Authorization method and apparatus, storage medium, and electronic device

By receiving the authorization request and obtaining the first target credential of the database instance based on the authorization identification, the problem of inefficient authorization on each database asset authorization page is solved, and the efficiency of sensitive data recognition is improved.

WO2025130141A1PCT designated stage expired Publication Date: 2025-06-26HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/115954
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-08-30
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

When a user needs a data security center to identify sensitive data for database assets, he can only authorize credentials to the data security center on the authorization page corresponding to each database asset, resulting in a relatively low efficiency in identifying sensitive data.

Method used

By receiving the authorization request initiated by the target object, determining the authorization method based on the authorization identification, obtaining the first target credentials of multiple database instances, and avoiding credential authorization on the authorization page corresponding to each database asset.

Benefits of technology

It improves the authorization efficiency of the data security center, and thus improves the efficiency of sensitive data identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024115954_26062025_PF_FP_ABST
    Figure CN2024115954_26062025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose an authorization method and apparatus, a storage medium, and an electronic device. The method comprises: receiving an authorization request initiated by a target entity, wherein the authorization request at least comprises an authorization identifier, and the authorization identifier is used for indicating an authorization mode for performing access authorization to a data security center; and on the basis of the authorization identifier, obtaining first target credentials of a plurality of database instances, wherein the first target credentials are used for determining whether the data security center has permission to access the plurality of database instances, and database instances among the plurality of database instances at least comprise a database.
Need to check novelty before this filing date? Find Prior Art

Description

Authorization method and device, storage medium and electronic device

[0001] Cross-reference

[0002] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on December 21, 2023, with application number 202311777054.4 and invention name “Authorization method and device, storage medium and electronic device”, the entire contents of which are incorporated by reference into this disclosure. Technical Field

[0003] The present disclosure relates to the field of data processing technology, and in particular to an authorization method and device, a storage medium, and an electronic device. Background Art

[0004] Currently, when using the Data Security Center, users must authorize the center to access their cloud product resources. Database resources are typically accessed through a connection string, username, and password. Users must host their username and password on the Data Security Center, which then assembles the connection string and connects to the user's database using the username and password to access data and identify sensitive data. Existing technology requires credential authorization for the Data Security Center on the authorization page for each database asset, severely impacting the efficiency of identifying sensitive database data.

[0005] To address the above-mentioned problems, no effective solutions have been proposed so far.

[0006] Summary of the Invention

[0007] The embodiments of the present disclosure provide an authorization method and device, a storage medium, and an electronic device to at least solve the technical problem that when a user requires a data security center to identify sensitive data of a database asset, the user can only authorize the data security center with credentials on the authorization page corresponding to each database asset, resulting in relatively low efficiency in sensitive data identification.

[0008] According to one aspect of an embodiment of the present disclosure, an authorization method is provided, which is applied to a data security center, including: receiving an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate the authorization method for authorizing access to the data security center; obtaining first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access multiple database instances.

[0009] Furthermore, obtaining the first target credentials of multiple database instances based on the authorization identifier includes: determining the authorization method for authorizing access to the data security center based on the authorization identifier, wherein the authorization method is one of the following: the first authorization method, the second authorization method and the third authorization method, the first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, the third authorization method is the authorization method when the target object provides credentials, and the authorization method when there is a correspondence between the credentials and the database instance; obtaining the first target credentials of multiple database instances based on the authorization method.

[0010] Furthermore, if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances based on the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, wherein the credentials include the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; establishing a first associated authorization relationship between the first credential and multiple database instances; obtaining the first target credential based on the first associated authorization relationship and the first credential.

[0011] Furthermore, if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to the multiple database instances, the credentials include the second credentials, and the second credentials include at least the second account and the password information corresponding to the second account; establishing a second association authorization relationship between the database in the multiple database instances and the second credentials according to the credential association request; obtaining the first target credential based on the second association authorization relationship and the second credential.

[0012] Further, if the authorization method is the second authorization method, obtaining the first target credentials of multiple database instances based on the authorization method includes: establishing a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; determining the third credential based on the third account and the password information corresponding to the third account, wherein the credentials include the third credential; establishing a third associated authorization relationship between the third credential and multiple database instances; and obtaining the first target credential based on the third associated authorization relationship and the third credential.

[0013] Furthermore, if the authorization method is the third authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving an authorization form input by the target object, wherein the authorization form includes at least fourth credentials corresponding to multiple database instances, identification information of the database instances in the multiple database instances, and a correspondence between the identification information and the fourth credentials, and the credentials include the fourth credential; identifying the authorization form to obtain the identification information and the fourth credential; establishing a fourth associated authorization relationship between the fourth credential and the multiple database instances based on the identification information and the correspondence; and obtaining the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0014] Furthermore, after obtaining the first target credentials of multiple database instances based on the authorization identifier, the method also includes: upon receiving a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object, accessing the target database instance based on the sensitive data identification request; performing sensitive data identification on the database in the target database instance to obtain an identification result.

[0015] Furthermore, in the event of receiving a sensitive data identification request initiated by a target object for a target database instance among multiple database instances, accessing the target database instance based on the sensitive data identification request includes: determining a second target credential of the target database instance from the first target credential based on the sensitive data identification request; and accessing the target database instance based on the second target credential.

[0016] Furthermore, accessing the target database instance based on the second target credential includes: determining the target server of the database in the target database instance; establishing a reverse access network between the data security center and the target server, and obtaining the access address and access port of the database in the target database instance based on the reverse access network; establishing a mapped access address and a mapped access port based on the access address and the access port; accessing the mapped access address and the mapped access port based on the second target credential to access the target database instance.

[0017] Furthermore, before receiving the authorization request initiated by the target object, the method also includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0018] According to another aspect of an embodiment of the present disclosure, an authorization device is also provided, including: a receiving component, configured to receive an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate the authorization method for authorizing access to a data security center; an acquisition component, configured to obtain first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access multiple database instances.

[0019] Furthermore, the acquisition component includes: a first determination sub-component, used to determine the authorization method for access authorization to the data security center based on the authorization identifier, wherein the authorization method is one of the following: a first authorization method, a second authorization method and a third authorization method, the first authorization method is an authorization method when the target object provides credentials, the second authorization method is an authorization method when the target object does not provide credentials, the third authorization method is an authorization method when the target object provides credentials, and an authorization method when there is a correspondence between the credentials and the database instance; an acquisition sub-component, used to obtain the first target credentials of multiple database instances based on the authorization method.

[0020] Furthermore, if the authorization method is the first authorization method, the acquisition sub-component includes: a first receiving component, used to receive the first credential entered by the target object through the credential management interface in the data security center, wherein the credential includes the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; a first establishment component, used to establish a first associated authorization relationship between the first credential and multiple database instances; a first acquisition component, used to obtain the first target credential based on the first associated authorization relationship and the first credential.

[0021] Furthermore, if the authorization method is the first authorization method, the acquisition subcomponent includes: a second receiving component, used to receive a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to multiple database instances, the credentials include the second credentials, and the second credentials include at least the second account and the password information corresponding to the second account; a second establishing component, used to establish a second association authorization relationship between the database in multiple database instances and the second credentials based on the credential association request; a second acquisition component, used to obtain the first target credential based on the second association authorization relationship and the second credential.

[0022] Furthermore, if the authorization method is the second authorization method, the acquisition sub-component includes: a third establishment component, used to establish a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; a first determination component, used to determine the third credential based on the third account and the password information corresponding to the third account; a fourth establishment component, used to establish a third associated authorization relationship between the third credential and multiple database instances; a third acquisition component, used to obtain the first target credential based on the third associated authorization relationship and the third credential.

[0023] Furthermore, if the authorization method is the third authorization method, the acquisition sub-component includes: a third receiving component, used to receive the authorization form input by the target object, wherein the authorization form includes at least fourth credentials corresponding to multiple database instances, identification information of the database instances in the multiple database instances, and the correspondence between the identification information and the fourth credentials, and the credentials include the fourth credentials; an identification component, used to identify the authorization form and obtain the identification information and the fourth credentials; a fifth establishment component, used to establish a fourth associated authorization relationship between the fourth credential and the multiple database instances based on the identification information and the correspondence; a fourth acquisition component, used to obtain the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0024] Furthermore, the device also includes: an access component, which is used to obtain the first target credentials of multiple database instances based on the authorization identifier, and then, upon receiving a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object, access the target database instance based on the sensitive data identification request; an identification component, which is used to perform sensitive data identification on the database in the target database instance to obtain an identification result.

[0025] Furthermore, the access component includes: a second determination subcomponent, used to determine the second target credential of the target database instance from the first target credential based on the sensitive data identification request; and an access subcomponent, used to access the target database instance based on the second target credential.

[0026] Furthermore, the access subcomponent includes: a second determination component, used to determine the target server of the database in the target database instance; a sixth establishment component, used to establish a reverse access network between the data security center and the target server, and obtain the access address and access port of the database in the target database instance based on the reverse access network; a sixth establishment component, used to establish a mapped access address and a mapped access port based on the access address and the access port; an access component, used to access the mapped access address and the mapped access port based on the second target credential to access the target database instance.

[0027] Furthermore, the device also includes: a first scanning component, which is used to scan the database assets corresponding to the target object according to a preset time period before receiving the authorization request initiated by the target object to obtain a list of database instances; or, a second scanning component, which is used to scan the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0028] According to another aspect of an embodiment of the present disclosure, a computer-readable storage medium is further provided, wherein the storage medium stores a program, wherein when the program is running, the device where the storage medium is located is controlled to execute any one of the above authorization methods.

[0029] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, which implements any one of the above authorization methods when executed by a processor.

[0030] According to another aspect of the present disclosure, a computer program product is provided, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, any one of the above authorization methods is implemented.

[0031] According to another aspect of the present disclosure, a computer program is provided, which implements any one of the above authorization methods when executed by a processor.

[0032] According to another aspect of an embodiment of the present disclosure, an electronic device is provided, including a memory storing an executable program; and a processor for running the program, wherein any one of the above authorization methods is executed when the program is running.

[0033] In an embodiment of the present disclosure, an authorization request is received from a target object, wherein the authorization request includes at least an authorization identifier, which indicates an authorization method for granting access to a data security center; and first target credentials for multiple database instances are obtained based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, wherein the database instances in the multiple database instances include at least one database. This solves the technical problem that when a user requires the data security center to identify sensitive data of a database asset, the user can only authorize the data security center with credentials on the authorization page corresponding to each database asset, resulting in relatively low efficiency in sensitive data identification. In an embodiment of the present disclosure, the data security center receives an authorization request from a target object, and then, based on the authorization method clearly adopted by the authorization identifier, the data security center obtains the first target credentials for multiple database instances of the target object based on the corresponding authorization method, avoiding the problem of needing to authorize the data security center with credentials on the authorization page corresponding to each database asset, thereby improving the authorization efficiency of the data security center and achieving the effect of improving the efficiency of sensitive data identification. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:

[0035] FIG1 is a schematic diagram of a computer terminal provided according to a first embodiment of the present disclosure;

[0036] FIG2 is a flowchart of an authorization method provided according to Embodiment 1 of the present disclosure;

[0037] FIG3 is a first schematic diagram of authorization provided according to the first embodiment of the present disclosure;

[0038] FIG4 is a second schematic diagram of authorization provided according to the first embodiment of the present disclosure;

[0039] FIG5 is a third authorization diagram provided according to the first embodiment of the present disclosure;

[0040] FIG6 is a fourth authorization diagram provided according to the first embodiment of the present disclosure;

[0041] FIG7 is a fifth authorization diagram provided according to the first embodiment of the present disclosure;

[0042] FIG8 is a flowchart of an optional authorization method provided according to the first embodiment of the present disclosure;

[0043] FIG9 is a second flowchart of an optional authorization method provided according to the first embodiment of the present disclosure;

[0044] FIG10 is a schematic diagram of an authorization device according to a second embodiment of the present disclosure;

[0045] FIG11 is a schematic diagram of a computer terminal provided according to a third embodiment of the present disclosure. DETAILED DESCRIPTION

[0046] In order to enable those skilled in the art to better understand the solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present disclosure.

[0047] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way are interchangeable where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or components is not necessarily limited to those steps or components clearly listed, but may include other steps or components that are not clearly listed or inherent to these processes, methods, products or devices.

[0048] First, some nouns or terms that appear in the description of the embodiments of the present disclosure are subject to the following explanations:

[0049] Credentials: Also known as credentials or evidence, these refer to the username and password used to access assets, which are hosted on the server in the form of credentials.

[0050] Instance: In computer language, a class is called an instance after it is instantiated. Classes are static and do not occupy process memory, while instances occupy dynamic memory. In a database, it represents a collection of programs. A database instance consists of a series of background processes and the memory blocks allocated by the system for these processes. A cloud server instance is a virtualized independent computing component within cloud computing resources, representing a real, user-accessible host.

[0051] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0052] According to an embodiment of the present disclosure, an authorization method is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0053] The method embodiment provided in the first embodiment of the present disclosure can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 shows a hardware structure block diagram of a computer terminal (or mobile device) for implementing the authorization method. As shown in Figure 1, the computer terminal (or mobile device) 10 may include a processor set 102 (the processor set 102 may include but is not limited to a processing device such as a microprocessor (Microcontroller Unit, referred to as MCU) or a programmable logic device (Field Programmable Gate Array, referred to as FPGA), and the processor set 102 may include a processor set, as shown in Figure 1 using 102a, 102b, ..., 102n), a memory 104 for storing data, and a transmission component 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that the structure shown in Figure 1 is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may also include more or fewer components than shown in FIG. 1 , or have a configuration different from that shown in FIG. 1 .

[0054] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing component, or may be incorporated in whole or in part into any of the other components of the computer terminal 10 (or mobile device). As described in the embodiments of the present disclosure, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0055] The memory 104 can be used to store software programs and components of application software, such as the program instructions / data storage device corresponding to the authorization method in the embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the software programs and components stored in the memory 104, that is, implementing the above-mentioned authorization method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0056] Transmission device 106 is used to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of computer terminal 10. In one embodiment, transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 106 may be a radio frequency (RF) component for wireless communication with the Internet.

[0057] The display may be, for example, a touch screen liquid crystal display that enables a user to interact with a user interface of the computer terminal 10 (or mobile device).

[0058] In the above operating environment, the present disclosure provides an authorization method as shown in Figure 2. Figure 2 is a flow chart of the authorization method provided according to the first embodiment of the present disclosure. The method includes:

[0059] Step S201: receiving an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to a data security center.

[0060] Optionally, the data security center receives an authorization request initiated by a user (i.e., the target object described above). It should be noted that the user's authorization request must include an authorization identifier, which indicates the authorization method for granting access to the data security center. For example, the authorization method may be credential authorization, where the credentials are provided by the user.

[0061] Step S202: Obtain first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

[0062] Optionally, the data security center obtains the first target credentials of the user's multiple database instances based on the above-mentioned authorization identifier. It should be noted that the data security center obtains permission to access multiple database instances based on the first target credentials. It should be noted that the database instance in the multiple database instances includes multiple databases.

[0063] To summarize, the data security center receives the authorization request initiated by the target object, and then, based on the authorization method clearly adopted by the authorization identifier, the data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, thereby avoiding the problem of needing to authorize the data security center for credentials on the authorization page corresponding to each database asset, improving the authorization efficiency of the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.

[0064] In an optional instance, before receiving the authorization request initiated by the target object, the method also includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0065] Optionally, the data security center will scan the user's database assets according to a preset time period or the user's trigger instruction to obtain the user's database instance list to subsequently verify whether the database instance actually exists when the user initiates the authorization request.

[0066] Optionally, after receiving the authorization request initiated by the target object, the target object's identity information and permission information will be verified to ensure information security. If the authorization request also includes the asset information to be authorized, that is, the database instance, the authenticity of the database instance can also be verified.

[0067] To summarize, the data security center receives the authorization request initiated by the target object, and then, based on the authorization method clearly adopted by the authorization identifier, the data security center obtains the first credentials of multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of needing to authorize the data security center with credentials on the authorization page corresponding to each database asset, improving the authorization efficiency of the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.

[0068] In order to improve the flexibility of authorization to the data security center, in the authorization method provided in the first embodiment of the present disclosure, obtaining the first target credentials of multiple database instances based on the authorization identifier includes: determining the authorization method for access authorization to the data security center based on the authorization identifier, wherein the authorization method is one of the following: the first authorization method, the second authorization method and the third authorization method, the first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, and the third authorization method is the authorization method when the target object provides credentials and the correspondence between the credentials and the database instance; obtaining the first target credentials of multiple database instances based on the authorization method.

[0069] Optionally, the authorization method for authorizing access to the data security center is determined based on the authorization identifier. It should be noted that the authorization methods include a first authorization method, a second authorization method, and a third authorization method. The first authorization method is an authorization method when the target object provides credentials, which can also be called a credential authorization method. The second authorization method is an authorization method when the target object does not provide credentials, which can also be called a one-click authorization method. The third authorization method is an authorization method when the target object provides credentials and the correspondence between the credentials and the database instance, which can also be called an import authorization method.

[0070] After determining the authorization method, the data security center obtains the first target credentials of multiple database instances according to the authorization method.

[0071] The data security center is authorized through the first authorization method, the second authorization method and the third authorization method mentioned above, thereby improving the flexibility and efficiency of authorization.

[0072] When the authorization method is the first authorization method, that is, the credential authorization method, authorization can be divided into two methods: 1) The credential management side performs asset association authorization and disassociation. 2) The asset center side, with assets as the center, associates existing credentials or creates new credential associations.

[0073] For the credential management side, in the authorization method provided in the first embodiment of the present disclosure, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, wherein the credentials include the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; establishing a first associated authorization relationship between the first credential and multiple database instances; and obtaining the first target credential based on the first associated authorization relationship and the first credential.

[0074] Optionally, the first credential input by the target object is received through the credential management interface in the data security center. For example, Figure 3 is an authorization schematic diagram provided according to the first embodiment of the present disclosure. As shown in Figure 3, the user can add the above-mentioned first credential in the credential management interface according to the product type of the database to be authorized, and the credential can be used for subsequent authorization of assets of the corresponding asset type.

[0075] The credentials are then associated with the actual assets, establishing a first association authorization relationship between the first credential and multiple database instances. For example, Figure 4 is a second authorization diagram provided according to the first embodiment of the present disclosure. As shown in Figure 4, data assets corresponding to the asset type are added under the first credential. It should be noted that the credential can be directly associated with a database instance or a database within the database instance.

[0076] It should be noted that in the credential management interface, you can also disassociate the credential from the associated database or database instance.

[0077] It should be noted that after receiving the user's input credentials, they need to be encrypted to protect data security. For example, the credentials are first encrypted using the Advanced Encryption Standard (AES) algorithm to obtain encrypted credentials, and then the encrypted credentials are re-encrypted using the Key Management Service (KMS) algorithm to obtain the ciphertext data of the credentials.

[0078] Finally, based on the first associated authorization relationship and the first credential, the first target credential is obtained.

[0079] For the asset center side, in the authorization method provided in the first embodiment of the present disclosure, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to the multiple database instances, wherein the second credential includes at least the second account and the password information corresponding to the second account; establishing a second association authorization relationship between the database in the multiple database instances and the second credential according to the credential association request; obtaining the first target credential according to the second association authorization relationship and the second credential.

[0080] Alternatively, users can initiate a credential association request for databases in multiple database instances through the asset management interface in the data security center. It should be noted that the credential association can be performed for a single or batch database in the asset management interface.

[0081] According to the above-mentioned credential association request, a second association authorization relationship is established between the database in the multiple database instances and the second credential. It should be noted that when establishing the association relationship, you can also choose to create a new credential, and then establish an association authorization between the newly created credential and the database. For example, Figure 5 is a third authorization diagram provided according to the first embodiment of the present disclosure. As shown in Figure 5, existing credentials and newly created credentials are selected for the database assets to be authorized. The database assets available for selection are Database 1 and Database 2.

[0082] Finally, the data security center obtains the above-mentioned first target credential based on the second associated authorization relationship and the second credential.

[0083] The above authorization method can enable the data security center to quickly obtain the credentials provided by the user, thereby improving the efficiency of sensitive data identification.

[0084] If the authorization method is the second authorization method, in the authorization method provided in the first embodiment of the present disclosure, obtaining the first target credentials of multiple database instances based on the authorization method includes: establishing a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; determining the third credential based on the third account and the password information corresponding to the third account, wherein the credential includes the third credential; establishing a third associated authorization relationship between the third credential and multiple database instances; and obtaining the first target credential based on the third associated authorization relationship and the third credential.

[0085] Optionally, if the user does not provide credentials and it is the second authorization method, that is, one-click authorization, the data security center will directly create a third account and the password information corresponding to the third account. It should be noted that the third account is a read-only account, that is, it is granted the minimum permission of read-only access to the specified database. Then, a third associated authorization relationship is established between the third credential and multiple database instances. For example, Figure 6 is a fourth authorization diagram provided according to the first embodiment of the present disclosure. As shown in Figure 6, one-click authorization is performed on the selected database instance. It should be noted that one-click authorization can be performed on a single or multiple database instances, or on only one database in a single database instance.

[0086] It should be noted that the third account and the password information corresponding to the third account will establish an associated authorization relationship with the database in the database instance. During this period, the user is not allowed to initiate the one-click authorization process for the database instance again.

[0087] Finally, the first target credential is obtained through the third associated authorization relationship and the third credential.

[0088] The second authorization method mentioned above can quickly complete access authorization to the data security center without the user providing credentials.

[0089] If the authorization mode is the third authorization mode, in the authorization method provided in the first embodiment of the present disclosure, obtaining the first target credentials of multiple database instances according to the authorization mode includes: receiving an authorization form input by the target object, wherein the authorization form includes at least fourth credentials corresponding to multiple database instances, identification information of the database instances in the multiple database instances, and a correspondence between the identification information and the fourth credentials, and the credentials include the fourth credential; identifying the authorization form to obtain the identification information and the fourth credential; establishing a fourth associated authorization relationship between the fourth credential and the multiple database instances based on the identification information and the correspondence; and obtaining the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0090] Optionally, the data security center can also obtain access rights to the database through a third authorization method. The user can obtain the account and password template file through the data security center, that is, the above-mentioned authorization template form. Figure 7 is the authorization diagram 5 provided according to the first embodiment of the present disclosure. As shown in Figure 7, the user can then add the account and password in the account and password template file and import the file to complete the authorization.

[0091] The data security center will obtain the identification information and the fourth credential based on the uploaded authorization form, and then establish a fourth associated authorization relationship between the fourth credential and multiple database instances, thereby obtaining the above-mentioned first target credential.

[0092] Optionally, if there is a database asset in the authorization form that does not have a corresponding credential, it can be directly processed through one-click authorization (ie, the second authorization method mentioned above).

[0093] Optionally, because the user authorizes the data security center to access the database, which is generally used to identify sensitive data, to prevent the performance of the user instance from being affected, the user can choose to enable or disable the "Scan Sensitive Data Immediately" function when performing asset authorization.

[0094] In an optional embodiment, after obtaining the first target credentials of the above-mentioned multiple database instances in the above-mentioned data center, the authorization method provided in the first embodiment of the present disclosure further includes the following steps: upon receiving a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object, accessing the target database instance based on the sensitive data identification request, and performing sensitive data identification on the database in the target database instance to obtain an identification result.

[0095] Optionally, after the data security center obtains the first target credential, if it receives a user's request for sensitive data identification for a target database instance among multiple database instances, it directly accesses the databases under the target database instance based on the credential of the target database instance, and performs sensitive data identification on the databases in the target database instance to obtain an identification result. By accessing the database using the credential of the target database instance, the technical effect of improving data security is achieved.

[0096] In order to improve data security, in the authorization method provided in the first embodiment of the present disclosure, when a sensitive data identification request for a target database instance among multiple database instances is received from a target object, accessing the target database instance based on the sensitive data identification request includes: determining a second target credential of the target database instance from the first target credential based on the sensitive data identification request; and accessing the target database instance based on the second target credential.

[0097] Accessing the target database instance based on the second target credential includes: determining the target server of the database in the target database instance; establishing a reverse access network between the data security center and the target server, and obtaining the access address and access port of the database in the target database instance based on the reverse access network; establishing a mapped access address and mapped access port based on the access address and access port; accessing the mapped access address and mapped access port based on the second target credential to access the target database instance.

[0098] Optionally, when the data security center receives a sensitive data identification request initiated by a user, the second target credential of the target database instance is determined from the above-mentioned first target credential.

[0099] Then, determine the target server of the database in the target database instance, establish a reverse access network between the data security center and the target server, obtain the access address and access port of the database in the target database instance, and map them to the mapped access address and mapped access port. Finally, access the mapped access address and mapped access port according to the second target credential to achieve the purpose of accessing the target database instance.

[0100] Optionally, Figure 8 is a flowchart of an optional authorization method provided according to the first embodiment of the present disclosure. The schematic diagram shown in Figure 8 can be used to complete the authorization of the data security center, determine the user's assets to be authorized (including multiple database instances), and then complete the authorization through three methods: credential authorization, one-click authorization, and import authorization. Credential authorization includes obtaining associated credential information and setting the user name and password. One-click authorization is for assets with empty account and password, and the one-click authorization flag can be set directly. Import authorization includes parsing the authorization file imported by the user, generating an authorized asset record, and if there is an asset without an account and password, a one-click authorization flag can be set.

[0101] Optionally, FIG9 is a flowchart of the second optional authorization method provided according to the first embodiment of the present disclosure. The flowchart shown in FIG9 is used to complete the authorization of the data security center, clarify the set of assets to be authorized, and perform authorization verification and specification checks. The authorization verification and specification checks here refer to the inspection and verification of the user's permissions and database assets. Then, it is determined whether there is a one-click authorization. If it is a one-click authorization, a read-only account and password are created, and it is determined whether there is a cache control requirement. If so, a cache flag is set. This refers to establishing an associated authorization relationship between the read-only account and password and the database in the database instance. During this period, the user is not allowed to initiate the one-click authorization process for the database instance again. Finally, the read-only account and password are recorded so that the user's authorized assets can be viewed later.

[0102] If it is not one-click authorization, obtain the credentials entered by the user (such as account number and password), and then associate the credentials with the database instance.

[0103] After the association is completed, the Data Security Center automatically sets up the whitelist and security group, opens the reverse access network, and records the mapped IP and port so that the Data Security Center can subsequently access database assets based on the mapped IP and port.

[0104] The aforementioned authorization methods provide flexible asset authorization access methods. Users can choose to authorize the Data Security Center to access their cloud assets using credential authorization, one-click authorization, or imported authorization. Users no longer need to worry about connecting cloud service networks with cloud product networks, configuring whitelists, and maintaining credentials. This greatly simplifies the authorization process when accessing large databases using the same account and password. This solution also offers a more convenient "one-click" authorization method, allowing users to complete the authorization process for a single instance or instance library with a single click.

[0105] In the authorization method provided in the first embodiment of the present disclosure, an authorization request initiated by a target object is received, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate the authorization method for granting access to a data security center; first target credentials of multiple database instances are obtained based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, and the database instances in the multiple database instances include at least one database; when a sensitive data identification request for a target database instance in the multiple database instances is received initiated by the target object, the target database instance is accessed based on the sensitive data identification request, and sensitive data identification is performed on the database in the target database instance to obtain an identification result, thereby solving the technical problem that when a user needs the data security center to perform sensitive data identification on a database asset, the user can only perform credential authorization on the data security center on the authorization page corresponding to each database asset separately, resulting in relatively low efficiency in sensitive data identification. In the embodiment of the present disclosure, the data security center directly receives the authorization request initiated by the target object, and then, based on the authorization method clearly adopted by the authorization identifier, the data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, thereby avoiding the problem of needing to authorize the data security center for credentials on the authorization page corresponding to each database asset, improving the authorization efficiency of the data security center, and thereby achieving the effect of improving the efficiency of sensitive data identification.

[0106] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present disclosure is not limited by the order of the actions described, because according to the present disclosure, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and components involved are not necessarily required by the present disclosure.

[0107] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present disclosure.

[0108] According to an embodiment of the present disclosure, a data processing device for implementing the above authorization method is also provided. As shown in FIG10 , the device includes: a receiving component 1001 and an acquiring component 1002 .

[0109] The receiving component 1001 is configured to receive an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, which is used to indicate an authorization method for authorizing access to the data security center;

[0110] Acquisition component 1002 is used to obtain the first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has the authority to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

[0111] In the authorization device provided in the second embodiment of the present disclosure, a receiving component 1001 receives an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, which is used to indicate an authorization method for granting access authorization to a data security center; an obtaining component 1002 obtains first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, wherein the database instances in the multiple database instances include at least one database, thereby solving the technical problem that when a user requires the data security center to identify sensitive data of a database asset, the user can only authorize the data security center with credentials separately on the authorization page corresponding to each database asset, resulting in a relatively low efficiency in sensitive data identification. In the embodiment of the present disclosure, the data security center directly receives the authorization request initiated by the target object, and then, based on the authorization method clearly adopted by the authorization identifier, the data security center obtains the first target credentials of multiple database instances of the target object according to the corresponding authorization method, thereby avoiding the problem of needing to authorize the data security center with credentials on the authorization page corresponding to each database asset, thereby improving the authorization efficiency of the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.

[0112] Optionally, in the authorization device provided in the second embodiment of the present disclosure, the acquisition component includes: a first determination sub-component, used to determine the authorization method for access authorization to the data security center based on the authorization identifier, wherein the authorization method is one of the following: a first authorization method, a second authorization method and a third authorization method, the first authorization method is an authorization method when the target object provides credentials, the second authorization method is an authorization method when the target object does not provide credentials, and the third authorization method is an authorization method when the target object provides credentials and the correspondence between the credentials and the database instance; an acquisition sub-component, used to obtain the first target credentials of multiple database instances based on the authorization method.

[0113] Optionally, in the authorization device provided in the second embodiment of the present disclosure, if the authorization method is the first authorization method, the acquisition subcomponent includes: a first receiving component, used to receive the first credential input by the target object through the credential management interface in the data security center, wherein the credential includes the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; a first establishing component, used to establish a first associated authorization relationship between the first credential and multiple database instances; a first acquisition component, used to obtain the first target credential based on the first associated authorization relationship and the first credential.

[0114] Optionally, in the authorization device provided in the second embodiment of the present disclosure, if the authorization method is the first authorization method, the acquisition subcomponent includes: a second receiving component, used to receive a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to the multiple database instances, wherein the credentials include the second credentials, and the second credentials include at least the second account and the password information corresponding to the second account; a second establishing component, used to establish a second association authorization relationship between the database in the multiple database instances and the second credentials based on the credential association request; a second acquisition component, used to obtain the first target credential based on the second association authorization relationship and the second credential.

[0115] Optionally, in the authorization device provided in the second embodiment of the present disclosure, if the authorization method is the second authorization method, the acquisition sub-component includes: a third establishment component, used to establish a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; a first determination component, used to determine the third credential based on the third account and the password information corresponding to the third account, wherein the credential includes the third credential; a fourth establishment component, used to establish a third associated authorization relationship between the third credential and multiple database instances; a third acquisition component, used to obtain the first target credential based on the third associated authorization relationship and the third credential.

[0116] Optionally, in the authorization device provided in the second embodiment of the present disclosure, if the authorization method is the third authorization method, the acquisition sub-component includes: a third receiving component, used to receive the authorization form input by the target object, wherein the authorization form includes at least a plurality of database instance fourth credentials, identification information of the database instance in the plurality of database instances, and a correspondence between the identification information and the fourth credentials, and the credentials include the fourth credentials; an identification component, used to identify the authorization form and obtain the identification information and the fourth credentials; a fifth establishing component, used to establish a fourth associated authorization relationship between the fourth credential and the plurality of database instances based on the identification information and the correspondence; and a fourth acquisition component, used to obtain the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0117] Optionally, in the authorization device provided in the second embodiment of the present disclosure, the device also includes: an access component for obtaining the first target credentials of multiple database instances based on the authorization identifier, and upon receiving a sensitive data identification request for a target database instance among the multiple database instances initiated by the target object, accessing the target database instance based on the sensitive data identification request; an identification component for performing sensitive data identification on the database in the target database instance to obtain an identification result.

[0118] Optionally, in the authorization device provided in embodiment 2 of the present disclosure, the access component includes: a second determination sub-component, used to determine the second target credential of the target database instance from the first target credential based on the sensitive data identification request; and an access sub-component, used to access the target database instance based on the second target credential.

[0119] Optionally, in the authorization device provided in the second embodiment of the present disclosure, the access subcomponent includes: a second determination component, used to determine the target server of the database in the target database instance; a sixth establishment component, used to establish a reverse access network between the data security center and the target server, and obtain the access address and access port of the database in the target database instance based on the reverse access network; the sixth establishment component, used to establish a mapped access address and a mapped access port based on the access address and the access port; and an access component, used to access the mapped access address and the mapped access port based on the second target credential to access the target database instance.

[0120] Optionally, in the authorization device provided in the second embodiment of the present disclosure, the device also includes: a first scanning component, used to scan the database assets corresponding to the target object according to a preset time period before receiving the authorization request initiated by the target object to obtain a list of database instances; or, a second scanning component, used to scan the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0121] It should be noted that the receiving component 1001 and the acquiring component 1002 described above correspond to steps S201 to S202 in Example 1. The examples and application scenarios implemented by the two components and the corresponding steps are the same, but are not limited to the contents disclosed in Example 1. It should be noted that the above components, as part of the device, can be run in the computer terminal 10 provided in Example 1.

[0122] It should be noted that the preferred implementation scheme involved in the above embodiments of the present disclosure is the same as the solution provided in Example 1, as well as the application scenario and implementation process, but is not limited to the solution provided in Example 1.

[0123] The embodiment of the present disclosure may provide a computer terminal, which may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the computer terminal may also be replaced by a terminal device such as a mobile terminal.

[0124] Optionally, in this embodiment, the computer terminal may be located in at least one network device among a plurality of network devices of a computer network.

[0125] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the authorization method: receiving an authorization request initiated by the target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate the authorization method for authorizing access to the data security center; obtaining the first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has the authority to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

[0126] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: obtaining the first target credentials of multiple database instances based on the authorization identifier includes: determining the authorization method for access authorization to the data security center based on the authorization identifier, wherein the authorization method is one of the following: the first authorization method, the second authorization method and the third authorization method, the first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, the third authorization method is the authorization method when the target object provides credentials, and the authorization method when there is a correspondence between the credentials and the database instance; obtaining the first target credentials of multiple database instances based on the authorization method.

[0127] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: If the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, wherein the credentials include the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; establishing a first associated authorization relationship between the first credential and multiple database instances; obtaining the first target credential based on the first associated authorization relationship and the first credential.

[0128] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to multiple database instances, wherein the credentials include the second credentials, and the second credentials include at least the second account and the password information corresponding to the second account; establishing a second association authorization relationship between the database in the multiple database instances and the second credentials according to the credential association request; obtaining the first target credential based on the second association authorization relationship and the second credential.

[0129] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: if the authorization method is the second authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: establishing a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; determining the third credential based on the third account and the password information corresponding to the third account, wherein the credential includes the third credential; establishing a third associated authorization relationship between the third credential and multiple database instances; and obtaining the first target credential based on the third associated authorization relationship and the third credential.

[0130] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: if the authorization method is the third authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving an authorization form input by the target object, wherein the authorization form includes at least fourth credentials corresponding to multiple database instances, identification information of the database instances in the multiple database instances, and a correspondence between the identification information and the fourth credentials, and the credentials include the fourth credentials; identifying the authorization form to obtain identification information and the fourth credentials; establishing a fourth associated authorization relationship between the fourth credential and the multiple database instances based on the identification information and the correspondence; obtaining the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0131] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: after obtaining the first target credentials of multiple database instances based on the authorization identifier, the method also includes: upon receiving a sensitive data identification request initiated by the target object for a target database instance among the multiple database instances, accessing the target database instance based on the sensitive data identification request; performing sensitive data identification on the database in the target database instance to obtain an identification result.

[0132] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: when receiving a sensitive data identification request initiated by the target object for a target database instance among multiple database instances, accessing the target database instance based on the sensitive data identification request includes: determining the second target credential of the target database instance from the first target credential based on the sensitive data identification request; and accessing the target database instance based on the second target credential.

[0133] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: accessing the target database instance based on the second target credential includes: determining the target server of the database in the target database instance; establishing a reverse access network between the data security center and the target server, and obtaining the access address and access port of the database in the target database instance based on the reverse access network; establishing a mapped access address and a mapped access port based on the access address and the access port; accessing the mapped access address and the mapped access port based on the second target credential to access the target database instance.

[0134] The above-mentioned computer terminal can execute the program code of the following steps in the authorization method: before receiving the authorization request initiated by the target object, the method also includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0135] Optionally, Figure 11 is a block diagram of a computer terminal according to an embodiment of the present disclosure. As shown in Figure 11, the computer terminal 10 may include: one or more (only one is shown in Figure 11) processors 102, and a memory 104. The computer terminal 10 may also include a memory controller to control and manage the memory 104; the computer terminal 10 may also include a peripheral interface to connect to radio frequency components, audio components, and a display screen, etc.

[0136] Among them, the memory can be used to store software programs and components, such as the program instructions / components corresponding to the authorization method and device in the embodiment of the present disclosure. The processor executes various functional applications and data processing by running the software programs and components stored in the memory, that is, implementing the above-mentioned authorization method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories can be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0137] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: receiving an authorization request initiated by the target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate the authorization method for authorizing access to the data security center; obtaining the first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has the authority to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

[0138] Optionally, the processor may also execute the program code of the following steps: obtaining the first target credentials of multiple database instances based on the authorization identifier includes: determining the authorization method for authorizing access to the data security center based on the authorization identifier, wherein the authorization method is one of the following: the first authorization method, the second authorization method and the third authorization method, the first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, the third authorization method is the authorization method when the target object provides credentials, and the authorization method when there is a correspondence between the credentials and the database instance; obtaining the first target credentials of multiple database instances based on the authorization method.

[0139] Optionally, the processor may also execute the program code of the following steps: if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, wherein the credentials include the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; establishing a first associated authorization relationship between the first credential and multiple database instances; obtaining the first target credential based on the first associated authorization relationship and the first credential.

[0140] Optionally, the processor may also execute the program code of the following steps: if the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to the multiple database instances, the credentials include the second credentials, and the second credentials include at least the second account and the password information corresponding to the second account; establishing a second association authorization relationship between the database in the multiple database instances and the second credentials according to the credential association request; obtaining the first target credential based on the second association authorization relationship and the second credential.

[0141] Optionally, the processor may also execute the program code of the following steps: if the authorization method is the second authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: establishing a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; determining the third credential based on the third account and password information corresponding to the third account, wherein the credential includes the third credential; establishing a third associated authorization relationship between the third credential and multiple database instances; and obtaining the first target credential based on the third associated authorization relationship and the third credential.

[0142] Optionally, the processor may also execute the program code of the following steps: if the authorization method is the third authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving an authorization form input by the target object, wherein the authorization form includes at least multiple database instance fourth credentials, identification information of the database instance in the multiple database instances, and the correspondence between the identification information and; identifying the authorization form to obtain the identification information and the fourth credential; establishing a fourth associated authorization relationship between the fourth credential and the multiple database instances based on the identification information and the correspondence; obtaining the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0143] Optionally, the processor may also execute the program code of the following steps: after obtaining the first target credentials of multiple database instances based on the authorization identifier, the method further includes: upon receiving a sensitive data identification request for a target database instance among multiple database instances initiated by the target object, accessing the target database instance based on the sensitive data identification request; performing sensitive data identification on the database in the target database instance to obtain an identification result.

[0144] Optionally, the above-mentioned processor can also execute the program code of the following steps: when receiving a sensitive data identification request initiated by the target object for a target database instance among multiple database instances, accessing the target database instance based on the sensitive data identification request includes: determining the second target credential of the target database instance from the first target credential based on the sensitive data identification request; and accessing the target database instance based on the second target credential.

[0145] Optionally, the above-mentioned processor can also execute the program code of the following steps: accessing the target database instance based on the second target credential includes: determining the target server of the database in the target database instance; establishing a reverse access network between the data security center and the target server, and obtaining the access address and access port of the database in the target database instance based on the reverse access network; establishing a mapped access address and a mapped access port based on the access address and the access port; accessing the mapped access address and the mapped access port based on the second target credential to access the target database instance.

[0146] Optionally, the processor may also execute the program code of the following steps: before receiving the authorization request initiated by the target object, the method further includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0147] Those skilled in the art will appreciate that the structure shown in FIG11 is merely illustrative, and the computer terminal may also be a smartphone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile internet device (MID), a PAD, or other terminal device. FIG11 does not limit the structure of the aforementioned electronic devices. For example, the computer terminal 10 may include more or fewer components (such as a network interface, a display device, etc.) than those shown in FIG11, or may have a configuration different from that shown in FIG11.

[0148] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0149] The embodiment of the present disclosure further provides a computer-readable storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the authorization method provided in the first embodiment.

[0150] Optionally, in this embodiment, the above-mentioned storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.

[0151] Optionally, in this embodiment, the above-mentioned storage medium is configured to store program code for executing the following steps: receiving an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate the authorization method for authorizing access to the data security center; obtaining first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

[0152] The above-mentioned storage medium is configured to store program code for executing the following steps: obtaining the first target credentials of multiple database instances based on the authorization identifier includes: determining the authorization method for authorizing access to the data security center based on the authorization identifier, wherein the authorization method is one of the following: the first authorization method, the second authorization method and the third authorization method, the first authorization method is the authorization method when the target object provides credentials, the second authorization method is the authorization method when the target object does not provide credentials, the third authorization method is the authorization method when the target object provides credentials, and the authorization method when there is a correspondence between the credentials and the database instance; obtaining the first target credentials of multiple database instances based on the authorization method.

[0153] The above-mentioned storage medium is configured to store program code for executing the following steps: If the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving the first credentials input by the target object through the credential management interface in the data security center, wherein the credentials include the first credential, and the first credential includes at least the first account and the password information corresponding to the first account; establishing a first associated authorization relationship between the first credential and multiple database instances; obtaining the first target credential based on the first associated authorization relationship and the first credential.

[0154] The above-mentioned storage medium is configured to store program code for executing the following steps: If the authorization method is the first authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving a credential association request for a database in multiple database instances through the asset management interface in the data security center, wherein the credential association request includes at least the second credentials corresponding to multiple database instances, the credentials include the second credentials, and the second credentials include at least the second account and the password information corresponding to the second account; establishing a second association authorization relationship between the database in the multiple database instances and the second credentials according to the credential association request; obtaining the first target credential based on the second association authorization relationship and the second credential.

[0155] The above-mentioned storage medium is configured to store program code for executing the following steps: if the authorization method is the second authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: establishing a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; determining the third credential based on the third account and the password information corresponding to the third account, wherein the credential includes the third credential; establishing a third associated authorization relationship between the third credential and multiple database instances; obtaining the first target credential based on the third associated authorization relationship and the third credential.

[0156] The above-mentioned storage medium is configured to store program code for executing the following steps: if the authorization method is the third authorization method, obtaining the first target credentials of multiple database instances according to the authorization method includes: receiving an authorization form input by the target object, wherein the authorization form includes at least fourth credentials corresponding to multiple database instances, identification information of the database instances in the multiple database instances, and a correspondence between the identification information and the fourth credentials, and the credentials include the fourth credentials; identifying the authorization form to obtain the identification information and the fourth credentials; establishing a fourth associated authorization relationship between the fourth credential and the multiple database instances based on the identification information and the correspondence; obtaining the first target credential based on the fourth associated authorization relationship and the fourth credential.

[0157] The above-mentioned storage medium is configured to store program code for executing the following steps: after obtaining the first target credentials of multiple database instances based on the authorization identifier, the method also includes: upon receiving a sensitive data identification request initiated by the target object for a target database instance among the multiple database instances, accessing the target database instance based on the sensitive data identification request; performing sensitive data identification on the database in the target database instance to obtain an identification result.

[0158] The above-mentioned storage medium is configured to store program code for executing the following steps: upon receiving a sensitive data identification request initiated by a target object for a target database instance among multiple database instances, accessing the target database instance based on the sensitive data identification request includes: determining a second target credential of the target database instance from the first target credential based on the sensitive data identification request; and accessing the target database instance based on the second target credential.

[0159] The above-mentioned storage medium is configured to store program code for executing the following steps: accessing the target database instance based on the second target credential includes: determining the target server of the database in the target database instance; establishing a reverse access network between the data security center and the target server, and obtaining the access address and access port of the database in the target database instance based on the reverse access network; establishing a mapped access address and a mapped access port based on the access address and the access port; accessing the mapped access address and the mapped access port based on the second target credential to access the target database instance.

[0160] The above-mentioned storage medium is configured to store program code for executing the following steps: before receiving the authorization request initiated by the target object, the method also includes: scanning the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or scanning the database assets corresponding to the target object according to the trigger instruction of the target object to obtain a list of database instances.

[0161] According to another aspect of the present disclosure, a computer program product is provided, comprising a computer program. Optionally, when executed by a processor, the computer program implements any one of the above authorization methods.

[0162] According to another aspect of the present disclosure, a computer program product is provided, comprising a non-volatile computer-readable storage medium. Optionally, the non-volatile computer-readable storage medium stores a computer program, which, when executed by a processor, implements any of the above authorization methods.

[0163] According to another aspect of the present disclosure, a computer program is further provided. Optionally, when executed by a processor, the computer program implements any one of the above authorization methods.

[0164] According to another aspect of an embodiment of the present disclosure, an electronic device is provided, including a memory storing an executable program; and a processor for running the program, wherein any one of the above authorization methods is executed when the program is running.

[0165] The serial numbers of the above-mentioned embodiments of the present disclosure are for description only and do not represent the advantages or disadvantages of the embodiments.

[0166] In the above embodiments of the present disclosure, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0167] In the several embodiments provided in this disclosure, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of components is merely a logical functional division. In actual implementation, other divisions may be used, such as combining or integrating multiple components or assemblies into another system, or omitting or not implementing certain features. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interface, or the indirect coupling or communication connection between components or assemblies may be electrical or otherwise.

[0168] The components described as separate parts may or may not be physically separate, and the components shown as components may or may not be physical components, that is, they may be located in one place or distributed across multiple network components. Some or all of these components may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0169] In addition, the functional components in the various embodiments of the present disclosure may be integrated into a single processing component, each component may exist physically separately, or two or more components may be integrated into a single component. The aforementioned integrated components may be implemented in the form of hardware or software functional components.

[0170] If the integrated components are implemented in the form of software functional components and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0171] The above is only a preferred embodiment of the present disclosure. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present disclosure. These improvements and modifications should also be regarded as within the scope of protection of the present disclosure. Industrial Applicability

[0172] The solution provided by the embodiment of the present disclosure can be applied to the process of a user using a data security center, by receiving an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, which is used to indicate the authorization method for authorizing access to the data security center; obtaining first target credentials for multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, wherein the database instances in the multiple database instances include at least one database. This solves the technical problem that when a user requires the data security center to identify sensitive data of a database asset, the data security center can only authorize the credentials of the data security center separately on the authorization page corresponding to each database asset, resulting in relatively low efficiency in sensitive data identification. In the embodiment of the present disclosure, the data security center receives the authorization request initiated by the target object, and then, based on the authorization method clearly adopted by the authorization identifier, the data security center obtains the first target credentials of the multiple database instances of the target object according to the corresponding authorization method, avoiding the problem of needing to authorize the credentials of the data security center on the authorization page corresponding to each database asset, improving the authorization efficiency of the data security center, and thus achieving the effect of improving the efficiency of sensitive data identification.

Claims

1. An authorization method, the authorization method being applied to a data security center, comprising: Receive an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to the data security center; Obtain first target credentials for multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

2. The method according to claim 1, wherein: The step of obtaining first target credentials of multiple database instances according to the authorization identifier includes: Determine an authorization method for authorizing access to the data security center based on the authorization identifier, wherein the authorization method is one of the following: a first authorization method, a second authorization method, and a third authorization method, wherein the first authorization method is an authorization method in which the target object provides credentials, the second authorization method is an authorization method in which the target object does not provide the credentials, and the third authorization method is an authorization method in which the target object provides the credentials and there is a correspondence between the credentials and a database instance; Obtain first target credentials of multiple database instances according to the authorization method.

3. The method according to claim 2, wherein: If the authorization method is the first authorization method, obtaining first target credentials of multiple database instances according to the authorization method includes: Receiving, through the credential management interface in the data security center, a first credential input by the target object, wherein the credential includes the first credential, and the first credential includes at least a first account and password information corresponding to the first account; Establishing a first association authorization relationship between the first credential and the plurality of database instances; Obtain the first target credential based on the first associated authorization relationship and the first credential.

4. The method according to claim 2, wherein: If the authorization method is the first authorization method, obtaining first target credentials of multiple database instances according to the authorization method includes: Receiving, through the asset management interface in the data security center, a credential association request for a database in the multiple database instances, wherein the credential association request includes at least a second credential corresponding to the multiple database instances, the credential includes the second credential, and the second credential includes at least a second account and password information corresponding to the second account; Establishing a second association authorization relationship between a database in the plurality of database instances and the second credential according to the credential association request; Obtain the first target credential based on the second associated authorization relationship and the second credential.

5. The method according to claim 2, wherein: If the authorization method is the second authorization method, obtaining the first target credentials of the plurality of database instances according to the authorization method includes: Establishing a third account and password information corresponding to the third account, wherein the access permission of the third account is read-only access; Determine a third credential based on the third account and the password information corresponding to the third account, wherein the credential includes the third credential; Establishing a third association authorization relationship between the third credential and the plurality of database instances; The first target credential is obtained based on the third associated authorization relationship and the third credential.

6. The method according to claim 2, wherein: If the authorization method is the third authorization method, obtaining the first target credentials of the plurality of database instances according to the authorization method includes: receiving an authorization form input by the target object, wherein the authorization form at least includes fourth credentials corresponding to the multiple database instances, identification information of database instances among the multiple database instances, and a correspondence between the identification information and the fourth credentials, and the credentials include the fourth credentials; Identify the authorization form and obtain the identification information and the fourth credential; Establishing a fourth association authorization relationship between the fourth credential and the multiple database instances according to the identification information and the corresponding relationship; Obtain the first target credential based on the fourth associated authorization relationship and the fourth credential.

7. The method according to claim 1, wherein: After obtaining first target credentials of multiple database instances according to the authorization identifier, the method further includes: Upon receiving a sensitive data identification request initiated by the target object for a target database instance among the multiple database instances, accessing the target database instance according to the sensitive data identification request; Sensitive data is identified on the database in the target database instance to obtain an identification result.

8. The method according to claim 7, wherein: In a case where a sensitive data identification request for a target database instance among the multiple database instances is received, the accessing the target database instance according to the sensitive data identification request includes: Determining, based on the sensitive data identification request, a second target credential of the target database instance from the first target credential; The target database instance is accessed according to the second target credential.

9. The method according to claim 8, wherein: The accessing the target database instance according to the second target credential comprises: Determine a target server for a database in the target database instance; Establishing a reverse access network between the data security center and the target server, and obtaining an access address and an access port of a database in the target database instance based on the reverse access network; According to the access address and the access port, establish a mapped access address and a mapped access port; The mapped access address and the mapped access port are accessed according to the second target credential to access the target database instance.

10. The method according to claim 1, wherein: Before receiving the authorization request initiated by the target object, the method further includes: Scan the database assets corresponding to the target object according to a preset time period to obtain a list of database instances; or, The database assets corresponding to the target object are scanned according to the trigger instruction of the target object to obtain the database instance list.

11. An authorization device, comprising: A receiving component, configured to receive an authorization request initiated by a target object, wherein the authorization request includes at least an authorization identifier, and the authorization identifier is used to indicate an authorization method for authorizing access to a data security center; An acquisition component is configured to acquire first target credentials of multiple database instances based on the authorization identifier, wherein the first target credentials are used to determine whether the data security center has permission to access the multiple database instances, and the database instances in the multiple database instances include at least one database.

12. A computer program product comprising: A computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 10.

13. A computer program product comprising: A non-volatile computer-readable storage medium storing a computer program, wherein the computer program implements the method according to any one of claims 1 to 10 when executed by a processor.

14. A computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

15. A computer-readable storage medium, wherein: The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the storage medium is located is controlled to execute the authorization method according to any one of claims 1 to 10.

16. An electronic device, characterized in that: include: A memory storing an executable program; A processor is configured to run the program, wherein the program executes the authorization method described in any one of claims 1 to 10 when running.

Citation Information

Patent Citations

  • Online authorization method for semi-open wireless network access based on invitation mechanism

    CN111835678A

  • Database processing method and device, equipment and medium

    CN116933321A

  • Data processing method and device based on trusted execution environment, equipment and medium

    CN116980163A

  • Information access control system, server device thereof, and information access control method

    JP2011100362A

  • Computer user credentialing and verification system

    US11770374B1