Database storage data encryption processing method, and database management system

The proposed method addresses the limitations of existing database encryption methods by using an API-based hooking module to perform encryption and decryption at the DB client level, ensuring secure and efficient data handling without burdening the DBMS.

JP2025086347AActive Publication Date: 2025-06-06OWL SYSTEMS INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024204788
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-27
Filing Date
2024-11-25
Publication Date
2025-06-06
Estimated Expiration
2044-11-25

AI Technical Summary

Technical Problem

Existing database encryption methods, such as the 'View/Trigger' method, concentrate encryption and decryption load on the DB server, exposing decrypted data during network transmission and causing performance issues.

Method used

A method using an API-based hooking module that intercepts encrypted column queries and data inputs, performing encryption and decryption at the DB client level without modifying the application source, thus avoiding load on the DBMS and maintaining data encryption during network transmission.

Benefits of technology

This approach allows for automatic encryption and decryption without modifying the application source, reduces the load on the DBMS, ensures data security by keeping it encrypted over the network, and improves database server performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025086347000001_ABST
    Figure 2025086347000001_ABST
Patent Text Reader

Abstract

To provide a database storage data encryption processing method that brings about an effect as if a View / Trigger method is applied, while an encryption / decryption function does not put any load on a database management system (DBMS) at all, using an API.SOLUTION: According to a database storage data encryption processing method, a hooking module is caused to implement in a step S210, when receiving an encrypted column inquiry request through an application in a step S200, then, the implemented hooking module inquiries about encrypted data from a database of a DBMS, captures encrypted table column information from the DB in a step S220, perses SQL a user performs through the application in a step S230, as a result of the parsing, checks whether an encryption object of nearby table columns is present in a step S240, and decrypts the inquired encrypted data to transmit the decrypted data to the application in a step S250.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The embodiment relates to an encryption technology for data stored in a database. [Background technology]

[0002] The methods for applying DB encryption are broadly divided into the "API method" and the "plug-in method." API is an encryption / decryption function provided for each development language such as C and JAVA, and is mainly used by developers.

[0003] The plug-ins are provided in the form of SQL functions, making them easy to use for developers and general DB users.

[0004] Generally, both methods are used together, which is called a hybrid method.

[0005] Both API and plug-in methods have in common the part that inputs and outputs data, and users must create and process encryption / decryption functions themselves. This is the biggest inconvenience users will experience after installing a DB encryption product.

[0006] In particular, developers must search for all the code related to encrypted DB columns in the existing source code that is running stably and apply the encryption / decryption functions, which can be a heavy burden.

[0007] For this reason, the "View / Trigger" method is preferred, which allows you to access data in the same way as before without modifying the source code and without additional work in the query tool. This is a method in which encrypted data is automatically decrypted through the view created in the DB when querying data, and conversely, when entering data, it is automatically encrypted by the trigger.

[0008] However, the 'View / Trigger' method works based on plug-ins, but the 'Plug-in' method uses the CPU and memory of the server on which the DBMS is running, so the disadvantage is that all the load related to encryption / decryption in the entire network system is concentrated on the DB server.

[0009] In addition, data decrypted using the "plug-in" method travels across the network already in a decrypted state through the DBMS, which means that if someone tries to sniff network packets using methods like packet sniffing, the decrypted data is immediately exposed, creating a security vulnerability.

[0010] This creates security issues as data is automatically decrypted and visible through views in all environments where the DBMS can be accessed. For this reason, DB encryption products themselves provide a minimum access control function, but this method has inherent limitations in terms of achieving complete access control, and this function also generates additional I / O in the DBMS, resulting in a performance burden.

[0011] Also, in order to use the "View / Trigger" method smoothly, tuning of existing SQL code is required, which is a limitation. [Prior art documents] [Patent documents]

[0012] [Patent Document 1] Republic of Korea Patent Publication No. 10-2023-0123715 [Patent Document 2] Republic of Korea Patent Publication No. 10-1476039 Summary of the Invention [Problem to be solved by the invention]

[0013] The present invention has been derived from the above technical background, and its purpose is to provide a database encryption / decryption application method that can achieve the same effect as if the "View / Trigger" method was applied, while the encryption / decryption function does not put any load on the DBMS by using API. [Means for solving the problem]

[0014] In order to achieve the above object, the present invention includes the following configuration.

[0015] That is, a method for encrypting data stored in a database according to one embodiment of the present invention is a method performed in a computing device having one or more processors and a memory storing one or more programs executed by the one or more processors, and includes the steps of executing a hooking module when an encrypted column query request is received through an application, the executed hooking module querying encrypted data from a database of a database management system (DBMS), and decrypting the queried encrypted data and transmitting it to the application.

[0016] Meanwhile, a database management system according to one embodiment is a system including a computer device having one or more processors and a memory storing one or more programs executed by the one or more processors, and includes a DB server that performs database management, and an application server including a hooking module that queries encrypted data through a DB client module when an encrypted column query request is received from a database of the DB server through an application, and decrypts the queried encrypted data and transmits it to the application. Effect of the Invention

[0017] According to the present invention, the DB client automatically performs encryption and decryption by intervening in the SQL transmission and data reception process to the DB server, so that encrypted data can be automatically decrypted without modifying the application source, or data can be input to the DB in an encrypted state.

[0018] In addition, since encryption and decryption are performed at the DB client end, the data is transmitted over the network in an encrypted state, which is advantageous in terms of security, and there is also the advantage that no load is placed on the DBMS due to data encryption and decryption.

[0019] In addition, according to one embodiment of the encryption processing method for database stored data, not only does it maintain security and provide maximum convenience to users, but it also has the effect of providing the additional benefit of improved performance for database servers. [Brief description of the drawings]

[0020] [Figure 1] 4 is a flowchart illustrating an encryption method for data stored in a database according to an embodiment of the present invention. [Diagram 2] 13 is an exemplary diagram illustrating a process of querying an encrypted column TEL in the encryption processing method for data stored in a database according to an embodiment; FIG. [Diagram 3] 13 is an exemplary diagram illustrating a process of querying an encrypted column TEL in the encryption processing method for data stored in a database according to an embodiment; FIG. [Figure 4] 1 is an exemplary diagram illustrating a data input or modification process in a method for encrypting data stored in a database according to an embodiment; [Diagram 5] 1 is an exemplary diagram illustrating a data input or modification process in a method for encrypting data stored in a database according to an embodiment; [Figure 6] FIG. 1 is a block diagram illustrating a configuration of a database management system according to an embodiment. [Figure 7]FIG. 1 is a block diagram illustrating an exemplary computing environment including a computing device suitable for use with the exemplary embodiments. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0021] The technical terms used in the present invention are merely used to describe specific embodiments and are not intended to limit the present invention. Furthermore, unless otherwise defined in the present invention, the technical terms used in the present invention are generally understood by those having ordinary knowledge in the technical field to which the present invention belongs, and should not be interpreted in an overly comprehensive or overly narrow sense.

[0022] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings.

[0023] The database management system according to the embodiment of the present invention may be embodied by at least one computer device, and the encryption method for database stored data according to the embodiment of the present invention may be performed through at least one computer device included in the database management system. At this time, a computer program according to an embodiment of the present invention may be installed and run in the computer device, and the computer device may perform the encryption method for database stored data according to the embodiment of the present invention under the control of the run computer program. The computer program may be stored in a computer-readable recording medium combined with the computer device to cause the computer to execute the encryption method for database stored data.

[0024] FIG. 1 is a flowchart illustrating a method for encrypting data stored in a database according to an embodiment of the present invention.

[0025] In the method for encrypting data stored in a database according to an embodiment, the encryption / decryption function uses an API, but can achieve the same effect as if a "View / Trigger" method was applied.

[0026] In other words, the user does not modify the source at all, and the user who creates SQL using the query tool uses the same SQL as before without any additional work, but as a result, the input data is automatically encrypted and saved, and the output data is automatically decrypted.

[0027] In particular, since this is performed on the application side, not on the DBMS, it places no burden on the DBMS, and since the data remains encrypted even when it travels over the network, it is secure from a security standpoint.

[0028] To handle this, hooking is performed to the existing DB Client module that transmits the SQL created by the application to the DBMS.

[0029] In one embodiment of the method for managing data stored in a database, when an encrypted column query request is received through an application (S200), a hooking module is executed (S210).

[0030] The executed hooking module then queries the encrypted data from the database of the database management system DBMS.

[0031] In one aspect, in order to query the encrypted data, the system obtains table-column information to which encryption has been applied from the database (S220), and parses the SQL executed by the user through the application (S230).

[0032] Then, the SQL executed by the user is parsed. SQL parsing can be performed by an SQL parser built into the database management system DBMS. Parsing is a process in which the SQL parser analyzes the SQL statement and generates a syntax tree or an execution plan. The SQL parser uses a set of rules to interpret the SQL statement and convert it into a form that the database engine can understand.

[0033] In one embodiment, the SQL parser breaks down an SQL statement into small units, splits it into meaningful parts called tokens, converts the tokenized SQL statement into a tree structure according to syntax rules, analyzes the statement tree to determine the meaning of objects such as tables, columns, functions, etc., and checks for consistency with a database schema to determine the validity of the query.

[0034] Then, based on the parsing result, it is determined whether there is an encryption target among the approaching table columns (S240).

[0035] At this time, whether or not there is an encryption target can be determined based on preset security requirements.

[0036] For example, sensitive information can be identified through data classification and monitoring, i.e., tables and columns containing sensitive data can be identified, and access to and changes to such data can be monitored to detect security events.

[0037] In addition, a security policy can be defined in advance, and policy-based security can be used to determine access rights to a specific table or column, or to determine whether encryption is required.

[0038] You can use user-defined functions (UDFs) to check data before executing a specific query or data manipulation operation to determine whether encryption is required, or you can perform static analysis of SQL statements to understand the characteristics of the query and determine whether the tables and columns used in the query handle sensitive data and then determine whether encryption is required.

[0039] Also, the system may be embodied to dynamically analyze SQL queries at run time to identify queries that access specific data and provide additional protection to the corresponding data through encryption.

[0040] Thereafter, the requested encrypted data is decrypted and transmitted to the application (S250).

[0041] In this case, the transfer step involves, depending on the type of SQL statement in the query step, if the SQL statement is a query target column of a SELECT statement, decoding the user's data and transferring the result value of the SQL to the application.

[0042] In the inquiry stage, depending on the type of SQL statement, if the SQL statement is input data or comparison data other than a SELECT statement, the SQL is modified with the user's data encrypted and transmitted to the database management system.

[0043] In an additional aspect of the present invention, the executed hooking module causes the hooking module to be executed (S215) when data is entered or modified (S260) in a database of a database management system DBMS.

[0044] The executed hooking module then queries the encrypted data from the database of the database management system DBMS.

[0045] In one aspect, in order to query the encrypted data, the system obtains table-column information to which encryption has been applied from the database (S225), and parses the SQL executed by the user through the application (S235).

[0046] Then, based on the parsing result, it is determined whether there is an encryption target among the approaching table-columns (S245).

[0047] At this time, whether or not there is an encryption target can be confirmed based on preset security requirements.

[0048] Then, the input or modified data is automatically encrypted (S270).

[0049] At this time, the encryption step involves selecting an encryption key and an encryption algorithm according to a predefined policy, determining whether or not to encrypt the data, and then performing encryption.

[0050] That is, the method for encrypting data stored in a database according to an embodiment of the present invention can select an encryption key to be applied in the process of encrypting and decrypting data stored in a database according to a predefined policy.

[0051] In this case, different criteria may be applied to select the encryption key depending on security, efficiency, and the specific case.

[0052] That is, an encryption key can be selected based on the importance of stored data and security policies. For example, one of a Data Encryption Key (DEK), which plays an important role in protecting sensitive data in a database, a Master Key, which plays a role in protecting symmetric keys to manage multiple symmetric keys used in a database, or one of a Public Key, a Private Key, a Hash Key, a key used in a Key Management Service, and a key used for tokenization can be selected, but is not limited to these.

[0053] Additionally, the encryption algorithm may be selected according to a predefined policy.

[0054] For example, the Advanced Encryption Standard (AES), the RSA algorithm mainly used for key exchange and digital signatures, Elliptic Curve Cryptography (ECC), which is advantageous when used in mobile devices and environments with limited resources, and a blockchain-based encryption algorithm can be selected in the case of a distributed database and blockchain-based application. That is, it can be embodied to select the optimal algorithm from among various algorithms based on predefined policies and monitored data storage conditions. However, the present invention is not limited to these.

[0055] In addition, the setting for whether or not partial encryption is performed may be applied differently. For example, the setting may be set to encrypt only data stored in a specific field or column, and fields containing sensitive information such as credit card numbers and social security numbers may be selectively encrypted.

[0056] Alternatively, depending on the importance of the data, important data may be completely encrypted, and data of relatively low importance may be set not to be encrypted or only partially encrypted, or an option may be provided to allow the user or application level to select whether or not to apply encryption, and only selected sensitive information may be encrypted as needed.

[0057] According to the encryption processing method for data stored in a database according to an embodiment, the DB client automatically performs encryption and decryption by intervening in the SQL transmission and data reception process to the DB server. Therefore, the user can decrypt the automatically encrypted data without modifying the source, or input the data in the encrypted state to the database (DB).

[0058] In addition, since this series of processes is performed at the DB client side, it is advantageous for security because it is transmitted in an encrypted state when crossing the network, and there is no burden on the DBMS due to encryption and decryption.

[0059] In other words, the method for encrypting data stored in a database according to an embodiment does not require modification of application sources, and can automatically decrypt encrypted data and query data entered by a user without using plug-in functions in a query tool such as SQL*Plus, Toad, Orange, etc.

[0060] Since views / triggers are not used, no additional work is required in the database, and data security can be maintained without burdening the database with encryption and decryption.

[0061] In addition, data is encrypted before being transmitted between the DB server and the application, making it safe even over the network.

[0062] In a further aspect, the base stored data encryption processing method according to one embodiment may further perform verification as to whether columns that require encryption among data transmitted by an application from a DB server are actually encrypted.

[0063] 2 and 3 are diagrams illustrating an example of a process for querying an encrypted column TEL in the method for encrypting data stored in a database according to an embodiment.

[0064] Generally, when an application queries an encrypted column TEL, the application obtains data according to the process shown in Figure 2. Figure 2 shows the SELECT process in a general situation.

[0065] In Figure 2, dbclient.dll, which is the DB Client module used when the application executes SQL, is changed to client_org.dll, and then the dll file created for hooking is changed to its original name, client.dll.

[0066] Accordingly, when an application executes SQL, the hooking module client.dll is loaded instead of the original module, and this module internally calls the original module client_org.dll so that the basic functions of DB Client can be performed as is.

[0067] Referring to FIG. 3, the process of processing a SELECT statement through a hooking module, that is, the automatic decryption process, the encrypted data queried from the DB by the hooking module is automatically decrypted and transmitted to the application.

[0068] Specifically, the DB client module (client_org.dll) retrieves table-column information to which encryption has been applied in the DB.

[0069] Then, the SQL executed by the user is parsed, and it is checked whether there is an encryption target in the table-column that is close as a result of the parsing.

[0070] If an access to the encryption target is detected, the corresponding operation is carried out depending on the type of SQL statement.

[0071] For example, in the case of a column queried in a SELECT statement, the user data is decrypted and returned to the application as the SQL result value.

[0072] And, in case of input data or comparison data in the WHERE clause of other statements (INSERT, UPDATE, DELETE), the SQL is modified with the user's data encrypted and transmitted to the DBMS.

[0073] 4 and 5 are diagrams illustrating an example of a data input or modification process in a method for encrypting data stored in a database according to an embodiment.

[0074] That is, when new data is input (INSERT) to the DBMS or data stored in the DBMS is modified (UPDATE), the data is automatically encrypted and sent to the DB Server for storage.

[0075] Generally, security and user convenience are generally contradictory, and one must often be sacrificed for the other. However, according to one embodiment of the encryption processing method for database stored data, it is possible to maintain security while providing maximum convenience to users, and also to provide the additional benefit of improved performance for the database server.

[0076] FIG. 6 is a block diagram illustrating the configuration of a database management system according to an embodiment.

[0077] The database management system according to one embodiment includes a DB server 120 and an application server 110 .

[0078] The DB server 120 performs database management. The DB server 120 executes a database management system (DBMS) and processes various operations on the database. The DB server 120 can operate the database system by creating, managing, updating, and processing queries on the database.

[0079] In one embodiment, DB server 120 runs a particular DBMS through which all administrative tasks for the database are performed, which can be one of, but is not limited to, MySQL, PostgreSQL, Microsoft SQL Server, and Oracle Database.

[0080] The DB server 120 creates or modifies database objects such as tables, indexes, views, stored procedures, etc. to create new databases, manages the structure of existing databases, processes data requests from applications or client application programs run by the application server 110 or from other systems, executes queries, and returns results.

[0081] It is possible to search, insert, update, and delete data, manage database access rights, apply security policies to protect sensitive information, and maintain database integrity and security through user authentication and authorization.

[0082] The application server 110 includes a hooking module 112 that, when an encrypted column query request is received from a database of the DB server 120 through an application, queries the encrypted data through a DB client module, decrypts the queried encrypted data, and transmits the decrypted data to the application.

[0083] The application server 110 is a server that executes and manages software application programs. The application server 110 accepts and processes user requests, and returns results to provide to client applications or users, and can be used in web applications and enterprise applications.

[0084] The application server 110 can execute and manage multiple application programs simultaneously, manage communication with clients, and support various protocols. For example, it can interact with clients using protocols such as HTTP, HTTPS, and TCP / IP. The application server 110 efficiently manages threads using a thread pool to handle multiple simultaneous requests, and provides security features such as user authentication, authorization, and data protection. Application servers are used in various languages ​​and frameworks such as Java EE, .NET, PHP, and Python, and are implemented such that the server configuration and settings can be changed in various ways depending on the specific use case.

[0085] The hooking module 112 is a software module that intercepts or modifies a specific event, function, or operation in a computer program or system. The hooking module 112 is used to monitor and modify the behavior of a program, and can be used for a variety of purposes, including debugging, security, tracking specific actions, and modifying the user interface.

[0086] In one embodiment, the hooking module 112 performs hooking on an existing DB Client module that transmits SQL created by an application in the application server 110 to the DBMS of the DB server 120. The hooking module 112 can perform functions such as API hooking, which intercepts or modifies a particular API function when a program calls the function, function hooking, which intercepts or modifies the call of a particular function to perform a desired operation, message hooking, which intercepts or modifies the transmission of messages between systems or application programs, event hooking, which is a method of intercepting or processing a particular event when the event occurs, and file system hooking, which intercepts or modifies file system operations to monitor or control a particular file operation, but is not limited thereto.

[0087] The client DB module 114 supports interactions between applications and databases, and performs tasks related to linking with and querying the DB server 120. The client DB module 114 is responsible for communication between client applications and databases, and can process CRUD (Create, Read, Update, Delete) operations on data.

[0088] The Client DB Module 114 can set up and manage connections with the DB Server 120. Connection pooling is used to provide efficient connection management and allow applications to securely connect to databases on the DB Server 120.

[0089] The client DB module 114 can query the database using SQL or other query languages ​​to perform operations such as querying, updating, inserting, and deleting data at the request of a user or application.

[0090] It can also receive query execution results from the DB server 120, process them into a required format, and return them to the application. It can also perform error processing, data conversion, and filtering on the results.

[0091] FIG. 7 is a block diagram illustrating an exemplary computing environment 10 including a computing device suitable for use with the exemplary embodiments.

[0092] In the illustrated embodiment, each component may have different functions and capabilities than those described below and may include additional components than those described below.

[0093] The illustrated computing environment 10 includes a computing device 12. In one embodiment, computing device 12 can be a longitudinal observation-based active learning algorithm learner.

[0094] Computing device 12 includes at least one processor 14, a computer readable storage medium 16, and a communication bus 18. Processor 14 may cause computing device 12 to operate in accordance with the exemplary embodiments described above. For example, processor 14 may execute one or more programs stored on computer readable storage medium 16. The one or more programs may include one or more computer executable instructions that, when executed by processor 14, may configure computing device 12 to perform operations in accordance with the exemplary embodiments.

[0095] The computer readable storage medium 16 is configured to store computer executable instructions or program code, program data, and / or other suitable forms of information. The program 20 stored on the computer readable storage medium 16 includes a set of instructions that are executable by the processor 14. In one embodiment, the computer readable storage medium 16 may be memory (volatile memory, such as random access memory, non-volatile memory, or a suitable combination thereof), one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other different forms of storage media that can be accessed by the computing device 12 to store the desired information, or any suitable combination thereof.

[0096] A communications bus 18 interconnects the processor 14 , the computer-readable storage medium 16 , and various other components of the computing device 12 .

[0097] The computing device 12 may also include one or more input / output interfaces 22 and one or more network communication interfaces 26 that provide an interface for one or more input / output devices 24. The input / output interfaces 22 and the network communication interfaces 26 are coupled to the communication bus 18. The input / output devices 24 may be coupled to other components of the computing device 12 through the input / output interfaces 22. Exemplary input / output devices 24 may include input devices such as a pointing device (such as a mouse or trackpad), a keyboard, a touch input device (such as a touchpad or touchscreen), a voice or sound input device, various types of sensor devices and / or imaging devices, and / or output devices such as a display device, a printer, a speaker, and / or a network card. The exemplary input / output devices 24 may be included within the computing device 12 as one component constituting the computing device 12, or may be coupled to the computing device 12 as a separate device distinct from the computing device 12.

[0098] The above-described methods may be implemented in the form of program instructions that can be implemented in an application or executed by various computer components and stored in a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, and the like, alone or in combination.

[0099] The program instructions recorded on the computer-readable recording medium may be those specially designed and constructed for the present invention, or may be those well known and usable by those skilled in the computer software art.

[0100] Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, flash memory, etc.

[0101] Examples of program instructions include not only machine code, such as produced by a compiler, but also high level language code that may be executed by a computer using an interpreter, etc. The hardware devices may be configured to operate as one or more software modules to perform the processes of the present invention, and vice versa.

[0102] Although the present invention has been described with reference to the embodiments, those skilled in the art may make various modifications and variations of the present invention without departing from the spirit and scope of the present invention as set forth in the claims below. [Explanation of symbols]

[0103] 12: Computing equipment 14: Processor 16: Computer-readable storage media 20: Program 22: Input / Output Interface 24: Input / output device 26: Network communication interface 110: Application Server 120:DB server

Claims

1. one or more processors; and 1. A method executed on a computing device having a memory storing one or more programs to be executed by the one or more processors, comprising: Executing a hooking module when an encrypted column query request is received through an application in an application server to which the API is applied; The executed hooking module queries encrypted data from a database of a database management system (DBMS); and decrypts the retrieved encrypted data and transmits the decrypted data to the application; The step of querying comprises: obtaining, from the database, table-column information to which encryption has been applied; Parsing SQL executed through an application; and As a result of parsing, it is necessary to check whether there is an encryption target among the approaching table-column. The transmitting step includes: in the querying step, if the SQL statement is a column to be queried in a SELECT statement, decoding the user's data and transmitting the result value of the SQL statement to the application according to the type of the SQL statement; and In the step of querying, if the SQL statement is input data or comparison data other than a SELECT statement according to the type of SQL statement, modifying the SQL statement with the user's data encrypted and transmitting the modified SQL statement to the database management system; Data transmitted between the application server and the database management system is configured to be kept encrypted; The encrypted data is Encrypting or decrypting in the application in the application server to reduce load on the database management system; The application server includes: dbclient.dll, which is a DB client module used when executing SQL, is changed to the preset client_org.dll, and the dll file created for hooking is changed to the original name client.dll and managed. The application may include When the SQL is executed, the hooking module client.dll is loaded, and the loaded client.dll internally calls the original module client_org.dll to perform the encryption or decryption process.

2. A method for encrypting data stored in a database, comprising:

2. performing automatic encryption of input or modified data when a hooking module executed in an application server to which the API is applied inputs or modifies data in a database of a database management system (DBMS); The method for encrypting data stored in a database according to claim 1.

3. The step of performing encryption comprises: Select an encryption key and an encryption algorithm according to a predefined policy, and perform encryption after determining whether or not to encrypt the data. The method for encrypting data stored in a database according to claim 2.

4. one or more processors; and 1. A system including a computer device having a memory storing one or more programs executed by the one or more processors, A DB server that performs database management; and an application server including a hooking module that queries encrypted data through a DB client module when an encrypted column query request is received from a database of the DB server through an application, decrypts the queried encrypted data, and transmits the decrypted data to the application; The application server includes: Obtains encrypted table-column information from the database, parses the SQL executed through the application, and checks whether there is an encryption target among the tables-columns that are nearby based on the parsing result. Depending on the type of SQL statement, if the SQL statement is a column to be queried in a SELECT statement, the user's data is decrypted and the result value of the SQL statement is transmitted to the application, and if the SQL statement is input data or comparison data of a statement other than a SELECT statement, the SQL is modified with the user's data encrypted and transmitted to the database management system; Data transmitted between the application server and the database management system is configured to be kept encrypted; The encrypted data is Encrypting or decrypting in the application in the application server to reduce the load on the database management system; The application server includes: dbclient.dll, which is a DB client module used when executing SQL, is changed to the preset client_org.dll, and the dll file created for hooking is changed to the original name client.dll and managed. The application may include When the SQL is executed, the hooking module client.dll is loaded, and the loaded client.dll internally calls the original module client_org.dll to perform the encryption or decryption process. A database management system comprising:

Citation Information

Patent Citations

  • Connection method to external library function and recording medium in which the connection method is recorded and programmed

    JP1999110194A

  • User query processing system and method by query encryption transformation in database including encrypted column

    JP2009099151A

  • Function adding program and print control system

    JP2013168112A

  • Database encryption

    US20190286837A1

  • Method for encrypting database and method for real-time search thereof

    KR101476039B1