Method for SQL engine to execute security policy, and SQL engine

By obtaining the software sources for different types of security policies for the SQL engine, the problem of strong binding between data security policies and a single software on the SQL engine is solved, and the flexibility of the data security system and the improvement of user experience is achieved.

WO2025123968A1PCT designated stage expired Publication Date: 2025-06-19HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Patent Information

Application Number
PCT/CN2024/128171
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-23
Filing Date
2024-10-29
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

In the prior art, the various data security policies configured by the SQL engine must rely on a certain software (for example, Apache Ranger), resulting in a relatively rigid data security system and reducing the user experience.

Method used

By obtaining software sources for different types of security policy configurations for each SQL engine, the SQL engine allows the SQL engine to flexibly use data security policies provided by different software, avoiding strong binding relationships with one software.

Benefits of technology

It realizes the flexibility of the data security system, improves the user experience, allows multiple security protection to take effect at the same time, and enhances the security and privacy protection of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128171_19062025_PF_FP_ABST
    Figure CN2024128171_19062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application is a method for an SQL engine to execute a security policy. The method is applied to a database system, wherein the database system comprises a database and at least one SQL engine, the at least one SQL engine being used for acquiring, on the basis of an SQL statement, data stored in the database. The method comprises: an SQL engine acquiring first configuration information, wherein the first configuration information is used for indicating that different types of security policies executed on the SQL engine are each configured with at least one respective corresponding software source, and the at least one software source corresponding to each of the different types of security policies is not exactly the same; and on the basis of the first configuration information, the SQL engine executing the corresponding security policies respectively provided by the different software sources indicated in the first configuration information, so as to protect the security and / or privacy of data stored in a database. The method can make a data security system relatively flexible, thereby improving the experience of users.
Need to check novelty before this filing date? Find Prior Art

Description

Method for SQL engine to execute security policy and SQL engine

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 15, 2023, with application number 202311733024.3, entitled “Method for using SQL engine and computing device”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 23, 2024, with application number 202410095005.0, entitled “Method for executing security policy by SQL engine and SQL engine”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of databases, and more specifically, to a method for executing a security policy using a structured query language (SQL) engine, an SQL engine, and a computing device. Background Art

[0003] Ensuring data security and privacy is crucial for enterprise-level applications. As the underlying computing engine of the data stack, the database engine (for example, the SQL engine) must ensure that data is accessible only to authorized personnel to prevent data leakage and misuse. Specifically, by configuring a data security policy for the SQL engine, the SQL engine can protect data security and privacy according to the configured data security policy.

[0004] In related technical solutions, if a SQL engine uses software that provides data security policies (e.g., Apache Ranger), then all data security policies configured on the SQL engine must rely on this software (e.g., Apache Ranger). This makes the current data security system rather rigid and reduces the user experience.

[0005] In view of this, how to make the data security system more flexible and thus improve the user experience has become a technical problem that needs to be solved urgently.

[0006] Summary of the Invention

[0007] This application provides a method for an SQL engine to execute security policies, which can make the data security system more flexible and improve the user experience.

[0008] In a first aspect, a method for an SQL engine to execute security policies is provided, which is applied to a database system, wherein the database system includes a database and at least one SQL engine, and the at least one SQL engine is used to obtain data stored in the database according to SQL statements. The method includes: each of the SQL engines respectively obtains first configuration information, and the first configuration information is used to indicate at least one software source corresponding to different types of security policy configurations executed on the SQL engine, and the at least one software source corresponding to the different types of security policies is not exactly the same; each of the SQL engines protects the security and / or privacy of the data stored in the database by executing the corresponding security policies provided by different software sources indicated in the first configuration information according to the first configuration information.

[0009] The above technical solution enables the SQL engine to flexibly use data security policies provided by different software, avoiding the strong binding relationship between all types of data security policies on the SQL engine and one software, making the data security system more flexible and improving the user experience.

[0010] In combination with the first aspect, in certain implementations of the first aspect, each of the SQL engines obtains the first configuration information through at least one of the following methods: an interface, a configuration file, or a visual configuration interface of each of the SQL engines.

[0011] In combination with the first aspect, in certain implementations of the first aspect, the different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include a first software and a second software. Each SQL engine determines that the SQL engine has passed the security verification of the first type of security policy when it passes the verification of the first type of security policy provided by the first software and the second software respectively.

[0012] In the above technical solution, multiple security protections can be effective at the same time, thereby better protecting the security and / or privacy of data.

[0013] In combination with the first aspect, in certain implementations of the first aspect, the method further includes: each of the SQL engines separately obtains second configuration information, and the second configuration information is used to configure the SQL engine to execute part of the security policies or all of the security policies of the different types; each of the SQL engines separately executes part of the security policies or all of the security policies of the different types according to the second configuration information received.

[0014] The above technical solution can enable the SQL engine to flexibly use some or all of various types of security policies, making the data security system more flexible and improving the user experience.

[0015] In combination with the first aspect, in certain implementations of the first aspect, the different types of security policies include at least two of the following: security policies of data access permission control type, security policies of data desensitization type, and security policies of data row-level filtering type.

[0016] In combination with the first aspect, in certain implementations of the first aspect, the software source includes: Ranger, Hive metadata repository (Hive meta store, HMS), and Hive access permission list ACL.

[0017] In combination with the first aspect, in certain implementations of the first aspect, the method is applied to a cloud management platform, which is used to manage the infrastructure for providing cloud services, the infrastructure including at least one cloud data center, each of which is provided with at least one server, and the SQL engine is running in the at least one server.

[0018] In a second aspect, a SQL engine is provided, the SQL engine being located in a database system that also includes a database. The SQL engine is configured to obtain data stored in the database based on SQL statements, and the SQL engine includes: an acquisition module and a processing module. The acquisition module is configured to obtain first configuration information, the first configuration information being configured to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, the at least one software source corresponding to each of the different types of security policies being different; and the processing module is configured to protect the security and / or privacy of the data stored in the database by executing, based on the first configuration information, the corresponding security policies provided by each of the different software sources indicated in the first configuration information.

[0019] In combination with the second aspect, in some implementations of the second aspect, the acquisition module is specifically used to: obtain the first configuration information through at least one of the following methods: an interface, a configuration file, or a visual configuration interface of the SQL engine.

[0020] In combination with the second aspect, in certain implementations of the second aspect, the different types of security policies include a first type of security policy, the software sources corresponding to the first type of security policy include a first software and a second software, and the processing module is specifically used to: determine that the SQL engine passes the security verification of the first type of security policy when the first type of security policy provided by the first software and the second software are verified respectively.

[0021] In combination with the second aspect, in certain implementations of the second aspect, the acquisition module is further used to obtain second configuration information, and the second configuration information is used to configure the SQL engine to execute some or all of the different types of security policies; the processing module is further used to execute some or all of the different types of security policies based on the second configuration information.

[0022] In combination with the second aspect, in certain implementations of the second aspect, the different types of security policies include at least two of the following: security policies of data access permission control type, security policies of data desensitization type, and security policies of data row-level filtering type.

[0023] In combination with the second aspect, in certain implementations of the second aspect, the software source includes: Apache Ranger, Hive metadata repository HMS, and Hive access permission list ACL.

[0024] In combination with the second aspect, in certain implementations of the second aspect, the SQL engine runs in at least one server, the at least one server is located in at least one cloud data center, and the at least one server is an infrastructure for providing cloud services managed by a cloud management platform.

[0025] It should be understood that the beneficial effects of the second aspect and its various implementations can be referred to the beneficial effects of the first aspect and its various implementations, and will not be repeated here.

[0026] In a third aspect, a database system is provided, which includes a database and at least one SQL engine as provided in the second aspect and any one of the implementations of the second aspect, wherein the at least one SQL engine is used to obtain data stored in the database according to an SQL statement.

[0027] In a fourth aspect, a computing device is provided, comprising a processor and a memory, and optionally, an input / output interface. The processor is configured to control the input / output interface to send and receive information, the memory is configured to store a computer program, and the processor is configured to retrieve and execute the computer program from the memory, so that the computing device performs the method of the first aspect or any possible implementation of the first aspect.

[0028] Optionally, the processor may be a general-purpose processor, which may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like; when implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory, which may be integrated into the processor or located independently of the processor.

[0029] In a fifth aspect, a computing device cluster is provided, comprising at least one computing device, each computing device comprising a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method in the first aspect or any possible implementation of the first aspect.

[0030] In a sixth aspect, a chip is provided, which obtains instructions and executes the instructions to implement the method in the above-mentioned first aspect and any implementation manner of the first aspect.

[0031] Optionally, as an implementation, the chip includes a processor and a data interface, and the processor reads instructions stored in the memory through the data interface to execute the method in the above-mentioned first aspect and any implementation of the first aspect.

[0032] Optionally, as an implementation method, the chip may also include a memory, in which instructions are stored, and the processor is used to execute the instructions stored on the memory. When the instructions are executed, the processor is used to execute the method in the first aspect and any one of the implementation methods of the first aspect.

[0033] In a seventh aspect, a computer program product comprising instructions is provided, which, when executed by a computing device, enables the computing device to execute the method in the first aspect and any one of the implementations of the first aspect.

[0034] In an eighth aspect, a computer program product comprising instructions is provided. When the instructions are executed by a computing device cluster, the computing device cluster executes the method in the first aspect and any one of the implementations of the first aspect.

[0035] In a ninth aspect, a computer-readable storage medium is provided, comprising computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method as described in the first aspect and any one of the implementations of the first aspect.

[0036] By way of example, these computer-readable storages include, but are not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM), and a hard drive.

[0037] Optionally, as an implementation manner, the above-mentioned storage medium may specifically be a non-volatile storage medium.

[0038] In a tenth aspect, a computer-readable storage medium is provided, comprising computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method as described in the first aspect and any one of the implementations of the first aspect.

[0039] By way of example, these computer-readable storages include, but are not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM), and a hard drive.

[0040] Optionally, as an implementation manner, the above-mentioned storage medium may specifically be a non-volatile storage medium. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] FIG1 is a schematic block diagram of a cloud scenario applicable to an embodiment of the present application.

[0042] FIG2 is a schematic flowchart of a method for executing a security policy in an SQL engine according to an embodiment of the present application.

[0043] FIG3 shows the correspondence between multiple data security policies and security policy sources of an SQL engine provided in an embodiment of the present application.

[0044] FIG4 is a schematic block diagram of software sources corresponding to different categories of data security policies configured for a SQL engine, provided in an embodiment of the present application.

[0045] FIG5 is a flow chart of a SQL engine executing a security policy according to an embodiment of the present application.

[0046] FIG6 is a schematic block diagram of an SQL engine 600 provided in an embodiment of the present application.

[0047] FIG7 is a schematic block diagram of a database system 700 provided in an embodiment of the present application.

[0048] FIG8 is a schematic diagram of the architecture of a computing device 1500 provided in an embodiment of the present application.

[0049] FIG9 is a schematic diagram of the architecture of a computing device cluster provided in an embodiment of the present application.

[0050] FIG10 is a schematic diagram of a network connection between computing devices 1500A and 1500B provided in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The technical solution in this application will be described below with reference to the accompanying drawings.

[0052] This application will present various aspects, embodiments, or features around systems including multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.

[0053] Additionally, in the embodiments of this application, words such as "exemplary" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.

[0054] In the embodiments of the present application, “corresponding” and “relevant” may sometimes be used interchangeably. It should be noted that when the distinction between them is not emphasized, the meanings they intend to express are consistent.

[0055] The business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person skilled in the art will appreciate that, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.

[0056] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0057] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: including the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0058] For the convenience of description, the concepts involved in the embodiments of the present application are first explained below.

[0059] 1. Structured Query Language (SQL) engine

[0060] The SQL engine is a software component used to process SQL queries. It is one of the core components of a database management system (DBMS).

[0061] The following describes the main functions of the SQL engine.

[0062] 1) Parsing SQL statements: converting SQL statements into an internal representation, namely a parse tree;

[0063] 2) Optimize query plan: Optimize the parse tree to generate an efficient query execution plan;

[0064] 3) Execute the query plan: Execute the query according to the query plan and retrieve the results from the data stored in the database.

[0065] 4) Return results: Return the query results to the client application.

[0066] Several common SQL engines are listed below.

[0067] 1) Hive engine is a data warehouse tool based on Hadoop, used for data extraction, transformation, and loading. It is a mechanism for storing, querying, and analyzing large-scale data stored in Hadoop.

[0068] 2) Spark engine is a fast and general computing engine designed for large-scale data processing.

[0069] 3) Presto engine is an open source distributed SQL query engine launched by Facebook. It can support data scales from GB to PB and is mainly used in scenarios where queries require seconds.

[0070] 4) The Trino engine is an analytical engine designed for OLAP, enabling efficient distributed queries on large amounts of data. The Trino engine and the Presto engine are two branches of the same open source ecosystem.

[0071] 2. Data security

[0072] Data security is used to protect the security and privacy of data stored in a database, preventing data leakage and / or data misuse. Specifically, data security can be divided into data security at the engine layer and data security at the storage layer.

[0073] Data security at the engine layer mainly involves the SQL engine protecting the security and privacy of data stored in the database by executing data security policies.

[0074] The following are some common data security strategies.

[0075] 1) Data access permission control security policy

[0076] The security policy of the data access permission control class defines the data access permissions. The dimensions of this definition are generally: data source / library / table / column (from large to small).

[0077] 2) Data masking security policies

[0078] Data desensitization security policies generally define corresponding data desensitization policies (which can be implemented by specific functions) for a user accessing a specific column of a specific table, so that different people can see different content for the same data, making sensitive data invisible to low-privileged users.

[0079] It should be understood that data masking is a technical means of protecting personal privacy. Its primary purpose is to maintain the confidentiality of sensitive information while ensuring data usability and validity, thereby mitigating the security risks associated with data leaks. Data masking can conceal or alter portions of sensitive data, thereby reducing the risk of data leaks and protecting personal privacy and data security. Data masking must adhere to two principles: first, retaining as much meaningful information as possible for the desensitized application; second, minimizing hacker access. Data masking can be categorized as static data masking and dynamic data masking. Static data masking involves masking sensitive information from raw data before providing it to relevant personnel. This ensures that sensitive information is not leaked during data use. Dynamic data masking involves real-time masking of sensitive information during data transmission, ensuring that unauthorized access to sensitive information is prevented during data transmission.

[0080] 3) Row level filter security policy

[0081] The data row-level filtering security policy refers to filtering each row of data during data processing, retaining only the data rows that meet specific conditions, thereby controlling users to only access specific data rows in the data table.

[0082] 3. Software that provides data security strategies

[0083] The software that provides the data security policy may also be referred to as the source of the data security policy. It is used to provide the above data security policy to the SQL engine. The types of data security policies provided by different software may be the same or different.

[0084] The following are some common software that provide data security strategies.

[0085] 1) Apache Ranger

[0086] Apache Ranger, also known as Ranger, is an open source component related to Hadoop security that provides a comprehensive data security management framework.

[0087] Apache Ranger offers a wealth of security-related features and detailed control. Specifically, Apache Ranger provides three different types of data security policies for SQL engines: data access control, data desensitization, and row-level filtering.

[0088] 2) Hive Metastore (HMS)

[0089] The Hive metadata repository is where Hive stores metadata. Hive is a data warehouse tool based on Hadoop that maps structured data files to database tables and provides SQL-like query capabilities. Hive metadata includes descriptions of tables, databases, partitions, buckets, and other information, all stored in the metadata repository.

[0090] In Hive, metadata is stored in a relational database management system (RDBMS), such as MySQL or Derby. Hive uses Derby internally to store metadata, while MetaStore provides metadata services, managing client access to metadata. Hive's metadata warehouse can be stored on the Hadoop distributed file system (HDFS), linking the data and metadata in the data warehouse.

[0091] In Hive, metadata management is relatively independent of data management and can be accessed and manipulated through the metadata service. Hive's metadata warehouse allows for convenient management and maintenance of metadata information such as tables, databases, partitions, and buckets within Hive, ensuring data integrity and consistency.

[0092] 3) Hive access permission list (ACL)

[0093] Ensuring data security and privacy is crucial for enterprise-level applications. As the underlying computing engine of the data stack, the database engine (for example, the SQL engine) must ensure that data is accessible only to authorized personnel to prevent data leakage and misuse. Specifically, by configuring a data security policy for the SQL engine, the SQL engine can protect data security and privacy according to the configured data security policy.

[0094] In the relevant technical solutions, for the SQL engine, if the SQL engine uses a certain software that provides data security policies (for example, Apache Ranger), then the various data security policies configured on the SQL engine must rely on this software (for example, Apache Ranger). That is, if the data access permission control security policy used by the SQL engine is provided by Apache Ranger, then other security policies, such as data desensitization security policies and data row-level filtering security policies, must all be provided by Apache Ranger. This results in a strong binding between the security policy in the SQL engine and a certain software (the software that provides the data security policy), making the current data security system relatively rigid. The SQL engine cannot flexibly use the data security policies provided by different software, which reduces the user experience.

[0095] In view of this, an embodiment of the present application provides a method for an SQL engine to execute security policies. This method enables the SQL engine to flexibly use data security policies provided by different software, avoiding the strong binding relationship between all types of data security policies on the SQL engine and one software, making the data security system more flexible and improving the user experience.

[0096] In a possible implementation, the method provided in the embodiment of the present application can be applied to a cloud service scenario. For ease of description, the cloud service scenario is described in detail below with reference to FIG1 .

[0097] FIG1 is a schematic block diagram of a cloud scenario applicable to an embodiment of the present application. As shown in FIG1 , the cloud scenario may include: a cloud management platform 110 , the Internet 120 , and a client 130 .

[0098] As shown in Figure 1, the cloud management platform 110 is used to manage the infrastructure that provides multiple cloud services. The infrastructure includes multiple cloud data centers, each of which includes multiple servers, each of which includes cloud service resources to provide corresponding cloud services to tenants.

[0099] Specifically, a SQL engine runs on a server in a cloud data center, and the SQL engine executes the method provided in the embodiment of the present application.

[0100] The cloud management platform 110 can be located in a cloud data center, which can provide an access interface (such as an interface or an application program interface (API)). The tenant can operate the client 130 to remotely access the access interface to register a cloud account and password on the cloud management platform 110, and log in to the cloud management platform 110. After the cloud management platform 110 successfully authenticates the cloud account and password, the tenant can further pay to select and purchase a virtual machine with specific specifications (processor, memory, disk) on the cloud management platform 110. After the payment is successful, the cloud management platform 110 provides the remote login account and password of the purchased virtual machine, and the client 130 can remotely log in to the virtual machine, install and run the tenant's application in the virtual machine. Therefore, the tenant can create, manage, log in and operate virtual machines in the cloud data center through the cloud management platform 110. Among them, the virtual machine can also be called a cloud server (elastic compute service, ECS) or an elastic instance (different cloud service providers have different names).

[0101] It should be understood that tenants of cloud services can be individuals, enterprises, schools, hospitals, administrative agencies, etc.

[0102] The functions of the cloud management platform 110 include, but are not limited to, a user console, computing management services, network management services, storage management services, authentication services, and image management services. The user console provides an interface or API for interacting with tenants. The computing management service is used to manage servers running virtual machines and containers, as well as bare metal servers. The network management service is used to manage network services (such as gateways and firewalls). The storage management service is used to manage storage services (such as data bucket services). The authentication service is used to manage tenant accounts and passwords. The image management service is used to manage virtual machine images. Tenants can use the client 130 to log in to the cloud management platform 110 via the Internet 120 to manage the rented cloud services.

[0103] Below, in conjunction with Figure 2, a method for executing a security policy in a SQL engine provided by an embodiment of the present application is described in detail. It should be understood that the example in Figure 2 is merely to help those skilled in the art understand the embodiment of the present application, and is not intended to limit the embodiment of the application to the specific numerical values ​​or specific scenarios illustrated in Figure 2. It is obvious that those skilled in the art can make various equivalent modifications or changes based on the following example given in Figure 2, and such modifications and changes also fall within the scope of the embodiment of the present application.

[0104] Figure 2 is a schematic flow chart of a method for executing a security policy in a SQL engine according to an embodiment of the present application. As shown in Figure 2 , the method may include steps 210-220, which are described in detail below.

[0105] In one example, the method is applied to a database system, which includes a database and at least one SQL engine, and the at least one SQL engine is used to obtain data stored in the database according to an SQL statement.

[0106] Step 210: The SQL engine obtains configuration information, which is used to configure the corresponding source software for each type of data security policy.

[0107] In the embodiment of the present application, each SQL engine can be allowed to freely define different acquisition sources for the multiple data security policies it uses or consumes. In other words, the corresponding acquisition source can be configured for each type of data security policy.

[0108] It should be understood that each type of data security policy may correspond to one acquisition source, or may correspond to multiple acquisition sources, and this application does not make specific limitations on this.

[0109] It should also be understood that the acquisition sources corresponding to different types of data security policies may include the same acquisition source, or may not include the same acquisition source, and this application does not make specific limitations on this.

[0110] The above-mentioned acquisition source can also be called a data security policy source, which can be understood as software that provides data security policies. The software that provides data security policies may include but is not limited to: Apache Ranger, HMS, Hive ACL, etc.

[0111] It should be noted that in addition to deploying the SQL engine required for business purposes, users also need to deploy at least one software that provides data security policies.

[0112] The above-mentioned various data security policies may include, but are not limited to: data access permission control security policies, data desensitization security policies, data row-level filtering security policies, etc.

[0113] Optionally, in the embodiment of the present application, each SQL engine may be allowed to freely define whether to enable some or all of the above-mentioned data security policies.

[0114] In one possible implementation, an administrator can configure different acquisition sources for the various data security policies used by each SQL engine. This configuration can be implemented in a variety of ways, and this embodiment of the present application does not specifically limit this. Several possible implementations are described below.

[0115] 1. The administrator configures different acquisition sources for the various data security policies used by the SQL engine through the interface of the SQL engine.

[0116] Specifically, the administrator configures different acquisition sources of multiple data security policies used by the SQL engine through the application programming interface (API) of the SQL engine.

[0117] For example, if the SQL engine is located on the client, the SQL engine can be configured through this implementation method.

[0118] 2. The administrator configures different acquisition sources for the various data security policies used through configuration files or visual interfaces.

[0119] For example, if the SQL engine is located on the server, the SQL engine can be configured in this way.

[0120] For example, as shown in Figure 3, the administrator configures the acquisition source for the data access permission control security policy (also referred to as the access configuration item) as security policy source 1, the acquisition source configured for the data masking security policy (also referred to as the masking configuration item) as security policy source 2 and security policy source 3, and the acquisition source configured for the data row-level filtering security policy (also referred to as the row level filter configuration item) as security policy source 3.

[0121] In the embodiment of the present application, it is assumed that the above-mentioned security policy source 1 is HMS, the security policy source 2 is Apache Ranger, and the security policy source 3 is other software. As shown in Figure 4, through the security policy configuration interface of the SQL engine, the acquisition source configured for the data access permission control security policy (also referred to as the access configuration item) is HMS, the acquisition source configured for the data desensitization security policy (also referred to as the masking configuration item) is Apache Ranger and other software, and the acquisition source configured for the data row-level filtering security policy (also referred to as the row level filter configuration item) is other software.

[0122] That is, the SQL engine uses data access permission control security policies provided by HMS, data desensitization security policies provided by Apache Ranger and other software, and data row-level filtering security policies provided by other software.

[0123] The following takes the example of an administrator configuring the SQL engine through a configuration file as an example, and combines Figure 4 to illustrate the specific implementation of the configuration file.

[0124] In one possible implementation, taking Spark as an example, the following parameters can be added and saved in the Spark system startup configuration file:

[0125] spark.ranger.plugin.authorization.enable=false;

[0126] spark.HMS.plugin.access.enable=true;

[0127] spark.ranger and others.plugin.masking.enable=true;

[0128] spark.others.plugin.row_level_filter.enable=true;

[0129] Among them, "spark.ranger.plugin.authorization.enable=false" means setting the data security policy provided by Ranger to be disabled; "spark.HMS.plugin.access.enable=true" means setting the security policy for starting the data access permission control type provided by HMS (referred to as access); "spark.ranger and others.plugin.masking.enable=true" means setting the security policy for starting the data masking type provided by Ranger and other software (referred to as masking); "spark.others.plugin.row level filter.enable=true" means setting the security policy for starting the data row-level filtering type provided by other software (referred to as row level filter).

[0130] It should be understood that in the above implementation, it is assumed that all data security policies in the SQL engine are provided by Ranger. Therefore, it is necessary to first set the data security policy provided by Ranger to be disabled, and then set the data security policy provided by different sources to be enabled.

[0131] Since Spark has two SQL task submission methods, users can choose to configure the above parameters in the following three different locations.

[0132] 1) Spark's JDBC server;

[0133] 2) Spark client's local conf file;

[0134] 3) Spark command line parameters.

[0135] It should be noted that the above description is based on Spark as an example SQL engine, and is applicable to other SQL engines.

[0136] In another possible implementation, taking Presto as an example, the following parameters can be added and saved in the Presto system startup configuration file:

[0137] security.access.source=HMS;

[0138] security.masking.source=Ranger / others;

[0139] security.row_level_filter.source=others;

[0140] Among them, "security.access.source=HMS" means the security policy used to set and enable the data access permission control type provided by HMS (referred to as access); "security.masking.source=Ranger / others" means the security policy used to set and enable the data desensitization type provided by Ranger and other software (referred to as masking); "security.row_level_filter.source=others" means the security policy used to set and enable the data row-level filtering type provided by other software (referred to as row level filter).

[0141] It should be noted that the above description uses Presto as an example SQL engine, and is applicable to other SQL engines.

[0142] Step 220: The SQL engine executes the data security policy provided by the corresponding software source to protect the security and / or privacy of the data stored in the database.

[0143] In an embodiment of the present application, after obtaining the above configuration information, the SQL engine can enable a data security policy based on the configuration information to protect the security and / or privacy of the data stored in the database.

[0144] In one implementation, for the security policy of the data access permission control class, the SQL engine can execute the security policy of the data access permission control class before obtaining data from the database according to the SQL statement, and perform security verification on the user's access permission to the database, thereby protecting the security of the data stored in the database.

[0145] In another implementation method, for data desensitization security policies or data row-level filtering security policies, the SQL engine can execute the data desensitization security policies or data row-level filtering security policies after obtaining data from the database according to the SQL statement, and desensitize or row-level filter the data stored in the database, thereby protecting the privacy of the data stored in the database.

[0146] In the embodiment of the present application, since each type of data security policy can come from one software, or can also come from two or more software. For the same type of data security policy provided by two or more software, the execution process of the SQL engine needs to support the simultaneous effectiveness of the same type of data security policy provided by these two or more software. In other words, it is necessary to determine whether the security verification of the same type of data security policy provided by these two or more software can pass. In this way, multiple security protections can be effective at the same time, thereby better protecting the security and / or privacy of the data.

[0147] For example, the aforementioned data desensitization security policy includes both the data desensitization policy provided by Apache Ranger and the data desensitization policy provided by other software. As shown in Figure 5, when executing the data desensitization security policy, the SQL engine must determine whether it can pass the security check of the data desensitization policy provided by Apache Ranger and the data desensitization policy provided by other software.

[0148] In one case, as shown in Figure 5, if the SQL engine passes both the security verification of the data desensitization security policy provided by Apache Ranger and the security verification of the data desensitization security policy provided by other software, then the verification can be considered successful.

[0149] In another case, as shown in Figure 5, if the SQL engine passes the security verification of the data desensitization security policy provided by Apache Ranger but fails the security verification of the data desensitization security policy provided by other software, then it can be understood as a verification failure.

[0150] In another case, as shown in Figure 5, if the SQL engine passes the security verification of the data desensitization security policy provided by other software, but fails the security verification of the data desensitization security policy provided by Apache Ranger, then this can also be understood as a verification failure.

[0151] In another case, as shown in Figure 5, if the SQL engine fails the security verification of the data desensitization security policy provided by Apache Ranger or the data desensitization security policy provided by other software, then it can also be understood as a verification failure.

[0152] In the above technical solution, the SQL engine can flexibly use the data security policies provided by different software, avoiding the strong binding relationship between all types of data security policies on the SQL engine and one software, making the data security system more flexible and improving the user experience.

[0153] The above describes in detail the method provided by the embodiment of the present application in conjunction with Figures 1 to 5. The following describes in detail the embodiment of the device of the present application in conjunction with Figures 6 to 9. It should be understood that the description of the method embodiment corresponds to the description of the device embodiment. Therefore, for parts not described in detail, reference can be made to the above method embodiment.

[0154] Figure 6 is a schematic block diagram of an SQL engine 600 provided in an embodiment of the present application. The SQL engine 600 can be implemented by software, hardware, or a combination of both. The SQL engine 600 provided in an embodiment of the present application can implement the method flow shown in Figure 2 of the embodiment of the present application, and the SQL engine 600 includes: an acquisition module 610 and a processing module 620. Among them, the acquisition module 610 is used to obtain first configuration information, and the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, and the at least one software source corresponding to each of the different types of security policies is not exactly the same; the processing module 620 is used to protect the security and / or privacy of the data stored in the database by executing the corresponding security policies provided by each of the different software sources indicated in the first configuration information according to the first configuration information.

[0155] Optionally, the acquisition module 610 is specifically configured to: acquire the first configuration information through at least one of the following methods: an interface, a configuration file, or a visual configuration interface of the SQL engine.

[0156] Optionally, the different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include a first software and a second software. The processing module 620 is specifically used to: determine that the SQL engine passes the security verification of the first type of security policy when the first type of security policy provided by the first software and the second software are verified respectively.

[0157] Optionally, the acquisition module 610 is also used to obtain second configuration information, which is used to configure the SQL engine to execute some or all of the different types of security policies; the processing module 620 is also used to execute some or all of the different types of security policies based on the second configuration information.

[0158] Optionally, the different types of security policies include at least two of the following: a data access permission control type security policy, a data desensitization type security policy, and a data row-level filtering type security policy.

[0159] Optional software sources include: Apache Ranger, Hive metadata repository HMS, and Hive access permission list ACL.

[0160] Optionally, the SQL engine 600 runs in at least one server, which is located in at least one cloud data center and is an infrastructure for providing cloud services managed by a cloud management platform.

[0161] The SQL engine 600 can be implemented as a functional module. The term "module" can be implemented in software and / or hardware, and is not specifically limited thereto.

[0162] For example, a "module" can be a software program, a hardware circuit, or a combination of the two that implements the aforementioned functions. For example, the implementation of acquisition module 610 will be described below using acquisition module 610 as an example. Similarly, the implementation of other modules, such as processing module 620, can refer to the implementation of acquisition module 610.

[0163] The acquisition module 610 is taken as an example of a software functional unit, and the acquisition module 610 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the acquisition module 610 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple geographically close data centers. Generally, a region may include multiple AZs.

[0164] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.

[0165] As an example of a hardware functional unit, acquisition module 610 may include at least one computing device, such as a server. Alternatively, acquisition module 610 may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0166] The multiple computing devices included in acquisition module 610 can be distributed in the same region or in different regions. The multiple computing devices included in acquisition module 610 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in acquisition module 610 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.

[0167] Therefore, the modules of each example described in the embodiments of this application can be implemented with electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0168] It should be noted that: when the SQL engine 600 provided in the above embodiment executes the above method, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the SQL engine 600 can be divided into different functional modules to complete all or part of the functions described above. For example, the acquisition module 610 can be used to execute any step in the above method, and the processing module 620 can be used to execute any step in the above method. The steps that the acquisition module 610 and the processing module 620 are responsible for implementing can be specified as needed, and all the functions of the above SQL engine 600 can be realized by respectively implementing different steps in the above method through the acquisition module 610 and the processing module 620.

[0169] In addition, the SQL engine 600 provided in the above embodiment and the method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment above, which will not be repeated here.

[0170] Figure 7 is a database system 700 provided in an embodiment of the present application. The database system 700 includes a database 710 and at least one SQL engine 600. The at least one SQL engine 600 is used to execute the above-mentioned different types of security policies when obtaining data stored in the database 710 according to SQL statements, so as to protect the security and / or privacy of the data stored in the database 710.

[0171] The method provided in the embodiment of the present application can be performed by a computing device, which can also be referred to as a computer system. It includes a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a processing unit, a memory and a memory control unit, and the function and structure of the hardware are subsequently described in detail. The operating system is any one or more computer operating systems that implement business processing through a process, for example, a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system or a Windows operating system. The application layer includes applications such as a browser, an address book, a word processing software, and an instant messaging software. Furthermore, optionally, the computer system is a handheld device such as a smart phone, or a terminal device such as a personal computer, and this application is not particularly limited, as long as the method provided in the embodiment of the present application can be used. The execution subject of the method provided in the embodiment of the present application can be a computing device, or a functional module in a computing device that can call a program and execute a program.

[0172] A computing device provided in an embodiment of the present application is described in detail below in conjunction with FIG8 .

[0173] FIG8 is a schematic diagram of the architecture of a computing device 1500 provided in an embodiment of the present application. The computing device 1500 may be a server, a computer, or other device with computing capabilities. The computing device 1500 shown in FIG8 includes: at least one processor 1510 and a memory 1520.

[0174] It should be understood that this application does not limit the number of processors and memories in the computing device 1500.

[0175] The processor 1510 executes the instructions in the memory 1520 so that the computing device 1500 implements the method provided in this application. Alternatively, the processor 1510 executes the instructions in the memory 1520 so that the computing device 1500 implements the functional modules provided in this application, thereby implementing the method provided in this application.

[0176] Optionally, the computing device 1500 further includes a communication interface 1530. The communication interface 1530 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1500 and other devices or a communication network.

[0177] Optionally, the computing device 1500 further includes a system bus 1540, wherein the processor 1510, the memory 1520, and the communication interface 1530 are respectively connected to the system bus 1540. The processor 1510 can access the memory 1520 through the system bus 1540. For example, the processor 1510 can read and write data or execute code in the memory 1520 through the system bus 1540. The system bus 1540 is a peripheral component interconnect express (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The system bus 1540 is divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in Figure 8, but this does not mean that there is only one bus or one type of bus.

[0178] In one possible implementation, the processor 1510 is primarily responsible for interpreting computer program instructions (or codes) and processing data in the computer software. The computer program instructions and the data in the computer software may be stored in the memory 1520 or the cache 1516.

[0179] Optionally, the processor 1510 may be an integrated circuit chip having signal processing capabilities. By way of example and not limitation, the processor 1510 is a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The general-purpose processor is a microprocessor, etc. For example, the processor 1510 is a central processing unit (CPU).

[0180] Optionally, each processor 1510 includes at least one processing unit 1512 and a memory control unit 1514 .

[0181] Processing unit 1512, also known as a core, is the most important component of a processor. Processing unit 1512 is manufactured from single-crystal silicon using a specific production process. All processor calculations, command reception, command storage, and data processing are performed by the core. Each processing unit independently executes program instructions, leveraging parallel computing capabilities to accelerate program execution. Each processing unit has a fixed logical structure. For example, a processing unit includes logical units such as a level 1 cache, a level 2 cache, an execution unit, an instruction-level unit, and a bus interface.

[0182] In one implementation example, the memory control unit 1514 is configured to control data exchange between the memory 1520 and the processing unit 1512. Specifically, the memory control unit 1514 receives memory access requests from the processing unit 1512 and controls access to the memory based on the memory access requests. By way of example and not limitation, the memory control unit is a device such as a memory management unit (MMU).

[0183] In one implementation example, each memory control unit 1514 addresses the memory 1520 via the system bus. An arbiter (not shown in FIG8 ) is configured in the system bus to handle and coordinate competing accesses by multiple processing units 1512 .

[0184] In an implementation example, the processing unit 1512 and the memory control unit 1514 are connected to each other via connection lines inside the chip, such as address lines, so as to achieve communication between the processing unit 1512 and the memory control unit 1514.

[0185] Optionally, each processor 1510 also includes a cache 1516, which is a buffer for data exchange (called a cache). When a processing unit 1512 needs to read data, it first searches the cache for the required data. If the data is found, it executes the request directly; if not, it searches the memory. Because the cache runs much faster than the memory, the cache helps the processing unit 1512 run faster.

[0186] Memory 1520 can provide runtime space for processes in computing device 1500. For example, memory 1520 stores computer programs (specifically, program code) used to generate processes. After the computer program is executed by the processor to generate a process, the processor allocates corresponding storage space for the process in memory 1520. Furthermore, the aforementioned storage space further includes a text segment, an initialized data segment, a bit-initialized data segment, a stack segment, a heap segment, and the like. Memory 1520 stores data generated during the execution of the process, such as intermediate data or process data, in the storage space corresponding to the aforementioned process.

[0187] Optionally, the memory is also called the internal memory. Its function is to temporarily store the data processed by the processor 1510 and the data exchanged with external storage such as a hard disk. As long as the computer is running, the processor 1510 will load the data to be calculated into the internal memory for calculation. When the calculation is completed, the processing unit 1512 will transmit the result.

[0188] By way of example and not limitation, memory 1520 is a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Non-volatile memory is read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory is random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory 1520 of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0189] The structure of the computing device 1500 listed above is only for illustrative purposes, and the present application is not limited thereto. The computing device 1500 of the embodiment of the present application includes various hardware in the computer system in the prior art. For example, the computing device 1500 also includes other memories in addition to the memory 1520, such as disk storage, etc. Those skilled in the art should understand that the computing device 1500 may also include other devices necessary to achieve normal operation. At the same time, according to specific needs, those skilled in the art should understand that the above-mentioned computing device 1500 may also include hardware devices that implement other additional functions. In addition, those skilled in the art should understand that the above-mentioned computing device 1500 may also include only the devices necessary to implement the embodiment of the present application, and does not necessarily include all the devices shown in Figure 8.

[0190] The present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0191] As shown in Figure 9, the computing device cluster includes at least one computing device 1500. The memory 1520 in one or more computing devices 1500 in the computing device cluster may store the same instructions for executing the above method.

[0192] In some possible implementations, the memory 1520 of one or more computing devices 1500 in the computing device cluster may also store some instructions for executing the above method. In other words, the combination of one or more computing devices 1500 can jointly execute the instructions of the above method.

[0193] It should be noted that the memory 1520 in different computing devices 1500 in the computing device cluster can store different instructions, each for executing part of the functions of the above-mentioned SQL engine. In other words, the instructions stored in the memory 1520 in different computing devices 1500 can implement the functions of one or more modules in the above-mentioned SQL engine.

[0194] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. The network can be a wide area network (WAN) or a local area network (LAN), among others. FIG. 10 illustrates one possible implementation. As shown in FIG. 10 , two computing devices 1500A and 1500B are connected via a network. Specifically, each computing device is connected to the network via a communication interface within the computing device.

[0195] It should be understood that the functionality of the computing device 1500A shown in FIG10 may also be implemented by multiple computing devices 1500. Similarly, the functionality of the computing device 1500B may also be implemented by multiple computing devices 1500.

[0196] This embodiment also provides a computer program product including instructions. The computer program product may be software or a program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on a computing device, it causes the computing device to perform the above-mentioned method or implement the above-mentioned SQL engine functionality.

[0197] This embodiment also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium capable of storing data on a computing device, or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that, when executed on a computing device, cause the computing device to perform the method provided above.

[0198] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0199] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0200] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0201] In the several embodiments provided in this application, it should be understood that the disclosed systems, SQL engines, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0202] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0203] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0204] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0205] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for executing a security policy using a structured query language SQL engine, characterized in that: The method is applied to a database system, the database system includes a database and at least one SQL engine, the at least one SQL engine is used to obtain data stored in the database according to an SQL statement, and the method includes: Each of the SQL engines obtains first configuration information respectively, where the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, and the at least one software source corresponding to each of the different types of security policies is not completely the same; Each of the SQL engines protects the security and / or privacy of the data stored in the database according to the first configuration information by executing corresponding security policies provided by different software sources indicated in the first configuration information.

2. The method according to claim 1, characterized in that Each of the SQL engines obtains the first configuration information, including: Each of the SQL engines obtains the first configuration information in at least one of the following ways: an interface, a configuration file, or a visual configuration interface of each of the SQL engines.

3. The method according to claim 1 or 2, characterized in that: The different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include first software and second software. Each of the SQL engines protects the security and / or privacy of the data stored in the database according to the first configuration information by executing corresponding security policies provided by different software sources indicated in the first configuration information, including: When each of the SQL engines passes the verification of the first type of security policy provided by the first software and the second software respectively, it is determined that the SQL engine passes the security verification of the first type of security policy.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Each of the SQL engines obtains second configuration information respectively, where the second configuration information is used to configure the SQL engine to execute part of or all of the different types of security policies; Each of the SQL engines executes part of or all of the different types of security policies according to the second configuration information received by the SQL engine.

5. The method according to any one of claims 1 to 4, characterized in that The different types of security policies include at least two of the following: security policies of data access permission control type, security policies of data desensitization type, and security policies of data row-level filtering type.

6. The method according to any one of claims 1 to 5, characterized in that The software sources include: Apache Ranger, Hive metadata repository HMS, and Hive access permission list ACL.

7. The method according to any one of claims 1 to 6, characterized in that The method is applied to a cloud management platform, which is used to manage an infrastructure for providing cloud services. The infrastructure includes at least one cloud data center, each of which is provided with at least one server, and the SQL engine runs in the at least one server.

8. A structured query language SQL engine, characterized in that: The SQL engine is located in a database system, and the database system also includes a database. The SQL engine is used to obtain data stored in the database according to an SQL statement. The SQL engine includes: an acquisition module, configured to acquire first configuration information, wherein the first configuration information is used to indicate at least one software source corresponding to each of the different types of security policy configurations executed on the SQL engine, wherein the at least one software source corresponding to each of the different types of security policies is not completely the same; A processing module is used to protect the security and / or privacy of the data stored in the database according to the first configuration information by executing corresponding security policies provided by different software sources indicated in the first configuration information.

9. The SQL engine according to claim 8, characterized in that: The acquisition module is specifically used for: The first configuration information is obtained by at least one of the following methods: an interface, a configuration file, or a visual configuration interface of the SQL engine.

10. The SQL engine according to claim 8 or 9, characterized in that: The different types of security policies include a first type of security policy, and the software sources corresponding to the first type of security policy include first software and second software. The processing module is specifically used for: In the case of passing the verification of the first type of security policy respectively provided by the first software and the second software, it is determined that the SQL engine passes the security verification of the first type of security policy.

11. The SQL engine according to any one of claims 8 to 10, characterized in that: The acquisition module is further used to acquire second configuration information, where the second configuration information is used to configure the SQL engine to execute some or all of the different types of security policies; The processing module is further configured to execute part or all of the different types of security policies according to the second configuration information.

12. The SQL engine according to any one of claims 8 to 11, characterized in that: The different types of security policies include at least two of the following: security policies of data access permission control type, security policies of data desensitization type, and security policies of data row-level filtering type.

13. The SQL engine according to any one of claims 8 to 12, characterized in that: The software sources include: Apache Ranger, Hive metadata repository HMS, and Hive access permission list ACL.

14. The SQL engine according to any one of claims 8 to 13, characterized in that: The SQL engine runs in at least one server, the at least one server is located in at least one cloud data center, and the at least one server is an infrastructure for providing cloud services managed by a cloud management platform.

15. A database system, characterized in that: The database system comprises a database and at least one SQL engine according to any one of claims 8 to 14, wherein the at least one SQL engine is used to obtain data stored in the database according to an SQL statement.

16. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 7.

17. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster is caused to perform the method according to any one of claims 1 to 7.

18. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method as claimed in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for executing security policy by SQL engine and SQL engine

    CN120162341A

  • Security policy configuring method and apparatus thereof

    CN101364877A

  • Permission control method for SparkSQL thriftserver query and Hive operation

    CN110175164A

  • Systems and methods for analyzing application security policies

    US8117640B1

  • Systems and methods for enforcing security in mobile computing

    WO2015138931A1

Cited By

  • Intelligent data verification method and device and related equipment

    CN120930190A

  • Plann reuse method, device and equipment for row-level security policy, medium and product

    CN121681590A