Data access methods, devices, storage media, and electronic devices
The data access method enhances data security by performing field-level protection operations on access requests, addressing the coarse protection granularity of existing technologies and effectively blocking unauthorized access.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2021-07-16
- Publication Date
- 2026-07-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing data protection technologies rely solely on privileges, providing coarse protection granularity and are ineffective against privileged users, leading to potential security issues.
Implementing a data access method that performs field-level data protection operations by analyzing access requests, determining controlled fields, and synthesizing access requests based on access parameters and request types to enhance security.
This approach provides flexible and effective field-level access control, protecting sensitive data by allowing only authorized access and blocking unauthorized access, ensuring real-time and transparent data security.
Smart Images

Figure 0007891464000010 
Figure 0007891464000011 
Figure 0007891464000012
Abstract
Description
Technical Field
[0006] , ,
[0001] (Cross - Reference to Related Applications) This disclosure is based on Chinese Patent Application CN202010688666.6, titled "Data Access Method, Apparatus, Storage Medium, and Electronic Device", filed on July 16, 2020, and claims the priority of the patent application. All of its disclosure content is incorporated herein by reference.
[0002] Embodiments of the present disclosure relate to the field of communications, specifically, to a data access method, apparatus, storage medium, and electronic device.
Background Art
[0003] With the advent of the big data era, the problem of user privacy leakage has become increasingly serious. At the same time, as various big data technologies emerge one after another, and new technology architectures, support platforms, and big data software emerge one after another, data security and privacy protection technologies are facing greater challenges.
[0004] In related technologies, in order to protect certain very sensitive information (such as credit cards, names, and identification numbers, or other data considered important), generally, authorization control and transparent encryption technologies are used. Transparent encryption prevents possible attackers from bypassing the database and directly reading sensitive information from memory by performing data encryption at the database layer.
[0005] Applications and users that have successfully passed the database authorization verification can continue to transparently access the encrypted data. Operating system users who attempt to read sensitive data in the table space file, and unauthorized persons who attempt to read disk or backup information are not permitted access to the plaintext data.
[0006] Simultaneously, privileged accounts can access any application program data within the database. Because privileged accounts and characters can access the database without restriction, they become a primary target for hackers and can also be exploited by internal personnel to obtain confidential information. Transparent encryption and privileges are ineffective against privileged users. Therefore, if the relevant technologies rely solely on privileges as a prerequisite and primary means of protecting sensitive fields, the level of protection is coarse, and there are potential security problems.
[0007] As can be seen, there is a problem with the coarse level of data protection in related technologies, which presents potential security issues.
[0008] Currently, no effective solutions have been proposed to address the above-mentioned problems in related technologies. [Overview of the project] [Problems that the invention aims to solve]
[0009] The embodiments of this disclosure provide data access methods, apparatus, storage media, and electronic devices to address the problem of coarse data protection granularity and potential security issues in at least the related technologies. [Means for solving the problem]
[0010] According to one embodiment of the present disclosure, a data access method is provided, which includes: receiving a first access request for requesting access to data in a database; parsing the first access request and obtaining data corresponding to the first access request, which is a first access parameter, a first request type, and a first controlled field list; performing a first data protection operation on the first controlled field list based on the first access parameter and the first request type and obtaining a target result; and synthesizing a second access request based on the target result and obtaining an access result by accessing the data in the database based on the second access request.
[0011] Another embodiment of the present disclosure provides a data access device comprising: a receiving module configured to receive a first access request for requesting access to data in a database; a acquiring module configured to parse the first access request and acquire data corresponding to the first access request, which is a first access parameter, a first request type, and a first controlled field list; an executing module configured to perform a first data protection operation on the first controlled field list based on the first access parameter and the first request type and acquire a target result; and an access module configured to synthesize a second access request based on the target result and acquire an access result by accessing data in the database based on the second access request.
[0012] According to another embodiment of the present disclosure, a computer-readable storage medium is further provided in which a computer program is stored, and the computer program is configured to perform the steps in any of the above embodiments of the method when it is executed.
[0013] Another embodiment of the present disclosure further provides an electronic device comprising a memory in which a computer program is stored, and a processor configured to execute the computer program and perform the steps in any of the embodiments of the above method. [Brief explanation of the drawing]
[0014] [Figure 1] This is a hardware configuration block diagram of a mobile terminal for a data access method according to an embodiment of the present disclosure. [Figure 2] This is a flowchart of the data access method according to the embodiment of this disclosure. [Figure 3] This is a flowchart of a data access method relating to a specific embodiment of the present disclosure. [Figure 4] This is a flowchart illustrating the operation of a management field-level security policy related to a specific embodiment of the present disclosure. [Figure 5] This is a flowchart of a field-level security policy relating to a specific example of the disclosure. [Figure 6] This is a diagram showing the configuration of a data protection device according to a specific embodiment of the present disclosure. [Figure 7] This is a flowchart of a data access method relating to a specific embodiment of the present disclosure. [Figure 8] This is a schematic diagram of an execution scene of a data access method according to a specific embodiment of this disclosure. [Figure 9] This is a block diagram of the configuration of a data access device according to an embodiment of the present disclosure. [Modes for carrying out the invention]
[0015] The embodiments of this disclosure will be described in detail below with reference to the drawings.
[0016] Note that terms such as "first", "second", etc. in the specification, claims, and drawings of the present disclosure are not used to describe a specific order or sequence, but are used to distinguish similar objects.
[0017] Examples of the method according to the embodiments of the present disclosure can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking the execution on a mobile terminal as an example, FIG. 1 is a hardware configuration block diagram of a mobile terminal of the data access method according to the embodiments of the present disclosure.
[0018] As shown in FIG. 1, the mobile terminal includes one or more (only one is shown in FIG. 1) processors 102 (the processor 102 includes a processing device such as a microprocessor MCU or a programmable logic device FPGA, but is not limited thereto) and a memory 104 configured to store data. The mobile terminal may further include a transmission device 106 and an input / output device 108 configured to perform a communication function.
[0019] As will be understood by those skilled in the art, the structure shown in FIG. 1 is schematic and does not limit the structure of the mobile terminal. For example, the mobile terminal may further include more or fewer components than those shown in FIG. 1, or may have a configuration different from that shown in FIG. 1.
[0020] The memory 104 may be configured to store software programs and modules of application software, for example, a computer program corresponding to the data access method in the embodiments of the present disclosure. The processor 102 executes the computer program stored in the memory 104 to perform various functional applications and data processing, that is, to implement the above method.
[0021] Memory 104 may include a high-speed random access memory, and may further include non-volatile memory such as, for example, one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some embodiments, memory 104 may further include memory that is remotely installed with respect to processor 102, and these remote memories may be connected to the mobile terminal via a network.
[0022] Examples of the above network include, but are not limited to, the Internet, a corporate intranet, a local area network, a mobile communication network, and combinations thereof.
[0023] Transmission device 106 is configured to transmit and receive data via one network. Specific examples of the above network may include a wireless network provided by a mobile terminal's communication carrier. In one embodiment, transmission device 106 includes a network adapter (abbreviated as NIC) that is connected to other network devices by a base station and can communicate with the Internet. In one embodiment, transmission device 106 may be a radio frequency (RF) module configured to communicate with the Internet wirelessly.
[0024] In this embodiment, a data access method is provided. FIG. 2 is a flowchart of the data access method according to an embodiment of the present disclosure. As shown in FIG. 2, the flow includes the following steps S202 to S208.
[0025] In step S202, a first access request for requesting access to data in a database is received.
[0026] In step S204, the first access request is analyzed, and data corresponding to the first access request, which is the first access parameter, the first request type, and the first controlled field list, is obtained.
[0027] In step S206, a first data protection operation is performed on the first controlled field list based on the first access parameter and the first request type, and the target result is obtained.
[0028] In step S208, a second access request is synthesized based on the target result, and the access result is obtained by accessing the data in the database based on the second access request.
[0029] In the above embodiment, the first access request may be SQL (Structured Query Language). After receiving the client's SQL, the SQL can be parsed to obtain the client's access parameters, request type, and list of controlled fields.
[0030] Next, a data protection operation can be performed on each field in the controlled field list, i.e., the first data protection operation can be performed. Once all controlled fields have been processed, the first SQL statement is reconstructed, a second access request is obtained, the database engine executes the first SQL statement, and the feedback result is fed back to the client. The client may be various applications, programs, commands, or scripts that access the database.
[0031] In the above embodiment, the access parameters include, but are not limited to, the original request such as the request SQL, user identity such as username, user group, and character, user access level, access time, and network parameters such as IP address and hostname.
[0032] In this disclosure, a first access request for requesting access to data in a database is analyzed to obtain a first access parameter, a first request type, and a first controlled field list corresponding to the first access request; a first data protection operation is performed on the first controlled field list based on the first access parameter and the first request type to obtain a target result; a second access request is then synthesized based on the target result, and the data in the database is accessed using the second access request.
[0033] By performing field-level data protection operations on access data, this approach solves the problem of coarse data protection granularity and potential security issues in related technologies, achieving efficient data protection and improving data security.
[0034] In one exemplary embodiment, the step of analyzing the access request and obtaining a first controlled field list corresponding to the first access request includes, if the first access request is a request of the Data Query Language (DQL) type, determining the top-level output field list of the DQL type request as the first controlled field list; and if the first access request is a request other than the DQL type, determining the target field list operated by the other request and determining the target field list as the first controlled field list.
[0035] In this embodiment, for DQL (Select query) type requests, the top-level output field list is first obtained, and then this top-level output field list can be used as the controlled field list. For other types of requests, the fields manipulated by the SQL statement are first analyzed, and the manipulated fields can be added to the controlled field list.
[0036] For example, for the following DQL type request, select ename,deptno,sal from emp where deptno= (select deptno from dept where loc=′NEW YORK′); The retrieved list of controlled fields is: emp.ename, dept.deptno, emp.sal; Furthermore, for example, for the following DML type update type request, UPDATE Customers SET ContactName=′Alfred Schmidt′, City = 'Frankfurt' WHERE Customer ID=1; The retrieved list of controlled fields is: These are Customers.ContactName and Customers.City.
[0037] In one exemplary embodiment, the step of performing a first data protection operation on the first controlled field list and obtaining a target result based on the first access parameter and the first request type includes: selecting one controlled field from the first controlled field list in a predetermined order as the first controlled field; determining a first field protection rule, a data security classification, and a data security level corresponding to the first controlled field, wherein different field protection rules correspond to different combinations of trust conditions, request types, and processing actions, and the trust conditions include permission conditions corresponding to the first access parameter; and performing the first data protection operation on the first controlled field and obtaining the target result based on the first processing action corresponding to the first field protection rule.
[0038] In this embodiment, a first controlled field can be selected from a list of controlled fields in a predetermined order, and a field protection rule corresponding to the first controlled field can be obtained. The field protection rule may include data security classification and data security level, etc.
[0039] By determining field protection rules, the data security level corresponding to the controlled field can be determined. The data security level itself can be one of a set of trust conditions, meaning that it is possible to determine whether the user's security level is equal to or greater than the data security level.
[0040] In this embodiment, when performing classification protection on the first controlled field, the same protection rules and data security levels can be set for fields of the same type. If the acquired data security level of the first controlled field is empty, the data security level of the data security classification of the first controlled field can be acquired as the data level of the first controlled field, or if the acquired data security level of the first controlled field is empty, the field protection rule of the data classification of the first controlled field can be acquired as the protection rule of the first controlled field.
[0041] In one exemplary embodiment, the step of performing the first data protection operation on the first controlled field based on the first processing operation corresponding to the first field protection rule and obtaining the target result includes: performing a set of trust conditions corresponding to the first field protection rule based on the obtained first access parameters, wherein the first access parameters include at least one of the original request statement, user identity, user access level, access time, and network parameters; determining a first operation type and a first operation factor included in the first processing operation based on the result of performing the set of trust conditions, wherein the first operation type indicates a specific protection operation, and the first operation factor indicates the specific protection operation operator name and the actual parameters of the object being processed; and obtaining the target result by performing protection processing on the first controlled field based on the first operation factor.
[0042] In this embodiment, based on the acquired first access parameters, a set of confidence conditions corresponding to the field protection rules of the first controlled field are executed, and based on the calculation results of the confidence conditions, a corresponding operation type is selected and a specific protection operation factor is executed. The above first processing operation represents a protection method to be performed on sensitive data and includes the operation type and operation factor.
[0043] The operation types may include access denial, access permission, display of original data, masking, encryption, decryption, anonymization, auditing, warning, and custom operations, and the operation factors may represent the name of the specific protection operation operator performed and the actual parameters, the actual parameters mainly consisting of the content to be processed in the first controlled field.
[0044] Furthermore, the operation type and operating factors can be customized and extended to accommodate data protection in different scenarios. For execution denial actions, the client can be directly fed back the result, and the flow can be terminated.
[0045] In one exemplary embodiment, the step of obtaining the target result by performing a protection operation on the first controlled field based on the first operating factor includes, if the first processing operation type includes one of a masking operation, an encryption operation, a decryption operation, anonymization operation, and a customization operation, the step of obtaining the target result by composing the first controlled field into a new SQL statement based on the first operating factor.
[0046] In this embodiment, for masking operations, encryption operations, decryption operations, anonymization operations, customization operations, etc., new SQL statements can be synthesized based on the operating factors in the field protection rules, and the original corresponding SQL statements can be replaced.
[0047] In one exemplary embodiment, the method further includes the step of deploying a field protection rule based on a first deployment command received, wherein the field protection rule comprises a combination of a request type, a set of trust conditions, and a processing action, wherein the request type comprises at least one of a Data Query Language (DQL) type and a Data Manipulation Language (DML) type, the trust conditions are for defining a basic decision unit of trusted access and comprise at least a trusted access type, a trusted access parameter name, a decision operator, and a parameter value, wherein the trusted access type comprises at least one of a Identity trust condition, a Level trust condition, a Network trust condition, and a Time trust condition, the decision operator comprises "greater than", "greater than or equal to", "less than or equal to", "less than", "equal to", and "not equal to", the processing action comprises an action type and an action factor, wherein the action type indicates a specific protection operation, the action factor indicates the specific protection action operator name and the actual parameter being processed, and the action type comprises at least one of Deny Access, Allow Access, Reveal Original Data, Masking, Encryption, Decryption, Anonymization, Audit, and Warning.
[0048] In this embodiment, a field protection rule can be placed and recorded based on a first placement command, and the field protection rule includes a combination of request type, trust conditions, and processing actions, the processing actions may include action types and action factors. Depending on different field protection methods for different command types (i.e., request types), the field protection rule can be combined in a logical operation expression of a command type and a set of trust conditions, and the corresponding action can be executed based on the execution result of the set of trust conditions. The command type includes at least a DQL type (Data Query Language), a DML type (Data Manipulation Language), and the logical operation may include AND, OR, and NOT operations.
[0049] In one exemplary embodiment, if the first access parameter includes the user's access level, the trust condition includes the level trust condition corresponding to the user's access level, and the level trust condition determines that the user's access level satisfies the level trust condition if it determines that the user's access level is equal to or greater than the data security level.
[0050] In this embodiment, the trust condition can define the basic decision unit for trusted access. The basic decision unit is at least: User identity is restricted and includes, but is not limited to, username, user group, character, etc. Based on the user's access level, data security level, and data security classification, a level of trust condition restricts the user from obtaining sensitive data. Restricting access to the network, network trust conditions include, but are not limited to, IP addresses and hostnames, Restrict access time and include one of the following time confidence conditions, which include but are not limited to access time.
[0051] The user's access level is used to describe the user's status level and includes the user's access level name and the user's access level value.
[0052] Furthermore, the data types for user access levels and data security levels must be of the same type and maintain the same order. Trust conditions may include trusted access types, trusted access parameter names, decision operators, and parameter values. Decision operators may include "greater than," "greater than or equal to," "less than or equal to," "less than," "equal to," and "not equal to."
[0053] In one exemplary embodiment, the method further includes the step of assigning a data security classification and a data security level corresponding to each controlled field based on a received second assignment command, wherein the data security levels corresponding to multiple controlled fields belonging to the same data security classification are the same. In this embodiment, the data security classification can be based on the service type of sensitive data and may include a classification name, a default data security level, and a default field protection rule. The data security level may include a data security level name and a data security level value, etc.
[0054] In the above embodiment, specifically, field protection rules can be set by the following steps 1 to 5.
[0055] Step 1 involves defining classification and leveling levels (including user access levels, data security levels, and data security classifications).
[0056] Step 2 involves setting the user's access level.
[0057] In Step 3, assign data protection classification types and data security levels to the sensitive fields.
[0058] In step 4, you set the confidence criteria.
[0059] In step 5, you will set up field protection rules.
[0060] In a preferred embodiment, the above method can be performed in a data access device, which includes a data protection module and a policy module for implementing sensitive data protection functions of a database engine. The device may be integrated into the database engine.
[0061] The data protection module can retrieve sensitive data protection policies from the policy module and perform corresponding data protection actions such as denying access, full masking, partial masking, encryption, anonymization, auditing, and alerting. The policy module includes a classification / leveling unit, a policy management unit, and a policy storage unit to provide policy support to the data protection module.
[0062] The classification and leveling unit is for classifying and managing users and data, including user access levels, data security levels, and data security types. The policy management unit is for managing data protection policies and providing policy access interfaces. The policy storage unit is for storing data protection policies.
[0063] The following describes data access with reference to specific embodiments.
[0064] Figure 3 is a flowchart of a data access method according to a specific embodiment of the present disclosure, and as shown in Figure 3, the flowchart includes the following steps S302 to S312.
[0065] In step S302, the client's access request is received.
[0066] In step S304, the client's access parameters are retrieved.
[0067] In step S306, the access request SQL is parsed to obtain the request type and the list of controlled fields.
[0068] In step S308, a data protection operation is performed one by one for each field in the above controlled field list.
[0069] In step S310, once processing of all controlled fields is complete, the first SQL statement is reconstructed.
[0070] In step S312, the database engine executes the first SQL statement described above and feeds the result back to the client.
[0071] The client may be various applications, programs, commands, or scripts that access the database, and its access parameters are: (1) The original request, including but not limited to the request SQL, (2) User identity including, but not limited to, username, user group, character, etc. (3) User access level and (4) Access time and (5) Network parameters including, but not limited to, IP addresses and hostnames, and may also include
[0072] The operation to obtain the list of controlled fields in step S306 may include the following steps.
[0073] For DQL (Select query) type requests, first, the top-level output field list is obtained, and then this top-level output field list is used as the controlled field list. For other types of requests, first, the fields manipulated by the SQL statement are analyzed, and the manipulated fields are added to the controlled field list.
[0074] In step S308, the data protection operation includes the following steps 1 to 3.
[0075] In step 1, the first controlled field is selected from the above-mentioned controlled field list in a predetermined order.
[0076] In Step 2, the data security classification, data security level, and field protection rules corresponding to the first controlled field described above are obtained.
[0077] Furthermore, when applying classification protection to sensitive fields, the same field protection rules and data security levels can be set for sensitive fields of the same type. If the acquired data security level of the first controlled field is empty, the data security level of the data security classification of the first controlled field is acquired as the data level of the first controlled field. If the acquired field protection rule of the first controlled field is empty, the field protection rule of the data classification of the first controlled field is acquired as the field protection rule of the first controlled field.
[0078] In step 3, a set of trust conditions corresponding to the field protection rules of the first controlled field described above are executed. Based on the calculation results of the trust conditions, the corresponding action type is selected, and the specific protection action factor is executed. For example, for an action to deny execution, the result is directly fed back to the client, and the flow is terminated. For actions such as masking, encryption, decryption, and anonymization, a new SQL statement is synthesized based on the action factor in the field protection rule, and the original corresponding SQL statement is replaced.
[0079] Figure 4 is an operational flowchart of a managed field-level security policy relating to a specific embodiment of the present disclosure, and as shown in Figure 4, the flow includes field protection rules, data security classifications, data security levels, and client access parameters.
[0080] Field protection rules define different field protection methods for different command types and may include a command type and a set of trust condition logical operation expressions, which can perform corresponding processing actions based on the execution result of the set of trust conditions. Command types include at least DQL types (Data Query Language) and DML types (Data Manipulation Language). Logical operations include, but are not limited to, AND, OR, and NOT operations.
[0081] Trust conditions can define the basic decision units for trusted access, and at a minimum, User identity is restricted and includes, but is not limited to, username, user group, character, etc. Based on the user's access level, data security level, and data security classification, a level of trust condition restricts the user from obtaining sensitive data. Restricting access to the network, network trust conditions include, but are not limited to, IP addresses and hostnames, Restrict access time and include one of the following time confidence conditions, which include but are not limited to access time.
[0082] A trust condition includes at least a trust access type, a trust access parameter name, a decision operator, and a parameter value. Decision operators include "greater than," "greater than or equal to," "less than or equal to," "less than," "equal to," and "not equal to."
[0083] The processing action describes the protection method performed on sensitive data and includes the action type and action factors. The action type includes at least one of the following actions: deny access, grant access, display original data, masking, encryption, decryption, anonymization, auditing, warning, and customization. The action factors represent the specific protection action operator name and actual parameters performed. Note that the action type and action factors can be customized and extended to accommodate data protection in different scenarios.
[0084] Data security classifications can be based on the service type of sensitive data and include at least a classification name, a default data security level, and default field protection rules.
[0085] The data security level includes at least the data security level name and the data security level value.
[0086] The parameters included in the client's access parameters are basically the same as those described above, and therefore will not be explained here. The user's access level is used to describe the user's status level and includes at least the user's access level name and user's access level value. Furthermore, the data types of the user's access level and the data security level must be the same and maintain the same order.
[0087] By using the above steps, it is possible to flexibly and effectively provide field-level access control and attack defense functions based on policies, support various command types, allow access and retrieve sensitive data based on various combinations of trust factors, enable sensitive data access permission or dynamic data retrieval based on elements such as username, IP address, and access time, restrict users to retrieve only fully decrypted original data, partially masked data, tagged data, anonymized data, etc., that they have been authorized to access, based on the data confidentiality level and user identity level, and effectively block unauthorized access by enabling different displays when different users access the same sensitive data.
[0088] At the same time, by directly utilizing the processing power of the database engine itself, private data can be protected efficiently, in real time, and transparently, and users will not even be aware of the data protection process.
[0089] Figure 5 is a flowchart of a field-level security policy relating to a specific embodiment of the present disclosure, and as shown in Figure 5, the flowchart includes the following steps S502 to S510.
[0090] Step S502 defines the classification and leveling levels.
[0091] Step S502-1 defines the user's access level.
[0092] Users can be categorized according to their user privilege level, or according to their user group type (e.g., low-privilege user group, partial-privilege user group, or high-privilege user group), and further categorized according to their geographical location (e.g., China, Europe, or North America). As shown in Table 1, Table 1 is an overview table of user classification access levels.
[0093] [Table 1]
[0094] Step S502-2 defines the data security level.
[0095] Sensitive fields may be categorized according to the confidentiality of the data (e.g., public, secret, confidential, or top secret), or according to the department to which the data belongs (core departmental data, non-core departmental data). As shown in Table 2, Table 2 is an overview table of data security levels.
[0096] [Table 2]
[0097] Step S502-3 defines the data security classification.
[0098] Data protection classification categorizes sensitive data and identifies data of the same type and with similar functional meaning. For example, if "identity card number" is considered one type of sensitive data, then data fields for identity card numbers can be managed across all databases, and a unified default data level and default field protection rules can be implemented for that type. As shown in Table 3, Table 3 is an overview table of data security levels.
[0099] [Table 3]
[0100] Step S504 sets the user's access level.
[0101] As shown in Table 4, Table 4 is a schematic table for assigning access levels to users.
[0102] [Table 4]
[0103] In step S506, a data protection classification type and data security level are assigned to the sensitive field.
[0104] As shown in Table 5, Table 5 is a schematic table that assigns data protection classification types and data security levels to sensitive fields.
[0105] [Table 5]
[0106] In step S508, the confidence conditions are set.
[0107] As shown in Table 6, Table 6 is a summary table of confidence conditions.
[0108] [Table 6]
[0109] In step S510, you configure the field protection rules.
[0110] Field protection rules define different field protection methods for different command types and may include a command type and a logical operation expression for a set of trust conditions, which can then perform corresponding actions based on the execution results of the set of trust conditions.
[0111] As shown in Table 7, Table 7 is an overview table of field protection rules.
[0112] [Table 7]
[0113] As shown in Table 8, Table 8 is an overview of the processing operations.
[0114] [Table 8]
[0115] The above method allows for the flexible and effective provision of protection policies, enabling flexible control of database access methods and content based on the policy, and effectively blocking unauthorized access.
[0116] Figure 6 is a diagram of the configuration of a data protection device according to a specific embodiment of the present disclosure. The methods described above can all be executed using the network architecture shown in Figure 6, and as shown in Figure 6, the device includes a database client 62, a database engine 64, and a database 66.
[0117] The database client 62 may be an application, program, command, or script that accesses the database service, and is used to initiate access requests to the database engine over the network and to receive processing results. The client uses conventional technology and requires no modifications.
[0118] The database engine 64 is for completing the logical processing for the services requested by the client. A data protection device can be added to the database engine, which includes a data protection module and a policy module, and is for implementing sensitive data protection functions of the database engine. The data protection device is built into the database engine.
[0119] The data protection module can retrieve sensitive data protection policies from the policy module and perform corresponding data protection actions such as denying access, masking, encryption, decryption, anonymization, auditing, and alerting. The policy module includes a classification / leveling unit, a policy management unit, and a policy storage unit to provide policy support to the data protection module.
[0120] The classification and leveling unit is for classifying and managing users and data, including user access levels, data security levels, and data security types. The policy management unit is for managing data protection policies and providing policy access interfaces. The policy storage unit is for storing data protection policies.
[0121] Database 66 may also be the place where data is actually stored, and one database engine can support multiple database instances. After receiving an access request from a client, the database engine parses the access request with the receiving module and obtains the client's access parameters, parses the access request SQL with the data protection module and obtains the request type and the list of controlled fields, performs one data protection operation on each field in the list of controlled fields, and once all controlled fields have been processed, reconstructs the first SQL statement, executes the first SQL statement, and feeds the result back to the client.
[0122] For SQL-type database engines (including, but not limited to, Hive and SparkSQL), using the Hive database as an example, Figure 7 is a flowchart of a data access method according to a specific embodiment of the present disclosure, and as shown in Figure 7, the flow includes the following steps S702 to S734.
[0123] In step S702, the Hive client (Hive is a Hadoop-based data warehouse tool that can map structured data files to database tables and provide similar SQL query functionality) directly initiates an SQL access request to the Hive database engine over the network.
[0124] In step S704, the Hive database engine retrieves the client's access parameters. The access parameters are at least: (1) The original request, including but not limited to the request SQL, (2) User identity including, but not limited to, username, user group, character, etc. (3) User access level and (4) Access time and (5) Network parameters including, but not limited to, IP addresses and hostnames, and one of the following.
[0125] In step S706, the Hive database engine's SQL parser analyzes the SQL statement in the original request, builds a syntax tree, further abstracts and structures the SQL, and generates a reconstructed abstract syntax tree.
[0126] In step S708, the abstract syntax tree is analyzed, the request SQL statement is analyzed, the request type of the SQL statement is obtained, the top-level output field list is obtained as the controlled field list for DQL type requests, and for other types of requests, the fields manipulated by the SQL statement are first analyzed and the manipulated fields are added to the controlled field list.
[0127] In step S710, the command type is determined. If the command type is DQL, step S712 is executed. If the command type is not DQL, step S714 is executed.
[0128] In step S712, the top-level output field list is generated as the controlled field list.
[0129] Taking a DQL-type query as an example, select ename,deptno,sal from emp where deptno= (select deptno from dept where loc=′NEW YORK′); In this step, the list of controlled fields obtained is: These are emp.ename, dept.deptno, and emp.sal.
[0130] emp and dept are database table names, while the others are field names.
[0131] In step S714, the field name is obtained and added to the list of controlled fields.
[0132] Taking a DML-type update statement as an example, UPDATE Customers SET ContactName=′Alfred Schmidt′,City=′Frankfurt′ WHERE Customer ID=1; In this step, the list of controlled fields obtained is: These are Customers.ContactName and Customers.City.
[0133] "Customers" is the database table name, while the others are field names.
[0134] In step S716, a first controlled field is selected from the controlled field list in a predetermined order, and the data protection classification, data security level, and field protection rule corresponding to the first controlled field are obtained.
[0135] As shown in Table 9, Table 9 is an overview of the field protection rules obtained.
[0136] [Table 9]
[0137] In particular, if the acquired data security level of the first controlled field is empty, the data security level of the data classification of the first controlled field is acquired as the data security level of the first controlled field. In particular, if the field protection rule for the first controlled field obtained is empty, the field protection rule for the data classification of the first controlled field is obtained as the protection rule for the first controlled field.
[0138] In step S718, a set of confidence conditions corresponding to the field protection rule for the first controlled field described above is executed, and based on the calculation results of the confidence conditions, the corresponding operation type is selected and a specific protection operation factor is executed.
[0139] In step S720, the operation type is determined. If the operation type is "deny execution," step S722 is executed. If the operation type is masking, encryption, decryption, anonymization, etc., step S724 is executed. If the operation type is auditing, step S726 is executed.
[0140] In step S722, the results are directly fed back to the client, and the flow is terminated.
[0141] In step S724, a new SQL statement is synthesized based on the operating factors in the field protection rule, and the original corresponding SQL statement is replaced.
[0142] For example, for the ename field, the protection rule for its select statement type is Selector2->Action1, which executes the Selector2 check, i.e., whether the user's access level value is less than the data protection level value. If so, the Action1 operation is executed, i.e., execution is denied; otherwise, execution continues. For the sal field, the protection rule for its select statement type is Selector1->Action2, which executes the Selector1 check, i.e., whether the user is Zhang San. If so, the Action2 operation is executed, i.e., partialMask(sal,1,'*',100) is executed as the partial masking algorithm. In this step, the SQL statement partialMask(sal,1, '*',100) is replaced with the original value sal of the abstract syntax tree node corresponding to the controlled field sal.
[0143] Step S726 involves auditing.
[0144] In step S728, it is determined whether processing of all fields is complete. If the result is YES, step S730 is executed; if the result is NO, step S716 is executed.
[0145] In step S730, the abstract syntax tree is traversed, the first SQL statement is reconstructed, and it is determined that the above first SQL statement is the SQL statement that was ultimately executed.
[0146] select ename,deptno,partialMask(sal,1, '*',100) from emp where deptno= (select deptno from dept where loc=′NEW YORK′); The rewritten SQL statement automatically applies partial masking to the sensitive field `sal`.
[0147] Similarly, for the following SQL statement, UPDATE Customers SET ContactName=′Alfred Schmidt′,City=′Frankfurt′ WHERE Customer ID=1; Based on the protection rules, you may rewrite it as follows: UPDATE Customers SET ContactName=Mask(′Alfred Schmidt′, '*'),City=′Frankfurt′ WHERE Customer ID=1; Mask is a protective behavioral factor that sets the string to *.
[0148] In step S732, the database executes the rewritten SQL statement.
[0149] In step S734, the database feeds back the processing results to the client based on the SQL statement that was ultimately executed.
[0150] By using the above steps, it is possible to flexibly and effectively provide field-level access control and attack defense functions based on policies, support various command types, allow access and retrieve sensitive data based on various combinations of trust factors, enable sensitive data access permission or dynamic data retrieval based on elements such as username, IP address, and access time, restrict users to retrieve only fully decrypted original data, partially masked data, tagged data, anonymized data, etc., that they have been authorized to access, based on the data confidentiality level and user identity level, and effectively block unauthorized access by enabling different displays when different users access the same sensitive data. At the same time, by directly utilizing the processing power of the database engine itself, private data can be protected efficiently, in real time, and transparently, and users will not be aware of the data protection process at all.
[0151] A large amount of sensitive data is stored in the Hive database, and by setting flexible data protection policies, sensitive data in the Hive database can be protected transparently and in real time during the client access process. Figure 8 is a schematic diagram of the execution scene of the data access method according to a specific embodiment of this disclosure, and the following steps 1 to 4 are performed.
[0152] In Step 1, the compliance administrator logs in to the database system using their account and password.
[0153] In Step 2, the protection policy is configured, and the compliance administrator configures the field protection policy using either a command-line method or an interface deployment method.
[0154] In step 3, the user initiates an access request via the client, specifically by directly initiating a query request to the database engine.
[0155] In step 4, data protection is performed. Specifically, after the database engine receives the client's access request, the receiving module parses the access request and obtains the client's access parameters. The data protection module parses the access request SQL and obtains the request type and the list of controlled fields. One data protection operation is performed for each field in the list of controlled fields. Once all controlled fields have been processed, the database engine reconstructs the first SQL statement, executes the first SQL statement, and feeds the results back to the client.
[0156] Steps 1 and 2 are performed by the compliance manager, step 3 is performed by the user, and step 4 is performed by the data protection device.
[0157] From the above description of the embodiments, those skilled in the art will clearly understand that the methods according to the above embodiments may be implemented by combining software and a necessary general-purpose hardware platform, or of course by hardware alone, but in many cases the former is a preferred embodiment. Based on this understanding, the substantial or prior art contributions of the proposed technologies of this disclosure are embodied in the form of a software product, which is stored on a storage medium (e.g., ROM / RAM, magnetic disk, optical disk) and includes several instructions that cause a terminal device (which may be a mobile phone, computer, server, network device, etc.) to execute the methods described in each embodiment of this disclosure.
[0158] In this embodiment, a data access device is also provided, which is used to implement the above embodiment and preferred embodiment, and has already been described, so a repeated description is omitted. The term "module" as used below can implement a combination of software and / or hardware with a predetermined function. The devices described in the following embodiments are preferably implemented in software, but may be implemented in hardware, or a combination of software and hardware.
[0159] Figure 9 is a block diagram of a data access device according to an embodiment of the present disclosure, and as shown in Figure 9, the device is A receiving module 92 is configured to receive a first access request for requesting access to data in the database, An acquisition module 94 is configured to analyze the above-mentioned first access request and acquire data corresponding to the above-mentioned first access request, which consists of a first access parameter, a first request type, and a first controlled field list. An execution module 96 is configured to perform a first data protection operation on the first controlled field list and obtain a target result based on the first access parameter and the first request type described above, The system includes an access module 98 configured to synthesize a second access request based on the above target result, and to obtain an access result by accessing data in the database based on the above second access request.
[0160] The data access device corresponds to the database engine shown in Figure 6, the receiving module 92 corresponds to the receiving module shown in Figure 6, the execution module 96 corresponds to the data protection module shown in Figure 6, and the access module 98 corresponds to the execution engine. Specifically, the acquisition module 94 corresponds to the classification / leveling unit in the policy module, and the access module 98 corresponds to the policy storage unit and policy management unit in the policy module.
[0161] In one exemplary embodiment, the acquisition module 94 can analyze the access request in the following manner and obtain a first controlled field list corresponding to the first access request. If the first access request is a request of the Data Query Language (DQL) type, the top-level output field list of the DQL type request is determined as the first controlled field list. If the first access request is a request other than a DQL type request, the target field list operated by the other request is determined, and the target field list is determined as the first controlled field list.
[0162] In one exemplary embodiment, the execution module 96 can perform a first data protection operation on the first controlled field list and obtain a target result based on the first access parameter and the first request type in the following manner: Select one controlled field from the first controlled field list in a predetermined order as the first controlled field, determine a first field protection rule, data security classification, and data security level corresponding to the first controlled field, the different field protection rules correspond to different combinations of trust conditions, request types, and processing operations, the trust conditions include permission conditions corresponding to the first access parameter, and perform the first data protection operation on the first controlled field and obtain the target result based on the first processing operation corresponding to the first field protection rule.
[0163] In one exemplary embodiment, the execution module 96 can perform the first data protection operation on the first controlled field and obtain the target result based on a first processing operation corresponding to the first field protection rule in the following manner: Based on the obtained first access parameters, a set of trust conditions corresponding to the first field protection rule is executed, the first access parameters include at least one of the original request statement, user identity, user access level, access time, and network parameters; based on the execution result of the set of trust conditions, a first operation type and a first operation factor included in the first processing operation are determined; the first operation type indicates a specific protection operation; the first operation factor indicates the specific protection operation operator name and the actual parameters of the target of processing; and based on the first operation factor, the target result is obtained by performing protection processing on the first controlled field.
[0164] In one exemplary embodiment, the execution module 96 can obtain the target result by performing protection processing on the first controlled field based on the first operating factor in the following manner. If the first processing operation type includes one of masking, encryption, decryption, anonymization, and customization, the target result is obtained by composing the first controlled field into a new SQL statement based on the first operating factor.
[0165] In one exemplary embodiment, the device is configured to deploy a field protection rule based on a first deployment command received, the field protection rule comprising a combination of a request type, a set of trust conditions, and a processing action, wherein the request type comprises at least one of a Data Query Language (DQL) type and a Data Manipulation Language (DML) type, the trust conditions are for defining a basic decision unit of trusted access and comprise at least a trusted access type, a trusted access parameter name, a decision operator, and a parameter value, the trusted access type comprises at least one of a Identity trust condition, a Level trust condition, a Network trust condition, and a Time trust condition, the decision operator comprises "greater than", "greater than or equal to", "less than or equal to", "less than", "equal to", and "not equal to", the processing action comprises an action type and an action factor, wherein the action type indicates a specific protection operation, the action factor indicates the specific protection action operator name and the actual parameter being processed, and the action type comprises at least one of Deny Access, Allow Access, Display Original Data, Masking, Encryption, Decryption, Anonymization, Audit, and Warning.
[0166] In one exemplary embodiment, if the first access parameter includes the user's access level, the trust condition includes the level trust condition corresponding to the user's access level, and the level trust condition determines that the user's access level satisfies the level trust condition if it determines that the user's access level is equal to or greater than the data security level.
[0167] In one exemplary embodiment, the device is further configured to assign data security classifications and data security levels corresponding to each controlled field based on a received second assignment command, wherein the data security levels corresponding to multiple controlled fields belonging to the same data security classification are the same.
[0168] Each of the above modules can be implemented using software or hardware. In the latter case, the modules can be implemented in a way that all of them are located on the same processor, or in a way that each of the modules is located on a different processor in any combination, but is not limited to these two methods.
[0169] In embodiments of the present disclosure, a computer-readable storage medium is further provided in which a computer program is stored, and the computer program is configured to perform the steps of any of the embodiments of the above method when executed.
[0170] In one exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB disks, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical disks.
[0171] In embodiments of the present disclosure, an electronic device is provided that further includes a memory in which a computer program is stored, and a processor configured to execute the computer program and perform the steps in any of the embodiments of the above method.
[0172] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, the transmission device being connected to the processor, and the input / output device being connected to the processor.
[0173] Specific examples in this embodiment can be found by referring to the examples described in the above embodiment and exemplary embodiment; therefore, this embodiment will not be described again here.
[0174] Clearly, those skilled in the art will understand that each module or step in the above-described disclosure may be implemented on a general-purpose computing device, they may be concentrated on a single computing device, or they may be distributed across a network of multiple computing devices, and they may be implemented as program code executable on a computing device, and that they may be stored in a memory device and executed on a computing device, and in some cases the illustrated or described steps may be executed in an order different from that specified herein, or they may be implemented by creating each of them on an integrated circuit module, or by creating multiple of them on a single integrated circuit. Thus, the disclosure is not limited to any particular combination of hardware and software.
[0175] The foregoing are merely preferred embodiments of the Disclosure and do not limit the Disclosure, and those skilled in the art can make various modifications and changes to the Disclosure. Any modifications, equivalent substitutions, and improvements made within the principles of the Disclosure should be within the scope of protection of the Disclosure.
Claims
1. A data access method applied to a database, The steps include receiving a first access request to request access to data in the database, A step of analyzing the first access request and obtaining data corresponding to the first access request, which is a first access parameter, a first request type, and a first controlled field list, wherein if the first access request is a request of the data query language DQL type, the top-level output field list of the DQL type request is determined as the first controlled field list, and if the first access request is a request other than the DQL type request, the target field list operated by the other request is determined and the target field list is determined as the first controlled field list. The steps include: selecting one controlled field from the first controlled field list in a predetermined order as the first controlled field; determining a first field protection rule, data security classification, and data security level corresponding to the first controlled field, where different field protection rules correspond to different combinations of trust conditions, request types, and processing operations, the trust conditions include permission conditions corresponding to the first access parameters; and performing the first data protection operation on the first controlled field based on the first processing operation corresponding to the first field protection rule to obtain the target result. The process includes the steps of synthesizing a second access request based on the aforementioned target result, and obtaining an access result by accessing data in the database based on the second access request, Data access method.
2. The steps of performing a first data protection operation on the first controlled field and obtaining the target result based on a first processing operation corresponding to the first field protection rule are: A step of performing a set of trust conditions corresponding to a first field protection rule based on a first access parameter obtained, wherein the first access parameter includes at least one of the original request statement, user identity, user access level, access time, and network parameters. A step of determining a first operation type and a first operation factor included in the first processing operation based on the execution result of a set of trust conditions, wherein the first operation type specifies a specific protection operation, and the first operation factor specifies the specific protection operation operator name and the actual parameters of the processing target, The process includes the step of obtaining the target result by performing a protection process on the first controlled field based on the first operating factor, The method according to claim 1.
3. The step of obtaining the target result by performing a protection process on the first controlled field based on the first operating factor is: If the first operation type includes one of masking, encryption, decryption, anonymization, and customization, the process includes the step of obtaining the target result by composing the first controlled field into a new SQL statement based on the first operation factor. The method according to claim 2.
4. The process further includes the step of deploying a field protection rule based on a first deployment command received, wherein the field protection rule includes a combination of request type, a set of trust conditions, and a processing action. The aforementioned request type includes at least one of the Data Query Language (DQL) type and the Data Manipulation Language (DML) type. The aforementioned trust conditions are for defining the basic decision unit of trusted access and include at least the trusted access type, trusted access parameter name, decision operator, and parameter value. The aforementioned trust access type includes at least one of the following: identity trust conditions, level trust conditions, network trust conditions, and time trust conditions. The aforementioned determination operators include "greater than", "greater than or equal to", "less than or equal to", "less than", "equal to", and "not equal to", The processing operation includes an operation type and an operation factor, the operation type instructs a specific protection operation, and the operation factor instructs the specific protection operation operator name and the actual parameters of the object being processed. The aforementioned operation type includes at least one of the following: deny access, grant access, display original data, masking, encryption, decryption, anonymization, audit, and warning. The method according to claim 2.
5. If the first access parameter includes the user's access level, the trust condition includes the level trust condition corresponding to the user's access level, and the level trust condition determines that the user's access level is equal to or greater than the data security level, and that the user's access level satisfies the level trust condition. The method according to claim 4.
6. The process further includes the step of assigning a data security classification and data security level to each controlled field based on a second assignment command received, wherein the data security levels for multiple controlled fields belonging to the same data security classification are the same. The method according to claim 5.
7. A receiving module configured to receive a first access request for requesting access to data in a database, An acquisition module configured to analyze the first access request and acquire data corresponding to the first access request, which includes a first access parameter, a first request type, and a first list of controlled fields; An executable module is configured to select one controlled field as the first controlled field in a predetermined order from the first controlled field list, determine a first field protection rule, data security classification, and data security level corresponding to the first controlled field, where different field protection rules correspond to different combinations of trust conditions, request types, and processing operations, the trust conditions include permission conditions corresponding to the first access parameters, and to perform the first data protection operation on the first controlled field and obtain a target result based on the first processing operation corresponding to the first field protection rule. Includes an access module configured to synthesize a second access request based on the aforementioned target result, and to obtain an access result by accessing data in the database based on the second access request, Data access device.
8. A computer-readable storage medium on which computer programs are stored, The computer program is configured to perform the method described in any one of claims 1 to 6 when it is executed. A computer-readable storage medium.
9. A computer includes a memory in which a computer program is stored, and a processor configured to execute the computer program and perform the method according to any one of claims 1 to 6, electronic equipment.