A dynamic path encryption database management method and system

By identifying the dynamic access paths and key access nodes of the database, a dynamic encryption architecture is constructed, which solves the problem of rigid encryption strategies in existing technologies, achieves high efficiency and improved security in database management, and optimizes the allocation and response capabilities of encrypted resources.

CN120744986BActive Publication Date: 2026-04-14XIAMEN ZHONGKA SCI TECH DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XIAMEN ZHONGKA SCI TECH DEV CO LTD
Filing Date
2025-09-02
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing database management technologies lack the ability to collaboratively determine multi-dimensional dynamic factors, resulting in rigid encryption strategies. This poses a risk of global data exposure after key cracking, and static high-strength encryption increases the computational efficiency of low-frequency data access, making it impossible to dynamically adjust encryption strength based on the real-time usage frequency of data.

Method used

By acquiring the dynamic access path of the target database, identifying key access nodes, dividing access ciphertext units, constructing a dynamic encryption architecture, extracting access load data for security classification and marking, determining access anomalies, dynamically marking risk areas, and formulating encryption optimization strategies, the system can achieve targeted allocation and dynamic adjustment of encryption resources.

Benefits of technology

It improves the efficiency and security of data management in the database, avoids the waste of resources caused by indiscriminate encryption, accurately identifies high-risk load links, and optimizes the database's security response capabilities and the flexibility of the encryption system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744986B_ABST
    Figure CN120744986B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of database management, and discloses a dynamic path encryption database management method and system, which comprises the following steps: firstly, a target database corresponding dynamic access path is acquired, a key node is identified through encrypted analysis, and a dynamic encryption architecture is constructed; secondly, access load data is extracted, a key distribution value is calculated after hierarchical marking, and an access abnormal point is determined; thirdly, a risk area is marked, and security data and a risk threshold value are obtained through analysis; finally, redundant encryption marking is identified, an optimized mark is obtained by matching a privacy standard, and a dynamic path control strategy is formulated. The application can improve the management efficiency of data in a database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a database management method and system with dynamic path encryption, belonging to the field of database management technology. Background Technology

[0002] Database management refers to the systematic organization, storage, maintenance, and access control of data, aiming to ensure data integrity, security, availability, and efficient access. Its core tasks include data modeling, storage optimization, access control, backup and recovery, and performance tuning, and it is widely used in enterprise information systems, cloud computing platforms, and big data analytics.

[0003] Currently, encryption technologies for database management mainly employ static encryption with fixed key distribution (such as AES and RSA) or access control based on a single role (RBAC). These technologies lack the ability to collaboratively determine multi-dimensional dynamic factors (such as user frequency attenuation scores, network attack scenarios, and data sensitivity levels), and their encryption strategies are rigid. For example, they may maintain the original key permissions when abnormal logins are detected, or fail to dynamically adjust the encryption strength based on the real-time usage frequency of data. This leads to the risk of global data exposure after key cracking. In addition, static high-strength encryption will increase the computational efficiency of low-frequency access data. Therefore, a database management method with dynamic path encryption is needed to improve the management efficiency of data in the database. Summary of the Invention

[0004] This invention provides a database management method and system with dynamic path encryption, the main purpose of which is to improve the management efficiency of data in the database.

[0005] To achieve the above objectives, the present invention provides a database management method with dynamic path encryption, comprising:

[0006] Obtain the dynamic access path corresponding to the target database, encrypt and parse the dynamic access path to obtain the path encryption feature, and identify the key access nodes in the dynamic access path based on the path encryption feature.

[0007] Based on the key access node, the access ciphertext in the dynamic access path is identified, and the access ciphertext is divided into segmented ciphertext units corresponding to the access ciphertext. Based on the segmented ciphertext units, a dynamic encryption architecture corresponding to the target database is constructed.

[0008] Extract access load data from the dynamic encryption architecture, and mark the access load data with security classification to obtain a hierarchical security queue. Calculate the key allocation value corresponding to the hierarchical security queue, and determine the access anomaly point in the target database based on the key allocation value.

[0009] The risk area corresponding to the access anomaly point is determined, and the risk area is dynamically marked to obtain an area encryption label. The area encryption label is then subjected to security analysis to obtain security analysis data, and the risk threshold corresponding to the security analysis data is calculated.

[0010] Based on the risk threshold, redundant encryption markers in the security analysis data are identified, and the redundant encryption markers are optimized and matched with preset privacy protection standards to obtain encryption optimization identifiers. Based on the encryption optimization identifiers, dynamic path control strategies corresponding to the target database are formulated.

[0011] Optionally, identifying key access nodes in the dynamic access path based on the path encryption features includes:

[0012] Parse the access trajectory attribute in the path encryption feature;

[0013] Based on the access trajectory attributes, traverse the node access directories in the pre-built path topology architecture;

[0014] Extract the path access logs from the node's access directory;

[0015] Filter out sensitive entry points in the path access logs;

[0016] Based on the aforementioned sensitive entry points, key access nodes in the dynamic access path are identified.

[0017] Optionally, identifying the access ciphertext in the dynamic access path based on the key access node includes:

[0018] Locate the path segment where the key access node is located;

[0019] Extract the encrypted data stream from the path segments;

[0020] Scan the ciphertext identifiers in the encrypted data stream;

[0021] Query the encryption mode corresponding to the ciphertext identifier;

[0022] Based on the identifier encryption mode, the access ciphertext in the dynamic access path is identified.

[0023] Optionally, constructing the dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units includes:

[0024] Identify the storage location and access level corresponding to the segmented ciphertext unit;

[0025] The storage location and the access level are associated and mapped to generate a ciphertext mapping table;

[0026] Extract the core encryption group from the ciphertext mapping table;

[0027] Dynamically deploy the encryption engine corresponding to the core encryption group;

[0028] Based on the encryption engine, a dynamic encryption architecture corresponding to the target database is constructed.

[0029] Optionally, calculating the key allocation value corresponding to the hierarchical security queue includes:

[0030] Query the queue security index and queue risk index in the hierarchical security queue;

[0031] Analyze the safety sensitivity coefficient and risk amplification coefficient corresponding to the safety index and the risk index;

[0032] Combining the security sensitivity coefficient and the risk amplification coefficient, the key allocation value corresponding to the hierarchical security queue is calculated using the following formula:

[0033]

[0034] in, This represents the key allocation value corresponding to the hierarchical security queue. This represents the total number of elements in the hierarchical security queue. Indicates the index of the number of elements. Represents the security sensitivity coefficient. Indicates the first The security classification score of each element Indicates the first The frequency decay fraction of each element This represents the smoothing constant corresponding to the frequency attenuation fraction. This represents the risk amplification factor. This indicates a cyberattack risk score. This represents the safety fraction offset constant. Indicates the key strength benchmark factor. This represents the frequency attenuation fraction threshold.

[0035] Optionally, determining the access anomaly point in the target database based on the key allocation value includes:

[0036] Parse the access allocation details corresponding to the key allocation value;

[0037] Based on the access allocation details, extract the abnormal access data corresponding to the access unit in the target database;

[0038] Determine the data security baseline corresponding to the abnormal access data;

[0039] Based on the data security baseline, analyze the instantaneous access rate of the data in the target database;

[0040] Based on the instantaneous access rate, access anomalies in the target database are determined.

[0041] Optionally, the step of dynamically marking the risk area to obtain an area encryption label includes:

[0042] Extract abnormal access features from the risk area;

[0043] Analyze the threat fluctuation frequency corresponding to the abnormal access characteristics;

[0044] Divide the risk level ranges corresponding to the frequency of the aforementioned threat fluctuations;

[0045] Statistically analyze the encryption strength parameters within the aforementioned risk level range;

[0046] Based on the encryption strength parameter, the risk area is dynamically marked to obtain an area encryption label.

[0047] Optionally, the step of performing security analysis on the encrypted label of the area to obtain security analysis data includes:

[0048] Extract the tag strength index from the encrypted tags of the region;

[0049] Query the regional vulnerability level corresponding to the tag strength index;

[0050] Match the security protocol standards corresponding to the vulnerability level of the region;

[0051] Based on the aforementioned security protocol standard, security analysis is performed on the encrypted tags of the region to obtain security analysis data.

[0052] Optionally, identifying redundant encryption markers in the security analysis data based on the risk threshold includes:

[0053] Analyze the threshold baseline corresponding to the risk threshold;

[0054] Based on the threshold baseline, the security analysis data is risk-labeled to obtain a labeled dataset;

[0055] Determine the data redundancy domain corresponding to the labeled dataset;

[0056] Extract redundant encryption points from the data redundancy domain;

[0057] Based on the redundant encryption points, redundant encryption markers in the security analysis data are identified.

[0058] To address the above problems, the present invention also provides a database management system with dynamic path encryption, the system comprising:

[0059] The node identification module is used to obtain the dynamic access path corresponding to the target database, and to encrypt and parse the dynamic access path to obtain the path encryption feature. Based on the path encryption feature, the key access nodes in the dynamic access path are identified.

[0060] An architecture building module is used to identify access ciphertext in the dynamic access path based on the key access node, divide the access ciphertext into segmented ciphertext units corresponding to the access ciphertext, and construct the dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units.

[0061] The anomaly detection module is used to extract access load data from the dynamic encryption architecture, mark the access load data with security classification to obtain a hierarchical security queue, calculate the key allocation value corresponding to the hierarchical security queue, and determine access anomalies in the target database based on the key allocation value.

[0062] The threshold calculation module is used to determine the risk area corresponding to the access anomaly point, dynamically mark the risk area to obtain the area encryption label, perform security analysis on the area encryption label to obtain security analysis data, and calculate the risk threshold corresponding to the security analysis data.

[0063] The strategy formulation module is used to identify redundant encryption tags in the security analysis data based on the risk threshold, optimize and match the redundant encryption tags with preset privacy protection standards to obtain encryption optimization identifiers, and formulate dynamic path control strategies corresponding to the target database based on the encryption optimization identifiers.

[0064] Compared to the problems described in the background technology, this invention, by obtaining the dynamic access path corresponding to the target database, can capture the complete link of user-data interaction in real time, providing a precise basis for the dynamic adjustment of subsequent encryption strategies. This helps to achieve targeted allocation of encryption resources, avoids resource waste caused by indiscriminate encryption, and optimizes the security and efficiency of database management from the source. Based on the key access nodes, this invention identifies the access ciphertext in the dynamic access path, accurately locating encrypted data associated with core security links, improving the targeting and efficiency of ciphertext identification; at the same time, it avoids redundant identification of ciphertext unrelated to non-critical nodes, reducing unnecessary computational resource consumption while ensuring the accuracy of data security analysis, and optimizing the overall efficiency of ciphertext management. Furthermore, this invention extracts access load data from the dynamic encryption architecture and performs security classification marking on the access load data to obtain a graded security queue, which can accurately identify high-security queues. In the risk load phase, security resources are tilted towards critical loads, improving the targeting of protection. Simultaneously, through queued management, systematic monitoring of the security status of load data is achieved, facilitating timely detection of potential risks and optimizing the dynamic response capability of database security control. Furthermore, by identifying the risk areas corresponding to the access anomalies and dynamically marking these risk areas to obtain regional encryption tags, this invention can accurately pinpoint database areas with concentrated security risks, quickly identify areas requiring key protection, improve database security response efficiency, and strengthen the targeting and dynamism of the overall security defense system. Finally, based on the risk threshold, this invention identifies redundant encryption tags in the security analysis data. Using threshold quantification standards, it can accurately filter over-encrypted tags, avoiding wasted encryption resources. This can contribute to a lightweight database security architecture, improve the flexibility and response efficiency of the encryption system, and ensure accurate and efficient security protection. Therefore, the dynamic path encryption database management method and system provided by this invention can improve the management efficiency of data in the database. Attached Figure Description

[0065] Figure 1 This is a flowchart illustrating a database management method with dynamic path encryption according to an embodiment of the present invention.

[0066] Figure 2 This is a schematic diagram of the dynamic encryption architecture in a database management method with dynamic path encryption provided in an embodiment of the present invention;

[0067] Figure 3 This is a schematic diagram of a module for implementing a database management system with dynamic path encryption, provided as an embodiment of the present invention.

[0068] The objectives, features, and advantages of this invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0069] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0070] This application provides a database management method with dynamic path encryption. The executing entity of this dynamic path encryption database management method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, the dynamic path encryption database management method can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.

[0071] Reference Figure 1 The diagram shown is a flowchart illustrating a dynamic path encryption database management method according to an embodiment of the present invention. In this embodiment, the dynamic path encryption database management method includes:

[0072] S1. Obtain the dynamic access path corresponding to the target database, and encrypt and parse the dynamic access path to obtain the path encryption feature. Based on the path encryption feature, identify the key access nodes in the dynamic access path.

[0073] This invention, by acquiring the dynamic access path corresponding to the target database, can capture the complete link of user-data interaction in real time, providing a precise basis for the dynamic adjustment of subsequent encryption strategies. This helps to achieve targeted allocation of encryption resources, avoid resource waste caused by indiscriminate encryption, and optimize the security and efficiency of database management from the source.

[0074] The target database refers to a specific database instance that requires dynamic path encryption management. It contains a set of structured data related to the business scenario and is the direct object of dynamic path encryption and other management operations. For example, an e-commerce platform's user transaction database stores 5 million user IDs (e.g., U001-U5000000), transaction amounts (e.g., 100-50000 yuan per transaction), payment times, and other data. Dynamic path encryption is needed to ensure the security of transaction information; this is the target database in this scenario. The dynamic access path refers to the real-time link formed when a user or application accesses the target database, changing with the access scenario. It consists of a series of continuous access nodes. This reflects the complete interactive process of a data request from initiation to response. For example, when a user queries an order through a mobile app, the path can be "mobile terminal → CDN node → Web server → authentication node → database proxy → order data table". However, when an administrator modifies data through the backend, the path becomes "management terminal → firewall → permission verification node → data modification interface → order data table". The two paths change dynamically due to the different access subjects and operation types. Optionally, obtaining the dynamic access path corresponding to the target database can be achieved through database middleware methods, such as using the MyBatis framework to dynamically construct and execute SQL query statements to obtain the dynamic access path.

[0075] Furthermore, by performing encrypted parsing on the dynamic access path, the present invention obtains the path encryption features, which can accurately extract the encryption attributes and interaction patterns of each link in the path, providing data support for subsequent key node identification; it can capture subtle changes in the path encryption status in real time, promptly detect potential encryption vulnerabilities or abnormal tampering, thereby improving the overall encryption effectiveness of database access.

[0076] The path encryption features refer to the set of key information extracted after encrypting and parsing the dynamic access path, reflecting the encryption status and interaction characteristics of the path. This includes dimensions such as encryption algorithm type, key update frequency, encryption transmission strength between nodes, and data encryption segment length. It is the core basis for identifying key access nodes. For example, in a certain access path, node A to node B uses AES-256 encryption (key updated every 30 minutes), with a data encryption segment length of 1024 bytes. Node B to node C uses RSA-2048 encryption (key updated every 2 hours), with an encryption segment length of 512 bytes. These specific parameters together constitute the encryption features of the path. Optionally, the encryption parsing of the dynamic access path can be implemented using an asymmetric encryption algorithm, such as using the RSA algorithm to encrypt the path string with a public key and decrypt it with a private key, thereby obtaining the path encryption features.

[0077] Furthermore, based on the path encryption features, the present invention identifies key access nodes in the dynamic access path, enabling it to focus on weak encryption links or high-risk interaction points and achieve precise allocation of encrypted resources; at the same time, it reduces over-encryption of non-critical nodes, improves overall access efficiency while ensuring core security, and optimizes the targeting and rationality of database encryption management.

[0078] The critical access nodes refer to the core nodes that are identified from the dynamic access path based on sensitive entry points and play a decisive role in data security. These nodes are usually key hubs for the flow of sensitive information or undertake core functions such as encryption key generation and permission verification. Their security status directly affects the security of the entire access path. For example, node K, which is responsible for generating encryption keys, and node L, which receives and verifies user bank card information, are both critical access nodes.

[0079] As an embodiment of the present invention, the step of identifying key access nodes in the dynamic access path based on the path encryption features includes: parsing the access trajectory attributes in the path encryption features; traversing the node access directories in the pre-built path topology based on the access trajectory attributes; extracting path access logs in the node access directories; filtering sensitive entry points in the path access logs; and identifying key access nodes in the dynamic access path based on the sensitive entry points.

[0080] The access trajectory attributes refer to a set of attributes in the path encryption features that reflect the flow pattern of access behavior. These attributes include the jump order of access nodes, the dwell time at each node, the direction of data transmission, and the frequency of interaction. They are crucial for tracing the logic of the access path flow. For example, in a certain access path, the jump interval from node X to node Y is 2 seconds. Node Y stays for 15 seconds before transmitting data to node Z, and this jump pattern occurs 20 times within one hour. All this information constitutes the access trajectory attributes. The pre-built path topology architecture refers to a pre-constructed framework model that reflects the connection relationships and hierarchical structure of each node in the database access path. It includes static basic information such as node type, inter-node association rules, and data transmission channels, providing a reference for parsing dynamic access paths. For example, a pre-constructed four-level structure including "user terminal node → authentication node → data query node → result return node" can be used. The architecture that clearly defines the unidirectional data transmission between nodes is the pre-built path topology. The node access directory refers to an index directory within the pre-built path topology that records basic information and access permissions for each node. It includes the node's unique identifier, function description, allowed user groups, and processable data types, used for quickly locating node-related information. For example, a directory recording "Node ID: N001, Function: Authentication, Allowed Users: Registered Members, Processable Data: Account Password" represents the node's access directory information. The path access log refers to a detailed record stored in the node access directory, documenting the actual access status of each node in the dynamic access path. It includes real-time information such as access time, access subject ID, operation type, data interaction volume, and access results. This is the raw data for analyzing access behavior. For example, a log recording "2025-07-10" would be valid. "08:30:00, Access subject: U12345, Operation: Query, Node: N003, Data interaction volume: 2048 bytes, Result: Success" constitutes a path access log. Sensitive entry points refer to the node locations in the path access log that involve the entry or processing of sensitive information. These nodes directly receive, verify, or transmit private data such as account passwords, ID card numbers, and bank card information, representing high-security-risk links in the access path. For example, in a certain access log, node M receives and verifies a 6-18 digit password entered by the user, and this node processes approximately 5000 password entry requests per hour; this node is a sensitive entry point.

[0081] Furthermore, the parsing of the access trajectory attributes in the encrypted path features can be achieved through time-series pattern mining algorithms, such as using the PrefixSpan algorithm to analyze the time-series features of the encrypted path to obtain the access trajectory attributes; the traversal of the node access directory in the pre-constructed path topology can be achieved through graph traversal algorithms, such as using a depth-first search algorithm to systematically scan the connection relationships in the topology to obtain the node access directory; the extraction of path access logs from the node access directory can be achieved through log parsing techniques, such as using the Logstash tool to collect and transform the structured logs in the directory to obtain the path access logs; the filtering of sensitive entry points in the path access logs can be achieved through rule matching methods, such as using a regular expression engine to identify log entries containing key fields to obtain sensitive entry points; the identification of key access nodes in the dynamic access path can be achieved through network centrality analysis, such as using the PageRank algorithm to calculate the importance score of path nodes to obtain key access nodes.

[0082] S2. Based on the key access node, identify the access ciphertext in the dynamic access path, divide the access ciphertext into segmented ciphertext units, and construct the dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units.

[0083] Based on the key access nodes, this invention identifies access ciphertext in the dynamic access path, accurately locating encrypted data associated with core security links, improving the targeting and efficiency of ciphertext identification; at the same time, it avoids redundant identification of ciphertext unrelated to non-key nodes, ensuring the accuracy of data security analysis while reducing unnecessary consumption of computing resources and optimizing the overall efficiency of ciphertext management.

[0084] The access ciphertext refers to the actual data content that has been encrypted during the interaction of key access nodes in the dynamic access path. It is the encrypted form of core sensitive information involved when a user or system accesses the database. Its decryption depends on the corresponding identifier encryption mode. For example, the string "Xy7$kL9...pQ2" generated after the bank card number "6222****1234" submitted by the user through a key node is encrypted with AES-256 is an access ciphertext.

[0085] As an embodiment of the present invention, the step of identifying access ciphertext in the dynamic access path based on the key access node includes: locating the path segment where the key access node is located; extracting the encrypted data stream in the path segment; scanning the ciphertext identifier in the encrypted data stream; querying the identifier encryption mode corresponding to the ciphertext identifier; and identifying the access ciphertext in the dynamic access path based on the identifier encryption mode.

[0086] The path segmentation refers to a continuous path segment in a dynamic access path, divided by key access nodes. Each segment contains a complete interaction link between the key node and its adjacent nodes, reflecting the data transmission process within a specific node interval. For example, in a dynamic path, key node A forms an interaction chain "B→A→C" with its predecessor node B and subsequent node C, thus dividing the path into two segments: "B to A" and "A to C". Each segment independently records the start and end nodes and duration of data transmission. The encrypted data stream refers to the continuous data sequence transmitted in the path segment that has undergone encryption processing, containing information such as user request instructions, data query results, and node interaction instructions. Its encryption state changes dynamically according to the security requirements of the path segment. For example, in the path segment from "authentication node to data query node", the transmitted data stream containing user ID (encrypted by hash) and query permission token (encrypted by AES) has a transmission volume of approximately 800KB every 10 seconds, which is the encrypted data stream of this segment. The ciphertext identifier refers to the encrypted data stream... Specific symbols or fields used to mark ciphertext attributes include information such as the encryption algorithm type, generation time, and associated data ID. They are important identifiers for distinguishing different ciphertexts. For example, in an encrypted data stream, a piece of ciphertext is marked with the identifier "#AES-256_202507100900_U789#", where "AES-256" represents the encryption algorithm, "202507100900" is the generation time, and "U789" is the associated user ID. This identifier is the ciphertext identifier. The encryption mode of the identifier refers to the set of encryption rules corresponding to the ciphertext identifier. It includes the specific parameters of the encryption algorithm (such as key length and padding method), decryption permission requirements, ciphertext validity period, etc., which determine the encryption strength and usage restrictions of the ciphertext. For example, the mode corresponding to the identifier "#AES-256_202507100900_U789#" is: key length 256 bits, PKCS#7 padding, and only allows user U789 to decrypt within 24 hours. This is the encryption mode of the identifier.

[0087] Furthermore, locating the path segment where the key access node is located can be achieved through network segmentation algorithms, such as using Dijkstra's algorithm to calculate the shortest path interval between key nodes to obtain the path segment; extracting the encrypted data stream in the path segment can be achieved through packet capture technology, such as using Wireshark to capture network transmission data of a specified path segment to obtain the encrypted data stream; scanning the ciphertext identifier in the encrypted data stream can be achieved through pattern recognition methods, such as applying the KMP string matching algorithm to detect specific encrypted header markers in the data stream to obtain the ciphertext identifier; querying the identifier encryption mode corresponding to the ciphertext identifier can be achieved through hash mapping methods, such as quickly retrieving the encryption scheme features corresponding to the identifier based on the SHA-256 hash dictionary to obtain the identifier encryption mode; identifying the access ciphertext in the dynamic access path can be achieved through ciphertext feature extraction technology, such as using the AES encrypted block feature analysis algorithm to locate the encrypted data segment in the path to obtain the access ciphertext.

[0088] This invention, by dividing the access ciphertext into segmented ciphertext units, can decompose complex ciphertext into independent and controllable sub-units, thereby achieving refined and modular encryption management. Targeted encryption strategies can be formulated based on the different security requirements of each unit, avoiding resource waste caused by overall encryption, and thus optimizing the overall control capability of the database encryption system.

[0089] The segmented ciphertext unit refers to an independent encrypted sub-unit formed by disassembling the access ciphertext according to preset rules (such as data sensitivity, encryption algorithm, associated business scenario, etc.). Each unit contains complete ciphertext content, encryption parameters, and associated node information, and can be individually adjusted for encryption strength or security control. For example, an access ciphertext containing a user's ID number (high sensitivity), mobile phone number (medium sensitivity), and registration time (low sensitivity) is split into three segmented ciphertext units: Unit 1 (ID number ciphertext, AES-256 encryption), Unit 2 (mobile phone number ciphertext, AES-128 encryption), and Unit 3 (registration time ciphertext, DES encryption). Each unit can independently update its key and adjust its encryption strategy. Optionally, the segmented ciphertext units corresponding to the access ciphertext can be divided using a block encryption segmentation method, such as using the PKCS#7 padding standard to segment the ciphertext data into 128-bit blocks to obtain segmented ciphertext units.

[0090] Furthermore, based on the segmented ciphertext units, the present invention constructs a dynamic encryption architecture corresponding to the target database, which enables modular deployment of encryption strategies, allowing different ciphertext units to adapt to differentiated encryption strengths as needed, thereby improving the flexibility of the encryption system; encryption parameters can be dynamically adjusted according to the security requirements of each unit, avoiding resource redundancy caused by overall encryption, and balancing security protection and access efficiency.

[0091] The dynamic encryption architecture refers to a framework built on an encryption engine that can adjust encryption strategies in real time based on the storage location, access level, and risk status of segmented ciphertext units. It includes a ciphertext unit management module, an encryption strategy scheduling center, and a risk response interface. For example, this architecture can automatically enable a "key updated every 5 minutes + real-time monitoring of access behavior" mode for core encryption groups, and a "key updated daily + lightweight encryption" mode for lower-level units. Furthermore, it can temporarily increase the encryption strength of the target unit when abnormal access is detected.

[0092] As an embodiment of the present invention, the step of constructing a dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units includes: identifying the storage location and access level corresponding to the segmented ciphertext units; associating and mapping the storage location and the access level to generate a ciphertext mapping table; extracting the core encryption group from the ciphertext mapping table; dynamically deploying the encryption engine corresponding to the core encryption group; and constructing a dynamic encryption architecture corresponding to the target database based on the encryption engine.

[0093] The storage location refers to the actual physical or logical address where the segmented encrypted unit is stored in the target database. It includes information such as the storage server number, disk partition, data table name, and row / column index, used to precisely locate the storage path of the encrypted unit. For example, if a segmented encrypted unit is stored in "rows 1200-1500, column 8 of the user information table (user_info) on the D drive partition of server S05," this address is its storage location and can be directly accessed through the database management system. The access level refers to the access permission level set for the segmented encrypted unit, based on data sensitivity and user... The division of roles and operation types determines the access scope and operation permissions of different subjects to the encrypted units. For example, the segmented encrypted units are divided into four levels: L1 (public), L2 (internal staff), L3 (administrator), and L4 (system level). Among them, the L4 level units only allow system administrators to perform read operations within a specific IP range (such as 192.168.1.0 / 24), and other subjects have no access permissions. The encrypted mapping table is a structured table that records the relationship between the storage location and access level of the segmented encrypted units, including fields such as unit ID, storage address, access level code, and associated node ID. This is used for quickly querying the storage and permission information of encrypted units. For example, a record in the table is "Unit ID: C007, Storage Location: S05-D-user_info[1200-1500,8], Access Level: L3, Associated Node: N004", clearly showing the storage and permission mapping relationship of this unit. The core encryption group refers to the set of segmented encrypted units extracted from the encrypted mapping table that contain high access levels (such as L3, L4) or associated key access nodes. These units directly involve core sensitive data and are the key targets for encryption protection. For example, by filtering access nodes from the mapping table... The core encryption group consists of 150 segmented ciphertext units with an L3 encryption level and associated nodes that are key generation nodes. A higher-strength encryption strategy is required. The encryption engine refers to a software module or hardware component used to perform encryption, decryption, and key management operations on the core encryption group. It includes functions such as an encryption algorithm library, a key generator, and an access verification interface. Encryption parameters can be adjusted dynamically according to requirements. For example, a certain encryption engine integrates AES-256 and RSA-2048 algorithm libraries, supports automatic key updates to the core encryption group every 10 minutes, and verifies access qualifications through an interface linked with the access control system.

[0094] Furthermore, identifying the storage location corresponding to the segmented ciphertext unit can be achieved through metadata indexing methods, such as using a B+ tree index structure to quickly locate the physical address of the ciphertext block in distributed storage, thereby obtaining the storage location; identifying the access level corresponding to the segmented ciphertext unit can be achieved through attribute-based encryption methods, such as applying the CP-ABE algorithm to parse the access policy attribute bound to the ciphertext unit, thereby obtaining the access level; associating and mapping the storage location and the access level can be achieved through hash table mapping methods, such as using a Redis key-value database to establish a bidirectional index relationship between location and level, thereby obtaining a ciphertext mapping table; extracting the core encryption group from the ciphertext mapping table can be achieved through clustering analysis methods, such as using the K-means algorithm to divide key encryption components according to access frequency and security level, thereby obtaining the core encryption group; dynamically deploying the encryption engine corresponding to the core encryption group can be achieved through containerization technology, such as quickly deploying a scalable microservice encryption module based on Docker containers, thereby obtaining the encryption engine; constructing the dynamic encryption architecture corresponding to the target database can be achieved through software-defined security methods, such as using OpenStack security group policies to implement on-demand encryption service orchestration, thereby obtaining the dynamic encryption architecture.

[0095] Specifically, for a more intuitive understanding of the execution logic and data flow relationship of the database dynamic encryption process in this solution, please refer to [link / reference]. Figure 2 ,Should Figure 2 As the core process framework of the database encryption system, it clearly presents the complete link from client data input to encrypted storage and processing: The client side focuses on the pre-encryption processing stage (reading plaintext, hash table partitioning, data smoothing, and data encryption), which is the basic step in building encrypted data; The server side realizes the storage and related query processing of encrypted data through the process of "persistent storage of ciphertext table → ciphertext table connection (including subquery expansion, query rewriting, hash join, etc.) → result filtering". It should be noted that the connection between the links in the framework diagram is essentially an abstract refinement of the dynamic encryption logic of the database. In actual scenarios, the complexity of encryption algorithms (such as different segmented ciphertext units adapting to different encryption engines) and the diversity of process adaptation (different access levels corresponding to different encryption strategy deployments) are far greater than what is shown in the diagram. This architecture is only a concise display of the core logic to provide an intuitive reference for understanding the systematic thinking of dynamic database encryption.

[0096] S3. Extract the access load data from the dynamic encryption architecture, and mark the access load data with security classification to obtain a hierarchical security queue. Calculate the key allocation value corresponding to the hierarchical security queue, and determine the access anomaly point in the target database based on the key allocation value.

[0097] This invention extracts access load data from the dynamic encryption architecture and marks the access load data with security classification to obtain a hierarchical security queue. This can accurately identify high-risk load links, tilt security protection resources toward critical loads, and improve the targeting of protection. At the same time, through queued management, it realizes systematic monitoring of the security status of load data, which facilitates the timely detection of potential risks and optimizes the dynamic response capability of database security management.

[0098] The access load data refers to the set of resource consumption and interaction data related to accessing segmented ciphertext units in a dynamic encryption architecture. It includes indicators such as access request frequency, data transmission volume, encryption / decryption time, concurrent access count, and node resource utilization. It is the basic data for assessing system load pressure and security risks. For example, in a certain dynamic encryption architecture, the core encryption group receives 300 access requests in 1 hour, with an average data transmission volume of 2048 bytes per request, a total encryption processing time of 120 seconds, and a peak concurrent access of 15 times / second. These data together constitute the access load data. The hierarchical security queue refers to an ordered queue formed by marking the access load data according to preset security level standards (such as risk probability and impact scope) and sorting them according to the level. It includes load data entries, security level labels, and associated ciphertext unit information to clarify the priority of security protection. For example, access load data can be divided into four levels: "extremely high (risk probability > 80%), high (50%-80%), medium (30%-50%), and low (< 30%)". Ten extremely high-risk load data entries (e.g., 50 abnormal accesses per minute on a single node) are placed at the top of the queue, followed by 20 high-risk data entries, forming a tiered security queue. Optionally, the extraction of access load data from the dynamic encryption architecture can be achieved using traffic mirroring technology, such as using port mirroring (SPAN) to capture real-time data packets transmitted within the encryption architecture, thereby obtaining the access load data. The security tiering and labeling of the access load data can be achieved using data classification algorithms, such as applying a random forest model to automatically label security levels based on data sensitivity, thus obtaining the tiered security queue.

[0099] Furthermore, by calculating the key allocation value corresponding to the hierarchical security queue, the present invention can match accurate key resources for load data of different security levels, enabling high-risk queues to obtain stronger encryption support, low-risk queues to avoid resource redundancy, and improving the rationality of key allocation; the key parameters can be dynamically adjusted based on the queue level to ensure that the key strength and security requirements are adapted in real time, and to enhance the pertinence of encryption protection.

[0100] The key allocation value refers to the numerical value used to quantify the key allocation requirements of the hierarchical security queue. It comprehensively reflects factors such as the queue's security characteristics, risk level, and frequency decay fraction, and guides the intensity of key resource allocation. For example, if the hierarchical security queue has 5 elements (n=5), the formula calculates MF=8.2, which means that the queue needs to match keys according to this quantification value. If the MF is high, more complex and longer keys will be allocated.

[0101] As an embodiment of the present invention, calculating the key allocation value corresponding to the hierarchical security queue includes:

[0102] Query the queue security index and queue risk index in the hierarchical security queue;

[0103] Analyze the safety sensitivity coefficient and risk amplification coefficient corresponding to the safety index and the risk index;

[0104] The key allocation value corresponding to the hierarchical security queue is calculated by combining the security sensitivity coefficient and the risk amplification coefficient.

[0105] The queue security index refers to a quantitative indicator that measures the overall security level of a tiered security queue by considering the security attributes of each element. It encompasses factors such as security level scores and operational compliance. For example, a tiered security queue with five elements has security level scores of 8, 7, 9, 6, and 8 (out of 10), and all have operational compliance rates exceeding 95%. After weighted calculation, the queue security index is 7.8, reflecting the security posture of data access in this queue. The queue risk index, on the other hand, is an indicator that assesses the degree of security threats faced by a queue based on the risk factors of its elements. It includes abnormal frequency decay scores and correlation with network attacks. For instance, in the aforementioned queue, the frequency decay scores of elements fluctuate greatly (some elements are operated 50 times per day, far exceeding the daily average of 20 times), and the associated network attack risk scores are high. 6 (out of 10), the calculated queue risk index is 6.2, indicating that the queue has certain potential risks. The security sensitivity coefficient is used to measure the security sensitivity of data and operations in a graded security queue. The larger the value, the higher the security requirements and the more stringent the encryption protection. It is preset by the system according to the data type (such as user privacy, transaction data). For example, for a queue processing user bank card information, α is set to 0.8 (α can be set to 0.3 for a regular log queue), reflecting the need for strong encryption for highly sensitive data. The risk amplification coefficient is a coefficient that strengthens the impact of network attack risks on key allocation. The larger the value, the more significant the increase in key allocation value when the network attack risk is high. It is used to highlight the encryption requirements of high-risk scenarios. For example, when the system detects a phishing attack trend... The value was temporarily increased from the default 0.5 to 1.2, allowing for a larger increase in the key allocation value for high-risk queues, thus enhancing protection.

[0106] Furthermore, the querying of the queue safety index in the hierarchical safety queue can be achieved using the analytic hierarchy process (AHP), such as using Expert Choice software to construct a judgment matrix and calculate weight scores to obtain the queue safety index; the querying of the queue risk index in the hierarchical safety queue can be achieved using Monte Carlo simulation, such as using Python's SimPy library to perform risk probability simulation calculations to obtain the queue risk index; the analysis of the safety sensitivity coefficient corresponding to the safety index can be achieved using Pearson correlation analysis, such as using SPSS to calculate the correlation coefficient between safety indicators to obtain the safety sensitivity coefficient; the analysis of the risk amplification coefficient corresponding to the risk index can be achieved using exponential smoothing prediction, such as using the forecast package in R language to perform risk trend analysis to obtain the risk amplification coefficient.

[0107] In another embodiment of the present invention, the key allocation value corresponding to the hierarchical security queue is calculated using the following formula, combining the security sensitivity coefficient and the risk amplification coefficient:

[0108]

[0109] in, This represents the key allocation value corresponding to the hierarchical security queue. This represents the total number of elements in the hierarchical security queue. Indicates the index of the number of elements. Represents the security sensitivity coefficient. Indicates the first The security classification score of each element Indicates the first The frequency decay fraction of each element This represents the smoothing constant corresponding to the frequency attenuation fraction. This represents the risk amplification factor. This indicates a cyberattack risk score. This represents the safety fraction offset constant. Indicates the key strength benchmark factor. This represents the frequency attenuation fraction threshold.

[0110] In detail, the security classification score refers to the score of the first security level in the hierarchical security queue. Each element is assigned a security level score based on dimensions such as data importance and the risk of leakage (e.g., a 1-10 scale). Higher scores indicate higher security priority and encryption requirements. For example, the "user password change operation" element in the queue involves identity authentication. "Access via regular announcement" This reflects differences in security risks; the frequency attenuation fraction refers to the first [number] in the graded security queue. The number of times an element is accessed or manipulated within a unit of time (e.g., 1 hour) reflects the level of data interaction activity and influences the dynamic adjustment of key allocation (high-frequency operations require more flexible key updates). For example, a login verification operation element might be called 500 times in 1 hour. The background configuration read operation is called 20 times per hour. The smoothing constant refers to a small, pre-set constant (e.g., 0.01) used to mitigate the impact of extreme values ​​of the frequency decay fraction (fᵢ) on the formula calculation (e.g., to avoid drastic fluctuations in results when the frequency suddenly increases / decreases). This constant ensures calculation stability. For example, if the frequency decay fraction of a certain element... =0 (extreme case), add Then, in the formula Become To avoid calculation errors caused by the denominator approaching 0; the network attack risk score refers to a quantitative score (e.g., 1-10 points) of the network attack risk faced by the graded security queue based on system security monitoring (such as intrusion detection and abnormal traffic analysis). The higher the score, the greater the risk. For example, if the queue involves a payment interface and high-frequency access from suspicious IPs is detected, r=7 (r can be set to 2 in normal scenarios), triggering a risk-weighted calculation for key allocation; the security score offset constant refers to adjusting the security grade score. The constant used to calculate the baseline is used to correct for biases in the scoring system (such as unifying score ranges and compensating for historical scoring loopholes), ensuring that the formula adapts to different scenarios. For example, if the original security classification scores sᵢ are concentrated between 3 and 7 points, adding δ=2 will change the formula. Become This expands the difference in the calculation range, allowing for more accurate differentiation of security levels; the key strength benchmark factor refers to a factor associated with the basic key strength (such as key length, encryption algorithm complexity), representing the key parameters (such as...) corresponding to a unit of "strength requirement". The larger, the same A stronger key needs to be allocated, which is preset by the system according to the encryption algorithm. For example, when using the AES-256 algorithm, Set to 1.5 (AES-128 algorithm) (Can be set to 1), ensuring that high-security queues match high-strength keys; the frequency attenuation fraction threshold refers to the threshold for determining frequency attenuation fraction. The critical value for whether something is "too high" is used in the formula. To avoid abnormal results due to an excessively small denominator when the frequency attenuation fraction is extremely low, the system uses empirical values ​​set based on business scenarios. For example, during peak business periods, the frequency attenuation fraction is approximately 300 times per hour. Set to 200, if a certain element =150 (lower than) ),but This ensures the stability of the computational logic.

[0111] Furthermore, based on the key allocation value, the present invention determines access anomalies in the target database. By leveraging the quantitative logic of key allocation, it can accurately capture access behaviors that deviate from normal key requirements, making anomaly identification more targeted. The key allocation value can also be used as a dynamic benchmark to monitor changes in access patterns in real time, helping to respond to security threats promptly and improving the accuracy and timeliness of database security protection.

[0112] The access anomaly point refers to the specific time point, operating entity, or functional module in the database access behavior that violates the security policy or deviates from the normal mode by comparing the instantaneous access rate with the data security baseline and combining the characteristics of abnormal access data. It is a risk point that needs to be intercepted and audited. For example, if the instantaneous rate of the "user login" access unit reaches 100 times / second at a certain moment (security baseline ≤ 10 times / second) and the access data contains "brute force password cracking characteristics", the high-frequency access behavior of this time point and this unit is the access anomaly point.

[0113] As an embodiment of the present invention, determining the access anomaly point in the target database based on the key allocation value includes: parsing the access allocation details corresponding to the key allocation value; extracting abnormal access data corresponding to the access unit in the target database based on the access allocation details; determining the data security baseline corresponding to the abnormal access data; analyzing the instantaneous access rate corresponding to the data in the target database based on the data security baseline; and determining the access anomaly point in the target database based on the instantaneous access rate.

[0114] The access allocation details refer to the set of detailed information related to the access resources and permission allocation of the target database obtained after parsing the key allocation value. This includes the key strength, allocation rules, and associated security policies of each access unit, serving as the basis for subsequent analysis of access behavior. For example, after parsing the key allocation value MF=8.2, rules such as "the user login unit is allocated an AES-256 key, updated every 5 minutes; the backend configuration unit is allocated an RSA-2048 key, updated hourly" are obtained, which constitute the access allocation details. The access unit refers to the smallest functional module or data set in the target database that can independently identify and carry access operations, such as the "user login interface," "transaction record query module," and "order details data table." These are the basic objects for classifying access behaviors. For example, in an e-commerce database, "product review submission" (module) and "user address information table" (data table) are both access units, corresponding to user review submission and address query operations, respectively. Abnormal access data refers to operation records that deviate from the normal access pattern (such as frequency, data volume, and permissions) selected from the access behaviors associated with the access allocation details. This includes the abnormal access time, access subject, operation type, and data. Information such as interaction volume is key data for identifying risks. For example, if an access unit normally accesses 10-20 times per minute, but on a certain day there are 100 accesses within one minute (operation type: "batch read user passwords"), the time, subject, and behavior data of these 100 operations are abnormal access data. The data security baseline refers to a set of security thresholds set for the target database access unit based on historical normal access data and security policies. This includes indicators such as access frequency limits, data transmission volume benchmarks, and permission operation boundaries, used to determine whether access behavior is safe and compliant. For example, it could be "user transaction records..." The "Record" access unit has a security baseline: ≤5 accesses per second, ≤10KB of data transmitted per transmission, and batch export is only allowed by administrators; exceeding these limits will be considered abnormal. The instantaneous access rate refers to the number of times the target database access unit is accessed or the frequency of data interaction within a very short time interval (such as 1 second or 100 milliseconds). It is used to capture sudden changes in access behavior and is a core indicator for identifying short-term high-frequency attacks. For example, if the "Product Inventory" access unit is monitored and it is found that it is accessed 20 times per second at a certain moment (normal instantaneous rate ≤3 times / second), then 20 times / second is the instantaneous access rate, triggering an abnormal warning.

[0115] Furthermore, the parsing of the access allocation details corresponding to the key allocation value can be achieved through attribute parsing algorithms, such as using JSON Schema verification technology to parse the key allocation policy document to obtain the access allocation details; the extraction of abnormal access data corresponding to the access units in the target database can be achieved through anomaly detection methods, such as using the Isolation Forest algorithm to identify access records that deviate from the normal pattern to obtain abnormal access data; the determination of the data security baseline corresponding to the abnormal access data can be achieved through statistical modeling methods, such as applying the 3σ principle to calculate the normal fluctuation range of access parameters to obtain the data security baseline; the analysis of the instantaneous access rate corresponding to the data in the target database can be achieved through time series analysis methods, such as using the EWMA exponentially weighted moving average algorithm to calculate the real-time access frequency to obtain the instantaneous access rate; the determination of access anomalies in the target database can be achieved through outlier detection technology, such as using the DBSCAN clustering algorithm to identify spatiotemporal clusters of abnormal access rates to obtain access anomalies.

[0116] S4. Determine the risk area corresponding to the access anomaly point, dynamically mark the risk area to obtain an area encryption label, perform security analysis on the area encryption label to obtain security analysis data, and calculate the risk threshold corresponding to the security analysis data.

[0117] By identifying the risk areas corresponding to the access anomalies, this invention can accurately pinpoint database areas with concentrated security risks, quickly identify areas requiring key protection, improve database security response efficiency, and enhance the pertinence and dynamism of the overall security defense system.

[0118] The risk area refers to a specific data storage or access logic range in the target database that poses a security risk due to access anomalies. It can be a continuous data table partition, a collection of multiple related data tables, or a functional module group divided according to the access path. For example, rows 1000-2000 of the "User Transaction Table" in the database have 200 abnormally high-frequency accesses within 1 hour (normal ≤20 times). These rows and the corresponding partition of the "Transaction Details Table" together constitute a risk area that needs to be monitored and protected. Optionally, the risk area corresponding to the access anomaly can be determined by a spatial clustering algorithm, such as using the OPTICS density clustering method to identify the spatial clustering range of the anomaly, thereby obtaining the risk area.

[0119] Furthermore, by dynamically marking the risk areas, the present invention obtains regional encryption tags, which can pinpoint security weaknesses in the database in real time, making encryption protection more targeted; it can quickly respond to changes in risks and avoid the ineffective consumption of encryption resources; at the same time, it provides accurate regional directions for subsequent security analysis, improving the flexibility and efficiency of overall database security management.

[0120] The aforementioned regional encryption label refers to a dynamic identifier for a risky region that combines risk level ranges and encryption strength parameters. This identifier is used to visually present the encryption status and security protection level of the region, facilitating real-time management. For example, if a risky region is in a high-risk range and uses a 2048-bit RSA key with 10 encryption iterations, its regional encryption label can be set to "High Risk - RSA2048 - 10 Iterations - Real-time Monitoring," clearly indicating its risk level and encryption configuration.

[0121] As an embodiment of the present invention, the step of dynamically marking the risk area to obtain a region encryption label includes: extracting abnormal access features in the risk area; analyzing the threat fluctuation frequency corresponding to the abnormal access features; dividing the risk level intervals corresponding to the threat fluctuation frequency; statistically analyzing the encryption strength parameters in the risk level intervals; and dynamically marking the risk area based on the encryption strength parameters to obtain a region encryption label.

[0122] The abnormal access characteristics refer to key features in a risk area that deviate from normal access patterns, encompassing dimensions such as access time, frequency, permission requests, and data operation types. These characteristics reflect potential security threats. For example, in a certain risk area, a user account initiates 30 unauthorized data download requests during non-working hours (1-5 AM), far exceeding the normal daily average of 5 accesses, and all operations involve batch exporting sensitive data. These are typical abnormal access characteristics. The threat fluctuation frequency refers to the change in the number of threat events (such as abnormal logins, malicious attack attempts, and unauthorized data access) experienced by a risk area within a unit of time, reflecting the activity level and trend of threats. For example, in one hour, a risk area experiences 8 malicious SQL injection attacks in the first 10 minutes, drops to 2 in the middle 20 minutes, and then increases to 15 in the last 30 minutes. Its threat fluctuation frequency shows a "high-low-high" fluctuation, intuitively reflecting the threat's activity level. Dynamic fluctuation status; the risk level range refers to the numerical range of different levels of security risk in a risk area, based on factors such as threat fluctuation frequency and potential impact range, to clarify the severity of the risk. For example, a threat fluctuation frequency of 0-10 times / hour is set as a low-risk range, 11-30 times / hour as a medium-risk range, and 31 times / hour or more as a high-risk range. If the threat fluctuation frequency of a certain risk area is 25 times in 1 hour, then the area is in the medium-risk range. The encryption strength parameter refers to the specific indicator that measures the ability to implement encryption protection for a risk area, including encryption algorithm type, key length, number of encryption iterations, decryption verification complexity, etc. The higher the parameter value, the stronger the encryption protection capability. For example, when using the RSA algorithm, a key length of 1024 bits and 5 encryption iterations are basic parameters, while a key length of 2048 bits and 10 encryption iterations are advanced parameters. The latter encryption strength parameter is significantly higher than the former and can better resist brute-force attacks.

[0123] Furthermore, the extraction of abnormal access features in the risk area can be achieved through machine learning algorithms, such as training access log data using the Isolation Forest model in the Python scikit-learn library to obtain abnormal access features; the analysis of the threat fluctuation frequency corresponding to the abnormal access features can be achieved through time series analysis methods, such as applying the Fast Fourier Transform (FFT) in MATLAB to process event time series to obtain threat fluctuation frequencies; the division of risk level intervals corresponding to the threat fluctuation frequencies can be achieved through clustering algorithms, such as automatically binning frequency values ​​using the K-means algorithm in the Python pandas library to obtain risk level intervals; the statistical analysis of encryption strength parameters in the risk level intervals can be achieved through network packet parsing methods, such as using Wireshark to extract SSL / TLS handshake protocol parameters to obtain encryption strength parameters; and the dynamic labeling of the risk area can be achieved through a real-time labeling system, such as integrating the Kibana dashboard in the ELK Stack to update area status labels to obtain area encryption labels.

[0124] This invention performs security analysis on the encrypted tags of the regions to obtain security analysis data. It can deeply analyze the encryption status and security vulnerabilities of the risk areas reflected by the tags, providing data support for the optimization of encryption strategies. At the same time, by quantifying the changes in the security level of risk areas through data, it provides a basis for dynamically adjusting the allocation of encryption resources and improves the accuracy of database security protection.

[0125] The security analysis data refers to a set of quantitative data reflecting the security status of risky areas, generated after analyzing regional encryption labels based on security protocol standards. It includes the difference between label strength and the standard, vulnerability remediation priority, and suggestions for optimizing encryption measures. For example, some analysis data shows that the label strength index is 12 points lower than the standard (due to the key update frequency not meeting the standard), the vulnerability remediation priority is "medium", and it is recommended to shorten the key update frequency from 10 minutes to 5 minutes, providing specific directions for subsequent protection adjustments.

[0126] As an embodiment of the present invention, the step of performing security analysis on the regional encryption tag to obtain security analysis data includes: extracting the tag strength index from the regional encryption tag; querying the regional vulnerability level corresponding to the tag strength index; matching the security protocol standard corresponding to the regional vulnerability level; and performing security analysis on the regional encryption tag based on the security protocol standard to obtain security analysis data.

[0127] The tag strength index refers to a numerical value extracted from the regional encryption tag that quantifies the strength of the encryption measures corresponding to the tag. It encompasses dimensions such as encryption algorithm complexity, key update frequency, and the integrity of the protection mechanism. A higher value indicates stronger encryption. For example, a regional encryption tag with a strength index of 85 (out of 100) includes 30 points from the AES-256 algorithm, 25 points from the key update every 5 minutes, and 30 points from the real-time monitoring mechanism, comprehensively reflecting a high level of encryption strength. The regional vulnerability level refers to the classification of security vulnerabilities in the risk area corresponding to the tag strength index. It is determined based on vulnerability exploitability, impact scope, and remediation difficulty, and is typically divided into four levels: low, medium, high, and extremely high, used for assessment. The severity of vulnerabilities is assessed. For example, a tag strength index of 85 corresponds to a "medium" vulnerability level, indicating that the area contains vulnerabilities such as unencrypted key transmission logs (moderate exploitability) affecting approximately 5% of data (limited scope), which need to be fixed within 24 hours. The security protocol standard refers to the industry or system-built-in standard that matches the regional vulnerability level and is used to standardize the encryption protection of risky areas. It includes encryption algorithm requirements, key management specifications, vulnerability remediation procedures, etc., and serves as the benchmark for security analysis. For example, the "medium" level regional vulnerability level corresponds to Article 4.2 of the "Financial Database Security Protocol," which requires the use of AES-256 encryption, key updates every 10 minutes, and vulnerability remediation requiring double review, ensuring that the analysis has clear standards to follow.

[0128] Furthermore, the extraction of the tag strength index from the encrypted regional tag can be achieved through frequency domain analysis methods, such as applying Fourier transform to calculate the frequency domain energy distribution characteristics of the watermark signal to obtain the tag strength index; the query of the regional vulnerability level corresponding to the tag strength index can be achieved through vulnerability scoring methods, such as using the CVSS scoring system to map vulnerability severity based on strength values ​​to obtain the regional vulnerability level; the matching of the security protocol standard corresponding to the regional vulnerability level can be achieved through rule engine methods, such as using the Drools rule engine to automatically match vulnerability levels with security protocols to obtain the security protocol standard; and the security analysis of the encrypted regional tag can be achieved through threat modeling methods, such as using the STRIDE threat modeling framework system to evaluate the tag security attributes to obtain security analysis data.

[0129] This invention calculates the risk threshold corresponding to the security analysis data, which can set clear quantitative boundaries for the security status of risk areas, enabling security risk assessment to shift from qualitative to quantitative, improving the objectivity and accuracy of the assessment, and providing a quantitative basis for dynamically adjusting protection strategies, ensuring that protection measures are adapted to the actual risk level in real time, and strengthening the scientific and forward-looking nature of database security management.

[0130] The risk threshold refers to a critical value used to quantitatively determine whether the risk corresponding to security analysis data is "too high." When the actual risk indicator exceeds this threshold, a security response (such as encryption upgrade or vulnerability patching) must be triggered. It is the core quantitative basis for risk management. For example, the risk threshold calculated from the security analysis data of a certain database... =7.5. If the actual risk monitoring value is 8.2 (exceeding the threshold), it is determined that the "emergency encryption policy adjustment" process needs to be initiated to block high-risk access.

[0131] In another embodiment of the present invention, the risk threshold corresponding to the security analysis data can be calculated using the following formula:

[0132]

[0133] in, This indicates the risk threshold corresponding to the security analysis data. Indicates the risk sensitivity coefficient. This indicates the total number of security indicators in the security analysis data. Indicates the number of security indicators index. This represents the weight of the i-th security indicator. This represents the quantified value of the i-th security indicator. This represents the baseline mean of safety indicators. The benchmark standard deviation of safety indicators This represents the basic risk offset.

[0134] In detail, the risk sensitivity coefficient refers to the degree to which the risk threshold is sensitive to changes in security indicators. The larger the value, the more significant the impact of security indicator fluctuations on the risk threshold, reflecting the system's tolerance for risk (k takes a large value in high-sensitivity scenarios, such as financial systems; k takes a small value in low-sensitivity scenarios). For example, for a financial transaction database (high sensitivity), k=2.5, and for a general log database (low sensitivity), k=1.2. When the security indicator fluctuates by 10%, the risk threshold of the financial database changes more drastically, requiring a faster response to risk. The security indicators refer to specific dimensional parameters in security analysis data used to measure the security status of the database, such as "number of abnormal accesses," "encryption algorithm strength," and "vulnerability patching delay time," etc. They are the basic elements of risk quantification. For example, a certain security analysis data contains 3 security indicators (m=3): number of abnormal accesses ( =50 times / hour), encryption key length ( =256 bits), number of unpatched vulnerabilities ( =3), collectively describing the security status; the indicator weight refers to the weight coefficient assigned to each security indicator, reflecting the degree of influence of the indicator on the overall security risk (important indicators have higher weights, and secondary indicators have lower weights), which is set by the system according to security policies and business needs, such as the number of abnormal accesses ( =0.6, which has a significant impact), encryption key length ( =0.3, moderate impact), number of unpatched vulnerabilities ( =0.1 (small impact), reflecting the key role of "abnormal access" in risk assessment; the quantified value refers to the specific numerical representation of security indicators, transforming abstract security states (such as "high encryption strength" or "many abnormal accesses") into calculable numbers. For example, the security indicator "encryption algorithm strength" is quantified through algorithm complexity: AES-128 corresponds to... =60, AES-256 corresponds to =90, a higher value indicates stronger encryption; the baseline average refers to the historical average value of the security indicator under "normal security conditions," serving as a benchmark for judging whether the current indicator is abnormal. It is derived by the system through long-term security data statistics. For example, the "abnormal access count" indicator, under normal conditions over the past 3 months, averaged 10 accesses per hour. =10. If the current... If the value is 50, it deviates significantly from the benchmark, indicating a risk. The benchmark standard deviation refers to the statistical value of the fluctuation range of the safety indicator under "normal safety conditions," reflecting the historical stability of the indicator. The larger the value, the wider the normal fluctuation range of the indicator; The smaller the value, the more stable the indicator; for example, the baseline average of "abnormal access counts". =10, the baseline standard deviation σ=3, then the normal fluctuation range is approximately 7-13 times / hour (μ±σ). If the current =50, far exceeding the fluctuation range, is judged as abnormal; the basic risk offset refers to the basic offset value used to correct the risk threshold, reflecting the system's default "basic risk level" (such as hardware vulnerabilities, residual risks from historical attacks), ensuring that the threshold calculation covers inherent risks. For example, the database has inherent risks due to outdated hardware, β=1.5, even if all security indicators are normal (the summation term in the formula is 0), the risk threshold... This preserves the space for managing basic risks.

[0135] S5. Based on the risk threshold, identify redundant encryption markers in the security analysis data, optimize and match the redundant encryption markers with preset privacy protection standards to obtain encryption optimization identifiers, and formulate dynamic path control strategies corresponding to the target database based on the encryption optimization identifiers.

[0136] Based on the aforementioned risk threshold, this invention identifies redundant encryption markers in the security analysis data. By leveraging threshold quantification standards, it can accurately filter out over-encrypted markers, avoiding waste of encryption resources. This can help to lightweight database security architecture, improve the flexibility and response efficiency of the encryption system, and ensure accurate and efficient security protection.

[0137] The redundant encryption tag refers to the tag information extracted from the tag dataset based on redundant encryption points, which identifies that the database has excessive encryption. It includes the location of redundant encryption, encryption strength, and reasons for risk mismatch, and is used to guide the optimization of encryption strategy. For example, after identifying "user log table - log query operation" as a redundant encryption point, a tag is generated: "Redundant encryption tag: location (log query interface), encryption strength (double high-level algorithm), reason (low risk level but excessive encryption)", so that the system can adjust the encryption configuration.

[0138] As an embodiment of the present invention, the step of identifying redundant encryption markers in the security analysis data based on the risk threshold includes: analyzing the threshold baseline corresponding to the risk threshold; performing risk marking on the security analysis data based on the threshold baseline to obtain a marked dataset; determining the data redundancy domain corresponding to the marked dataset; extracting redundant encryption points in the data redundancy domain; and identifying redundant encryption markers in the security analysis data based on the redundant encryption points.

[0139] The threshold baseline refers to the threshold based on the risk threshold ( The generated critical reference line, used to determine the risk level of security analysis data, covers the risk assessment range of security indicators, encryption strength adaptation standards, etc., and clarifies the quantitative boundary of "security-risk", such as risk threshold. =7.5, corresponding to a threshold baseline of "abnormal access count > 30 times / hour or encryption vulnerability level ≥ medium" to be considered risky. In a certain security analysis data, abnormal access counts reached 40 times / hour, triggering the risk assessment of the baseline. The labeled dataset refers to the dataset obtained after risk labeling of security analysis data according to the threshold baseline, containing "security / risk" labels, indicator quantification values, and labeling rule associations. It is the basic data set for subsequent screening of redundant encryption. For example, security analysis data contains 5 indicators, and after being labeled according to the threshold baseline, the dataset generated is: {"abnormal access count": 40 (risk label), "encryption strength": 256 (security label), ...} The system clearly distinguishes the risk status of each indicator. The data redundancy domain refers to a set of indicators or areas in the marked dataset where the security protection does not match the actual risk due to over-configuration of encryption strategies (such as repeated encryption, high-level encryption covering low-risk areas). This reflects the ineffective investment of encryption resources. For example, the marked dataset shows that the "User Log Table" area has been encrypted with AES-256 (high level), but the risk is marked as "low" (abnormal access < 5 times / hour). This area and the associated encryption indicators constitute the data redundancy domain. The redundant encryption point refers to the smallest unit in the data redundancy domain where there is over-encryption. It can be accurately located to a certain piece of data, a certain operation, or a certain encryption parameter. It is the "specific risk point" of redundant encryption. For example, in the data redundancy domain of the "User Log Table", it is found that the "log query operation" is repeatedly encrypted (both AES-256 and RSA-2048 are enabled at the same time), and the risk is marked as "low". This "repeatedly encrypted query operation" is the redundant encryption point.

[0140] Furthermore, the threshold baseline corresponding to the risk threshold can be obtained through statistical quantile methods, such as calculating the normal fluctuation range of risk values ​​using box plot quartiles to obtain the threshold baseline; the risk labeling of the security analysis data can be achieved through supervised learning methods, such as automatically labeling data categories based on risk features using an SVM classifier to obtain a labeled dataset; the determination of the data redundancy domain corresponding to the labeled dataset can be achieved through principal component analysis methods, such as using PCA dimensionality reduction technology to identify highly correlated feature dimensions in the dataset to obtain the data redundancy domain; the extraction of redundant encryption points in the data redundancy domain can be achieved through pattern matching methods, such as matching repeating feature sequences in encrypted data based on regular expressions to obtain redundant encryption points; the identification of redundant encryption tags in the security analysis data can be achieved through feature hashing methods, such as using the SimHash algorithm to detect repeating tags with similar encryption features to obtain redundant encryption tags.

[0141] This invention optimizes and matches the redundant encryption markers with preset privacy protection standards to obtain an encryption optimization identifier. By leveraging standard specifications for redundant encryption processing, the encryption strategy can meet privacy requirements while avoiding resource waste. It can provide clear guidance for subsequent encryption strategy iterations and help build a more efficient and compliant database security protection system.

[0142] The preset privacy protection standard refers to a set of rules predefined by the database system to regulate data encryption and privacy protection. It covers encryption strength requirements, key management specifications, and access restrictions for different data types (such as user privacy and transaction data), ensuring data privacy compliance. For example, for user ID number data, the standard stipulates that AES-256 encryption must be used, the key must be updated every 2 hours, and access is limited to authorized administrators (≤5 people), ensuring that privacy data protection meets security and compliance requirements. The encryption optimization identifier refers to an identifier generated by matching redundant encryption tags with the preset privacy protection standard, used to indicate the direction of encryption strategy optimization, including those requiring adjustment. The system is guided to accurately optimize encryption configurations by specifying the encryption area, target encryption strength, and standard clauses for optimization. For example, after matching a redundant encryption tag, an identifier is generated: "Optimization area: user log query module; target encryption: switch to AES-128 (according to standard clause 3.2, low-sensitivity data is suitable for this strength); optimization direction: reduce encryption redundancy, retain basic protection." This clarifies the encryption optimization operation path. Optionally, the optimization matching of the redundant encryption tag with the preset privacy protection standard can be achieved through similarity calculation methods, such as using a cosine similarity algorithm to measure the feature matching degree between the encryption tag and the standard clause, thereby obtaining the encryption optimization identifier.

[0143] Furthermore, based on the encryption optimization identifier, the present invention formulates a dynamic path control strategy corresponding to the target database, which enables the control path to be accurately matched with the encryption optimization requirements, ensures that resources are tilted towards the core protection path, avoids ineffective control consumption, and can dynamically adjust path permissions and encryption rules according to the identifier, so that the control strategy can be adapted in real time with the data security status, thereby optimizing the effectiveness of the overall protection system.

[0144] The dynamic path control strategy refers to a set of control rules based on encryption optimization identifiers, tailored to the access paths of the target database (such as data transmission links, operation interfaces, and interaction channels between storage nodes), which can be adjusted in real time according to the security status. This includes path permission allocation, encryption algorithm adaptation, and access frequency restrictions. For example, a strategy might stipulate that when the encryption optimization identifier for the "user payment path" is detected as "high risk requiring strengthening," the access permissions for that path are automatically reduced from 10 accounts to 5, the encryption algorithm is upgraded from AES-128 to AES-256, and the access limit per second is reduced from 20 to 10. Simultaneously, a real-time audit node is added to the path to ensure secure and controllable access. Optionally, the dynamic path control strategy corresponding to the target database can be implemented through policy automation methods, such as using the Open Policy Agent framework to define attribute-based access control rules, thereby obtaining the dynamic path control strategy.

[0145] Compared to the problems described in the background technology, this invention, by obtaining the dynamic access path corresponding to the target database, can capture the complete link of user-data interaction in real time, providing a precise basis for the dynamic adjustment of subsequent encryption strategies. This helps to achieve targeted allocation of encryption resources, avoids resource waste caused by indiscriminate encryption, and optimizes the security and efficiency of database management from the source. Based on the key access nodes, this invention identifies the access ciphertext in the dynamic access path, accurately locating encrypted data associated with core security links, improving the targeting and efficiency of ciphertext identification; at the same time, it avoids redundant identification of ciphertext unrelated to non-critical nodes, reducing unnecessary computational resource consumption while ensuring the accuracy of data security analysis, and optimizing the overall efficiency of ciphertext management. Furthermore, this invention extracts access load data from the dynamic encryption architecture and performs security classification marking on the access load data to obtain a graded security queue, which can accurately identify high-security queues. In the risk load phase, security resources are tilted towards critical loads, improving the targeting of protection. Simultaneously, through queued management, systematic monitoring of the security status of load data is achieved, facilitating timely detection of potential risks and optimizing the dynamic response capability of database security control. Furthermore, by identifying the risk areas corresponding to the access anomalies and dynamically marking these risk areas to obtain regional encryption tags, this invention can accurately pinpoint database areas with concentrated security risks, quickly identify areas requiring key protection, improve database security response efficiency, and strengthen the targeting and dynamism of the overall security defense system. Finally, based on the risk threshold, this invention identifies redundant encryption tags in the security analysis data. Using threshold quantification standards, it can accurately filter over-encrypted tags, avoiding wasted encryption resources. This can contribute to a lightweight database security architecture, improve the flexibility and response efficiency of the encryption system, and ensure accurate and efficient security protection. Therefore, the dynamic path encryption database management method and system provided by this invention can improve the management efficiency of data in the database.

[0146] like Figure 3 The diagram shown is a functional block diagram of a dynamic path encryption database management system according to the present invention.

[0147] The dynamic path encryption database management system 200 described in this invention can be installed in an electronic device. Depending on the functions implemented, the dynamic path encryption database management system may include a node identification module 201, an architecture construction module 202, an anomaly point determination module 203, a threshold calculation module 204, and a strategy formulation module 205. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.

[0148] In this embodiment of the invention, the functions of each module / unit are as follows:

[0149] The node identification module 201 is used to obtain the dynamic access path corresponding to the target database, and to encrypt and parse the dynamic access path to obtain the path encryption feature. Based on the path encryption feature, the key access nodes in the dynamic access path are identified.

[0150] The architecture construction module 202 is used to identify access ciphertext in the dynamic access path based on the key access node, divide the access ciphertext into segmented ciphertext units corresponding to the access ciphertext, and construct the dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units.

[0151] The anomaly point determination module 203 is used to extract access load data in the dynamic encryption architecture, mark the access load data with security classification to obtain a hierarchical security queue, calculate the key allocation value corresponding to the hierarchical security queue, and determine the access anomaly point in the target database based on the key allocation value.

[0152] The threshold calculation module 204 is used to determine the risk area corresponding to the access anomaly point, dynamically mark the risk area to obtain an area encryption label, perform security analysis on the area encryption label to obtain security analysis data, and calculate the risk threshold corresponding to the security analysis data.

[0153] The strategy formulation module 205 is used to identify redundant encryption markers in the security analysis data based on the risk threshold, optimize and match the redundant encryption markers with preset privacy protection standards to obtain encryption optimization identifiers, and formulate dynamic path control strategies corresponding to the target database based on the encryption optimization identifiers.

[0154] In detail, the modules in the dynamic path encryption database management system 200 described in this embodiment of the invention employ the same methods as described above. Figure 1 This method uses the same technical means as the dynamic path encryption database management method described above and can produce the same technical effect, so it will not be elaborated here.

[0155] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0156] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. In the above multiple embodiments, each embodiment can be combined with each other or independent. Deleting any one of them will not affect the technical implementation of other embodiments. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A database management method with dynamic path encryption, characterized in that, The method includes: Obtain the dynamic access path corresponding to the target database, encrypt and parse the dynamic access path to obtain the path encryption feature, and identify the key access nodes in the dynamic access path based on the path encryption feature. Based on the key access node, the access ciphertext in the dynamic access path is identified, and the access ciphertext is divided into segmented ciphertext units corresponding to the access ciphertext. Based on the segmented ciphertext units, a dynamic encryption architecture corresponding to the target database is constructed. Extract access load data from the dynamic encryption architecture, and mark the access load data with security classification to obtain a hierarchical security queue. Calculate the key allocation value corresponding to the hierarchical security queue, and determine the access anomaly point in the target database based on the key allocation value. The risk area corresponding to the access anomaly point is determined, and the risk area is dynamically marked to obtain an area encryption label. The area encryption label is then subjected to security analysis to obtain security analysis data, and the risk threshold corresponding to the security analysis data is calculated. Based on the risk threshold, redundant encryption markers in the security analysis data are identified, and the redundant encryption markers are optimized and matched with preset privacy protection standards to obtain encryption optimization identifiers. Based on the encryption optimization identifiers, dynamic path control strategies corresponding to the target database are formulated.

2. The database management method with dynamic path encryption as described in claim 1, characterized in that, The step of identifying key access nodes in the dynamic access path based on the path encryption features includes: Parse the access trajectory attribute in the path encryption feature; Based on the access trajectory attributes, traverse the node access directories in the pre-built path topology architecture; Extract the path access logs from the node's access directory; Filter out sensitive entry points in the path access logs; Based on the aforementioned sensitive entry points, key access nodes in the dynamic access path are identified.

3. The database management method with dynamic path encryption as described in claim 1, characterized in that, The step of identifying access ciphertext in the dynamic access path based on the key access node includes: Locate the path segment where the key access node is located; Extract the encrypted data stream from the path segments; Scan the ciphertext identifiers in the encrypted data stream; Query the encryption mode corresponding to the ciphertext identifier; Based on the identifier encryption mode, the access ciphertext in the dynamic access path is identified.

4. The database management method with dynamic path encryption as described in claim 1, characterized in that, The step of constructing the dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units includes: Identify the storage location and access level corresponding to the segmented ciphertext unit; The storage location and the access level are associated and mapped to generate a ciphertext mapping table; Extract the core encryption group from the ciphertext mapping table; Dynamically deploy the encryption engine corresponding to the core encryption group; Based on the encryption engine, a dynamic encryption architecture corresponding to the target database is constructed.

5. The database management method with dynamic path encryption as described in claim 1, characterized in that, The calculation of the key allocation value corresponding to the hierarchical security queue includes: Query the queue security index and queue risk index in the hierarchical security queue; Analyze the safety sensitivity coefficient and risk amplification coefficient corresponding to the safety index and the risk index; Combining the security sensitivity coefficient and the risk amplification coefficient, the key allocation value corresponding to the hierarchical security queue is calculated using the following formula: in, This represents the key allocation value corresponding to the hierarchical security queue. This represents the total number of elements in the hierarchical security queue. Indicates the index of the number of elements. Represents the security sensitivity coefficient. Indicates the first The security classification score of each element Indicates the first The frequency decay fraction of each element This represents the smoothing constant corresponding to the frequency attenuation fraction. This represents the risk amplification factor. This indicates a cyberattack risk score. This represents the safety fraction offset constant. Indicates the key strength benchmark factor. This represents the frequency attenuation fraction threshold.

6. The database management method with dynamic path encryption as described in claim 1, characterized in that, The step of determining access anomalies in the target database based on the key allocation value includes: Parse the access allocation details corresponding to the key allocation value; Based on the access allocation details, extract the abnormal access data corresponding to the access unit in the target database; Determine the data security baseline corresponding to the abnormal access data; Based on the data security baseline, analyze the instantaneous access rate of the data in the target database; Based on the instantaneous access rate, access anomalies in the target database are determined.

7. The database management method with dynamic path encryption as described in claim 1, characterized in that, The step of dynamically marking the risk area to obtain an encrypted area label includes: Extract abnormal access features from the risk area; Analyze the threat fluctuation frequency corresponding to the abnormal access characteristics; Divide the risk level ranges corresponding to the frequency of the aforementioned threat fluctuations; Statistically analyze the encryption strength parameters within the aforementioned risk level range; Based on the encryption strength parameter, the risk area is dynamically marked to obtain an area encryption label.

8. The database management method with dynamic path encryption as described in claim 1, characterized in that, The security analysis of the encrypted label in the region to obtain security analysis data includes: Extract the tag strength index from the encrypted tags of the region; Query the regional vulnerability level corresponding to the tag strength index; Match the security protocol standards corresponding to the vulnerability level of the region; Based on the aforementioned security protocol standard, security analysis is performed on the encrypted tags of the region to obtain security analysis data.

9. The database management method with dynamic path encryption as described in claim 1, characterized in that, The step of identifying redundant encryption markers in the security analysis data based on the risk threshold includes: Analyze the threshold baseline corresponding to the risk threshold; Based on the threshold baseline, the security analysis data is risk-labeled to obtain a labeled dataset; Determine the data redundancy domain corresponding to the labeled dataset; Extract redundant encryption points from the data redundancy domain; Based on the redundant encryption points, redundant encryption markers in the security analysis data are identified.

10. A database management system with dynamic path encryption, characterized in that, The system includes: The node identification module is used to obtain the dynamic access path corresponding to the target database, encrypt and parse the dynamic access path to obtain the path encryption feature, and identify the key access nodes in the dynamic access path based on the path encryption feature. An architecture building module is used to identify access ciphertext in the dynamic access path based on the key access node, divide the access ciphertext into segmented ciphertext units corresponding to the access ciphertext, and construct a dynamic encryption architecture corresponding to the target database based on the segmented ciphertext units. The anomaly detection module is used to extract access load data from the dynamic encryption architecture, mark the access load data with security classification to obtain a hierarchical security queue, calculate the key allocation value corresponding to the hierarchical security queue, and determine the access anomaly in the target database based on the key allocation value. The threshold calculation module is used to determine the risk area corresponding to the access anomaly point, dynamically mark the risk area to obtain the area encryption label, perform security analysis on the area encryption label to obtain security analysis data, and calculate the risk threshold corresponding to the security analysis data. The strategy formulation module is used to identify redundant encryption markers in the security analysis data based on the risk threshold, optimize and match the redundant encryption markers with preset privacy protection standards to obtain encryption optimization identifiers, and formulate dynamic path control strategies corresponding to the target database based on the encryption optimization identifiers.

Citation Information

Patent Citations

  • A computer software security encryption management system and method

    CN119783142A

  • System and method for secure data transmission and storage

    US20170061138A1