A data processing method, apparatus and device, and a storage medium

CN122838501APending Publication Date: 2026-09-29TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510374174.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]实践中发现,当数据管控平台遭受网络攻击时,数据管控平台所管控的数据库均将面临数据泄露的风险,影响数据库的数据安全性

Benefits of technology

[0030]本申请创建了前置设备集群,前置设备集群中存在至少两个前置设备所关联的数据库不相同,即将不同数据库的访问权限开放给不同的前置设备,这样可以避免将所有数据库的访问权限均开放给数据管控平台,能够降低数据库数据泄露的风险,提高了数据库的数据安全性。在第一终端获取第一数据表的表结构信息的过程中,各个前置设备可以基于表结构获取事件验证该第一数据表是否属于自身所关联的数据库,当第一前置设备验证得到第一数据表属于自身所关联的数据库时,可以从自身所关联的数据库中读取第一数据表的表结构信息,这样可以避免第一前置设备获取非授权数据,提高数据库的数据安全性。另外,该第一数据表的表结构信息被加密后存储在区块链上,由管控设备从区块链上读取表结构信息的加密数据,并解密得到表结构信息,将表结构信息发送至第一终端,这样可以避免非法设备获取到表结构信息,提高表结构信息的安全性。同时,该第一数据表的表结构信息的获取过程被记录在区块链上,全程留痕、可追述可审计。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122838501A_ABST
    Figure CN122838501A_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a data processing method, device and equipment and a storage medium, the method comprises the following steps: a first front-end device reads a table structure from a blockchain to obtain an event. When the table structure obtaining event indicates that a first data table belongs to a database associated with the first front-end device, the table structure information of the first data table is obtained from the database associated with the first front-end device. The table structure information of the first data table is encrypted by using the public key of a management device associated with the blockchain to obtain encrypted data. The encrypted data is stored in the blockchain; the management device is used for reading the encrypted data from the blockchain, decrypting the encrypted data to obtain the table structure information of the first data table, and sending the table structure information of the first data table to a first terminal, and the first terminal is used for creating a data directory of the first data table based on the table structure information of the first data table. Through the application, the data security of the database can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to fields such as blockchain technology, and in particular to a data processing method, apparatus, device, and storage medium. Background Technology

[0002] As data volumes continue to grow, the need for data management is increasing, and users are placing greater emphasis on building data catalogs and managing data tables. Currently, all databases have access permissions to the data management platform, allowing users to obtain information about any data table in any database and create data catalogs based on that information.

[0003] In practice, it has been found that when a data management platform is subjected to a cyberattack, all databases managed by the platform will face the risk of data leakage, affecting the data security of the databases. Summary of the Invention

[0004] This application provides a data processing method, apparatus, device, and storage medium that can improve the data security of a database.

[0005] One embodiment of this application provides a data processing method, including:

[0006] The first front-end device reads the table structure from the blockchain to obtain the event; the first front-end device is any one of at least two front-end devices included in the front-end device cluster, and any front-end device is associated with at least one database; the table structure acquisition event is generated by the control device according to the table structure acquisition request for the first data table sent by the first terminal;

[0007] When the above table structure acquisition event indicates that the above first data table belongs to the database associated with the above first front-end device, the table structure information of the above first data table is obtained from the database associated with the above first front-end device.

[0008] Using the public key of the control device associated with the aforementioned blockchain, the table structure information of the first data table is encrypted to obtain encrypted data;

[0009] The encrypted data is stored in the blockchain; the control device is used to read the encrypted data from the blockchain, decrypt the encrypted data to obtain the table structure information of the first data table, and send the table structure information of the first data table to the first terminal. The first terminal is used to create the data directory of the first data table based on the table structure information of the first data table.

[0010] One embodiment of this application provides a data processing method, including:

[0011] The control device receives a request from the first terminal to obtain the table structure of the first data table;

[0012] Based on the above table structure retrieval request, a table structure retrieval event is generated and stored on the blockchain.

[0013] Encrypted data is read from the aforementioned blockchain; the aforementioned encrypted data is obtained by the first front-end device encrypting the table structure information of the aforementioned first data table using the public key of the aforementioned control device; the table structure information of the aforementioned first data table is obtained by the first front-end device from the database associated with the aforementioned first front-end device when the aforementioned table structure acquisition event indicates that the aforementioned first data table belongs to the database associated with the aforementioned first front-end device; the aforementioned first front-end device is any one of at least two front-end devices included in the front-end device cluster, and any front-end device is associated with at least one database;

[0014] Using the private key of the aforementioned control device, the encrypted data is decrypted to obtain the table structure information of the aforementioned first data table;

[0015] The table structure information of the first data table is sent to the first terminal; the first terminal is used to create a data directory for the first data table based on the table structure information of the first data table.

[0016] One embodiment of this application provides a data processing apparatus, including:

[0017] The first reading module is used for the first front-end device to read table structure retrieval events from the blockchain; the first front-end device is any front-end device in the front-end device cluster, any front-end device is associated with at least one database, and there are at least two front-end devices in the front-end device cluster that are associated with different databases; the table structure retrieval event is generated by the control device based on the table structure retrieval request of the first data table and uploaded to the blockchain; the table structure retrieval request is sent by the first terminal to the control device.

[0018] The first processing module is used to obtain the table structure information of the first data table from the database associated with the first front-end device when the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device.

[0019] The encryption module is used to encrypt the table structure information of the first data table using the public key of the aforementioned control device, thereby obtaining encrypted data.

[0020] The storage module is used to store the encrypted data in the blockchain; the control device is used to read the encrypted data from the blockchain, decrypt the encrypted data to obtain the table structure information of the first data table, and send the table structure information of the first data table to the first terminal. The first terminal is used to create the data directory of the first data table based on the table structure information of the first data table.

[0021] One embodiment of this application provides a data processing apparatus, including:

[0022] The receiving module is used to control the device to receive a table structure retrieval request for the first data table sent by the first terminal;

[0023] The second processing module is used to generate a table structure retrieval event based on the above table structure retrieval request, and store the above table structure retrieval event on the blockchain.

[0024] The second reading module is used to read encrypted data from the aforementioned blockchain. The encrypted data is obtained by the first front-end device encrypting the table structure information of the first data table using the public key of the aforementioned control device. The table structure information of the first data table is obtained by the first front-end device from the database associated with the aforementioned first front-end device when the aforementioned table structure acquisition event indicates that the aforementioned first data table belongs to the database associated with the aforementioned first front-end device. The aforementioned first front-end device is any front-end device in the front-end device cluster, any front-end device is associated with at least one database, and there are at least two front-end devices in the aforementioned front-end device cluster that are associated with different databases.

[0025] The decryption module is used to decrypt the encrypted data using the private key of the aforementioned control device to obtain the table structure information of the aforementioned first data table.

[0026] The sending module is used to send the table structure information of the first data table to the first terminal; the first terminal is used to create a data directory of the first data table based on the table structure information of the first data table.

[0027] One embodiment of this application provides a computer device, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of the method described above.

[0028] One embodiment of this application provides a computer storage medium storing a computer program, which, when executed by a processor, performs the steps of the above-described method.

[0029] One aspect of this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the above-described method.

[0030] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices, preventing the data management platform from granting access to all databases. This reduces the risk of database data leakage and improves database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on table structure acquisition events. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from obtaining unauthorized data, improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The management device reads the encrypted data of the table structure information from the blockchain, decrypts it to obtain the table structure information, and sends the table structure information to the first terminal. This prevents unauthorized devices from obtaining the table structure information, improving the security of the table structure information. Simultaneously, the process of acquiring the table structure information of the first data table is recorded on the blockchain, ensuring full traceability and auditability. Attached Figure Description

[0031] Figure 1 This is a schematic diagram of the architecture of a data processing system provided in an embodiment of this application;

[0032] Figure 2 This is a schematic diagram of a data processing method provided in an embodiment of this application;

[0033] Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 1 ;

[0034] Figure 4 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 2 ;

[0035] Figure 5 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 3 ;

[0036] Figure 6 This is a schematic diagram illustrating the interaction between various devices under a data processing method provided in an embodiment of this application;

[0037] Figure 7This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 1 ;

[0038] Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 2 ;

[0039] Figure 9 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0040] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0041] To facilitate understanding, the following brief explanations are provided for some of the terms:

[0042] (1) The data management platform is a platform that facilitates data providers in creating data catalogs and managing data tables. Specifically, data providers can use the data management platform to obtain the table structure information of data tables in the database and construct data catalogs based on the table structure information; data providers can also store this data catalog in the database through the data management platform. Based on this, data users can easily obtain the data catalog of data tables through the data management platform.

[0043] The backend equipment of the data management platform can be the management equipment described in this application. Both the data provider and the data user are users of the data management platform; the data provider is the management user of the data table, and the data user is the user of the data table. In this application, the object corresponding to the first terminal and the object corresponding to the second terminal are both the data provider.

[0044] (2) Public and Private Keys: Any front-end device or control device can generate public and private keys based on an asymmetric encryption algorithm. This asymmetric encryption algorithm can include RSA, ElGamal, elliptic curve cryptography, etc. Both the public and private keys can be a set of numbers generated by the encryption algorithm. The public key is publicly available, while the private key is stored locally on the device. The public key can be used to encrypt data (such as the table structure information of the first data table) to obtain encrypted data; the private key is used to decrypt the encrypted data. Asymmetric encryption improves data security.

[0045] Please refer to Figure 1 , Figure 1 This is a schematic diagram of the structure of a data processing system provided in an embodiment of this application, such as... Figure 1As shown, the data processing system includes a control device 12, a front-end device cluster, a blockchain network 11, and a blockchain management device 10. The control device is the back-end device corresponding to the data control platform.

[0046] It should be noted that a front-end device cluster can include at least two front-end devices, such as Figure 1 As shown, the example given is a front-end device cluster containing two front-end devices. Specifically, the front-end device cluster includes front-end device 15 and front-end device 16. Each front-end device can be associated with at least one database, for example, ... Figure 1 As shown, front-end device 16 is associated with database 19, and front-end device 15 is associated with both databases 17 and 18. This association can mean that the databases grant access permissions to the front-end devices. In other words, front-end device 16 can have access permissions to database 19, and front-end device 15 can have access permissions to both databases 17 and 18.

[0047] It should be noted that the blockchain management device 10 is used to manage and maintain the blockchain network 11, and the specific usage of the blockchain management device 10 is not limited in this application. The blockchain network 11 may include multiple node devices, and the number of node devices is not limited here, such as... Figure 1 As shown, the example illustrates a blockchain network comprising four nodes. Specifically, the blockchain network 11 includes node 111, node 112, node 113, and node 114. It can be understood that node 111, node 112, node 113, and node 114 are interconnected via a network, enabling data exchange between each node.

[0048] It should be noted that each node device in blockchain network 11 maintains a blockchain, which includes a series of blocks sequentially generated in chronological order. Once a new block is added to the blockchain, it is never removed. Each block records the data submitted by the node devices in the blockchain system. Each block includes the hash value of the transaction records stored in that block (the hash value of this block) and the hash value of the previous block. The blocks are linked together by their hash values ​​to form the blockchain. Additionally, blocks may include information such as a timestamp when they were generated. A blockchain, essentially a decentralized database, is a chain of data blocks linked using cryptographic methods. Each data block contains relevant information used to verify the validity of the information (anti-counterfeiting) and to generate the next block. In this application, the blocks on the blockchain can be used to record relevant information during the acquisition of the data table's structural information, as well as relevant information during the storage of the data table's data directory.

[0049] It should be noted that a node device can be a single physical server, a server cluster or distributed system consisting of at least two physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, ContentDelivery Network (CDN), and big data and artificial intelligence platforms.

[0050] The control device 12 can receive a table structure retrieval request for the first data table from a first terminal (such as terminal 13 or terminal 14), generate a table structure retrieval event based on the request, and store the table structure retrieval event on the blockchain in the blockchain network 11. Based on this, a first front-end device (such as front-end device 15 or front-end device 16) can read the table structure retrieval event from the blockchain. In particular, if front-end device 16 determines that the table structure retrieval event indicates that the first data table belongs to database 19, front-end device 16 can also obtain the table structure information of the first data table from database 19. The first data table may include an object information table, a product information table, a transaction data table, etc.; terminals 13 and 14 can refer to in-vehicle terminals, smartphones, tablets, laptops, desktop computers, smart speakers, speakers with screens, smart TVs, smartwatches, etc., but are not limited to these.

[0051] For details on the entire process of obtaining table structure information, please refer to [link / reference]. Figure 2 , Figure 2 This is a schematic diagram illustrating a data processing method provided in an embodiment of this application. Taking the first data table as an object information table as an example, as follows... Figure 2 As shown, terminal 13 can send a request to obtain the table structure of the object information table to management device 12. Upon receiving the request, management device 12 can generate a table structure acquisition event and send it to any node device in the blockchain network 11. For example, node device 111 can receive the table structure acquisition event, package it into a block, and store it on the blockchain. At this time, front-end device 16 can read the table structure acquisition event from the blockchain. Front-end device 16 can determine whether the table structure acquisition event indicates that the object information table belongs to the database (i.e., database 19) associated with front-end device 16. When front-end device 16 determines that the table structure acquisition event indicates that the object information table belongs to database 19, front-end device 16 can obtain the table structure information of the object information table from database 19. Figure 2 Table structure information 22.

[0052] Furthermore, the front-end device 16 can obtain the public key of the control device 12 from the blockchain in the blockchain network 11, i.e. Figure 2 The public key 21 is used by the front-end device 16 to encrypt the table structure information 22, obtaining encrypted data 23, which is then sent to any node device in the blockchain network 11. Taking node device 112 as an example, node device 112 can receive the encrypted data 23, package it into a block, and store it on the blockchain. Based on this, the control device 12 can read the encrypted data 23 from the blockchain in the blockchain network 11 using its private key (i.e., public key 21). Figure 2 Using the private key 24, the encrypted data 23 is decrypted to obtain the table structure information 22. At this time, the control device 12 can send the table structure information 22 to the terminal 13; the terminal 13 can create the data target of the object information table based on the table structure information 22. This ensures that the table structure information of the object information table will not be captured by unauthorized devices and objects, which helps to improve the security of the object information table.

[0053] Further, please see Figure 3 , Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 1 .like Figure 3 As shown, this method can be derived from... Figure 1 The method can be executed by any front-end device in the front-end cluster, and the front-end device executing the method can be referred to as the first front-end device. The method may include the following steps:

[0054] S101, The first front-end device reads the table structure from the blockchain to obtain events.

[0055] It should be noted that the first front-end device can be any front-end device in the front-end device cluster; each front-end device in the cluster is associated with at least one database. Furthermore, at least two front-end devices in the cluster are associated with different databases. In other words, the front-end device cluster supports different databases granting access permissions to different front-end devices, preventing all databases from simultaneously granting access permissions to the same front-end device. This helps reduce the access permissions of individual front-end devices and improves database security.

[0056] It should be noted that the table structure retrieval event is used to indicate the retrieval of the table structure information of the first data table. The table structure retrieval event is generated by the control device based on the table structure retrieval request for the first data table, and the table structure retrieval event is uploaded to the blockchain by the control device. This table structure retrieval request is sent from the first terminal to the control device.

[0057] The table structure retrieval request can carry table structure request information, the terminal identifier of the first terminal, etc. This table structure request information can include object attribute information corresponding to the object of the first terminal, access attribute information of the database to which the first data table belongs, etc. Object attribute information can include object name, object password, etc.; access attribute information can include the name, identifier, port number, and Internet Protocol (IP) address of the device where the database is located, etc., and can also include the name and identifier of the first data table, etc. The first data table can refer to an object information table, a transaction data table, a product information table, etc. The database type can include MySQL, Oracle, PostgreSQL, etc. Table structure information can be used to indicate the data structure of the corresponding data table, which can include the name and data type of each field in the data table. Data types can include integer, string, date, etc. For example, if the first data table is a product information table, the table structure information can include the name, data type, and constraints of each field in the product information table. Specifically, the table structure information can include three fields from the product information table; the first field is named the product name and is of string type; the third field is named the product price and is of integer type; and the fourth field is named the product production time and is of date type.

[0058] In this application, any front-end device in the front-end device cluster (i.e., the first front-end device) can subscribe to table structure retrieval events in the blockchain. That is, the blockchain can store device information (such as device identifiers) of the front-end devices that subscribe to table structure retrieval events. When a table structure retrieval event is stored on the blockchain by the managed device, node devices in the blockchain network can broadcast a notification that the table structure retrieval event has been uploaded to the blockchain to the front-end devices that have subscribed to the event, based on the device information of the front-end devices that have subscribed to the event. Therefore, when the first front-end device receives this notification, it can read the table structure retrieval event from the blockchain.

[0059] S102. When the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device, the table structure information of the first data table is obtained from the database associated with the first front-end device.

[0060] In this application, the first front-end device can parse the table structure retrieval event. When the table structure retrieval event is successfully parsed, the first front-end device can determine that the first data table belongs to the database associated with the first front-end device. The first front-end device can then obtain the table structure information of the first data table from the database associated with the first front-end device. Only the front-end device associated with the database to which the first data table belongs can access the database, preventing information leakage from the database and improving database security.

[0061] In one embodiment, when parsing the table structure retrieval event fails, the first front-end device can determine that the first data table does not belong to the database associated with the first front-end device, and the first front-end device cannot obtain the table structure information of the first data table. At this time, the first front-end device can generate a first notification message indicating the failure to retrieve the table structure information and store this first notification message on the blockchain. The control device can read this first notification message from the blockchain and forward it to the first terminal.

[0062] S103. Using the public key of the control device, encrypt the table structure information of the first data table to obtain encrypted data.

[0063] In this application, the first front-end device may store the public key of the control device in its local storage space. The first front-end device can obtain the public key of the control device in its local storage space and use the public key of the control device to encrypt the table structure information of the first data table to obtain encrypted data. This can prevent unauthorized devices from obtaining the table structure information and improve data security. The encrypted data can refer to data that cannot be directly understood or used.

[0064] In one embodiment, there can be a correspondence between the public key and the device identifier of the control device. Both the public key and the device identifier can be stored in the blockchain. Simultaneously, the table structure retrieval event can carry the device identifier of the control device. Therefore, the first front-end device can obtain the device identifier of the control device from the table structure retrieval event. Based on the device identifier, it can retrieve the public key corresponding to the device identifier from the blockchain, which is the public key of the control device. Using this public key, the table structure information of the first data table is encrypted to obtain encrypted data.

[0065] S104. Store encrypted data in the blockchain.

[0066] In this application, the first front-end device can send encrypted data to any node device in the blockchain network. This node device can package the encrypted data into blocks and store the blocks in the blockchain. The control device can then read the encrypted data from the blockchain and decrypt it to obtain table structure information. The control device can then send this table structure information to the first terminal, facilitating the first terminal to construct a data directory based on the table structure information.

[0067] It should be noted that the data catalog can be used to indicate the data content of the corresponding data table. The data content can include each piece of data in the data table. For example, if the first data table is a product information table, the data catalog can include information about each product in the product information table. Specifically, the data catalog can include information corresponding to the three products in the product information table; where the first product is named shower gel, the product price is 20, and the product production time is February 2025; the second product is named facial cleanser, the product price is 50, and the product production time is January 2025; the third product is named shampoo, the product price is 30, and the product production time is February 2025.

[0068] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices, preventing the data management platform from granting access to all databases. This reduces the risk of database data leakage and improves database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on table structure acquisition events. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from obtaining unauthorized data, improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The management device reads the encrypted data of the table structure information from the blockchain, decrypts it to obtain the table structure information, and sends the table structure information to the first terminal. This prevents unauthorized devices from obtaining the table structure information, improving the security of the table structure information. Simultaneously, the process of acquiring the table structure information of the first data table is recorded on the blockchain, ensuring full traceability and auditability.

[0069] Further, please see Figure 4 , Figure 4 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 2 .like Figure 4 As shown, this method can be derived from... Figure 1The method can be executed by any front-end device in the front-end cluster, and the front-end device executing the method can be referred to as the first front-end device. The method may include the following steps:

[0070] S201, The first front-end device reads the table structure from the blockchain to obtain events.

[0071] S202. Use the private key of the first front-end device to decrypt the table structure acquisition event.

[0072] It should be noted that the table structure retrieval event can be obtained by the control device encrypting the table structure request information using the public key of the second front-end device in the front-end device cluster. This second front-end device is the device specified by the first terminal.

[0073] In this application, the first front-end device can obtain its private key from local storage and use that private key to decrypt table structure events. If the first front-end device and the second front-end device are the same front-end device, the table structure request information can be obtained through decryption; if the first front-end device and the second front-end device are not the same front-end device, the table structure request information cannot be obtained through decryption. This decryption operation effectively prevents front-end devices without access rights from obtaining the table structure request information.

[0074] S203. When the table structure acquisition event is successfully decrypted and the table structure request information is obtained, it is determined that the second front-end device and the first front-end device belong to the same front-end device, and the first data table belongs to the database associated with the first front-end device.

[0075] In this application, after the first front-end device decrypts the table structure event, it obtains the decrypted information. At this point, the first front-end device can detect whether the table structure retrieval event was successfully decrypted and obtain a detection result. When the detection result indicates that the table structure retrieval event was successfully decrypted, the first front-end device can determine that the second front-end device and the first front-end device belong to the same front-end device, the first data table belongs to the database associated with the first front-end device, and the decrypted information is table structure request information. When the detection result indicates that the table structure retrieval event was not successfully decrypted, the first front-end device can determine that the second front-end device and the first front-end device do not belong to the same front-end device, the first data table does not belong to the database associated with the first front-end device, and the decrypted information is not table structure request information. The decryption operation effectively prevents unauthorized front-end devices from accessing the database, avoids unauthorized front-end devices obtaining sensitive table structure request information, and helps improve database data security.

[0076] It should be noted that the above-mentioned detection of whether the table structure acquisition event has been successfully decrypted can yield a detection result that includes any of the following: 1. The table structure acquisition event can also carry a raw hash value, which is obtained by performing a hash operation on the information contained in the table structure acquisition event using a hash function. After the first front-end device obtains the decrypted information, it can calculate the hash value corresponding to the decrypted information. If the hash value corresponding to the decrypted information is consistent with the raw hash value, a detection result indicating that the table structure acquisition event has been successfully decrypted is generated; 2. The table structure request information can include the device identifier of the second front-end device. That is, the second front-end device can refer to the front-end device specified by the first terminal that is associated with the database to which the first data table belongs. After the first front-end device obtains the decrypted information, if the decrypted information contains a device identifier, and the device identifier is consistent with the device identifier of the first front-end device, it indicates that the first data table belongs to the database associated with the first front-end device, and a detection result indicating that the table structure acquisition event has been successfully decrypted can be generated.

[0077] S204. Based on the table structure request information, obtain the table structure information of the first data table from the database associated with the first front-end device.

[0078] Optionally, step 204 may further include: the first front-end device can obtain object attribute information corresponding to the object corresponding to the first terminal and access attribute information of the database to which the first data table belongs from the table structure request information. The first front-end device can obtain M first candidate object attribute information locally, where each first candidate object attribute information corresponds to an object that has the permission to obtain table structure information of the first data table; where M is a positive integer. The object corresponding to the first candidate object attribute information may be a data provider that manages the database to which the first data table belongs, or it may be an object authorized by the data provider. The first front-end device can compare the object attribute information corresponding to the object corresponding to the first terminal with the M first candidate object attribute information one by one. If there is a first candidate object attribute information among the M first candidate object attribute information that is consistent with the object attribute information corresponding to the object corresponding to the first terminal, a verification result is obtained that the object corresponding to the first terminal has the permission to obtain table structure information of the first data table. If none of the M candidate object attribute information is consistent with the object attribute information corresponding to the first terminal, the verification result is that the object corresponding to the first terminal does not have the permission to obtain the table structure information of the first data table. In this way, only objects that have been verified to have the permission can obtain the table structure information, thus avoiding the risk of leakage of table structure information.

[0079] Based on this, when the verification result indicates that the object corresponding to the first terminal has the permission to access the table structure information of the first data table, that is, the object corresponding to the first terminal can access the table structure information of the first data table, the first front-end device can retrieve the table structure information of the first data table from the database associated with the first front-end device according to the access attribute information of the database to which the first data table belongs. When the verification result indicates that the object corresponding to the first terminal does not have the permission to access the table structure information of the first data table, that is, the object corresponding to the first terminal cannot access the table structure information of the first data table, the first front-end device cannot retrieve the table structure information of the first data table, and the first front-end device can generate a notification message indicating that the retrieval of the table structure information failed and store the notification message on the blockchain. In this way, only the data provider of the database to which the first data table belongs, or an object authorized by the data provider of the database to which the first data table belongs, can access the table structure information of the first data table. At the same time, the front-end device can further unify the management of database access, prevent unauthorized objects from accessing data, and further ensure the data security of the database.

[0080] In one embodiment, the first front-end device can store the attribute information of M candidate objects in the blockchain. Before performing the comparison operation of the object attribute information, the first front-end device can read the attribute information of M candidate objects from the blockchain.

[0081] S205. Using the public key of the control device, encrypt the table structure information of the first data table to obtain encrypted data.

[0082] S206. Store encrypted data in the blockchain.

[0083] Optionally, any front-end device in the front-end device cluster (i.e., the first front-end device) can subscribe to directory storage events in the blockchain. That is, the blockchain can store device information (such as device identifiers) of front-end devices that have subscribed to directory storage events. When a directory storage event is stored on the blockchain by the managing device, node devices in the blockchain network can broadcast a notification that the directory storage event has been uploaded to the blockchain to the front-end devices that have subscribed to the event, based on the device information of those devices. Therefore, when the first front-end device receives this notification, it can read the directory storage event from the blockchain. The directory storage event is generated by the managing device based on a directory storage request from the second data table and uploaded to the blockchain; the directory storage request is sent to the managing device by the second terminal. Furthermore, the first front-end device can parse the directory storage event. Based on the directory storage event, the first front-end device can store the data directory of the second data table into the database associated with the first front-end device. After successful storage, the first front-end device can generate response information indicating that the data directory of the second data table has been successfully stored. This response information is then stored in the blockchain. This allows the control device to retrieve the response information from the blockchain and send it to the second terminal. The corresponding object on the second terminal can quickly understand the storage result of the data directory of the second data table. A public-key encryption and private-key decryption mechanism is employed to ensure the confidentiality of directory storage events during transmission and storage.

[0084] It should be noted that the directory storage event is used to indicate the data directory storing the second data table. The directory storage request may carry object attribute information corresponding to the object corresponding to the second terminal, access attribute information of the database to which the second data table belongs, first attribute information of the database to which the second data table belongs, and second attribute information of the second data table. It should also be noted that the second data table may include an object information table, a product information table, a transaction data table, etc. The first attribute information may include at least one of the database name, identifier, etc., to which the second data table belongs; the second attribute information may include at least one of the name, identifier, etc., of the second data table.

[0085] In one embodiment, the directory storage event can be obtained by the control device encrypting the directory storage request using the public key of a third front-end device in the front-end device cluster; the third front-end device is the device specified by the second terminal. The aforementioned storage of the data directory of the second data table into the database associated with the first front-end device based on the aforementioned directory storage event includes: the first front-end device can obtain its private key from its local storage space and use that private key to decrypt the directory storage event. If the first front-end device and the third front-end device are the same front-end device, the directory storage request can be decrypted; if the first front-end device and the third front-end device are not the same front-end device, the directory storage request cannot be decrypted. The first front-end device can then store the data directory of the second data table into the database associated with the first front-end device based on the aforementioned directory storage request.

[0086] In one embodiment, the first front-end device can obtain object attribute information corresponding to the object corresponding to the second terminal and access attribute information of the database to which the second data table belongs from the aforementioned directory storage request. The first front-end device can obtain S second candidate object attribute information locally, where S is a positive integer. The object corresponding to the second candidate object attribute information can be the data provider managing the database to which the second data table belongs, or it can be an object authorized by the data provider. The first front-end device can compare the object attribute information corresponding to the object corresponding to the second terminal with the S second candidate object attribute information one by one. If there is a second candidate object attribute information among the S second candidate object attribute information that matches the object attribute information corresponding to the object corresponding to the second terminal, a verification result is obtained that the object corresponding to the second terminal has storage permission for the data directory of the aforementioned second data table. If there is no second candidate object attribute information among the S second candidate object attribute information that matches the object attribute information corresponding to the object corresponding to the second terminal, a verification result is obtained that the object corresponding to the second terminal does not have storage permission for the data directory of the aforementioned second data table. Thus, only objects that have been verified to have permission can store the data directory.

[0087] Therefore, when the verification result indicates that the object corresponding to the second terminal has storage permissions for the data directory of the second data table, the first front-end device can store the data directory of the second data table in the database associated with the first front-end device. When the verification result indicates that the object corresponding to the second terminal does not have storage permissions for the data directory of the second data table, the first front-end device cannot store the data directory of the second data table in the database associated with the first front-end device. By verifying whether the object corresponding to the second terminal has storage permissions for the data directory of the second data table, access by unauthorized users can be effectively prevented, ensuring the data security of the database.

[0088] Optionally, the number of databases associated with the first front-end device can be N, where N is an integer greater than 1; each database associated with the first front-end device can store at least one data table. The first front-end device can store attribute information corresponding to each of the N associated databases, which may include at least one of the following: database name, database identifier, etc. The first front-end device can obtain the first attribute information of the database to which the second data table belongs, and the second attribute information of the second data table, from the aforementioned directory storage event. The first front-end device can search for a database whose attribute information matches the first attribute information from the N associated databases based on the attribute information corresponding to each of the N associated databases. Further, the matched database may include multiple data tables, and the first front-end device can search for a data table that matches the second attribute information from the multiple data tables in the matched database based on the second attribute information. If a data table matching the second attribute information is found in the matched database, the data directory of the second data table is stored in the found data table; if no data table matching the second attribute information is found in the matched database, it indicates that the data directory storage has failed. This enables automatic searching of multiple databases and tables, speeds up data catalog storage, and improves work efficiency.

[0089] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices. This avoids granting access to all databases to a single data management platform, reducing the risk of database data leakage and improving database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on the table structure acquisition event. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from acquiring unauthorized data, improving database security. The table structure acquisition event can be encrypted. The first front-end device can only obtain the table structure information of the first data table from its associated database after successfully decrypting the table structure acquisition event using its private key and obtaining the table structure request information. Decryption effectively prevents unauthorized front-end devices from accessing the database, avoiding unauthorized access to sensitive table structure request information and improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The control device reads the encrypted data from the blockchain, decrypts it to obtain the table structure information, and sends it to the first terminal. This prevents unauthorized devices from obtaining the table structure information, enhancing its security. Simultaneously, the process of obtaining the table structure information of the first data table is recorded on the blockchain, ensuring a complete traceability and auditability.

[0090] Further, please see Figure 5 , Figure 5 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 3 .like Figure 5 As shown, this method can be derived from... Figure 1 The method is executed by the control device in the system. The method may include the following steps:

[0091] S301, The control device receives a request from the first terminal to obtain the table structure of the first data table.

[0092] In this application, the control device can receive a table structure retrieval request for the first data table sent by the first terminal, indicating that the first terminal needs to retrieve the table structure information of the first data table from the database at this time.

[0093] It should be noted that the table structure retrieval request mentioned above may carry table structure request information, the terminal identifier of the first terminal, etc. For a detailed explanation of the table structure request information, please refer to the above content, which will not be repeated here.

[0094] S302. Based on the table structure retrieval request, generate a table structure retrieval event and store the table structure retrieval event on the blockchain.

[0095] In this application, the control device can generate a table structure retrieval event based on a table structure retrieval request, and send the table structure retrieval event to any node device in the blockchain network. The node device can package the table structure retrieval event into a block and store the block in the blockchain.

[0096] Optionally, the blockchain can store the device identifiers and public keys of all front-end devices, with a corresponding relationship between each device identifier and public key. The above-mentioned generation of a table structure retrieval event based on the table structure retrieval request includes: the control device can obtain the device identifier of the second front-end device from the table structure request information, i.e., the second front-end device is the device specified by the first terminal. The control device can obtain the public key corresponding to the device identifier of the second front-end device from the blockchain, i.e., the public key of the second front-end device. The control device can use the public key of the second front-end device to encrypt the table structure retrieval request to obtain the table structure retrieval event.

[0097] S303, Read encrypted data from the blockchain.

[0098] In this application, the control device can monitor the data upload status on the blockchain in real time. That is, when the control device detects that encrypted data has been uploaded to the blockchain, the control device can read the encrypted data from the blockchain.

[0099] It should be noted that the encrypted data is obtained by the first front-end device encrypting the table structure information of the first data table using the public key of the control device. The table structure information of the first data table is obtained by the first front-end device from the database associated with it when it determines that the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device. The encryption process of the encrypted data and the process of obtaining the table structure information of the first data table can be referred to the above content, and will not be repeated here.

[0100] It should be noted that the first front-end device refers to any front-end device in the front-end device cluster. Each front-end device is associated with at least one database, and at least two front-end devices in the front-end device cluster are associated with different databases. For a detailed explanation of front-end devices and databases, please refer to the above content, which will not be repeated here.

[0101] S304. Using the private key of the control device, the encrypted data is decrypted to obtain the table structure information of the first data table.

[0102] In this application, after reading the encrypted data, the control device can obtain its private key from its local storage space. The control device can then use this private key to decrypt the encrypted data and obtain the table structure information of the first data table.

[0103] S305. Send the table structure information of the first data table to the first terminal.

[0104] In this application, the control device can send the decrypted table structure information to the first terminal, so that the first terminal can create the data directory of the first data table based on the table structure information.

[0105] Optionally, the control device can receive a directory storage request for the second data table sent by the second terminal, indicating that the second terminal needs to store the data directory of the second data table in its associated database. The control device can obtain the device identifier of the third front-end device from the directory storage request, i.e., the third front-end device is the device specified by the second terminal. The control device can obtain a public key from the blockchain that corresponds to the device identifier of the third front-end device, i.e., the public key of the third front-end device. The control device can use the public key of the third front-end device to encrypt the directory storage request, obtaining a directory storage event. The control device can send the above directory storage event to any node device in the blockchain network. The node device can package the directory storage event into a block and store it on the blockchain. This facilitates the first front-end device to read the directory storage event from the blockchain, and when it determines that the above directory storage event indicates that the second data table belongs to the database associated with the first front-end device, it stores the data directory of the second data table in the database associated with the first front-end device according to the above directory storage event. The specific implementation process of storing the data directory of the second data table can be referred to the above content and will not be repeated here. The control device can read response information from the blockchain indicating that the data directory of the second data table has been successfully stored; the response information may be generated by the first front-end device after storing the data directory. The control device can send the response information to the second terminal.

[0106] Please refer to Figure 6 , Figure 6This is a schematic diagram illustrating the interaction between various devices under a data processing method provided in this application embodiment. The interaction process may include the following steps: S1, Sending a table structure retrieval request; If the object corresponding to the terminal (such as a first terminal or a second terminal) needs to create a data directory about the product information table, the terminal can send a table structure retrieval request for the product information table to the management device. S2, Generating a table structure retrieval event; After receiving the table structure retrieval request for the product information table, the management device can obtain the device identifier of the front-end device specified by the terminal (i.e., the device identifier of the second front-end device) from the table structure retrieval request, and obtain the public key of the second front-end device from the blockchain based on the device identifier of the second front-end device. Specifically, when the front-end device specified by the terminal is the first front-end device, that is, when the second front-end device and the first front-end device are the same front-end device, the management device actually obtains the public key of the first front-end device. Further, the management device can encrypt the table structure request information in the table structure retrieval request based on the obtained public key to obtain a table structure retrieval event. S3. Retrieve Table Structure Event: The control device can send the table structure retrieval event to any node device in the blockchain network. The node device can package the table structure retrieval event into a first block and store the first block in the blockchain. S4. Return First Successful On-Chain Message: After successfully storing the first block, the node device can generate a first successful on-chain message to indicate that the table structure retrieval event has been successfully uploaded to the blockchain. The node device can send the first successful on-chain message to the control device; the control device can forward the first successful on-chain message to the terminal. S5. Read Table Structure retrieval Event: The first front-end device can detect the on-chain status of events in the blockchain. After detecting that the table structure retrieval event has been uploaded, it can retrieve the table structure retrieval event from the blockchain. S6. Decrypt Table Structure Request Information from Table Structure retrieval Event: The first front-end device can use its private key to decrypt the table structure retrieval event. When the table structure retrieval event is successfully decrypted and the first front-end device obtains the table structure request information, it indicates that the product information table belongs to the database associated with the first front-end device. S7. Accessing the Database: The first front-end device can verify the terminal's access permissions for the product information table's structure based on the table structure request information. When the verification confirms that the terminal has the access permissions for the product information table's structure, the first front-end device can obtain the name of the database to which the product information table belongs and the name of the product information table itself from the table structure request information. It then searches for a database whose name matches the name of the database to which the product information table belongs from the N databases associated with the first front-end device. The first front-end device can then send the name of the product information table to the matched database. S8. Sending Table Structure Information: The matched database can search for the product information table based on its name and send the table structure information of the product information table to the first front-end device.

[0107] Further, S9, encrypt the table structure information to obtain encrypted data; the first front-end device can use the public key of the control device to encrypt the table structure information to obtain encrypted data. S10, upload the encrypted data to the blockchain; the first front-end device can upload the encrypted data to the blockchain. The specific implementation process of steps 9 and 10 can be referred to the above content, and will not be repeated here. S11, return the second successful upload information; after the node device in the blockchain network successfully uploads the encrypted data to the blockchain, it can generate a second successful upload information to indicate that the encrypted data has been successfully uploaded to the blockchain. The node device can send the second successful upload information to the first front-end device. S12, read the encrypted data; the control device can read the encrypted data from the blockchain. S13, decrypt the encrypted data to obtain table structure information; the control device can use the private key of the control device to decrypt the encrypted data to obtain the table structure information of the product information table. S14, send the table structure information; the control device can send the table structure information of the product information table to the terminal. The specific implementation processes of steps 12, 13, and 14 can be referred to the above content and will not be repeated here. S15, Send a directory storage request; the terminal can construct the data directory of the product information table, i.e., the product information directory, based on the table structure information of the obtained product information table. The terminal can generate a directory storage request based on the data directory of the product information table and send the directory storage request to the control device. S16, Encrypt the directory storage request to obtain a directory storage event; after receiving the directory storage request, the control device can generate a directory storage event based on the directory storage request. The specific implementation process of step 16 can be referred to the above content and will not be repeated here. S17, Upload the directory storage event to the blockchain; the control device can send the directory storage event to any node device in the blockchain network. The node device can package the table structure acquisition event into a second block and store the second block in the blockchain. S18, Return the third successful uploading information; after the node device successfully stores the second block, it can generate the first successful uploading information to indicate that the table structure acquisition event has been successfully uploaded to the blockchain. The node device can send the first successful on-chain message to the control device; the control device can forward the first successful on-chain message to the terminal. S19, Read directory storage events; the first front-end device can read directory storage events from the blockchain. S20, Decrypt directory data from directory storage events; the first front-end device can use its private key to decrypt directory storage events to obtain directory data. S21, Store data directory; the first front-end device can store the data directory in the database.

[0108] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices, preventing the data management platform from granting access to all databases. This reduces the risk of database data leakage and improves database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on table structure acquisition events. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from obtaining unauthorized data, improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The management device reads the encrypted data of the table structure information from the blockchain, decrypts it to obtain the table structure information, and sends the table structure information to the first terminal. This prevents unauthorized devices from obtaining the table structure information, improving the security of the table structure information. Simultaneously, the process of acquiring the table structure information of the first data table is recorded on the blockchain, ensuring full traceability and auditability.

[0109] Please see Figure 7 , Figure 7 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 1 .like Figure 7 As shown, the data processing apparatus may include:

[0110] The first reading module 711 is used for the first front-end device to read table structure acquisition events from the blockchain; the first front-end device is any front-end device in the front-end device cluster, any front-end device is associated with at least one database, and there are at least two front-end devices in the front-end device cluster that are associated with different databases; the table structure acquisition event is generated by the control device based on the table structure acquisition request of the first data table and uploaded to the blockchain; the table structure acquisition request is sent by the first terminal to the control device.

[0111] The first processing module 712 is used to obtain the table structure information of the first data table from the database associated with the first front-end device when the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device.

[0112] The encryption module 713 is used to encrypt the table structure information of the first data table using the public key of the aforementioned control device to obtain encrypted data.

[0113] The storage module 714 is used to store the encrypted data in the blockchain; the control device is used to read the encrypted data from the blockchain, decrypt the encrypted data to obtain the table structure information of the first data table, and send the table structure information of the first data table to the first terminal. The first terminal is used to create the data directory of the first data table based on the table structure information of the first data table.

[0114] Optionally, the table structure acquisition event mentioned above is obtained by encrypting the table structure request information using the public key of the second front-end device in the aforementioned front-end device cluster, wherein the second front-end device is the device specified by the first terminal.

[0115] The first processing module 712 described above can also be used to perform the following operations:

[0116] The private key of the first front-end device is used to decrypt the table structure acquisition event.

[0117] When the above table structure acquisition event is successfully decrypted and the above table structure request information is obtained, it is determined that the above second front-end device and the above first front-end device belong to the same front-end device, and it is determined that the above first data table belongs to the database associated with the above first front-end device.

[0118] Based on the table structure request information, the table structure information of the first data table is obtained from the database associated with the first front-end device.

[0119] Optionally, the first processing module 712 described above can also be used to perform the following operations:

[0120] From the above table structure request information, obtain the object attribute information corresponding to the object corresponding to the first terminal, and the access attribute information of the database to which the first data table belongs;

[0121] Based on the object attribute information of the above objects, verify the access permissions of the above objects to the table structure information of the above first data table, and obtain the verification result;

[0122] When the verification result indicates that the object has permission to obtain the table structure information of the first data table, the table structure information of the first data table is obtained from the database associated with the first front-end device according to the access attribute information of the database to which the first data table belongs.

[0123] Optionally, the above-mentioned data processing apparatus can also be used for:

[0124] The directory storage event is read from the aforementioned blockchain; the aforementioned directory storage event is generated by the aforementioned control device based on the directory storage request of the second data table and uploaded to the aforementioned blockchain; the aforementioned directory storage request is sent to the aforementioned control device by the second terminal;

[0125] When the aforementioned directory storage event indicates that the second data table belongs to the database associated with the first front-end device, the data directory of the second data table is stored in the database associated with the first front-end device according to the aforementioned directory storage event;

[0126] A response message is generated to indicate that the data directory of the second data table has been successfully stored, and the response message is stored in the blockchain. The control device is used to read the response message from the blockchain and send the response message to the second terminal.

[0127] Optionally, the number of databases associated with the first front-end device is N, where N is an integer greater than 1;

[0128] The above-mentioned data processing device can also be used for:

[0129] From the above-mentioned directory storage event, obtain the first attribute information of the database to which the second data table belongs, and the second attribute information of the second data table.

[0130] Search the N databases associated with the first front-end device for a database that matches the first attribute information.

[0131] Based on the second attribute information mentioned above, the second data table is searched from the matched database, and the data directory of the second data table is stored in the second data table.

[0132] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0133] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices, preventing the data management platform from granting access to all databases. This reduces the risk of database data leakage and improves database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on table structure acquisition events. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from obtaining unauthorized data, improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The management device reads the encrypted data of the table structure information from the blockchain, decrypts it to obtain the table structure information, and sends the table structure information to the first terminal. This prevents unauthorized devices from obtaining the table structure information, improving the security of the table structure information. Simultaneously, the process of acquiring the table structure information of the first data table is recorded on the blockchain, ensuring full traceability and auditability.

[0134] Please see Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 2 .like Figure 8 As shown, the data processing apparatus may include:

[0135] The receiving module 811 is used to control the device to receive a table structure retrieval request for the first data table sent by the first terminal;

[0136] The second processing module 812 is used to generate a table structure retrieval event based on the above table structure retrieval request and store the above table structure retrieval event on the blockchain.

[0137] The second reading module 813 is used to read encrypted data from the blockchain. The encrypted data is obtained by the first front-end device encrypting the table structure information of the first data table using the public key of the control device. The table structure information of the first data table is obtained by the first front-end device from the database associated with the first front-end device when the first front-end device determines that the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device. The first front-end device is any front-end device in the front-end device cluster, and any front-end device is associated with at least one database. Furthermore, there are at least two front-end devices in the front-end device cluster that are associated with different databases.

[0138] The decryption module 814 is used to decrypt the encrypted data using the private key of the aforementioned control device to obtain the table structure information of the aforementioned first data table.

[0139] The sending module 815 is used to send the table structure information of the first data table to the first terminal; the first terminal is used to create a data directory of the first data table based on the table structure information of the first data table.

[0140] Optionally, the second processing module 812 described above can also be used to perform the following operations:

[0141] From the above table structure retrieval request, obtain table structure request information; the above table structure request information includes the device identifier of the second front-end device; the above second front-end device is the device specified by the above first terminal;

[0142] Based on the device identifier of the second front-end device, obtain the public key of the second front-end device from the blockchain;

[0143] Using the public key of the second front-end device, the table structure request information is encrypted to obtain the table structure acquisition event.

[0144] Optionally, the above-mentioned data processing apparatus can also be used for:

[0145] Receive a directory storage request for the second data table sent by the second terminal;

[0146] Based on the above directory storage request, a directory storage event is generated and stored on the above blockchain;

[0147] The response information indicating that the data directory of the second data table has been successfully stored is read from the blockchain. The response information is generated by the first front-end device after it determines that the directory storage event indicates that the second data table belongs to the database associated with the first front-end device and stores the data directory of the second data table into the database associated with the first front-end device according to the directory storage event.

[0148] The above response information is sent to the second terminal.

[0149] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0150] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices, preventing the data management platform from granting access to all databases. This reduces the risk of database data leakage and improves database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on table structure acquisition events. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from obtaining unauthorized data, improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The management device reads the encrypted data of the table structure information from the blockchain, decrypts it to obtain the table structure information, and sends the table structure information to the first terminal. This prevents unauthorized devices from obtaining the table structure information, improving the security of the table structure information. Simultaneously, the process of acquiring the table structure information of the first data table is recorded on the blockchain, ensuring full traceability and auditability.

[0151] Please see Figure 9 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 9 As shown, the aforementioned computer device 900 can refer to a resource allocation device, including: a processor 901, a network interface 904, and a memory 905. Furthermore, the aforementioned computer device 900 may also include: a user interface 903, and at least one communication bus 902. The communication bus 902 is used to implement communication between these components. In some embodiments, the user interface 903 may include a display screen and a keyboard; optionally, the user interface 903 may also include a standard wired interface or a wireless interface. The network interface 904 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 905 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. The memory 905 may also optionally be at least one storage device located remotely from the aforementioned processor 901. Figure 9 As shown, the memory 905, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and computer programs.

[0152] exist Figure 9In the computer device 900 shown, the network interface 904 provides network communication functionality; the user interface 903 is mainly used to provide an input interface; and the processor 901 can be used to call computer programs stored in the memory 905 to execute:

[0153] The first front-end device reads the table structure from the blockchain to obtain the event; the first front-end device is any one of at least two front-end devices included in the front-end device cluster, and any front-end device is associated with at least one database; the table structure acquisition event is generated by the control device according to the table structure acquisition request for the first data table sent by the first terminal;

[0154] When the above table structure acquisition event indicates that the above first data table belongs to the database associated with the above first front-end device, the table structure information of the above first data table is obtained from the database associated with the above first front-end device.

[0155] Using the public key of the control device associated with the aforementioned blockchain, the table structure information of the first data table is encrypted to obtain encrypted data;

[0156] The encrypted data is stored in the blockchain; the control device is used to read the encrypted data from the blockchain, decrypt the encrypted data to obtain the table structure information of the first data table, and send the table structure information of the first data table to the first terminal. The first terminal is used to create the data directory of the first data table based on the table structure information of the first data table.

[0157] This application creates a front-end device cluster. Within this cluster, at least two front-end devices are associated with different databases. Access permissions for different databases are granted to different front-end devices, preventing the data management platform from granting access to all databases. This reduces the risk of database data leakage and improves database security. During the process of the first terminal acquiring the table structure information of the first data table, each front-end device can verify whether the first data table belongs to its associated database based on table structure acquisition events. When the first front-end device verifies that the first data table belongs to its associated database, it can read the table structure information of the first data table from its associated database. This prevents the first front-end device from obtaining unauthorized data, improving database security. Furthermore, the table structure information of the first data table is encrypted and stored on the blockchain. The management device reads the encrypted data of the table structure information from the blockchain, decrypts it to obtain the table structure information, and sends the table structure information to the first terminal. This prevents unauthorized devices from obtaining the table structure information, improving the security of the table structure information. Simultaneously, the process of acquiring the table structure information of the first data table is recorded on the blockchain, ensuring full traceability and auditability.

[0158] Furthermore, it should be noted that this application also provides a computer-readable storage medium storing a computer program executed by the aforementioned data processing apparatus. This computer program includes program instructions, which, when executed by the processor, enable the execution of the data processing method described in the corresponding embodiments above. Therefore, further details will not be repeated here. Additionally, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the embodiments of the computer-readable storage medium involved in this application, please refer to the description of the method embodiments of this application.

[0159] As an example, the above program instructions can be deployed and executed on a computer device, or deployed and executed on at least two computer devices in one location, or executed on at least two computer devices distributed in at least two locations and interconnected by a communication network. At least two computer devices distributed in at least two locations and interconnected by a communication network can form a blockchain network.

[0160] The aforementioned computer-readable storage medium may be a data processing apparatus provided in any of the foregoing embodiments or a central storage unit of the aforementioned computer device, such as a hard disk or central storage of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, smart memory card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium may include both the central storage unit and external storage devices of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0161] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish content in different media, rather than to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.

[0162] In practice, the collection and processing of data in this application should strictly comply with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the data subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the data subject.

[0163] This application also provides a computer program product, including a computer program. When executed by a processor, the computer program implements the data processing method and decoding method described in the preceding embodiments, and therefore will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the embodiments of the computer program product involved in this application, please refer to the description of the method embodiments of this application.

[0164] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0165] The methods and related apparatus provided in this application are described with reference to the method flowcharts and / or structural diagrams provided in this application. Specifically, each block of the method flowchart and / or structural diagram, as well as combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable network-connected device to create a machine, such that the instructions, which execute via the processor of the computer or other programmable network-connected device, generate instructions for implementing the process. Figure 1 A schematic diagram of one or more processes and / or structures. Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable network-connected device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 A schematic diagram of one or more processes and / or structures. Figure 1The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable network-connected device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 A process or multiple processes and / or structures illustrate the steps of the functions specified in one or more boxes.

[0166] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.

Claims

1. A data processing method, characterized in that, include: The first front-end device reads the table structure from the blockchain to obtain events; The first front-end device is any front-end device in the front-end device cluster. Each front-end device is associated with at least one database, and there are at least two front-end devices in the front-end device cluster that are associated with different databases. The table structure acquisition event is generated by the control device based on the table structure acquisition request of the first data table and uploaded to the blockchain. The table structure acquisition request is sent by the first terminal to the control device. When the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device, the table structure information of the first data table is obtained from the database associated with the first front-end device. The table structure information of the first data table is encrypted using the public key of the control device to obtain encrypted data; The encrypted data is stored in the blockchain; The control device is used to read the encrypted data from the blockchain, decrypt the encrypted data to obtain the table structure information of the first data table, and send the table structure information of the first data table to the first terminal. The first terminal is used to create a data directory of the first data table based on the table structure information of the first data table.

2. The method according to claim 1, characterized in that, The table structure acquisition event is obtained by encrypting the table structure request information using the public key of the second front-end device in the front-end device cluster. The second front-end device is the device specified by the first terminal. When the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device, the table structure information of the first data table is acquired from the database associated with the first front-end device, including: The table structure acquisition event is decrypted using the private key of the first front-end device; When the table structure acquisition event is successfully decrypted and the table structure request information is obtained, it is determined that the second front-end device and the first front-end device belong to the same front-end device, and it is determined that the first data table belongs to the database associated with the first front-end device. Based on the table structure request information, the table structure information of the first data table is obtained from the database associated with the first front-end device.

3. The method according to claim 2, characterized in that, The step of obtaining the table structure information of the first data table from the database associated with the first front-end device based on the table structure request information includes: From the table structure request information, obtain the object attribute information corresponding to the object corresponding to the first terminal, and the access attribute information of the database to which the first data table belongs; Based on the object attribute information of the object, verify the object's access permission to the table structure information of the first data table, and obtain the verification result; When the verification result indicates that the object has permission to obtain the table structure information of the first data table, the table structure information of the first data table is obtained from the database associated with the first front-end device according to the access attribute information of the database to which the first data table belongs.

4. The method according to claim 1, characterized in that, The method further includes: The directory storage event is read from the blockchain; the directory storage event is generated by the control device based on the directory storage request of the second data table and uploaded to the blockchain; the directory storage request is sent to the control device by the second terminal. When the directory storage event indicates that the second data table belongs to the database associated with the first front-end device, the data directory of the second data table is stored in the database associated with the first front-end device according to the directory storage event; A response message is generated to indicate that the data directory of the second data table has been successfully stored, and the response message is stored in the blockchain; the control device is used to read the response message from the blockchain and send the response message to the second terminal.

5. The method according to claim 4, characterized in that, The number of databases associated with the first front-end device is N, where N is an integer greater than 1; The step of storing the data directory of the second data table into the database associated with the first front-end device according to the directory storage event includes: From the directory storage event, obtain the first attribute information of the database to which the second data table belongs, and the second attribute information of the second data table; Search among the N databases associated with the first front-end device for a database that matches the first attribute information; Based on the second attribute information, the second data table is searched from the matched database, and the data directory of the second data table is stored in the second data table.

6. A data processing method, characterized in that, include: The control device receives a request from the first terminal to obtain the table structure of the first data table; Based on the table structure retrieval request, a table structure retrieval event is generated, and the table structure retrieval event is stored on the blockchain; Encrypted data is read from the blockchain; the encrypted data is obtained by the first front-end device encrypting the table structure information of the first data table using the public key of the control device. The table structure information of the first data table is obtained by the first front-end device from the database associated with the first front-end device when the first front-end device determines that the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device; the first front-end device is any front-end device in the front-end device cluster, any front-end device is associated with at least one database, and there are at least two front-end devices in the front-end device cluster that are associated with different databases. Using the private key of the control device, the encrypted data is decrypted to obtain the table structure information of the first data table; The table structure information of the first data table is sent to the first terminal; The first terminal is used to create a data directory for the first data table based on the table structure information of the first data table.

7. The method according to claim 6, characterized in that, The step of generating a table structure retrieval event based on the table structure retrieval request includes: The table structure request information is obtained from the table structure request; the table structure request information includes the device identifier of the second front-end device; the second front-end device is the device specified by the first terminal; Based on the device identifier of the second front-end device, obtain the public key of the second front-end device from the blockchain; The table structure request information is encrypted using the public key of the second front-end device to obtain the table structure acquisition event.

8. The method according to claim 6, characterized in that, The method further includes: Receive a directory storage request for the second data table sent by the second terminal; Based on the directory storage request, a directory storage event is generated and stored on the blockchain; The response information indicating that the data directory of the second data table has been successfully stored is read from the blockchain; the response information is generated by the first front-end device after determining that the directory storage event indicates that the second data table belongs to the database associated with the first front-end device, and storing the data directory of the second data table into the database associated with the first front-end device according to the directory storage event. The response information is sent to the second terminal.

9. A data processing apparatus, characterized in that, include: The first reading module is used by the first front-end device to read the table structure from the blockchain to obtain events; The first front-end device is any front-end device in the front-end device cluster. Each front-end device is associated with at least one database, and there are at least two front-end devices in the front-end device cluster that are associated with different databases. The table structure acquisition event is generated by the control device based on the table structure acquisition request of the first data table and uploaded to the blockchain. The table structure acquisition request is sent by the first terminal to the control device. The first processing module is configured to, when the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device, acquire the table structure information of the first data table from the database associated with the first front-end device. The encryption module is used to encrypt the table structure information of the first data table using the public key of the control device to obtain encrypted data; A storage module is used to store the encrypted data in the blockchain; The control device is used to read the encrypted data from the blockchain, decrypt the encrypted data to obtain the table structure information of the first data table, and send the table structure information of the first data table to the first terminal. The first terminal is used to create a data directory of the first data table based on the table structure information of the first data table.

10. A data processing apparatus, characterized in that, include: The receiving module is used to control the device to receive a table structure retrieval request for the first data table sent by the first terminal; The second processing module is used to generate a table structure retrieval event based on the table structure retrieval request, and store the table structure retrieval event on the blockchain; The second reading module is used to read encrypted data from the blockchain; the encrypted data is obtained by the first front-end device encrypting the table structure information of the first data table using the public key of the control device; The table structure information of the first data table is obtained by the first front-end device from the database associated with the first front-end device when the first front-end device determines that the table structure acquisition event indicates that the first data table belongs to the database associated with the first front-end device; the first front-end device is any front-end device in the front-end device cluster, any front-end device is associated with at least one database, and there are at least two front-end devices in the front-end device cluster that are associated with different databases. The decryption module is used to decrypt the encrypted data using the private key of the control device to obtain the table structure information of the first data table; The sending module is used to send the table structure information of the first data table to the first terminal; The first terminal is used to create a data directory for the first data table based on the table structure information of the first data table.

11. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 8.

12. A computer storage medium, characterized in that, The computer storage medium stores a computer program, which, when executed by a processor, performs the method as described in any one of claims 1 to 8.

13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 8.