Data tamper-proofing method and device, computer equipment and storage medium
By constructing a dual-table structure of a master table and a shadow table in the database, and combining a verification mechanism of hash digest value and chained hash value, the problem of data tampering in the database system is solved, and real-time monitoring and security enhancement of data are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JINZHUAN INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-01-13
- Publication Date
- 2026-04-21
AI Technical Summary
Existing database systems lack effective anti-tampering capabilities in data storage and management, making it difficult to ensure data integrity and authenticity, and providing insufficient protection against complex attack methods and internal operations.
A dual-table structure of a master table and a shadow table is constructed in the database. Data verification is performed using hash digest values and chained hash values. Combined with an alarm mechanism, data tampering is detected and alarm information is returned when a preset threshold is reached.
It effectively improves the security of business data in the database, ensures the integrity and authenticity of the data, promptly detects and notifies potential tampering, and reduces business risks.
Smart Images

Figure CN121902209A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and specifically to a data anti-tampering method, apparatus, computer equipment, and computer-readable storage medium. Background Technology
[0002] In today's digital age, data has become one of the core assets of enterprises and organizations. With the rapid development of information technology, the storage, management, and use of data have become increasingly complex, while also facing numerous security threats. Among these, data tampering is particularly prominent, potentially leading not only to inconsistencies and errors but also to serious business risks such as financial transaction fraud, errors in medical records, and distortion of government information. Therefore, effectively preventing data tampering and ensuring its integrity and authenticity has become a pressing technical challenge.
[0003] Currently, traditional database systems have achieved remarkable success in data storage and management, but they suffer from significant shortcomings in tamper protection. Most database systems primarily focus on data storage efficiency, query performance, and transaction consistency, while their security measures during data storage and transmission are relatively weak. Although some systems employ basic security mechanisms such as data backup and access control, these measures often prove inadequate against complex attack methods and malicious manipulation by insiders.
[0004] Therefore, how to provide a data anti-tampering method, device, computer equipment, and computer-readable storage medium that can effectively improve the security of business data in the database is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] In view of the shortcomings of the prior art, the purpose of this invention is to provide a data anti-tampering method, apparatus, computer equipment and computer-readable storage medium, aiming to solve the problem of how to effectively improve the security of business data in databases.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a data anti-tampering method, comprising: A master table for business data and a shadow table corresponding to the master table are pre-built in the database. Receive the SQL statement sent by the client for the business data, and process the main data table and the shadow table accordingly based on the SQL statement to obtain the data processing result; In response to a data verification command, the main data table and the shadow table are verified based on the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and the data verification result is obtained. When the data verification result reaches the preset alarm threshold, an alarm message is returned to the client.
[0007] Secondly, the present invention provides a data anti-tampering device, comprising: The construction module is used to pre-build the main data table of business data and the shadow table corresponding to the main data table in the database; The receiving module is used to receive SQL statements sent by the client for the business data, and to process the main data table and the shadow table accordingly based on the SQL statements to obtain the data processing results; The verification module is used to respond to the data verification command, perform data verification on the main data table and the shadow table according to the data processing result, detect whether the data in the main data table and the shadow table has been tampered with, and obtain the data verification result; The alarm module is used to return alarm information to the client when the data verification result reaches a preset alarm threshold.
[0008] Thirdly, the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the data anti-tampering method as described above.
[0009] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the data anti-tampering method described above.
[0010] Compared to existing technologies, this invention provides a data anti-tampering method, apparatus, computer device, and computer-readable storage medium. The method involves pre-constructing a master data table and corresponding shadow tables for business data in a database; receiving SQL statements from a client targeting the business data; processing the master data table and shadow tables according to the SQL statements to obtain data processing results; responding to a data verification command, verifying the data in the master data table and shadow tables based on the data processing results to detect whether the data in the master data table and shadow tables has been tampered with, and obtaining a data verification result; and returning an alarm message to the client when the data verification result reaches a preset alarm threshold. Thus, this invention effectively improves the security of business data in the database. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 This is a schematic diagram illustrating the application environment of a data anti-tampering method provided in an embodiment of the present invention.
[0013] Figure 2 This is a flowchart illustrating a data anti-tampering method according to an embodiment of the present invention.
[0014] Figure 3 This is a schematic diagram of the program modules of a data anti-tampering device provided in an embodiment of the present invention.
[0015] Figure 4 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention.
[0016] Figure 5 This is another structural schematic diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0018] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0019] It should also be understood that the term “and / or” as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0020] As used in this specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once [the described condition or event] is detected," or "in response to detection of [the described condition or event]."
[0021] Furthermore, in the description of this invention and the appended claims, the terms "first," "second," "third," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance.
[0022] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of the invention include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0023] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0024] To illustrate the technical solution of the present invention, specific embodiments are described below.
[0025] An embodiment of the present invention provides a data anti-tampering method, which can be applied to, for example... Figure 1In the application environment shown, the client and server communicate via a network. The client includes, but is not limited to, handheld computers, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud computing devices, and personal digital assistants (PDAs). The server can be a standalone server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0026] Please see Figure 2 An embodiment of the present invention provides a data anti-tampering method, wherein the method includes the following steps: S100. Pre-build a main data table for business data and a shadow table corresponding to the main data table in the database; S200: Receive the SQL statement sent by the client for the business data, and process the main data table and the shadow table accordingly based on the SQL statement to obtain the data processing result; S300. In response to the data verification instruction, perform data verification on the main data table and the shadow table according to the data processing result, detect whether the data in the main data table and the shadow table has been tampered with, and obtain the data verification result; S400. When the data verification result reaches the preset alarm threshold, an alarm message is returned to the client.
[0027] In practical implementation, the data anti-tampering method in this embodiment constructs a dual-table structure of a master data table and a shadow table, and combines it with data verification and alarm mechanisms to effectively protect business data in the database, significantly improving data security. A detailed analysis follows: 1. A two-table structure consisting of a master table and a shadow table: The master table stores the actual business data, supports normal business operations, and ensures the efficient operation of the database system.
[0028] The shadow table stores the hash digest value, operation history information, and chained hash values corresponding to the main data table, used for data integrity and authenticity verification. This dual-table structure separates data storage and verification, which does not affect the performance of the main table and provides additional protection for data security.
[0029] 2. Data verification mechanism: Upon receiving a data verification command, the system verifies the data in the main data table and the shadow table based on the data processing results. By comparing the hash digest values in the main data table with those in the shadow table, and by checking the continuity of the chained hash values in the shadow table, the system can effectively detect whether the data has been tampered with.
[0030] This verification mechanism can not only detect direct data tampering, but also discover anomalies in data operations through chained hash value integrity checks, ensuring data integrity and immutability.
[0031] 3. Alarm mechanism: When the data verification results reach the preset alarm threshold, the system returns an alarm message to the client. The alarm threshold can be flexibly set according to actual business needs, such as the number of abnormal records or the severity of tampering.
[0032] The introduction of an alarm mechanism enables the system to promptly detect and notify target users (such as administrators) of data tampering, facilitating rapid response and handling, thereby further enhancing data security.
[0033] 4. Comprehensive protection capabilities: This method not only provides protection for data storage and verification but also enables real-time monitoring and response to potential tampering through an alarm mechanism. This comprehensive protection capability allows the database system to effectively prevent data tampering and ensure data authenticity and integrity in the face of external attacks and internal operational errors.
[0034] Through the aforementioned technical means, this data anti-tampering method can effectively improve the security of business data in the database, provide reliable protection for the enterprise's core data, and reduce the business risks caused by data tampering.
[0035] Furthermore, in one embodiment, the data anti-tampering method, wherein the pre-construction of a main data table for business data and a shadow table corresponding to the main data table in the database specifically includes: Based on the business requirements of the business data, determine in advance the field structure of the main data table to be built in the database and its corresponding shadow table; Based on the field structure, construct the main data table and the shadow table of the business data in the database.
[0036] In practice, the specific implementation process of this embodiment is roughly as follows: Step 1: Requirements Analysis and Field Planning 1. Analyze business requirements: Collaborate with business departments to gain a deep understanding of business processes and data usage scenarios, and clarify the types, uses, and security requirements of business data.
[0037] Determine which data fields need to be stored in the main data table, and which fields require additional tamper protection.
[0038] Identify key fields, such as amount fields in financial transactions and diagnosis result fields in medical records, as these fields are at high risk of tampering and require special attention.
[0039] 2. Design the field structure of the main data table: Based on business requirements, design the field structure of the main data table, including business data fields and hidden fields used to store hash digests.
[0040] Set primary keys, foreign keys, and indexes for the main data table to optimize query performance.
[0041] Determine the data type, length, and default value of the fields to ensure that the field structure meets the requirements of business logic and data integrity.
[0042] Step 2: Design the field structure of the shadow table 1. Determine the shadow table fields: Design the field structure of the shadow table, including hash digest field, operation history field (such as operation time, operation user, operation type), and chained hash field.
[0043] Add a validity flag field to mark whether the shadow table record is valid, which facilitates the processing of update and delete operations.
[0044] Determine the data type and length of the fields to ensure that the shadow table can store enough information to support data validation and auditing.
[0045] 2. Set the initial records for the shadow table: The initial record is set in the shadow table, and its chain hash value is a preset initial value to ensure that the starting point of the hash chain is clear and secure.
[0046] The initial record can include a timestamp of system initialization and user information, providing a baseline for subsequent data operations.
[0047] Step 3: Build the master table and shadow tables 1. Create the main data table: Create a master data table in the database, and define the table structure according to the designed field structure of the master data table.
[0048] Set constraints for the main data table, such as primary key constraints, unique constraints, and foreign key constraints, to ensure data integrity and consistency.
[0049] Set indexes for key fields to optimize query performance and ensure efficient system operation under high-concurrency read operations.
[0050] 2. Create a shadow table: Create a shadow table in the database and define the table structure according to the field structure of the designed shadow table.
[0051] Set constraints for shadow tables, such as primary key constraints and uniqueness constraints, to ensure the uniqueness and integrity of shadow table records.
[0052] Optimize the performance of data verification operations by setting an index on the chained hash field of the shadow table.
[0053] 3. Initialize the hash chain: After creating the shadow table, the hash chain is initialized by calculating the initial hash value and storing it in the chained hash field of the shadow table, ensuring that the starting point of the hash chain is safe and reliable.
[0054] Ensure that the choice of hash algorithm meets security standards, such as SHA-256, to provide sufficient security.
[0055] By following the steps above, a master data table and shadow tables can be systematically constructed, ensuring that their structure and functions meet business needs and data tamper-proof requirements.
[0056] Furthermore, in one embodiment, the data anti-tampering method, wherein receiving the SQL statement sent by the client for the business data, and processing the main data table and the shadow table accordingly based on the SQL statement to obtain the data processing result, specifically includes: Obtain the SQL statement for the business data input by the target user through the client, and perform format validation and integrity checks on the SQL statement; When both format validation and integrity checks pass, the SQL statement is parsed, and the main data table and the shadow table are processed accordingly based on the parsing results to obtain the data processing results. If the format validation and / or integrity check fails, a prompt message will be returned.
[0057] Furthermore, in the aforementioned data anti-tampering method, when both format validation and integrity checks pass, the content of the SQL statement is parsed, and the main data table and the shadow table are processed accordingly based on the parsing results to obtain the data processing result. Specifically, this includes: If both format validation and integrity checks pass, the SQL statement is parsed to extract the operation type and field information. Based on the extracted operation type and field information, the main data table and the shadow table are processed accordingly to obtain the data processing result.
[0058] In practice, the specific implementation process of this embodiment is roughly as follows: Step 1: Receive and initially process SQL statements 1. Receive SQL statements: Database systems receive SQL statements input by target users through a client interface. The client can be an application, a web interface, or other data manipulation tools.
[0059] Record the time when the SQL statement was received, the source user (such as user ID or IP address), and the operation context information for subsequent auditing and tracing.
[0060] 2. Format validation: Perform syntax validation on the received SQL statements to ensure they conform to SQL syntax rules. Check the completeness of the SQL statement structure and the correct use of keywords, table names, field names, operators, etc.
[0061] This function validates the SQL statement's format against a predefined template, checking for illegal characters or structural errors. If the format validation fails, it returns a format error message, such as "SQL statement format error, please check syntax".
[0062] 3. Integrity check: Perform integrity checks on the SQL statements to ensure that the fields and table names they operate on exist in the database and that the corresponding permissions are available. Verify that the table names and field names involved in the SQL statements match the structure of the main table and shadow tables in the database.
[0063] Check if the operation type (INSERT, UPDATE, DELETE, SELECT) is within the current user's permission scope. If the integrity check fails, return an integrity error message, such as "Table or field does not exist, or the user does not have permission to execute this operation".
[0064] Step 2: Parse the SQL statement 1. Parsing the SQL statement: If both format validation and integrity checks pass, the SQL statement is parsed to extract the operation type (INSERT, UPDATE, DELETE, SELECT) and the field information involved.
[0065] For INSERT operations, extract the inserted data value and target field; for UPDATE operations, extract the update condition, update field, and new value; for DELETE operations, extract the deletion condition; for SELECT operations, extract the query condition and target field.
[0066] 2. Verify the legality of the operation: Based on the extracted operation type and field information, further verify the legality of the operation. For example, check whether the data in an INSERT operation conforms to the data type and constraints of the fields; check whether an UPDATE operation involves tampering with critical fields and whether additional approval processes are required.
[0067] If an operation is found to have potential risks or not comply with business rules, a message indicating an error in the legality of the operation will be returned, such as "The operation does not comply with business rules, please check."
[0068] Step 3: Process the main data table and shadow tables 1. Perform data operations: Based on the parsing results, perform the corresponding data operations (INSERT, UPDATE, DELETE, SELECT) on the main data table. For each operation type, perform the following processing: INSERT operation: Insert a new data record into the main data table.
[0069] Calculate the hash digest value of the inserted data and store the hash digest value in the hash digest field of the main data table.
[0070] A record is appended to the shadow table, storing the hash digest of the inserted data, the operation time, the user performing the operation, the operation type (INSERT), and the chained hash value of the shadow table. The chained hash value is obtained by concatenating the hash digest value of the current record with the chained hash value of the previous record in the shadow table and then recalculating it.
[0071] UPDATE operation: Update the specified data record in the main data table.
[0072] Calculate the hash digest value of the updated data and store the hash digest value in the hash digest field of the main data table.
[0073] Append a record to the shadow table, storing the hash digest values before and after the update, the operation time, the user performing the operation, the operation type (UPDATE), and the chained hash value of the shadow table. Simultaneously, mark the previous record in the shadow table as invalid.
[0074] DELETE operation: Delete the specified data record from the main data table.
[0075] Append a record to the shadow table, storing the hash digest of the deleted data, the operation time, the user performing the operation, the operation type (DELETE), and the chained hash value of the shadow table. Simultaneously, mark the previous record in the shadow table as invalid.
[0076] SELECT operation: Data is read directly from the main data table, and the query results are returned. The query operation does not involve shadow tables to optimize read operation performance.
[0077] 2. Record operation logs: For each type of operation, the system automatically records operation logs, including information such as operation type, operation time, operation user, and operation result. These logs not only provide a basis for subsequent auditing and tracking, but can also be used to analyze system usage and performance bottlenecks.
[0078] Operation logs can be stored in a dedicated log table for later querying and analysis.
[0079] Step 4: Return the data processing results The system returns the data processing results to the client, including indicators of success or failure, and the number of rows affected. If the operation is successful, a success message is returned, such as "Processing successful, affected X rows"; if the processing fails, detailed error information is returned to help the client troubleshoot the problem.
[0080] Through the above steps, the data anti-tampering method can effectively receive and process SQL statements sent by the client, ensuring the legality, security, and consistency of data operations.
[0081] Furthermore, in one embodiment, the data anti-tampering method, wherein responding to a data verification instruction, performing data verification on the main data table and the shadow table based on the data processing result, detecting whether the data in the main data table and the shadow table has been tampered with, and obtaining a data verification result, specifically includes: Receive a data verification request for the business data, parse the content of the data verification request, and extract the data verification instruction, data verification time, and request source. The data verification time and the request source are stored, and based on the data verification instruction, the main data table and the shadow table are verified according to the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, so as to obtain the data verification result of the business data.
[0082] Furthermore, the data anti-tampering method, wherein storing the data verification time and the request source, and performing data verification on the main data table and the shadow table based on the data verification instruction and the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and obtaining the data verification result of the business data, specifically includes: To verify the compliance of the request source, if the request source is an authorized target user or a preset timer, the data verification time and the request source are stored. Based on the data verification instruction, the main data table and the shadow table are verified according to the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and the data verification result of the business data is obtained.
[0083] In practice, the specific implementation process of this embodiment is roughly as follows: Step 1: Receive and parse the data verification request 1. Receive data verification request: The database system receives data verification requests from clients or within the system through pre-defined interfaces. These requests can be triggered manually by the user or automatically by a system timer.
[0084] 2. Parse the request content: The received data verification request is parsed to extract key information, including the data verification instruction, data verification time, and request source (such as user ID, IP address, or system module name).
[0085] Step 2: Verify the compliance of the request source. 1. Verify the request source: Check if the request originates from an authorized target user or a preset timer. The list of authorized users and timer configurations can be predefined in a system configuration file or database.
[0086] If the request originates from an unauthorized user or a pre-defined timer, the request is rejected, and an error message such as "Unauthorized verification request" is returned.
[0087] 2. Record compliance requests: If the request originates from a compliant source, the data verification time and request origin are stored in the system log or a dedicated audit table. These records are used for subsequent auditing and tracing to ensure the traceability of verification requests.
[0088] The stored data verification time and request source can be used to analyze the frequency and source of data verification requests, helping to optimize system configuration and security policies.
[0089] Step 3: Perform data validation 1. Initialize the verification environment: Based on the data validation instructions, determine the scope and type of validation. For example, validate all records in a specific table or data changes within a specific time period.
[0090] Prepare the necessary tools and variables for verification, such as hash algorithm examples and verification result storage structures.
[0091] 2. Perform the verification process: For each record in the main data table, extract its hash digest value and compare it with the hash digest value of the corresponding record in the shadow table.
[0092] Check the continuity of the chained hash values in the shadow table. Verify that the chained hash value of the current record matches the actual stored value by concatenating the hash digest value of the current record with the chained hash value of the previous record and recalculating it.
[0093] Check the operation history information in the shadow table to ensure the completeness and consistency of the operation records. Verify that fields such as operation time, operation user, and operation type conform to logic and preset rules.
[0094] If inconsistent hash digest values, discontinuous chained hash values, or abnormal operation history are found, record detailed exception information, including the ID of the exception record, table name, field name, operation time, and operation user.
[0095] Step 4: Generate a data verification report 1. Summarize and verify information: A data verification report is generated based on the anomaly information recorded in the verification process. The report includes the verification time, verification scope, and verification results (such as "Data is complete and has not been tampered with" or "X records were tampered with," and may also include detailed information on the anomaly records).
[0096] If the verification result is normal, record the confirmation message of successful verification; if an anomaly is detected, record the severity of the anomaly and recommended measures.
[0097] 2. Store verification information: Store data validation reports in system logs or a dedicated audit table for later querying and analysis. Stored data validation reports can be used to assess the system's data security and integrity.
[0098] Through the above steps, the data anti-tampering method can effectively respond to data verification commands, execute detailed verification processes, and generate detailed data verification reports.
[0099] Furthermore, in one embodiment, the data anti-tampering method, wherein returning alarm information to the client when the data verification result reaches a preset alarm threshold, specifically includes: The data verification results are evaluated based on a preset alarm threshold. When the evaluation result indicates that the data verification result reaches the alarm threshold, an alarm message is generated. The alarm information is formatted according to the client's configuration information, and the formatted alarm information is returned to the client.
[0100] In practice, the specific implementation process of this embodiment is roughly as follows: Step 1: Evaluate the data validation results 1. Obtain the data validation results: Obtain data verification results, including the number of abnormal records detected, the type of abnormality (such as inconsistent hash values, discontinuous chained hash values, abnormal operation history, etc.), and detailed information of abnormal records (such as record ID, table name, field name, operation time, operation user, etc.).
[0101] The validation results can be stored in structured data format, such as JSON or XML, for easy subsequent processing.
[0102] 2. Evaluate based on preset alarm thresholds: Read preset alarm thresholds from the system configuration file or database. Alarm thresholds may include: Abnormal record count: An alarm is triggered when the number of detected tampered records exceeds a set value.
[0103] Severity of the anomaly: The severity is assessed based on the type of tampering (e.g., key fields were tampered with) or the scope of the impact (e.g., multiple tables were involved).
[0104] Anomaly frequency: An alarm is triggered when the frequency of anomalies detected within a certain period of time exceeds a set value.
[0105] The data verification results are compared with the preset alarm thresholds to assess whether the alarm conditions have been met.
[0106] Step 2: Generate alarm information 1. Determine the alarm level: Based on the assessment results, determine the alarm level (e.g., low, medium, high). The alarm level can be set according to the severity and scope of the anomaly.
[0107] For example, if a critical field is detected to have been tampered with, the alarm level can be set to "high"; if a non-critical field is detected to have been tampered with, the alarm level can be set to "medium" or "low".
[0108] 2. Generate detailed alarm information: Detailed alarm information is generated based on the assessment results, including: Alarm Time: Records the specific time when the alarm occurred.
[0109] Alarm level: The severity of the alarm.
[0110] Anomaly Details: Describe the detected anomaly in detail, including the specific location of the tampering (table name, field name, record ID), the time of tampering, the user who operated on it, and the type of tampering.
[0111] Recommended actions: Provide suggestions for handling the detected anomalies, such as data recovery and investigating the users involved.
[0112] Step 3: Format alarm information 1. Obtain client configuration information: Retrieve client configuration information from the client's configuration file or database, including alarm message format requirements and notification methods (such as real-time push notifications, emails, SMS messages, etc.).
[0113] The client configuration information can specify the display format, content length, language, etc. of alarm information.
[0114] 2. Formatting process: The generated alarm information is formatted according to the client configuration information. For example: If the client requests to receive alarm information in JSON format, then the alarm information will be converted to JSON format.
[0115] If the client requests that the alarm information be displayed in HTML format, then the alarm information will be converted to HTML format.
[0116] If the client requests to receive alarm information via SMS or email, the alarm information will be converted into the corresponding text format and the necessary title and signature will be added.
[0117] Step 4: Return alarm information 1. Select notification method: Based on the client configuration information, select an appropriate notification method to send the alarm information to the client. Notification methods may include: Real-time push notifications: Alarm information is pushed in real time via client applications or web pages.
[0118] Email notification: Send alert information to the designated administrator email address.
[0119] SMS notification: Sends alert information to the administrator's mobile phone.
[0120] 2. Send alarm information: Send the formatted alarm information to the client via the selected notification method. Ensure that the sending status of the alarm information is logged for subsequent auditing and troubleshooting.
[0121] If the client supports multiple notification methods, it can send alarm messages in multiple formats simultaneously to ensure that administrators receive alarm messages in a timely manner.
[0122] Through the above steps, the data anti-tampering method can effectively evaluate the data verification results, generate detailed alarm information, and format the data according to the client's configuration information to ensure that the alarm information can be notified to the administrator in a timely and accurate manner, thereby effectively improving the security and integrity of business data in the database.
[0123] As can be seen from the above method embodiments, the data anti-tampering method provided by the present invention includes: pre-constructing a main data table for business data and a shadow table corresponding to the main data table in the database; receiving an SQL statement sent by a client for the business data, and processing the main data table and the shadow table accordingly based on the SQL statement to obtain a data processing result; responding to a data verification instruction, performing data verification on the main data table and the shadow table based on the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and obtaining a data verification result; when the data verification result reaches a preset alarm threshold, returning alarm information to the client. Thus, the method of the present invention can effectively improve the security of business data in the database.
[0124] It should be understood that although this application provides the method operation steps as described in the embodiments or flowcharts, conventional or non-inventive labor may include more or fewer operation steps, and these operation steps are not necessarily executed sequentially according to the order of the embodiments or flowcharts. The order of steps listed in the embodiments or flowcharts is merely one way of executing many steps and does not represent the only execution order. It should be noted that there is no necessary sequential order between the above steps. Those skilled in the art can understand from the description of the embodiments of the present invention that the above steps may have different execution orders in different embodiments, that is, they may be executed in parallel or in exchange, etc. Moreover, at least some steps in the embodiments or flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but may be executed in turn, alternately, or synchronously with other steps or at least a part of the sub-steps or stages of other steps.
[0125] Based on the above method embodiments, please refer to Figure 3 Another embodiment of the present invention also provides a data anti-tampering device, wherein the device includes: Module 11 is used to pre-build a main data table for business data and a shadow table corresponding to the main data table in the database; The receiving module 12 is used to receive SQL statements sent by the client for the business data, and to process the main data table and the shadow table accordingly based on the SQL statements to obtain the data processing results; Verification module 13 is used to respond to a data verification command, perform data verification on the main data table and the shadow table according to the data processing result, detect whether the data in the main data table and the shadow table has been tampered with, and obtain the data verification result; The alarm module 14 is used to return alarm information to the client when the data verification result reaches a preset alarm threshold.
[0126] Furthermore, in one embodiment, the data anti-tampering device, wherein the data master table for pre-constructing business data in the database and the shadow table corresponding to the data master table specifically include: Based on the business requirements of the business data, determine in advance the field structure of the main data table to be built in the database and its corresponding shadow table; Based on the field structure, construct the main data table and the shadow table of the business data in the database.
[0127] Furthermore, in one embodiment, the data anti-tampering device, wherein receiving the SQL statement sent by the client for the business data, and processing the main data table and the shadow table accordingly based on the SQL statement to obtain the data processing result, specifically includes: Obtain the SQL statement for the business data input by the target user through the client, and perform format validation and integrity checks on the SQL statement; When both format validation and integrity checks pass, the SQL statement is parsed, and the main data table and the shadow table are processed accordingly based on the parsing results to obtain the data processing results. If the format validation and / or integrity check fails, a prompt message will be returned.
[0128] Furthermore, in the aforementioned data anti-tampering device, when both format validation and integrity checks pass, the content of the SQL statement is parsed, and the main data table and the shadow table are processed accordingly based on the parsing results to obtain data processing results, specifically including: If both format validation and integrity checks pass, the SQL statement is parsed to extract the operation type and field information. Based on the extracted operation type and field information, the main data table and the shadow table are processed accordingly to obtain the data processing result.
[0129] Furthermore, in one embodiment, the data anti-tampering device, wherein responding to a data verification command, performs data verification on the main data table and the shadow table based on the data processing result, detects whether the data in the main data table and the shadow table has been tampered with, and obtains a data verification result, specifically includes: Receive a data verification request for the business data, parse the content of the data verification request, and extract the data verification instruction, data verification time, and request source. The data verification time and the request source are stored, and based on the data verification instruction, the main data table and the shadow table are verified according to the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, so as to obtain the data verification result of the business data.
[0130] Furthermore, in the aforementioned data anti-tampering device, storing the data verification time and the request source, and performing data verification on the main data table and the shadow table based on the data verification instruction and the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and obtaining the data verification result of the business data, specifically includes: To verify the compliance of the request source, if the request source is an authorized target user or a preset timer, the data verification time and the request source are stored. Based on the data verification instruction, the main data table and the shadow table are verified according to the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and the data verification result of the business data is obtained.
[0131] Furthermore, in one embodiment, the data anti-tampering device, wherein returning alarm information to the client when the data verification result reaches a preset alarm threshold, specifically includes: The data verification results are evaluated based on a preset alarm threshold. When the evaluation result indicates that the data verification result reaches the alarm threshold, an alarm message is generated. The alarm information is formatted according to the client's configuration information, and the formatted alarm information is returned to the client.
[0132] It should be noted that, in the device embodiments of the present invention, the information interaction and execution process between the above modules are based on the same concept as in the method embodiments of the present invention. For details on their specific functions and the resulting technical effects, please refer to the aforementioned method embodiments section, which will not be repeated here.
[0133] Based on the above method embodiments, another embodiment of the present invention also provides a computer device, which can be a server, and its internal structure diagram can be as follows. Figure 4 As shown. The computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements the functions or steps of the data anti-tampering method on the server side as described in any of the above method embodiments.
[0134] Based on the above method embodiments, another embodiment of the present invention also provides a computer device, which can be a client, and its internal structure diagram can be as follows. Figure 5 As shown, the computer device includes a processor, memory, network interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When executed by the processor, the computer program implements the functions or steps of the data anti-tampering method on the client side as described in any of the above method embodiments.
[0135] Those skilled in the art will understand that Figure 4 and Figure 5 The structural schematic diagram shown is only a schematic diagram of a part of the structure related to the present invention and does not constitute a limitation on the computer device on which the present invention is applied. The specific computer device may include more components than shown in the figure, or combine certain components, or have different component arrangements.
[0136] The processor referred to herein can be a CPU, but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0137] The memory includes readable storage media, internal memory, etc., where internal memory can be the RAM of a computer device. Internal memory provides an environment for the operation of the operating system and computer-readable instructions stored in the readable storage media. The readable storage media can be the hard drive of the computer device, or in other embodiments, it can be an external storage device of the computer device, such as a plug-in hard drive, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card. Furthermore, the memory can include both internal storage units and external storage devices of the computer device. The memory is used to store the operating system, applications, bootloader, data, and other programs, such as program code for computer programs. The memory can also be used to temporarily store data that has been output or will be output.
[0138] Based on the above method embodiments, another embodiment of the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the data anti-tampering method as described in any of the above method embodiments. The computer-readable storage medium may be non-volatile or volatile.
[0139] It should be noted that the functions or steps that can be achieved by the computer-readable storage medium or computer device, and the technical effects brought about by the functions / steps, can be referred to the relevant descriptions in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0140] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc. The disclosed memory components or memories of the operating environment described herein are intended to include one or more of these and / or any other suitable types of memory.
[0141] Those skilled in the art will understand that, for the sake of convenience and brevity, the embodiments of the device of the present invention are only illustrated by the division of the above-mentioned functional units and modules. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of the present invention. The specific working process of the units and modules in the above device can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.
[0142] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0143] In the embodiments provided by this invention, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0145] It should be noted that if any software tools or components not belonging to this company appear in the embodiments of this application, they are merely illustrative examples and do not represent actual use. The above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for preventing data tampering, characterized in that, include: A master table for business data and a shadow table corresponding to the master table are pre-built in the database. Receive the SQL statement sent by the client for the business data, and process the main data table and the shadow table accordingly based on the SQL statement to obtain the data processing result; In response to a data verification command, the main data table and the shadow table are verified based on the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and the data verification result is obtained. When the data verification result reaches the preset alarm threshold, an alarm message is returned to the client.
2. The data anti-tampering method according to claim 1, characterized in that, The data master table for pre-built business data in the database and the shadow table corresponding to the data master table include: Based on the business requirements of the business data, determine in advance the field structure of the main data table to be built in the database and its corresponding shadow table; Based on the field structure, construct the main data table and the shadow table of the business data in the database.
3. The data anti-tampering method according to claim 1, characterized in that, The receiving client sends an SQL statement targeting the business data. Based on the SQL statement, the main data table and the shadow table are processed accordingly to obtain the data processing result, including: Obtain the SQL statement for the business data input by the target user through the client, and perform format validation and integrity checks on the SQL statement; When both format validation and integrity checks pass, the SQL statement is parsed, and the main data table and the shadow table are processed accordingly based on the parsing results to obtain the data processing results. If the format validation and / or integrity check fails, a prompt message will be returned.
4. The data anti-tampering method according to claim 2, characterized in that, When both format validation and integrity checks pass, the SQL statement is parsed, and the main data table and the shadow table are processed accordingly based on the parsing results to obtain the data processing results, including: If both format validation and integrity checks pass, the SQL statement is parsed to extract the operation type and field information. Based on the extracted operation type and field information, the main data table and the shadow table are processed accordingly to obtain the data processing result.
5. The data anti-tampering method according to claim 1, characterized in that, The step of responding to a data verification command, performing data verification on the main data table and the shadow table based on the data processing result, detecting whether the data in the main data table and the shadow table has been tampered with, and obtaining a data verification result includes: Receive a data verification request for the business data, parse the content of the data verification request, and extract the data verification instruction, data verification time, and request source. The data verification time and the request source are stored, and based on the data verification instruction, the main data table and the shadow table are verified according to the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, so as to obtain the data verification result of the business data.
6. The data anti-tampering method according to claim 5, characterized in that, The step of storing the data verification time and the request source, and performing data verification on the main data table and the shadow table based on the data verification instruction and the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and obtaining the data verification result of the business data, includes: To verify the compliance of the request source, if the request source is an authorized target user or a preset timer, the data verification time and the request source are stored. Based on the data verification instruction, the main data table and the shadow table are verified according to the data processing result to detect whether the data in the main data table and the shadow table has been tampered with, and the data verification result of the business data is obtained.
7. The data anti-tampering method according to claim 1, characterized in that, When the data verification result reaches a preset alarm threshold, an alarm message is returned to the client, including: The data verification results are evaluated based on a preset alarm threshold. When the evaluation result indicates that the data verification result reaches the alarm threshold, an alarm message is generated. The alarm information is formatted according to the client's configuration information, and the formatted alarm information is returned to the client.
8. A data anti-tampering device, characterized in that, include: The construction module is used to pre-build the main data table of business data and the shadow table corresponding to the main data table in the database; The receiving module is used to receive SQL statements sent by the client for the business data, and to process the main data table and the shadow table accordingly based on the SQL statements to obtain the data processing results; The verification module is used to respond to the data verification command, perform data verification on the main data table and the shadow table according to the data processing result, detect whether the data in the main data table and the shadow table has been tampered with, and obtain the data verification result; The alarm module is used to return alarm information to the client when the data verification result reaches a preset alarm threshold.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the data anti-tampering method as described in any one of claims 1-7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the data anti-tampering method as described in any one of claims 1-7.