Data isolation security access system and method based on SQL (Structured Query Language) analysis
By using a data isolation and secure access system based on SQL parsing, the high maintenance costs and ambiguous identity recognition issues of network security isolation devices in dynamic IP scenarios are resolved, achieving accurate identification of legitimate access and automated security policy management.
Patent Information
- Application Number
- CN202511632258.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-10
- Publication Date
- 2025-12-05
AI Technical Summary
Existing network security isolation devices are difficult to adapt to dynamic IP scenarios, have high maintenance costs and are unreliable, and result in ambiguous identity recognition and chaotic access control in business systems.
A data isolation and security access system based on SQL parsing is adopted. The system monitors and intercepts database access requests through a proxy component, generates dynamically time-salted encrypted identity authentication information, and performs deep parsing and multi-dimensional identity verification in network security isolation devices.
It reduced business adaptation costs, avoided the risk of IP spoofing, and achieved accurate identification of legitimate access and automated security policy management.
Smart Images

Figure CN121077833A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security access control, in particular to a data isolation security access system and method based on SQL analysis. BACKGROUND
[0002] In the current rapidly developing IT environment, enterprises are accelerating the transformation to cloud-native, microservices and containerized architecture. This transformation brings unprecedented flexibility and elasticity, but also poses serious challenges to traditional IT infrastructure management, especially database access security. In a private cloud or public cloud environment, business systems will be scaled up or down to cope with traffic peaks and valleys. Each time the system is scaled up or restarted, it may be assigned a new, dynamically changing IP address. To achieve high availability and resource optimization, container orchestration platforms frequently migrate containers between different physical nodes. Each migration may change the IP address of the container.
[0003] Existing network security isolation devices usually use IP whitelist mechanisms to restrict database access requests. In the face of the above dynamic IP scenarios, security administrators need to manually update the IP whitelist in real time or use the pass-through IP network segment method. Therefore, the existing technology has the following problems: 1. Maintenance costs skyrocket and business interruption risks: administrators need to manually update the whitelist of network security isolation devices in real time, which not only consumes time and effort, but also easily leads to business interruption due to delayed updates, and is completely unable to adapt to the dynamic environment of a private cloud; 2. IP-based trust model is unreliable: IP addresses are relatively easy to fake at the network layer, and in a multi-tenant private cloud environment, an idle IP may be reused by other tenants, leading to situations where a legitimate IP is used illegally; 3. Business system identity recognition is blurred and permission management is chaotic: the same business system may use different IPs at different times, and different business systems may share the same IP, making IP addresses unable to serve as unique identifiers for business systems, and changes in the roles of business systems cannot be reflected through IP. SUMMARY
[0004] The purpose of the present application is to provide a data isolation security access system and method based on SQL analysis to solve the problems raised in the background.
[0005] To achieve the above purpose, the present application provides the following technical solution: a data isolation security access system based on SQL analysis, comprising a business system, a network security isolation device and a backend database, the business system and the network security isolation device establishing a data connection, and the network security isolation device and the backend database establishing a data connection.
[0006] Preferably, the business system is deployed with an agent component for monitoring database access requests, adding rewritten database access control request data according to security identity authentication configuration.
[0007] Preferably, the network security isolation device comprises a data receiving module, a SQL parsing module, an identity authentication module and a data forwarding module, the data receiving module is used for receiving database access request data sent by the business system, the SQL parsing module is used for parsing a database protocol, the identity authentication module is used for verifying identity authentication information, and the data forwarding module is used for forwarding, to a backend database, the identity authentication information of a database access request meeting an identity authentication condition after the identity authentication information is deleted and restored to original data, and not forwarding the database access request not meeting the identity authentication condition and closing a TCP connection.
[0008] A data isolation security access method based on SQL parsing comprises the following steps: step one, data interception; step two, identity authentication information addition; step three, data receiving and protocol parsing; step four, identity authentication verification; and step five, access request processing.
[0009] In step one, the business system monitors and intercepts database access request TCP communication data sent by the business system through a deployed agent component.
[0010] In step two, the agent component identifies the database type corresponding to the intercepted TCP communication data, generates identity authentication information based on a dynamic time salt encryption algorithm, and inserts the identity authentication information into a non-key data segment of the TCP communication data, and then the business system sends the TCP communication data containing the identity authentication information to the network security isolation device.
[0011] In step three, the network security isolation device receives the TCP communication data containing the identity authentication information, parses the protocol structure of the TCP communication data, and locates the identity authentication information in the non-key data segment.
[0012] In step four, the network security isolation device decodes and decrypts the located identity authentication information, restores original identity information, and performs consistency judgment on the original identity information and a preset verification basis.
[0013] In step five, the network security isolation device processes the database access request TCP communication data according to the consistency judgment result in step four.
[0014] Preferably, in step one, the monitoring adopts an operating system kernel hooking method.
[0015] Preferably, in the step two, the specific method for identifying the database type corresponding to the intercepted TCP communication data is as follows: extracting the destination port in the TCP connection five-tuple corresponding to the TCP communication data, matching the preset database type and port corresponding relationship, and determining the database type.
[0016] Preferably, in the step three, the specific method for analyzing the protocol structure of the TCP communication data is as follows: first, pre-identifying the database service type based on the five-tuple information of the TCP connection, and then performing deep analysis of the protocol according to the database service type, so as to analyze the protocol header, message body and SQL statement field contained in the message body.
[0017] Preferably, in the step five, the specific method for processing the database access request TCP communication data is as follows: if the consistency judgment result is passed, the network security isolation device deletes the identity authentication information in the TCP communication data to restore the original data, and forwards to the rear-end database; if the consistency judgment result is not passed, the network security isolation device does not perform data forwarding, and closes the TCP connection.
[0018] Compared with the prior art, the present application has the following advantages: the present application monitors and intercepts data through the proxy component deployed in the business system, without the need to modify the application layer of the business system, thereby greatly reducing the business adaptation cost; the proxy component generates dynamically time-salted encrypted identity authentication information, thereby avoiding IP forgery and theft risk and adapting to dynamic IP scenarios; the network security isolation device performs deep SQL analysis and multi-dimensional identity verification, accurately identifies the legal access request, prevents illegal database access, and reduces the manual intervention through the automatic authentication and forwarding process, thereby reducing the security policy maintenance cost. BRIEF DESCRIPTION OF DRAWINGS
[0019] Figure 1 The system structure block diagram of the present application is shown in the figure;
[0020] Figure 2 The network security isolation device structure block diagram of the present application is shown in the figure;
[0021] Figure 3 The method step diagram of the present application is shown in the figure;
[0022] Figure 4 The proxy component interception process flowchart of the present application is shown in the figure;
[0023] Figure 5 The proxy component encryption process flowchart of the present application is shown in the figure;
[0024] Figure 6 The network security isolation device decryption process flowchart of the present application is shown in the figure;
[0025] Figure 7 The method flowchart of the present application is shown in the figure.
[0026] In the figure: 1, business system; 11, proxy component; 2, network security isolation device; 21, data receiving module; 22, SQL analysis module; 23, identity authentication module; 24, data forwarding module; 3, backend database. DETAILED DESCRIPTION
[0027] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0028] Please refer to the accompanying Figure 1 -Appendix Figure 2 An embodiment provided by the present application: a data isolation and secure access system based on SQL analysis, comprising a business system 1, a network security isolation device 2 and a backend database 3, the business system 1 establishes a data connection with the network security isolation device 2, the network security isolation device 2 establishes a data connection with the backend database 3, the business system 1 is a client system initiating a database access request, the network security isolation device 2 is the only data channel between the business system 1 and the backend database 3, and integrates data receiving, SQL analysis, identity authentication and data forwarding functions, realizes secure isolation and control of data access, and the backend database 3 is used for receiving original database access requests forwarded by the network security isolation device 2, and provides data storage and query services; the business system 1 is deployed with a proxy component 11, the proxy component 11 is used for monitoring database access requests, adding and rewriting database access control request data according to security identity authentication configuration; the network security isolation device 2 comprises a data receiving module 21, a SQL analysis module 22, an identity authentication module 23 and a data forwarding module 24, the data receiving module 21 is used for receiving database access request data sent by the business system 1, the SQL analysis module 22 is used for analyzing a database protocol, the identity authentication module 23 is used for verifying identity authentication information, and the data forwarding module 24 is used for forwarding, to the backend database 3, the database access request meeting the identity authentication condition after deleting and restoring the identity authentication information to original data according to the verification result of the identity authentication module 23, and not forwarding the database access request not meeting the identity authentication condition, and closing a TCP connection.
[0029] Please refer to the accompanying Figure 3 -Appendix Figure 7 An embodiment provided by the present application: a data isolation and secure access method based on SQL analysis, comprising the following steps: step one, data interception; step two, identity authentication information addition; step three, data receiving and protocol analysis; step four, identity authentication verification; step five, access request processing;
[0030] In the above step one, the business system 1 monitors and intercepts the database access request TCP communication data sent by the business system 1 through the deployed proxy component 11 in the operating system kernel hook mode;
[0031] In the above step two, the proxy component 11 identifies the database type corresponding to the intercepted TCP communication data, matches the preset database type and port corresponding relationship by extracting the destination port in the TCP connection five tuple corresponding to the TCP communication data, thereby determining the database type, generates identity authentication information based on the dynamic time salt encryption algorithm, and inserts it into the non-key data segment of the TCP communication data, and then the business system 1 sends the TCP communication data containing the identity authentication information to the network security isolation device 2;
[0032] In the above step three, the network security isolation device 2 receives the TCP communication data containing the identity authentication information, parses the protocol structure of the TCP communication data, and locates the identity authentication information in the non-key data segment; wherein, the protocol structure of the TCP communication data is parsed as follows: first, the database service type is pre-identified based on the five tuple information of the TCP connection, and then the protocol is deeply parsed according to the database service type, the protocol header, the message body and the SQL statement field contained in the message body are parsed out;
[0033] In the above step four, the network security isolation device 2 decodes and decrypts the located identity authentication information, restores the original identity information, and judges the consistency of the original identity information with the preset verification basis;
[0034] In the above step five, the network security isolation device 2 processes the database access request TCP communication data according to the consistency judgment result in step four, if the consistency judgment result passes, the network security isolation device 2 deletes the identity authentication information in the TCP communication data to restore the original data, and forwards it to the backend database 3; if the consistency judgment result does not pass, the network security isolation device 2 does not forward the data, and closes the TCP connection.
[0035] Based on the above, the advantages of the present application are that when the application is used, the agent component 11 monitors and intercepts the database access request TCP communication data issued by the business system 1 in the operating system kernel hook mode, determines the database type by extracting the destination port in the TCP connection five-tuple corresponding to the TCP communication data, matching the preset database type and port corresponding relationship, generating identity authentication information based on the preset rules, and inserting it into the non-key data segment of the TCP communication data, and then returning the data with the added identity authentication to the operating system kernel. The business system 1 sends the TCP communication data containing the identity authentication information to the network security isolation device 2 according to the original process; the network security isolation device 2 receives the TCP communication data containing the identity authentication information through the data receiving module 21, the SQL analysis module 22 identifies the database service type based on the five-tuple information of the TCP connection, and then performs deep analysis of the protocol according to the database service type, analyzes the protocol header, message body and SQL statement field contained in the message body, and locates the identity authentication information in the non-key data segment, realizes the protocol structure analysis of the TCP communication data, for example, when analyzing the MySQL protocol, first identify the fixed four-byte message header, then determine the byte number of the message body according to the message length field in the message header, and then analyze the message body content and the SQL statement field in it. The SQL analysis module 22 transmits the located identity authentication information to the identity authentication module 23, the identity authentication module 23 decodes and decrypts the identity authentication information to restore the original identity information, and judges the consistency of the original identity information with the preset verification basis, for example, verifies whether the source IP address in the original identity information is consistent with the TCP connection source IP recorded by the data receiving module 21, whether the user identity in the original identity information is consistent with the legal user information pre-stored by the network security isolation device 2, etc. If all the identity information is verified, the identity authentication module 23 triggers the data forwarding module 24, the data forwarding module 24 deletes the identity authentication information in the TCP communication data to restore the original data, and forwards it to the backend database 3; otherwise, the data forwarding module 24 refuses to forward the data, and closes the current TCP connection; wherein the identity verification encryption and decryption algorithm can use the dynamic time salt encryption algorithm, for example, when encrypting the original identity information, the agent component 11 obtains the original identity information, such as the source IP address of the business system 1, the user identity, etc., takes the system time of the current business system 1 as the salt value, combines the salt value with the original identity information and performs encryption operation to obtain the encrypted data, and then converts the encrypted data into an easy-to-identify format through BASE64 encoding; when decrypting the encrypted identity authentication information, first perform BASE64 decoding, and then decrypt the original identity authentication information data based on the current system time.
[0036] It will be apparent to those skilled in the art that the application is not limited to the details of the above-exemplified embodiments and that the present application can be implemented in other particular forms without departing from the spirit or essential characteristics of the present application. The embodiments should therefore be considered in all respects as illustrative and not restrictive, the scope of the application being indicated by the appended claims rather than by the above description, and all changes which come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein. No reference signs in the claims should be considered as limiting the scope of the claims with respect to the figures of the patent document.
Claims
1. A data isolation security access system based on SQL analysis, comprising a business system (1), a network security isolation device (2) and a backend database (3), characterized in that: The business system (1) establishes a data connection with a network security isolation device (2), and the network security isolation device (2) establishes a data connection with a backend database (3).
2. The data isolation security access system based on SQL parsing according to claim 1, characterized in that: The business system (1) is deployed with a proxy component (11) for monitoring database access requests and adding rewritten database access control request data according to security identity authentication configuration.
3. The data isolation security access system based on SQL parsing according to claim 1, characterized in that: The network security isolation device (2) comprises a data receiving module (21), an SQL parsing module (22), an identity authentication module (23) and a data forwarding module (24), the data receiving module (21) is used for receiving database access request data sent by the business system (1), the SQL parsing module (22) is used for parsing a database protocol, the identity authentication module (23) is used for verifying identity authentication information, and the data forwarding module (24) is used for forwarding, to the backend database (3), the identity authentication information deleted and restored to original data after the database access request meeting the identity authentication condition according to the verification result of the identity authentication module (23), and not forwarding the database access request not meeting the identity authentication condition and closing a TCP connection.
4. A data isolation security access method based on SQL parsing, comprising the following steps: step one, data interception; step two, identity authentication information addition; step three, data receiving and protocol parsing; step four, identity authentication verification; and step five, access request processing; characterized in that: In the above step one, the business system (1) monitors and intercepts database access request TCP communication data sent by the business system (1) through the deployed proxy component (11); In the above step two, the proxy component (11) identifies the database type corresponding to the intercepted TCP communication data, generates identity authentication information based on a dynamic time salt encryption algorithm, and inserts the identity authentication information into a non-key data segment of the TCP communication data, and then the business system (1) sends the TCP communication data containing the identity authentication information to the network security isolation device (2); In the above step three, the network security isolation device (2) receives the TCP communication data containing the identity authentication information, parses the protocol structure of the TCP communication data, and locates the identity authentication information in the non-key data segment; In the above step four, the network security isolation device (2) decodes and decrypts the located identity authentication information, restores the original identity information, and performs consistency judgment on the original identity information and a preset verification basis; In the above step five, the network security isolation device (2) processes the database access request TCP communication data according to the consistency judgment result in step four.
5. The method of claim 4, wherein the method is based on SQL parsing. In the above step one, the monitoring adopts an operating system kernel hooking method.
6. The method of claim 4, wherein the method further comprises: In the above step two, the specific method for identifying the database type corresponding to the intercepted TCP communication data is as follows: the destination port in the TCP connection five-tuple corresponding to the TCP communication data is extracted, a preset database type and port correspondence relationship is matched, and thus the database type is determined.
7. The method of claim 4, wherein the method further comprises: In the third step, the protocol structure of the TCP communication data is analyzed, specifically: first, the database service type is pre-identified based on the five-tuple information of the TCP connection, and then the protocol is deeply analyzed according to the database service type to analyze the protocol header, message body and SQL statement field contained in the message body.
8. The method of claim 4, wherein the method further comprises: In the fifth step, the TCP communication data of the database access request is processed, specifically: if the consistency judgment result is passed, the network security isolation device (2) deletes the identity authentication information in the TCP communication data to restore the original data and forwards to the backend database (3); if the consistency judgment result is not passed, the network security isolation device (2) does not forward the data and closes the TCP connection.
Citation Information
Patent Citations
Login verification method and device
CN112699350A
Intranet and extranet docking system and method based on proxy isolation device
CN114143066A
OpenVpn-based cloud edge data trusted communication method and system
CN118694592A