trusted domain wishes to read data from N storage nodes in the second trusted domain, the data management device sends a data acquisition request to the N storage nodes in the second trusted domain, requesting at least one type of data, thereby receiving ciphertext data from the second trusted domain. The data management device can then decrypt the ciphertext data to obtain at least one type of plaintext data, and then analyze the at least one type of plaintext data to obtain a data analysis result. In other words, during the data transfer process, the data passing through the non-trusted domain is encrypted ciphertext data, thereby ensuring data security when the data read from the trusted domain is transferred to the non-trusted domain. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 A schematic diagram of the structure of a communication system provided in an embodiment of the present application; Figure 2 A schematic diagram of a process for secure communication between distributed database nodes according to an embodiment of the present application; Figure 3 A schematic diagram of an application scenario of the distributed database node secure communication method provided in an embodiment of the present application; Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0023] Additionally, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as an "exemplary" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.
[0024] First, in this application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing a certain "information" as being used to indicate A, it can include whether the information directly indicates A or indirectly indicates A, but it does not necessarily mean that the information contains A.
[0025] The information indicated by a message is called the information to be indicated. During implementation, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be indicated directly, such as the information to be indicated itself or an index of the information to be indicated. Alternatively, the information to be indicated can be indicated indirectly by indicating other information, where the other information is associated with the information to be indicated. Alternatively, only a portion of the information to be indicated can be indicated, while the remaining portion is known or agreed upon in advance. For example, a pre-agreed (e.g., protocol-specified) order of information can be used to indicate specific information, thereby reducing indication overhead to a certain extent. Furthermore, common portions of various information can be identified and indicated uniformly, reducing the indication overhead associated with separately indicating the same information. Furthermore, the specific indication method can include various existing indication methods, such as, but not limited to, the aforementioned indication methods and various combinations thereof. The specific details of various indication methods can be referenced in the prior art and will not be elaborated upon herein. As can be seen from the foregoing, for example, when multiple pieces of information of the same type need to be indicated, different indication methods may be used for different pieces of information. During the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood as covering various methods that can enable the party to be indicated to obtain the information to be indicated.
[0026] Second, in the embodiments shown below, the first, second, and various numerical numbers are only used for the convenience of description and are not intended to limit the scope of the embodiments of the present application.
[0027] Third, “pre-set”, or “pre-defined”, or “pre-configured” can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in a device (for example, including a terminal device and a network device), or can be pre-specified in a protocol. This application does not limit its specific implementation method. Among them, “saving” can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, which is not limited by this application.
[0028] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0029] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0030] To facilitate understanding of the embodiments of the present application, first Figure 1 The communication system shown in FIG is used as an example to describe in detail the communication system applicable to the embodiment of the present application. Figure 1 A schematic diagram of the architecture of a communication system applicable to the method provided in an embodiment of the present application.
[0031] Figure 1 This is a schematic diagram of the architecture of a communication system, which mainly includes: data management equipment and distributed storage nodes.
[0032] The data management device can be a network device, such as a network element within the core network of a carrier network, such as the Network Data Analysis Function (NWDAF). The core network of the carrier network is a trusted network and is therefore referred to as the first trusted domain. The data management device is located in the first trusted domain. Communication between network elements / devices within the first trusted domain is considered secure.
[0033] Distributed storage nodes can be storage nodes in a distributed database. The distributed database can be a partitioned database, a replicated database, a distributed database system, etc., without limitation. A distributed database is also a trusted local area network and can therefore be referred to as a second trusted domain, i.e., the distributed storage nodes are located in the second trusted domain. The first trusted domain and the second trusted domain are connected via an untrusted domain. The untrusted domain can be a third-party network, meaning its security risks cannot be managed by the first and second trusted domains and is therefore considered an untrusted domain.
[0034] A storage node can be a terminal, such as a server or storage device. In a broad sense, a terminal can also be considered a terminal with data storage capabilities, or a chip or chip system installed in the terminal, or a device including the terminal. The terminal can also be called user equipment (UE), access terminal, subscriber unit (subscriber unit), subscriber station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. The terminal in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart home device (for example, a refrigerator, a television, an air conditioner, an electric meter, etc.), an intelligent robot, a robotic arm, workshop equipment, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, and a wireless terminal in a smart home.
[0035] For example, Figure 2 This is a flow chart of a distributed database node secure communication method provided in an embodiment of the present application. Figure 2 As shown, the process of the distributed database node secure communication method is as follows: S201: When at least one type of data needs to be analyzed, the data management device sends a data acquisition request to N storage nodes in a second trusted domain.
[0036] For example, before the data management device sends a data acquisition request to the N storage nodes in the second trusted domain, the method further includes: the data management device receives a data analysis request from a third-party application, the data management request requesting the data analysis device to analyze at least one type of data.
[0037] S202: The data management device receives encrypted data information from the second trusted domain.
[0038] The data acquisition request is used to request at least one type of data. The at least one type of data is stored in N storage nodes, where N is an integer greater than 1. The at least one type of data may include user data such as video, audio, games, and pictures. The data ciphertext information is information encrypted by some of the M storage nodes in the first trusted domain. The encryption of some of the storage nodes is instructed by the data management device. M is an integer greater than N. The M storage nodes include N storage nodes, and the M storage nodes also include MN storage nodes other than the N storage nodes. The MN storage nodes are used to forward the at least one type of data.
[0039] For example, in the case where at least one type of data needs to be analyzed, the method further includes: The data management device determines N storage nodes in the second trusted domain where at least one type of data is distributed and stored. For example, the data management device is preconfigured with which storage nodes in the second trusted domain each type of data is stored, thereby being able to determine the N storage nodes in which the at least one type of data is distributed and stored based on the type of the at least one type of data.
[0040] The data management device may determine a first topological relationship based on a topological relationship between storage nodes in the second trusted domain. The storage nodes in the first topological relationship are M storage nodes, and the first topological relationship indicates a routing path for data stored by the N storage nodes to be sent to a security gateway of the first trusted domain via the M storage nodes. The first trusted domain and the second trusted domain being connected via non-trusted domain communication includes: the data management device being connected to the security gateway via non-trusted domain communication.
[0041] Accordingly, the data acquisition request includes data routing information of each of the N storage nodes in the first topological relationship. For example, for the i-th storage node among the N storage nodes, where i is any integer from 1 to N, if the i-th storage node has a previous-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes information about the sending port of the previous-hop storage node (such as a port number, address, etc., used to identify data from the previous-hop storage node); if the i-th storage node has a next-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes information about the receiving port of the next-hop storage node (such as a port number, address, etc., used to indicate that only the data of the storage node needs to be sent by the next-hop storage node); or if the i-th storage node does not have a next-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes information about the receiving port of the security gateway (such as a port number, address, etc., used to indicate that only the data of the storage node needs to be sent by the next-hop storage node).
[0042] On this basis, the method also includes: The data management device determines the data encryption strategy based on the first topological relationship. Accordingly, the data acquisition request also includes the data encryption strategy, which indicates that some of the above-mentioned storage nodes need to perform encryption, that is, indicates which storage nodes among the M storage nodes are the nodes that need to perform encryption.
[0043] For example, the first topological relationship is a topological relationship of a tree-like branch structure, in which a storage node that serves as a root node in the tree-like branch structure among M storage nodes is connected to a security gateway, the tree-like branch structure includes multiple branches, and N storage nodes are distributed on the multiple branches. The data encryption policy indicates that the first type of storage nodes among the M storage nodes need to perform encryption, and the second type of storage nodes among the M storage nodes do not need to perform encryption. Among them, the second type of storage node is a storage node that serves as the root node of at least two of the multiple branches, and the first type of storage node is other storage nodes among the M storage nodes except the second type of storage node. Any storage node among the M storage nodes is used to determine whether it belongs to the first type of storage node or the second type of storage node based on its own data routing information in the first topological relationship. That is, if the storage node has two or more previous-hop storage nodes, then the storage node is a second type of storage node, otherwise it is a first type of storage node.
[0044] Therefore, taking the first storage node as an example, the first storage node is any storage node among the N storage nodes.
[0045] In the case where the first storage node belongs to a partial storage node that performs encryption, if the first storage node has a previous-hop storage node in the first topological relationship, the first storage node is configured to: encrypt the ciphertext or plaintext data received from the previous-hop storage node together with the plaintext data provided by the first storage node itself to obtain the ciphertext data, and send the ciphertext data to the next-hop storage node or security gateway of the first storage node in the first topological relationship.
[0046] In the case where the first storage node belongs to a partial storage node that performs encryption, if the first storage node does not have a previous-hop storage node in the first topological relationship, the first storage node is configured to: encrypt the plaintext data provided by the first storage node itself to obtain ciphertext data, and send the ciphertext data to the next-hop storage node or security gateway of the first storage node in the first topological relationship.
[0047] In the case that the first storage node does not belong to the partial storage nodes that perform encryption, if the first storage node has a previous-hop storage node in the first topological relationship, the first storage node is configured to: package the ciphertext or plaintext data received from the previous-hop storage node and the plaintext data provided by the first storage node itself and send them to the next-hop storage node or security gateway of the first storage node in the first topological relationship.
[0048] In the case that the first storage node does not belong to the partial storage nodes that perform encryption, if the first storage node does not have a previous-hop storage node in the first topological relationship, the first storage node is configured to: send the plaintext data provided by the first storage node itself to the next-hop storage node or security gateway of the first storage node in the first topological relationship.
[0049] The ciphertext or plaintext data belongs to at least one type of data, and the plaintext data provided by the first storage node itself also belongs to at least one type of data.
[0050] Taking the second storage node as an example, the second storage node is any storage node among the MN storage nodes; In a case where the second storage node belongs to a portion of the storage nodes that perform encryption, the second storage node is configured to: re-encrypt the ciphertext or plaintext data received from the previous-hop storage node to obtain ciphertext data, and send the ciphertext data to the next-hop storage node or security gateway of the second storage node in the first topological relationship; In a case where the second storage node does not belong to the part of the storage nodes that perform encryption, the second storage node is configured to: package the ciphertext or plaintext data received from the previous hop storage node and send it to the next hop storage node or security gateway of the second storage node in the first topological relationship; The ciphertext or plaintext data belongs to at least one type of data.
[0051] The above encryption refers to encrypting the payload portion of the message, that is, encrypting at least one type of data, while the header of the message is not processed, so as to achieve message forwarding.
[0052] S203: The data management device decrypts the ciphertext data to obtain at least one type of plaintext data.
[0053] The data management device decrypts the ciphertext data according to the data encryption policy to obtain at least one type of plaintext data. The encryption and decryption described above are symmetric. The data management device shares a key with the M storage nodes, meaning they can use the same key for decryption. Decryption is the inverse of the decryption process described above.
[0054] For easy understanding, such as Figure 3As shown in the example, M storage nodes include storage nodes 1 to 10, and N storage nodes include storage nodes 1, 2, 3, 4, 5, 6, and 7. The storage nodes performing encryption include storage nodes 1, 2, 3, 4, 6, 7, and 9. Storage node 4 obtains data #1, encrypts it using key #1 to obtain ciphertext data #1, and then sends it to storage node 5. Storage node 3 obtains data #2, encrypts it using key #2 to obtain ciphertext data #2, and then sends it to storage node 5. Storage node 5 obtains data #3, encrypts it using key #3 to obtain ciphertext data #3. Storage node 5 then waits to receive data from storage nodes 4 and 3 based on the topological relationship. After receiving ciphertext data #1 and ciphertext data #2, storage node 5 packages ciphertext data #1, ciphertext data #2, and ciphertext data #3 (i.e., encapsulates them in the payload of a message) and sends it to storage node 6. Storage node 6 obtains data #4 and encrypts it using key #4 to obtain ciphertext data #4. Storage node 6 then waits for data from storage node 6 based on the topology. Upon receiving the packaged ciphertext data #1, ciphertext data #2, and ciphertext data #3, storage node 6 packages ciphertext data #1, ciphertext data #2, ciphertext data #3, and ciphertext data #4 (i.e., encapsulates them in the payload of the message) and sends it to storage node 10. Storage node 7 obtains data #5, encrypts it using key #5 to obtain ciphertext data #5, and sends it to storage node 10. Storage node 2 obtains data #6, encrypts it using key #6 to obtain ciphertext data #6, and sends it to storage node 8. Storage node 1 obtains data #7, encrypts it using key #7 to obtain ciphertext data #7, and sends it to storage node 8. Storage node 8 then waits for data from storage nodes 1 and 2 based on the topology. Upon receiving ciphertext data #6 and ciphertext data #7, it packages ciphertext data #6 and ciphertext data #7 and sends them to storage node 9. Storage node 9 will wait to receive data from storage node 8 based on the topological relationship. When it receives the packaged ciphertext data #6 and ciphertext data #7, it will forward the packaged ciphertext data #6 and ciphertext data #7 to storage node 10. Storage node 10 will wait to receive data from storage node 6, storage node 7 and storage node 9 based on the topological relationship. When it receives ciphertext data #1 to ciphertext data #7, it will package ciphertext data #1 to ciphertext data #7 and send it to the security gateway. The security gateway will use the root key to encrypt ciphertext data #1 to ciphertext data #7 as a whole, and then send it to the data analysis device. The data analysis device pre-configures the root key and key #1 to key #7, and then performs decryption according to the inverse process of the above encryption to obtain data #1 to data #7.
[0055] It can be understood that in the above process, the root node does not perform encryption, but only aggregates data, thereby reducing the root node load, while non-root nodes usually only perform encryption, which can also reduce the load and achieve relative load balance.
[0056] S204: The data management device analyzes at least one type of plaintext data to obtain a data analysis result.
[0057] By collecting statistics on the time and data volume of each service in the data, the data analysis results can be the user's preferences, such as liking to watch videos, liking to make phone calls, etc.
[0058] Therefore, after the data management device analyzes at least one type of plaintext data and obtains the data analysis result, The data management device may also send a response to the data analysis request to the third-party application, where the response includes the data analysis result.
[0059] In summary, when a first trusted domain and a second trusted domain are connected via a non-trusted domain communication connection, if a data management device in the first trusted domain wishes to read data from N storage nodes in the second trusted domain, the data management device sends a data acquisition request to the N storage nodes in the second trusted domain, requesting at least one type of data, thereby receiving ciphertext data information from the second trusted domain. The data management device can then decrypt the ciphertext data information to obtain at least one type of plaintext data, and then analyze the at least one type of plaintext data to obtain a data analysis result. In other words, during the data transmission process, the data passing through the non-trusted domain is encrypted ciphertext data information, thus ensuring the data security of the data read from the trusted domain to the non-trusted domain.
[0060] Combination of the above Figure 2 The distributed database node secure communication method provided by the embodiment of the present application is described in detail. The following introduces a distributed database node secure communication system that executes the distributed database node secure communication method.
[0061] The system includes a data management device, which is located in a first trusted domain and distributed storage nodes are located in a second trusted domain. The first trusted domain and the second trusted domain are connected via non-trusted domain communication. The data management device is configured as follows: when it is necessary to analyze at least one type of data, the data management device sends a data acquisition request to N storage nodes in the second trusted domain, and the data acquisition request is used to request the provision of at least one type of data, and the at least one type of data is stored in the N storage nodes; the data management device receives data ciphertext information from the second trusted domain; the data management device decrypts the data ciphertext information to obtain at least one type of plaintext data; the data management device analyzes the at least one type of plaintext data to obtain a data analysis result.
[0062] The system is specifically configured to perform the above Figure 2 For the method described, please refer to the relevant introduction of the above method for details.
[0063] For example, Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may be a terminal or a network device, or a chip (system) or other component or assembly that can be provided in a terminal or a network device. Figure 4 As shown, the electronic device 500 may include a processor 501. Optionally, the electronic device 500 may further include a memory 502 and / or a transceiver 503. The processor 501 is coupled to the memory 502 and the transceiver 503, for example, via a communication bus.
[0064] The following combination Figure 4 The components of the electronic device 500 are described in detail. The processor 501 is the control center of the electronic device 500 and can be a single processor or a collective term for multiple processing elements. For example, the processor 501 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (digital signal processors, DSPs) or one or more field programmable gate arrays (FPGAs).
[0065] Optionally, the processor 501 can execute various functions of the electronic device 500 by running or executing the software program stored in the memory 502 and calling the data stored in the memory 502, such as executing the above Figure 3 The distributed database node secure communication method shown.
[0066] In a specific implementation, as an embodiment, the processor 501 may include one or more CPUs, such as Figure 4 CPU0 and CPU1 are shown in FIG.
[0067] In a specific implementation, as an example, the electronic device 1200 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0068] The memory 502 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 501. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0069] Alternatively, the memory 502 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 502 may be integrated with the processor 501 or exist independently and accessed through the interface circuit ( Figure 4 (not shown) is coupled to the processor 501, which is not specifically limited in this embodiment of the present application.
[0070] Transceiver 503 is used for communication with other electronic devices. For example, if electronic device 500 is a terminal, transceiver 503 can be used to communicate with a network device or another terminal device. For another example, if electronic device 500 is a network device, transceiver 503 can be used to communicate with a terminal or another network device.
[0071] Optionally, the transceiver 503 may include a receiver and a transmitter ( Figure 4 The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0072] Optionally, the transceiver 503 may be integrated with the processor 501 or may exist independently and communicate with the electronic device 500 through the interface circuit ( Figure 4 (not shown) is coupled to the processor 501, which is not specifically limited in this embodiment of the present application.
[0073] It should be noted that Figure 4 The structure of the electronic device 500 shown in the figure does not constitute a limitation on the electronic device. The actual electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0074] In addition, the technical effects of the electronic device 500 can refer to the technical effects of the distributed database node secure communication method described in the above method embodiment, and will not be repeated here.
[0075] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), but may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0076] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0077] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in the embodiments of this application are fully or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0078] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0079] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0080] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0081] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0082] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0083] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0084] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0085] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0086] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0087] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A distributed database node secure communication method, characterized in that: Applied to a data management device, the data management device is located in a first trusted domain, the distributed storage nodes are located in a second trusted domain, and the first trusted domain and the second trusted domain are connected via a non-trusted domain communication; the method includes: When at least one type of data needs to be analyzed, the data management device sends a data acquisition request to N storage nodes in the second trusted domain, where the data acquisition request is used to request the at least one type of data to be provided, and the at least one type of data is stored in the N storage nodes, where N is an integer greater than 1; The data management device receives encrypted data information from the second trusted domain; The data management device decrypts the data ciphertext information to obtain the at least one type of plaintext data; The data management device analyzes the at least one type of plaintext data to obtain a data analysis result.
2. The method according to claim 1, characterized in that The data ciphertext information is information encrypted by some of the M storage nodes in the first trusted domain, and the encryption performed by some of the storage nodes is instructed by the data management device, M is an integer greater than N, and the M storage nodes include the N storage nodes, and the M storage nodes also include MN storage nodes other than the N storage nodes, and the MN storage nodes are used to forward at least one type of data.
3. The method according to claim 2, characterized in that In the event that at least one type of data needs to be analyzed, the method further comprises: The data management device determines that the at least one type of data is distributedly stored on N storage nodes in the second trusted domain; The data management device determines a first topological relationship based on a topological relationship between storage nodes in the second trusted domain, the storage nodes in the first topological relationship being the M storage nodes, the first topological relationship indicating a routing path for sending data stored by the N storage nodes to a security gateway of the first trusted domain via the M storage nodes, and the first trusted domain being communicatively connected to the second trusted domain via the non-trusted domain communication including: the data management device being communicatively connected to the security gateway via the non-trusted domain communication; Correspondingly, the data acquisition request includes data routing information of each of the N storage nodes in the first topological relationship.
4. The method according to claim 3, characterized in that For an i-th storage node among the N storage nodes, where i is any integer from 1 to N, if the i-th storage node has a previous-hop storage node in the first topological relationship, then the data routing information of the i-th storage node in the first topological relationship includes information of a sending port of the previous-hop storage node; If the i-th storage node has a next-hop storage node in the first topological relationship, the data routing information of the i-th storage node in the first topological relationship includes the information of the receiving port of the next-hop storage node; or if the i-th storage node does not have a next-hop storage node in the first topological relationship, the data routing information of the i-th storage node in the first topological relationship includes the receiving port information of the security gateway.
5. The method according to claim 3, characterized in that The method further comprises: The data management device determines a data encryption policy based on the first topological relationship. Accordingly, the data acquisition request also includes a data encryption policy, and the data encryption policy indicates that encryption needs to be performed on some storage nodes.
6. The method according to claim 5, characterized in that The first topological relationship is a topological relationship of a tree-like branch structure, a storage node serving as a root node in the tree-like branch structure among the M storage nodes is connected to the security gateway, the tree-like branch structure includes a plurality of branches, and the N storage nodes are distributed on the plurality of branches, and the data encryption policy indicates that a first type of storage nodes among the M storage nodes need to perform encryption, and that a second type of storage nodes among the M storage nodes do not need to perform encryption; Among them, the second-type storage node is a storage node that serves as the root node of at least two of the multiple branches, and the first-type storage node is other storage nodes among the M storage nodes except the second-type storage node. Any storage node among the M storage nodes is used to determine whether it belongs to the first-type storage node or the second-type storage node based on its own data routing information in the first topological relationship.
7. The method according to claim 6, characterized in that The first storage node is any storage node among the N storage nodes; In the case where the first storage node belongs to the part of the storage nodes that perform encryption, if the first storage node has a previous-hop storage node in the first topological relationship, the first storage node is configured to: encrypt the ciphertext or plaintext data received from the previous-hop storage node together with the plaintext data provided by the first storage node itself to obtain ciphertext data, and send the ciphertext data to the next-hop storage node of the first storage node in the first topological relationship or the security gateway; In a case where the first storage node belongs to the part of the storage nodes that perform encryption, if the first storage node does not have a previous-hop storage node in the first topological relationship, the first storage node is configured to: encrypt plaintext data provided by the first storage node itself to obtain ciphertext data, and send the ciphertext data to a next-hop storage node of the first storage node in the first topological relationship or the security gateway; In a case where the first storage node does not belong to the part of the storage nodes that perform encryption, if the first storage node has a previous-hop storage node in the first topological relationship, the first storage node is configured to: package the ciphertext or plaintext data received from the previous-hop storage node and the plaintext data provided by the first storage node itself, and send them to the next-hop storage node of the first storage node in the first topological relationship or the security gateway; In a case where the first storage node does not belong to the part of the storage nodes that perform encryption, if the first storage node does not have a previous-hop storage node in the first topological relationship, the first storage node is configured to: send the plaintext data provided by the first storage node itself to the next-hop storage node of the first storage node in the first topological relationship or the security gateway; The ciphertext or plaintext data belongs to the at least one type of data, and the plaintext data provided by the first storage node itself also belongs to the at least one type of data.
8. The method according to claim 6, characterized in that The second storage node is any storage node among the MN storage nodes; In a case where the second storage node belongs to the part of the storage nodes that perform encryption, the second storage node is configured to: re-encrypt the ciphertext or plaintext data received from the previous-hop storage node to obtain ciphertext data, and send the ciphertext data to the next-hop storage node of the second storage node in the first topological relationship or the security gateway; In a case where the second storage node does not belong to the part of the storage nodes that perform encryption, the second storage node is configured to: package the ciphertext or plaintext data received from the previous-hop storage node and send it to the next-hop storage node of the second storage node in the first topological relationship or the security gateway; The ciphertext or plaintext data belongs to the at least one type of data.
9. The method according to claim 3, characterized in that The data management device decrypts the data ciphertext information to obtain the at least one type of plaintext data, including: The data management device decrypts the data ciphertext information according to the data encryption policy to obtain the at least one type of plaintext data.
10. A distributed database node secure communication system, characterized in that: The system includes a data management device, the data management device is located in a first trusted domain, and the distributed storage nodes are located in a second trusted domain. The first trusted domain and the second trusted domain are connected via a non-trusted domain communication. The data management device is configured to: In a case where at least one type of data needs to be analyzed, the data management device sends a data acquisition request to N storage nodes in the second trusted domain, wherein the data acquisition request is used to request provision of the at least one type of data, and the at least one type of data is stored in the N storage nodes; The data management device receives encrypted data information from the second trusted domain; The data management device decrypts the data ciphertext information to obtain the at least one type of plaintext data; The data management device analyzes the at least one type of plaintext data to obtain a data analysis result.
Citation Information
Patent Citations
Trusted computing system, corresponding attestation method and corresponding devices
CN103856477A
Database operation method and system for private data and storage medium
CN112000979A
Message processing method and device, node, storage medium and computer program product
CN118803062A
Safety protection method based on financial service data
CN119830332A