Fully encrypted database system, data processing method, security control apparatus, and device
Through the security control module and data processing engine in the fully-secret database system, the high complexity and high cost problems caused by database kernel transformation in the prior art are solved, and stable, secure and flexible data processing operations are achieved.
Patent Information
- Application Number
- PCT/IB2024/062165
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-15
- Filing Date
- 2024-12-04
- Publication Date
- 2025-07-24
AI Technical Summary
The existing encrypted database needs to transform the database kernel when processing the dense data, resulting in high complexity and increased engineering costs. The dense SQL operator is very different from ordinary databases, and the application access cost is high, making it difficult to meet diversified needs.
The fully-secret state database system is adopted, and the security control module and the data processing engine work independently in the trusted area. The security control module decrypts the encrypted data and sends it to the data processing engine for processing, realizing data processing operations without the need to modify the database core.
It realizes stable data processing without modifying the database core, reduces transformation costs, and ensures the security, reliability and flexibility of data processing.
Smart Images

Figure IB2024062165_24072025_PF_FP_ABST
Abstract
Description
[0001] This disclosure claims priority to Chinese patent application number 202410056599.4, filed with the China Patent Office on January 15, 2024, entitled "Fully Secret Database System, Data Processing Method, Security Control Device, and Equipment," the entire contents of which are incorporated herein by reference. Technical Field This disclosure relates to the field of database technology, and more particularly to a fully secret database system, data processing method, security control device, and equipment. Background: With the rapid development of science and technology, people's requirements for data security are becoming increasingly stringent, leading to the widespread use of encrypted databases. Currently, encrypted databases provide secret computing interfaces at the Structured Query Language (SQL) operator level, which enable database processing operations on secret data. However, implementing these secret computing interfaces at the SQL operator level requires updating, adjusting, or reconfiguring the database kernel, which not only increases complexity but also the cost of database modification. SUMMARY OF THE INVENTION Embodiments of the present disclosure provide a fully encrypted database system, data processing method, security control device, and equipment. These devices enable stable data processing operations without modifying the database kernel, reducing the cost of modifying a fully encrypted database. In a first aspect, embodiments of the present disclosure provide a fully encrypted database system comprising: a security control module, disposed in a trusted area corresponding to the fully encrypted database, configured to receive a data processing request, decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine for processing; the data processing request includes encrypted sensitive data; and a data processing engine, communicatively connected to the security control module and disposed in the trusted area corresponding to the fully encrypted database, configured to process the decrypted processing request and obtain a data processing result.In a second aspect, embodiments of the present disclosure provide a data processing method, applied to a fully encrypted database system. The fully encrypted database system includes a security control module and a data processing engine in communication with each other, wherein the security control module and the data processing engine are both located in a trusted zone corresponding to the fully encrypted database. The method comprises: the security control module obtaining a data processing request, wherein the data processing request includes encrypted sensitive data; the security control module decrypting the data processing request to obtain a decryption processing request, and sending the decryption processing request to the data processing engine for processing; the data processing engine processing the decryption processing request to obtain a data processing result. In a third aspect, embodiments of the present disclosure provide an electronic device, comprising: a memory and a processor; wherein the memory is configured to store one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the data processing method of the second aspect. In a fourth aspect, embodiments of the present disclosure provide a computer storage medium configured to store a computer program, wherein the computer program, when executed by a computer, implements the data processing method of the second aspect. In a fifth aspect, embodiments of the present disclosure provide a computer program product, comprising: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform the steps of the data processing method of the second aspect. In a sixth aspect, embodiments of the present disclosure provide a data processing method, applied to a security control module, wherein the security control module is communicatively connected to a data processing engine, and both the security control module and the data processing engine are located in a trusted zone corresponding to a fully encrypted database. The method comprises: obtaining a data processing request, wherein the data processing request includes encrypted sensitive data; decrypting the data processing request to obtain a decrypted processing request; and sending the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request and obtains a data processing result. In the seventh aspect, an embodiment of the present disclosure provides a security control device, which is communicatively connected to a data processing engine, and both the security control device and the data processing engine are located in a trusted area corresponding to a fully encrypted database; the security control device includes: a second acquisition module, used to obtain a data processing request, the data processing request including sensitive data after encryption processing; a second processing module, used to decrypt the data processing request, obtain a decryption processing request, and send the decryption processing request to the data processing engine for processing, so that the data processing engine processes the decryption processing request and obtains a data processing result.In an eighth aspect, embodiments of the present disclosure provide an electronic device, comprising: a memory and a processor; wherein the memory is configured to store one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the data processing method described in the sixth aspect. In a ninth aspect, embodiments of the present disclosure provide a computer storage medium, configured to store a computer program, wherein the computer program causes a computer to implement the data processing method described in the sixth aspect when executed. In a tenth aspect, embodiments of the present disclosure provide a computer program product, comprising: a computer program, wherein when executed by a processor of an electronic device, the computer program causes the processor to perform the steps of the data processing method described in the sixth aspect. The fully encrypted database system, data processing method, security control device, and apparatus provided in this embodiment obtain data processing requests through a security control module. Since the data processing requests are encrypted, the security control module decrypts the data processing requests to obtain a decrypted processing request, sends the decrypted processing request to the data processing engine for processing, and then uses the data processing engine to process the decrypted processing request. This effectively implements data encryption processing operations based on the fully encrypted database. Because the security control module and the data processing engine for performing data processing operations are independent of each other and both are located in the trusted zone corresponding to the fully encrypted database, stable data processing operations can be effectively achieved without modifying the database kernel. This also reduces database modification costs and further ensures the practicality of the system. To more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below represent some embodiments of the present disclosure. Persons skilled in the art can derive other drawings based on these drawings without inventive effort. Figure 1 is a schematic diagram of the principles of a fully secret database system provided in an embodiment of the present disclosure; Figure 2 is a schematic diagram of the structure of a fully secret database system provided in an embodiment of the present disclosure; Figure 3 is a schematic diagram of the structure of another fully secret database system provided in an embodiment of the present disclosure; Figure 4 is a flowchart of data processing operations implemented based on the fully secret database system provided in an embodiment of the present disclosure; Figure 5 is a schematic flow diagram of a data processing method provided in an embodiment of the present disclosure; Figure 6 is a schematic diagram of the structure of an electronic device corresponding to the data processing method provided in the embodiment of Figure 5; and Figure 7 is a schematic flow diagram of another data processing method provided in an embodiment of the present disclosure. Trusted Execution Environment: Trusted Execution Environment, referred to as TEE, can provide a secure execution environment isolated from the outside world. The secure execution environment can protect the code and data inside it from being leaked or maliciously tampered with. The instance of TEE runtime is called encryption. oRemote Attestation (RA) is used to prove that the target service is running in a trusted TEE environment and that the target service code functions as expected. Third-party applications can use RA to establish an end-to-end authenticated channel with the target service and further establish a secure channel. Trusted Domain: Users must trust services within this domain. Secure Gateway (SecureGW) operates on database connections and provides additional security features, such as data encryption and decryption, and data authorization and authentication. Data Encryption Key (DEK) is used to encrypt user data. Master Encryption Key (MEK) is used to encrypt the data key DEK. Transparent Data Encryption (TDE) is an application-insensitive, transparent encryption and decryption solution. Data is encrypted using a user-specified key before being stored on disk and decrypted before being loaded from disk into memory. Data stored in memory is plaintext. To facilitate understanding of the implementation principle and effect of the technical solution in this embodiment, the following is a brief description of the relevant technology: The fully encrypted database uses confidential computing capabilities, so that after the data is encrypted on the user side (client), it only needs to exist in ciphertext form on the untrusted server side throughout the process, but still supports all database transactions, queries, analysis and other operations. This not only minimizes the potential data security risks easily caused by uncontrollable factors such as personnel and platform management, but also effectively prevents cloud database services (or anyone other than data owners such as application services) from accessing users' plaintext data, avoiding cloud data leakage. At the same time, it can also prevent R&D and operation and maintenance from stealing data and not worry about database account leakage. Customers can fully own the data, ensuring that: (1) the user's plaintext data cannot be obtained by the outside world during the process of providing data services; (2) authorized users can read and write data in the database normally through existing protocols; (3) unauthorized users cannot obtain the plaintext data of protected users. Currently, fully encrypted databases generally implement database processing operations on encrypted data by providing encrypted computing interfaces at the Structured Query Language (SQL) operator level. However, this approach has drawbacks:
[0002] (1) The usage of dense SQL operators is different from that of ordinary databases. This means that when applications access the database, they usually need to be adapted, which increases the cost of transformation on the application side.
[0003] (2) The database's ability to process confidential data is limited by the richness of confidential SQL operators. Its functions are only a subset of those of ordinary databases, making it difficult to meet the diverse needs of applications.
[0004] (3) In the implementation of the secret SQL operator, it is usually necessary to modify the database kernel. This not only makes the modification more complex but also incurs high engineering costs. In order to solve the above technical problems, this embodiment provides a fully secret database system, a data processing method, a security control device and equipment. Referring to FIG1 , the fully secret database system may include: a security control module 200 and a data processing engine 300 arranged in a trusted area corresponding to the fully secret database. The security control module 200 is connected to the client 100 in communication so that the user can use the fully secret database system through the client 100. In some instances, the data processing engine 300 may be located in the database kernel, and the database kernel at this time may mainly include the data processing engine 300 for implementing data processing operations. oThe fully encrypted database system can be implemented as a cloud server or cloud service platform. The cloud service platform can provide fully encrypted database services, specifically by providing an external service interface. Users call this service interface to access the corresponding service. Service interfaces include software development kits (SDKs) and application programming interfaces (APIs). Alternatively, in physical implementation, the fully encrypted database system can be any device capable of providing computing services, responding to data processing requests, and performing processing, such as a cluster server, a conventional server, a cloud server, a cloud host, a virtual center, etc. The fully encrypted database system is primarily composed of a processor, a hard disk, memory, a system bus, etc., similar to a general computer architecture. The client 100 described above can be any computing device with certain data transmission capabilities. In specific implementations, the client 100 can be a mobile phone, a personal computer (PC), a tablet computer, a configuration application, etc. In addition, the basic structure of the client 100 may include at least one processor. The number of processors depends on the configuration and type of client 100. Client 100 may also include memory, which can be volatile, such as random access memory (RAM), non-volatile, such as read-only memory (ROM), flash memory, or both. The memory typically stores an operating system (OS), one or more application programs, and may also store program data. In addition to the processing unit and memory, client 100 also includes some basic configurations, such as a network card chip, an I / O bus, a display component, and some peripheral devices. Optionally, some peripheral devices may include, for example, a keyboard, a mouse, a stylus, a printer, etc. Other peripheral devices are well known in the art and are not described in detail here. In the above embodiment, client 100 can establish a network connection with security control module 200. This network connection can be wireless or wired.If the client 100 is in communication with the security control module 200, the mobile network standard may be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), Wi-Max, 5G, 6G, etc. In the disclosed embodiment, the client 100 may generate, store, or obtain an original processing request corresponding to the fully encrypted data system. To prevent data leakage and ensure data operation security, the plaintext original processing request may be encrypted to obtain the data processing request. To implement the data processing operation, the encrypted data processing request may be sent to the fully encrypted database system. This effectively transmits the plaintext original processing request to the fully encrypted data system in encrypted form, allowing the fully encrypted data system to obtain the encrypted data processing request. The security control module 200 is used to receive a data processing request sent by the client 100. This data processing request may include encrypted sensitive data. Since the security control module 200 is located in the trusted zone corresponding to the fully encrypted database, after receiving the data processing request, it can decrypt the data processing request to obtain a plaintext decrypted request. To stably implement data processing operations, the plaintext decrypted request can be sent to the data processing engine 300 for processing. The data processing engine 300 is used to receive the decrypted request sent by the security control module 200 and then perform the corresponding data processing operation based on the decrypted request, obtaining the plaintext data processing result, thereby effectively implementing data processing operations based on the fully encrypted database. In the above implementation, data processing operations on the fully encrypted database are performed by the security control module and the data processing engine, which are located in the trusted zone corresponding to the fully encrypted database. Since the security control module and the data processing engine for performing data processing operations are independent of each other, stable data processing operations can be effectively implemented without modifying the database kernel. This not only reduces database modification costs but also reduces data processing complexity. Some embodiments of the present disclosure are described in detail below, in conjunction with the accompanying drawings. The following embodiments and features thereof may be combined unless they conflict with each other. Furthermore, the sequence of steps in the following method embodiments is provided for illustrative purposes only and is not intended to be a strict limitation.FIG2 is a schematic diagram of the structure of a fully secret database system provided in an embodiment of the present disclosure. Referring to FIG2 , this embodiment provides a fully secret database system that can stably implement data processing operations without modifying the database kernel. Specifically, the fully secret database system may include: a security control module 200, disposed in a trusted area corresponding to the fully secret database, configured to obtain a data processing request, decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine 300 for processing; wherein the data processing request includes encrypted sensitive data; and a data processing engine 300, communicatively connected to the security control module 200 and disposed in the trusted area corresponding to the fully secret database, configured to process the decrypted processing request to obtain a data processing result. The fully encrypted database corresponds to a trusted zone, which is a user-trusted area. Services within the trusted zone can be trusted by users. Specifically, users can flexibly configure or adjust services within the trusted zone based on application or configuration requirements. To ensure stable and secure data processing operations based on the fully encrypted database, the security control module 200 and data processing engine 300 in the fully encrypted database system can be located in the trusted zone corresponding to the fully encrypted database. Furthermore, different deployment methods can be implemented for the security control module 200 and data processing engine 300 in different application scenarios. For example, as shown in FIG2 , the database kernel is located in the trusted zone, the data processing engine 300 is located within the database kernel, and the security control module 200 is located outside the database kernel and in communication with the database kernel. In this case, the data within the database kernel is plaintext data. Alternatively, as shown in FIG3 , the database kernel is located in the trusted zone, and both the security control module 200 and data processing engine 300 are located within the database kernel. The above-mentioned different deployment methods can be applied to different application scenarios, thereby effectively realizing the flexible and stable deployment of the security control module 200 and the data processing engine 300 in the trusted zone, which not only ensures the security and reliability of data processing, but also improves the flexibility and reliability of the fully encrypted database system.Regarding the layout of security control module 200 and data processing engine 300 in Figure 2 , if a user accesses the data processing engine 300 in the trusted zone without going through security control module 200, the data leakage risk in the aforementioned scenario cannot be prevented. For example, after obtaining the database kernel login method, the user can directly connect to the data processing engine in the trusted zone, and in this case, the plaintext data can always be seen. In this case, no security isolation technology can prevent active internal leakage. If a data leakage occurs in this scenario, management measures such as database logging and auditing can be used to conduct post-event accountability operations, thereby providing appropriate protection or penalties for the illegal user. For example, the user's local login method can be disabled. Regarding the layout of the security control module 200 and data processing engine 300 in Figure 3 , since both are located within the database kernel, the security control module 200 can prevent most data access operations to the database kernel. However, if a user logs in locally and dumps the database runtime memory, they can directly view the plaintext data stored in the database kernel. This does not prevent the data leakage risk in the aforementioned scenario. If a data leakage occurs in this scenario, post-event accountability can be implemented through management methods such as database and operating system logs and audits to provide appropriate protection against the unauthorized user or trigger actions. For example, local login can be disabled. Specifically, when a user requests data processing for a fully encrypted database, the security control module 200 in the fully encrypted database system can obtain a data processing request, which includes encrypted sensitive data. Specifically, the data processing request can be in ciphertext. In some instances, the security control module 200 may be communicatively connected to a client. A user may generate a plaintext data processing request through the client and encrypt sensitive data in the plaintext data processing request to obtain an encrypted data processing request. After the client obtains the encrypted data processing request, it may send the encrypted data processing request to the security control module 200, thereby enabling the security control module 200 to passively obtain the data processing request.In other examples, the security control module 200 may not only passively obtain data processing requests, but may also actively obtain data processing requests. In this case, the security control module 200 may be communicatively connected to a preset device, and the preset device may generate data processing requests (e.g., device maintenance requests, data security check requests, etc.) according to a preset period. The data processing requests include encrypted sensitive data. The security control module 200 may then actively obtain data processing requests through the preset device, thereby enabling the security control module 200 to stably obtain data processing requests. Since the security control module 200 is located in the trusted area corresponding to the fully encrypted database, processing operations can be performed in the trusted area based on plaintext data processing requests. Therefore, after obtaining the encrypted data processing request, a decryption operation can be performed on the data processing request. In some instances, decrypting the data processing request to obtain the decrypted processing request may include: obtaining sensitive data included in the data processing request; determining a decryption key for processing the sensitive data, where the decryption key may be obtained by deriving a random value and a user master key; and decrypting the data processing request using the decryption key to obtain a decrypted processing request. The decrypted processing request is the processing request obtained after the decryption operation, thereby effectively ensuring the stability and reliability of the analysis and processing of the decrypted processing request. To enable data processing operations based on a fully encrypted database, after the security control module 200 receives a decryption request, it can send the decryption request to the data processing engine 300 for processing. This allows the data processing engine 300 to stably receive the decryption request and then process the decryption request to obtain the data processing result. Because the data processing engine 300 is located in the trusted zone corresponding to the fully encrypted database, stable data processing operations are effectively achieved. Furthermore, for a fully encrypted database system, the data in the fully encrypted database can exist in plaintext in memory. To ensure the security and reliability of data processing, the stored data in the fully encrypted database can be stored on disk. Specifically, the data processing engine 300 can be connected to a storage area. If the storage area is a local storage area, the storage area is directly connected to the data processing engine 300; if the storage area is a cloud storage area, the storage area is connected to the data processing engine 300 through a network.For data stored in a fully encrypted database, transparent data encryption (TDE) technology can be used to encrypt the data in the fully encrypted database to obtain encrypted data, which is then stored in a storage area, thereby ensuring the security and reliability of data processing. The fully encrypted database system provided in this embodiment obtains data processing requests through a security control module. Since data processing requests are encrypted, the security control module decrypts the data processing requests to obtain a decrypted processing request, sends the decrypted processing request to the data processing engine for processing, and then uses the data processing engine to process the decrypted processing request. This effectively implements data encryption processing operations based on the fully encrypted database. Because the security control module and the data processing engine used to perform data processing operations are independent of each other and are both located in the trusted area corresponding to the fully encrypted database, stable data processing operations can be effectively achieved without modifying the database kernel. This also reduces database modification costs, further ensuring the practicality of the system and facilitating market promotion and application. Based on the above embodiment, as shown in Figures 2 and 3 , the security control module 200 can obtain data processing requests not only directly from the client but also through the database access module 400. In this case, the system may further include a database access module 400 communicatively connected to the security control module 200 and the client. The database access module 400 is configured to: obtain the original processing request from the client; if the original processing request includes sensitive data, encrypt the sensitive data to obtain the data processing request; and send the data processing request to the security control module 200. The database access module 400 may be disposed between the security control module 200 and the client, or it may be disposed within the client, that is, the database access module 400 may be integrated with the client, as long as the client can perform corresponding data processing operations on the fully encrypted database through the database access module 400. Specifically, when a user has a data processing requirement for a fully encrypted database, the client may generate or obtain an original processing request. In some instances, the client generating or obtaining the original processing request may include: displaying a human-computer interaction interface; obtaining an execution operation input by the user on the human-computer interaction interface; and generating or obtaining the original processing request based on the execution operation.Alternatively, the original processing request can be obtained not only through human-computer interaction but also through a preset timed task. In this case, in other examples, the client generating or obtaining the original processing request may include obtaining a preset timer period; when the time meets the preset period, the original processing request may be generated or obtained, thereby effectively ensuring the accurate and reliable acquisition of the original processing request. Alternatively, the original processing request may be generated by preset application code logic. Those skilled in the art may flexibly adjust or configure the method for obtaining the original processing request based on specific application scenarios or application requirements, as long as the stable and reliable acquisition of the original processing request is guaranteed. This will not be further elaborated here. Specifically, the original processing request generated by the client is plaintext processing data. To implement data processing operations based on a fully encrypted database, the client may send the plaintext original processing request to the database access module 400, so that the database access module 400 can stably obtain the original processing request from the client. Since the original processing request is a plaintext processing request, in order to ensure the security and reliability of data processing, it is possible to first identify whether the original processing request includes sensitive data. Identifying whether the original processing request includes sensitive data may include: obtaining encryption rule information for analyzing and processing the original processing request, and analyzing and processing the original processing request using the encryption rule information to identify whether the original processing request includes sensitive data. When the original processing request does not include sensitive data, it means that the original processing request does not involve relevant data that requires encryption operations. In this case, the database access module 400 can directly send the original processing request to the security control module 200 for corresponding data processing operations. When the original processing request includes sensitive data, it means that the original processing request involves relevant data that requires encryption operations. Therefore, in order to ensure the security and reliability of data processing, after the database access module 400 obtains the original processing request, it can encrypt the sensitive data in the original processing request to obtain a data processing request. The data processing request is the ciphertext request information, and the latter can send the data processing request to the security control module 200, thereby effectively ensuring that the security control module 200 can stably obtain the data processing request.Furthermore, this embodiment does not limit the specific implementation of the encryption processing operation for the sensitive data in the original processing request. In some instances, the encryption processing operation may be implemented using a preset encryption algorithm or a preset machine learning model. In this case, when the database access module 400 encrypts the sensitive data and obtains a data processing request, the database access module 400 is configured to: obtain the preset encryption algorithm or preset machine learning model used for encrypting the sensitive data; and encrypt the sensitive data in the original processing request using the preset encryption algorithm or preset machine learning model to obtain the data processing request. In other instances, the encryption processing operation may be implemented not only using the preset encryption algorithm or preset machine learning model, but also using a data encryption key. In this case, when the database access module 400 encrypts the sensitive data and obtains the data processing request, the database access module 400 is configured to: obtain a master key corresponding to the original processing request and a random value used to encrypt the sensitive data; generate a data encryption key based on the master key and the random value; and encrypt the sensitive data using the data encryption key to obtain the data processing request. Specifically, when the database access module 400 obtains an original processing request, it may obtain a master key corresponding to the original processing request. In some instances, obtaining the master key corresponding to the original processing request may include: obtaining a pre-configured mapping relationship between the original processing request and the master key. Specifically, a mapping relationship may exist between the master key and the user identity in the original processing request; and obtaining the master key corresponding to the original processing request based on the mapping relationship and the original processing request. This allows original processing requests executed by different users to implement the same function to correspond to different master keys. Alternatively, the master key corresponding to the original processing request may be stored in a preset area. In this case, the master key corresponding to the original processing request can be obtained by accessing the preset area, thereby effectively ensuring accurate and reliable acquisition of the master key.It should be noted that, for the master key corresponding to the original processing request, different types of original processing requests may correspond to different master keys. In some instances, when the original processing request is a first type operation and maintenance request, the master key corresponding to the original processing request is a null value. The first type operation and maintenance request is used to implement operation and maintenance operations unrelated to user data. For example, the original processing request may be a system startup request, a system stop request, an instance creation request, etc. The above data may refer to user data stored in a fully confidential database. When the original processing request is a second type operation and maintenance request, the master key corresponding to the original processing request is a non-null value. The non-control master keys corresponding to different users may be different. The second type operation and maintenance request is used to implement operation and maintenance operations related to user data. For example, the original processing request may be a data write request, a data update request, a data edit request, etc. After obtaining the original processing request, the database access module 400 may also obtain a random value used to encrypt sensitive data in order to accurately and stably encrypt the original processing request. After obtaining the master key and random value, the master key and random value may be analyzed and processed. Specifically, generating a data encryption key based on the master key and random value may include analyzing and processing the master key and random value using a preset algorithm or a preset machine learning model, thereby stably generating the data encryption key. After obtaining the data encryption key, the sensitive data in the original processing request is encrypted using the data encryption key, thereby effectively ensuring the accuracy and reliability of obtaining the data processing request. In this embodiment, the database access module obtains the original processing request from the client; if the original processing request includes sensitive data, the database access module may encrypt the sensitive data to obtain a data processing request; and then send the data processing request to the security control module. This effectively ensures the accuracy and reliability of obtaining the ciphertext data processing request, thereby ensuring the practicality of the fully encrypted database system.Based on the above embodiment, and with continued reference to FIG. 2 , after the database access module 400 obtains the original processing request, the database access module 400 can generate a data encryption key based on the master key, encrypt sensitive data using the data encryption key, and send the encrypted data processing request to the security control module 200. After receiving the encrypted data processing request, the security control module 200 needs to decrypt the encrypted data processing request. To stably decrypt the encrypted data processing request, the database access module 400 needs to transmit the master key used to encrypt the original processing request to the security control module 200. To stably and securely transmit the master key, the database access module 400 in this embodiment is further configured to: obtain a public key used to encrypt and transmit the master key; encrypt the master key using the public key to obtain an encrypted master key; and send the encrypted master key to the security control module 200 so that the security control module 200 processes the encrypted master key using the private key corresponding to the public key to obtain the master key. The master key is then used to decrypt the data processing request. Specifically, since the master key is user-preconfigured information used to implement data processing operations, transmitting the master key in plaintext within a fully encrypted database increases the risk of data leakage. Therefore, to prevent the transmission of the plaintext master key within a fully encrypted database system, after the database access module 400 obtains the master key corresponding to the original processing request, it can obtain a public key used to encrypt and transmit the master key. In some instances, obtaining the public key used to encrypt and transmit the master key can include: displaying a human-computer interaction interface; obtaining an execution operation entered by the user in the human-computer interaction interface; and obtaining the public key used to encrypt and transmit the master key based on the execution operation. Alternatively, the public key may be assigned by a fully encrypted database system. In this case, obtaining the public key for encrypting and transmitting the master key may include: the database access module 400 generates a public key acquisition request in response to the original processing request obtained; and sends the public key acquisition request to the security control module 200. The security control module 200 obtains a preset assigned public key corresponding to the public key acquisition request in response to the public key acquisition request, and sends the preset assigned public key to the database access module 400, so that the database access module 400 can stably obtain the public key for encrypting and transmitting the master key.To implement encrypted transmission of the master key, after obtaining the public key and the master key, the master key can be encrypted using the public key to obtain the encrypted master key. After obtaining the encrypted master key, the encrypted master key can be sent to the security control module 200, so that the security control module 200 processes the encrypted master key based on the private key corresponding to the public key to obtain the master key, and then uses the master key to decrypt the data processing request. This enables secure transmission of the ciphertext master key between the database access module 400 and the security control module 200, thereby ensuring the security and reliability of data processing. Based on the above embodiment, with continued reference to Figures 2 and 3 , the fully encrypted database system in this embodiment can not only implement encrypted data processing operations to obtain data processing results, but also securely transmit the data processing results, allowing clients to stably view the data processing results. Specifically, the data processing engine 300, the security control module 200, and the database access module 400 in this embodiment are configured to perform the following steps: the data processing engine 300 is further configured to send the data processing results to the security control module 200 after obtaining the data processing results; the security control module 200 is further configured to, when the data processing results include sensitive data, generate an encryption key, encrypt the data processing results using the encryption key to obtain an encrypted processing result, and send the encrypted processing result and a random value to the database access module 400, where the encryption key is determined by the random value and a master key corresponding to the data processing request; and the database access module 400 is configured to decrypt the encrypted processing result based on the random value to obtain a decrypted processing result, and send the decrypted processing result to the client. Specifically, after the data processing engine 300 obtains the data processing result, the plaintext data processing result may be sent to the security control module 200. After the security control module 200 obtains the data processing result, it may first identify whether the data processing result includes sensitive data. In some instances, the security control module 200 stores or caches encryption rule information for determining sensitive data. In this case, identifying whether the data processing result includes sensitive data may include: obtaining the encryption rule information stored in the security control module 200, and analyzing and processing the data processing result using the encryption rule information to identify whether the data processing result includes sensitive data.If the data processing results do not include sensitive data, the security control module 200 can directly send the data processing results to the database access module 400, so that the database access module 400 can send the data processing results to the client, allowing the user to directly view the data processing results through the client. If the data processing results include sensitive data, to ensure the security and reliability of data processing, the security control module 200 can generate an encryption key for encrypting the sensitive data in the data processing results. The encryption key can be determined by a random value and a master key corresponding to the data processing request. Specifically, the master key can correspond to the user identity in the data processing request. In some instances, the encryption key can be obtained by deriving the random value and the master key using a key derivation function (KDF) algorithm or other preset encryption algorithm. After obtaining the encryption key, the data processing result can be encrypted using the encryption key to ensure stable and secure transmission of the data processing result. This encrypted result and the random value are then sent to the database access module 400. The encryption key is determined by the random value and the master key corresponding to the data processing request. After obtaining the encryption result and the random value, the database access module 400 can decrypt the encryption result based on the random value to obtain a decrypted result. To allow the user to view the plaintext decrypted result, the database access module 400 can send the decrypted result to the client after obtaining it. In this embodiment, after obtaining the data processing result, the data processing engine 300 may send the data processing result to the security control module 200. When the data processing result includes sensitive data, the security control module 200 may generate an encryption key and then use the encryption key to encrypt the data processing result to obtain an encrypted processing result. The encrypted processing result and the random value are then sent to the database access module 400. After the database access module 400 obtains the encrypted processing result, the encrypted processing result may be decrypted based on the random value to obtain a decrypted processing result. The decrypted processing result is then sent to the client. This effectively implements stable, secure, and reliable transmission of the data processing result, further improving the practicality of the fully encrypted database system.Based on the above embodiment, with continued reference to Figures 2 and 3 , after the security control module 200 obtains a data processing request, to ensure the security and reliability of data processing, the security control module 200 in this embodiment can further implement a legitimacy verification operation on the user identity of the data processing operation. In this case, the security control module 200 in this embodiment is further configured to: obtain a user identity corresponding to the data processing request; determine, based on the user identity, whether the user making the data processing request is an authorized user; if the user is an authorized user, encrypt the data processing request using a master key corresponding to the user identity, so that the client obtains a plaintext data processing result that meets expected requirements; if the user is an unauthorized user, encrypt the data processing request using a master key that does not correspond to the user identity, so that the client cannot obtain a plaintext data processing result that meets expected requirements. Specifically, after the security control module 200 obtains the data processing request, in order to ensure the security and reliability of the data processing operation, the security control module 200 may obtain a user identity corresponding to the data processing request. In some instances, the user identity may be obtained through a preset mapping relationship. In this case, obtaining the user identity corresponding to the data processing request may include: obtaining a preset mapping relationship for analyzing and processing the data processing request, and determining the user identity corresponding to the data processing request based on the preset application relationship and the data processing request.After obtaining the user identity, whether the user making the data processing request is an authorized user can be determined based on a preset whitelist. Determining whether the user making the data processing request is an authorized user based on the user identity may include: obtaining a preset whitelist for analyzing the user making the data processing request, the preset whitelist including multiple standard identity identifiers of authorized users; identifying whether there is a standard identity identifier matching the user identity in the preset whitelist; if there is a standard identity identifier matching the user identity in the preset whitelist, determining that the user is an authorized user; if there is no standard identity identifier matching the user identity in the preset whitelist, determining that the user is an unauthorized user. In other examples, determining whether the user is an authorized user can be determined not only based on the preset whitelist but also based on whether the user has a corresponding master key. In this case, when the security control module 200 determines whether the user making the data processing request is an authorized user based on the user identity, the security control module 200 is further configured to: detect whether the user identity has a corresponding master key; if the user identity does not have a corresponding master key, determining that the user is an unauthorized user; When the user identity corresponds to a master key, the determination of whether the user making the data processing request is an authorized user is made based on the master key and the registration master key. Specifically, after obtaining the user identity, a preset mapping relationship can be used to detect whether the user identity corresponds to a master key. If the user identity does not correspond to a master key, the user can be determined to be an unauthorized user. If the user identity corresponds to a master key, the user can be directly determined to be an authorized user. Alternatively, to further ensure the accuracy and reliability of determining whether a user is an authorized user, when the user identity corresponds to a master key, the determination of whether the user making the data processing request is an authorized user can be further made based on the master key and the registration master key. In this case, determining whether the user making the data processing request is an authorized user based on the master key and the registration master key can include: obtaining a preset machine learning model or neural network model for analyzing and processing the master key and the registration master key, sending the master key and the registration master key to the preset machine learning model or neural network model, and obtaining a determination result output by the machine learning model or neural network model, wherein the determination result is used to determine whether the user making the data processing request is an authorized user.In other instances, not only can a preset machine learning model or neural network model be used to determine whether a user is an authorized user, but the authorized user determination operation can also be implemented by directly analyzing and calculating the master key and the registration master key. In this case, based on the master key and the registration master key, determining whether the user making a data processing request is an authorized user can include: calculating the master key to obtain a calculated hash value corresponding to the master key, calculating the registration master key to obtain a registered hash value corresponding to the registration master key, analyzing and matching the calculated hash value and the registered hash value. When the calculated hash value matches the registered hash value, the user is determined to be an authorized user; when the calculated hash value does not match the registered hash value, the user is determined to be an unauthorized user. In this way, accurate determination or identification of whether a user is an authorized user is stably implemented. If the user is determined to be an authorized user, it means that the user can now perform data processing operations securely. The data processing request can then be encrypted based on the master key corresponding to the user's identity, allowing the client to obtain a plaintext data processing result that meets the expected requirements. In other words, the user can obtain the desired data processing result. For example, if the data processing request is a request for the user to query the sales volume of a certain product in the past three months, the data processing operation of the fully encrypted database system may return a data processing result such as "The sales volume of a certain product in the past three months is 1 million units." If the user is unauthorized, this means that the user cannot safely perform data processing operations. Therefore, the data processing request can be encrypted based on a master key that does not correspond to the user's identity. The master key that does not correspond to the user's identity can include any of the following: a randomly generated master key, a pre-configured default master key, etc. Since the data processing request is not obtained by performing an encryption operation based on the master key corresponding to the user's identity, the security control module 200 cannot correctly decrypt the encrypted data processing result. Consequently, the client cannot obtain a plaintext data processing result that meets the expected requirements through the database access module 400. Even if the client cannot obtain a plaintext data processing result that meets the expected requirements, for example, if the data processing request is a user's request to query the sales volume of a certain product in the past three months, the data processing result returned through the data processing operation of the fully encrypted database system may be "the unit price of the product is 17 yuan per piece." Obviously, the data processing result does not correspond to the data processing request, thus preventing the user from completing the preset data processing operation.In other instances, after the user is an authorized user, the security control module 200 in this embodiment may determine whether the user has access rights for the data processing request. In this case, the security control module 200 in this embodiment is further configured to: determine the user's access rights based on the user identity; determine whether the user has access rights for the data corresponding to the data processing request based on the access rights; if the user has access rights, allow the data processing request to be encrypted using the master key corresponding to the user identity; and if the user does not have access rights, prohibit the data processing request from being encrypted using the master key corresponding to the user identity. For a fully encrypted database system, different users can be configured with different access rights. For example, User A may have access rights to all data in the fully encrypted database system, User B may have access rights to some data in the fully encrypted database system, and User C may not have access rights to any data in the fully encrypted database system. Therefore, when determining that a user is an authorized user, to ensure the security and reliability of data processing, after obtaining the user identity, the user's access rights may be determined based on the user identity. Specifically, the user's access rights may be determined based on a preset mapping relationship and the user identity. After determining the user's access rights, it can be determined based on the access rights whether the user has access rights to the data corresponding to the data processing request. In some instances, determining whether the user has access rights to the data corresponding to the data processing request based on the access rights may include: obtaining access rights requirements corresponding to the data corresponding to the data processing request; determining whether the access rights meet the access rights requirements; if the access rights meet the access rights requirements, determining that the user has access rights to the data corresponding to the data processing request; if the access rights do not meet the access rights requirements, determining that the user does not have access rights to the data corresponding to the data processing request. If the user has access rights to the data corresponding to the data processing request, it indicates that the user is not only a legitimate authorized user but also has the corresponding data access rights. Therefore, encryption of the data processing request based on the master key corresponding to the user's identity is permitted. Conversely, if the user does not have access rights to the data corresponding to the data processing request, it indicates that the user is a legitimate authorized user but does not have the corresponding data access rights. Therefore, encryption of the data processing request based on the master key corresponding to the user's identity may be prohibited, thereby effectively ensuring the security and reliability of data processing.In this embodiment, the security control module 200 obtains a user identity corresponding to a data processing request; based on the user identity, it is determined whether the user making the data processing request is an authorized user; if the user is an authorized user, the data processing request is encrypted using the master key corresponding to the user identity, so that the client obtains a plaintext data processing result that meets expected requirements; if the user is an unauthorized user, the data processing request is encrypted using a master key that does not correspond to the user identity, so that the client cannot obtain a plaintext data processing result that meets expected requirements. This effectively allows authorized users to perform legal data processing operations and obtain correct data processing results, while prohibiting unauthorized users from performing normal data processing operations, i.e., users cannot obtain correct data processing results, thereby effectively ensuring the security and reliability of the fully encrypted database system. Based on any of the above embodiments, and with continued reference to Figures 2 and 3 , the security control module 200 in this embodiment can not only implement secure and reliable data processing operations, but also manage ciphertext metadata. In this case, the security control module 200 in this embodiment is further configured to: obtain a data write request corresponding to the ciphertext metadata, where the ciphertext metadata includes at least one of the following for implementing the encrypted data processing operation: encryption rule information for identifying sensitive data, a user identity verification code, and encryption algorithm parameters, and the ciphertext metadata is stored in a metadata repository; determine user signature information corresponding to the data write request; and identify whether the data write request is legitimate based on the user signature information; if the data write request is legitimate, allow the ciphertext metadata to be stored in the metadata repository based on the data write request; and if the data write request is invalid, prohibit the ciphertext metadata from being stored in the metadata repository based on the data write request.Specifically, when a user calls the fully secret database system to perform a data processing operation, the fully secret database system may cache, store, and manage ciphertext metadata used to implement the data processing operation. The ciphertext metadata may include at least one of the following: encryption rule information for identifying sensitive data, a user identity verification code, and encryption algorithm parameters. The aforementioned management operation may include at least one of the following: a write operation of the ciphertext metadata, an update operation of the ciphertext metadata, a delete operation of the ciphertext metadata, and the like. The following description uses the write operation of the ciphertext metadata as an example of a management operation of the ciphertext metadata. When a user has a data write requirement for the ciphertext metadata, the security control module 200 may obtain a data write request corresponding to the ciphertext metadata. After obtaining the data write request, the legitimacy of the data write request may be verified. In this case, user signature information corresponding to the data write request may be first determined, and then, based on the user signature information, whether the data write request is a legitimate request may be identified. Specifically, when the user signature information matches the registered signature information corresponding to the data write request, the data write request may be determined to be a legitimate request. If the user signature information does not match the registered signature information corresponding to the data write request, the data write request may be determined to be an illegal request. If the data write request is determined to be legal, it indicates that a legal write operation can be performed on the ciphertext metadata, and storage of the ciphertext metadata in the metadata repository based on the data write request is permitted. If the data write request is illegal, storage of the ciphertext metadata in the metadata repository based on the data write request may be prohibited to ensure legal storage and management of the ciphertext metadata. In this embodiment, the security control module 200 obtains a data write request corresponding to the ciphertext metadata, determines user signature information corresponding to the data write request, and identifies whether the data write request is legitimate based on the user signature information. If the data write request is legitimate, storage of the ciphertext metadata in the metadata repository based on the data write request is permitted; if the data write request is illegal, storage of the ciphertext metadata in the metadata repository based on the data write request is prohibited, thereby effectively implementing legitimate write operations on the ciphertext metadata. Similarly, similar implementation methods and processes can be used to implement other management operations on the ciphertext metadata, such as write and read operations on the ciphertext metadata. The write operation may include at least one of the following: write operation, update operation, delete operation, etc., and the read operation may include a query operation. This allows for legitimacy and integrity protection of the ciphertext metadata, further improving the security and reliability of the fully encrypted database system.In specific applications, referring to Figures 2-4 , this application embodiment provides a general fully encrypted database system. This fully encrypted database system may include a database access module, a security control module, and a data processing engine. The database access module is communicatively connected to a client, or may be located within the client. The security control module is communicatively connected to the database access module and the data processing engine. The security control module and the data processing engine may be located in a trusted zone. In some instances, the security control module may be located within a fully encrypted database proxy service, meaning that the security control module may be implemented in conjunction with the fully encrypted database proxy service, with the fully encrypted database proxy service serving as a trusted node. Regarding the security control module and the data processing engine, in some instances, the data processing engine may be located within the kernel of the fully encrypted database, while the security control module may be located outside the kernel of the fully encrypted database; alternatively, both the security control module and the data processing engine may be located within the kernel of the fully encrypted database. Specifically, data processing operations can be implemented based on the above-mentioned fully encrypted database system. The data processing operations may include the following steps: Step 1: A user initiates a query request SQL on a client. The query request SQL is a plaintext request SQL, and the plaintext request SQL is then sent to a database access module. Step 2: After obtaining the plaintext request SQL, the database access module may encrypt the plaintext request SQL to obtain an encrypted SQL, and then send the encrypted ciphertext SQL to a security control module. The security control module plays the role of "data operation control". For database user access, including remote access by ordinary database users (from an application perspective) and local access by operation and maintenance database users (from an operation and maintenance perspective), both must pass through the security control module. This ensures that only ciphertext is always visible when querying. Step 3: After the security control module obtains the ciphertext SQL, it decrypts the ciphertext SQL to obtain the plaintext SQL, and can send the plaintext SQL to the data processing engine (database kernel). Specifically, after the security control module obtains the ciphertext SQL, it can decrypt the sensitive data in the ciphertext SQL to restore the plaintext SQL.Step 4: After the data processing engine obtains the plaintext SQL, it can execute query calculations based on the plaintext SQL to obtain data processing results, and then return the plaintext data processing results to the security control module. Step 5: After the security control module obtains the plaintext data processing results, it can obtain the encryption rules pre-configured by the user and use the encryption rules to determine whether the plaintext data processing results include sensitive data. If sensitive data is included, a random value for the local session is randomly generated, and a data key DEK is dynamically calculated based on the random value. The data key DEK can then be used to encrypt the sensitive data in the data processing results to obtain a ciphertext data result, and the ciphertext data result is sent to the database access module. Dynamically calculating the data key DEK based on the random value may include obtaining a user master key (UMK) and dynamically deriving the random value and the user master key based on a KDF algorithm to obtain the data key DEK. Specifically, DEK = KDF(MEK, nonce), where nonce is a random value (e.g., an 8-bit random number), MEK is the user master key, KDF is a preset encryption algorithm, and DEK is the data key. After obtaining the ciphertext data result, the random value and the ciphertext data result may be sent together to the database access module. Specifically, after obtaining the ciphertext data result and the random value, the random value and the ciphertext data result may be concatenated to obtain a concatenated result, which may then be sent to the database access module. For example, if nonce is a random value, DEK is a data key, and data is sensitive data, the ciphertext data result can be Enc(DEK, data). The concatenation of the random value and the ciphertext data result is Cipher, where Cipher = nonce | Enc(DEK, data). The random value can be concatenated at the header, the tail, or the middle of the ciphertext data result. Those skilled in the art can flexibly adjust or configure the concatenation method based on specific application scenarios or application requirements, as long as the concatenation result can be stably generated. This description will not be repeated here. It should be noted that a fully secret database system can have different usage modes, namely, a fully secret database mode and a normal database mode. Specifically, if encryption rules for identifying sensitive data are configured in the security control module, the fully secret database system is determined to be in fully secret data mode. If encryption rules for identifying sensitive data are not configured in the security control module, the fully secret database system is determined to be in normal database mode.In specific applications, users can flexibly configure or adjust the encryption rules in the security control module based on application or design requirements, effectively enabling flexible adjustment or configuration of the usage mode of the fully encrypted database system. Furthermore, to enhance the security and reliability of the fully encrypted database system, the roles / accounts used to configure the encryption rules are independent of the database login account. This ensures that even if the database account is compromised, management security is not affected. Step 6: Upon receiving the ciphertext data result, the database access module decrypts the ciphertext processing result to obtain a plaintext processing result, which is then sent to the client. If the ciphertext data result includes multiple query records, the database access module can process each query record individually and decrypt the ciphertext content therein to obtain the plaintext processing result. Specifically, decrypting the ciphertext content may include obtaining a random value included in the ciphertext data processing result, dynamically calculating a decryption key DEK in the same manner, and then decrypting the result using the decryption key DEK to obtain the plaintext processing result. Step 7: For the stored data or cached data in the fully encrypted database system, the transparent data encryption algorithm (TDE) can be used to encrypt the stored data or cached data in the fully encrypted database system and store the encrypted data in a preset area. The stored data or cached data may include encryption rules, log files, configuration data, or operational data. In the database kernel, data always exists in plaintext in memory. When stored on disk, it can be encrypted using TDE technology to ensure storage security. Furthermore, the fully encrypted database system in this embodiment can manage ciphertext metadata. This ciphertext metadata can include user-configured encryption rule information, user identity verification codes, and algorithm parameters used for encryption. The fully encrypted database system can persist the ciphertext metadata information in the database's internal protection tables and provide unified management capabilities. For the internal protection tables of the database, integrity protection can be provided. In this way, any write operation needs to be verified to be issued by a legitimate user. After verification, the write is performed by the fully confidential module. The data in the internal protection tables of the database cannot be modified by any user outside the fully confidential module. This effectively ensures the security and reliability of data storage.The fully encrypted database system provided in this application embodiment provides security protection by bypassing the security control module, achieving non-intrusiveness to the database kernel, easy engineering implementation, and versatility. Furthermore, the fully encrypted database system supports all existing SQL operators. Current SQL operators can be executed directly on the fully encrypted database without modification. For example, plaintext SQL can be used for fuzzy matching queries. Furthermore, the fully encrypted system solution does not require additional client modifications; only a few lines of configuration are required for integration, and existing code does not require any modification. The fully encrypted database system is compatible with existing databases, allowing databases to be seamlessly upgraded to fully encrypted databases or rolled back to normal databases, thereby ensuring the flexibility and reliability of the fully encrypted database system. Specifically, a security control module is placed in front of an existing database instance. The user-provided key is used to encrypt the sensitive data specified in the encryption rules in the query results. The result is returned in ciphertext to the database access module. The database access module then decrypts the ciphertext result, restores the plaintext result, and returns it to the client. Throughout this process, query results are always in ciphertext, except for the database kernel and application client. This functionality is transparent to applications. As part of the database service, all database access passes through the security control module, ensuring that neither remote nor local access can bypass security checks, thereby ensuring the security and reliability of data processing. Furthermore, by integrating the security control module into the database kernel, query results are encrypted before they are returned from the kernel. This reduces or prevents the risk of local platform users (from the platform's perspective) bypassing the security control module's access control by directly logging into the database kernel through the backend and obtaining plaintext data. Even database management and operations personnel can only see ciphertext query results, ensuring the security and reliability of data use and further improving the practicality of the system. This is conducive to market promotion and application. Figure 5 is a flow diagram of a data processing method provided by an embodiment of the present disclosure. Referring to Figure 5, this embodiment provides a data processing method executed by a fully encrypted database system. That is, the data processing method can be applied to a fully encrypted database system. Referring to Figures 2-4, the fully encrypted database system may include a security control module and a data processing engine in communication with each other. Both the security control module and the data processing engine are located in a trusted zone corresponding to the fully encrypted database.Based on the above-mentioned fully encrypted database system, the data processing method may include the following steps: Step S501: The security control module obtains a data processing request, the data processing request including encrypted sensitive data; Step S502: The security control module decrypts the data processing request to obtain a decrypted processing request, and sends the decrypted processing request to the data processing engine for processing; Step S503: The data processing engine processes the decrypted processing request to obtain a data processing result. In some instances, before the security control module obtains the data processing request, the method further includes: obtaining a user registration request; displaying a user registration page; and obtaining user registration information and a registration master key in response to a user operation on the user registration page. In some instances, the database access module obtains the original processing request sent by the client, wherein the database access module is in communication with the security control module and the client; if the original processing request includes sensitive data, the database access module encrypts the sensitive data to obtain a data processing request; and the database access module sends the data processing request to the security control module. In some instances, encrypting sensitive data to obtain a data processing request may include: obtaining a master key corresponding to the original processing request and a random value used to encrypt the sensitive data; generating a data encryption key based on the master key and the random value; and encrypting the sensitive data using the data encryption key to obtain the data processing request. In some instances, when the original processing request is a first-type operation and maintenance request, the master key corresponding to the original processing request is a null value. First-type operation and maintenance requests are used to perform operation and maintenance operations unrelated to user data, and user data is stored in a fully encrypted database. When the original processing request is a second-type operation and maintenance request, the master key corresponding to the original processing request is a non-null value. Second-type operation and maintenance requests are used to perform operation and maintenance operations related to user data. In some instances, the method in this embodiment may include: obtaining a public key for encrypting and transmitting a master key; encrypting the master key using the public key to obtain an encrypted master key; and sending the encrypted master key to a security control module, so that the security control module processes the encrypted master key based on a private key corresponding to the public key, obtains the master key, and decrypts the data processing request using the master key.In some instances, after obtaining the data processing result, the method in this embodiment may include: sending the data processing result to the security control module via the data processing engine; when the data processing result includes sensitive data, generating an encryption key via the security control module, encrypting the data processing result using the encryption key to obtain an encrypted processing result, and sending the encrypted processing result and a random value to the database access module, wherein the encryption key is determined by the random value and a master key corresponding to the data processing request; decrypting the encrypted processing result based on the random value via the database access module to obtain a decrypted processing result, and sending the decrypted processing result to the client. In some instances, after obtaining a data processing request, the method in this embodiment may include: obtaining, via a security control module, a user identity corresponding to the data processing request; determining, based on the user identity, whether the user making the data processing request is an authorized user; if the user is an authorized user, encrypting the data processing request based on a master key corresponding to the user identity, so that the client obtains a plaintext data processing result that meets expected requirements; if the user is an unauthorized user, encrypting the data processing request based on a master key that does not correspond to the user identity, so that the client cannot obtain a plaintext data processing result that meets expected requirements. In some instances, determining, based on the user identity, whether the user making the data processing request is an authorized user may include: detecting whether the user identity corresponds to a master key; if the user identity does not correspond to a master key, determining that the user is an unauthorized user; and if the user identity corresponds to a master key, determining whether the user making the data processing request is an authorized user based on the master key and a registered master key. In some instances, after the user is an authorized user, the method in this embodiment may further include: determining, by the security control module, the user's access rights based on the user identity; determining, based on the access rights, whether the user has access rights to the data corresponding to the data processing request; if the user has access rights, allowing encryption of the data processing request based on the master key corresponding to the user identity; and if the user does not have access rights, prohibiting encryption of the data processing request based on the master key corresponding to the user identity. In some instances, the security control module and the data processing engine are located in the database kernel, and the database kernel is located in a trusted zone; alternatively, the data processing engine is located in the database kernel, the security control module is located outside the database kernel and is in communication with the database kernel, and the database kernel is located in a trusted zone.In some instances, the method in this embodiment may include: obtaining, via a security control module, a data write request corresponding to ciphertext metadata, wherein the ciphertext metadata includes at least one of the following for implementing an encrypted data processing operation: encryption rule information for identifying sensitive data, a user identity verification code, and encryption algorithm parameters, and the ciphertext metadata is stored in a metadata repository; determining user signature information corresponding to the data write request; and identifying whether the data write request is legitimate based on the user signature information; if the data write request is legitimate, allowing the ciphertext metadata to be stored in the metadata repository based on the data write request; and if the data write request is invalid, prohibiting the ciphertext metadata from being stored in the metadata repository based on the data write request. It should be noted that the specific execution steps, implementation principles, and implementation effects of the data processing method in this embodiment are similar to those of the fully encrypted database system in Figures 1-4 . For portions not described in detail in this embodiment, reference may be made to the relevant description of the embodiment shown in Figures 1-4 . The execution process and technical effects of this technical solution are described in the embodiment shown in Figures 1-4 and will not be repeated here. In one possible design, the data processing method shown in FIG5 can be implemented as an electronic device. Referring to FIG6 , the data processing method in this embodiment can be implemented as a fully encrypted database system. The fully encrypted database system includes a communicatively connected security control module and a data processing engine, both of which are located in a trusted zone corresponding to the fully encrypted database. Specifically, the electronic device may include a first processor 21 and a first memory 22. OThe first memory 22 is used to store a program for the electronic device to execute the data processing method provided in the embodiment shown in FIG. 6 . The first processor 21 is configured to execute the program stored in the first memory 22. The program includes one or more computer instructions. When executed by the first processor 21, the one or more computer instructions can implement the following steps: the security control module obtains a data processing request, the data processing request including encrypted sensitive data; the security control module decrypts the data processing request to obtain a decryption request, and sends the decryption request to the data processing engine for processing; the data processing engine processes the decryption request to obtain a data processing result. Furthermore, the first processor 21 is also used to execute all or part of the steps in the embodiment shown in FIG. 5 . The electronic device may also include a first communication interface 23 for communicating with other devices or a communication network. Furthermore, embodiments of the present disclosure provide a computer storage medium for storing computer software instructions used by the electronic device, including the program for executing the data processing method in the embodiment shown in FIG. 5 . Furthermore, an embodiment of the present disclosure provides a computer program product, comprising: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform the data processing method of the method embodiment shown in FIG5 . FIG7 is a flow chart illustrating another data processing method provided by an embodiment of the present disclosure. Referring to FIG7 , this embodiment provides another data processing method, the method being executed by a security control module. Referring to FIG2 through FIG4 , the security control module is communicatively connected to a data processing engine, and both the security control module and the data processing engine are located in a trusted zone corresponding to a fully encrypted database. Based on the aforementioned security control module, the data processing method may include: Step S701: Obtaining a data processing request, the data processing request including encrypted sensitive data; Step S702: Decrypting the data processing request to obtain a decrypted processing request, and sending the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request and obtains a data processing result. It should be noted that the specific execution steps, implementation principles, and implementation effects of the data processing method in this embodiment are similar to those of the security control module in Figures 1 to 4 . For portions not described in detail in this embodiment, reference can be made to the relevant description of the embodiments shown in Figures 1 to 4 . The execution process and technical effects of this technical solution are described in the embodiments shown in Figures 1 to 4 and will not be repeated here.Figure 8 is a schematic structural diagram of a security control device provided in an embodiment of the present disclosure. Referring to Figure 8 , this embodiment provides a security control device that is communicatively connected to a data processing engine, with both the security control device and the data processing engine located in a trusted zone corresponding to a fully encrypted database. The security control device in this embodiment can execute the data processing method shown in Figure 7 . Specifically, the security control device may include: a second acquisition module 31 for acquiring a data processing request, the data processing request including encrypted sensitive data; a second processing module 32 for decrypting the data processing request to obtain a decrypted processing request, and sending the decrypted processing request to the data processing engine for processing, so that the data processing engine processes the decrypted processing request and obtains a data processing result. The device shown in Figure 8 can execute the method shown in the embodiment of Figure 7 . For portions not described in detail in this embodiment, please refer to the relevant description of the embodiment shown in Figure 7 . The execution process and technical effects of this technical solution are described in the embodiment shown in Figure 7 and will not be further elaborated here. In one possible design, the structure of the security control device shown in Figure 8 can be implemented as an electronic device. As shown in Figure 9 , the electronic device may include a second processor 41 and a second memory 42. The second memory 42 is used to store a program for the electronic device to execute the data processing method provided in the embodiment shown in FIG. 7 . The second processor 41 is configured to execute the program stored in the second memory 42 . The program includes one or more computer instructions. When executed by the second processor 41, the one or more computer instructions can implement the following steps: obtaining a data processing request, the data processing request including encrypted sensitive data; decrypting the data processing request to obtain a decryption processing request; and sending the decryption processing request to a data processing engine for processing, so that the data processing engine processes the decryption processing request and obtains a data processing result. Furthermore, the second processor 41 is also used to execute all or part of the steps in the embodiment shown in FIG. The electronic device may also include a second communication interface 43 for communicating with other devices or a communication network. Furthermore, embodiments of the present disclosure provide a computer storage medium for storing computer software instructions used by the electronic device, including the program for executing the data processing method in the embodiment shown in FIG. 7 .In addition, an embodiment of the present disclosure provides a computer program product, comprising: a computer-readable storage medium storing computer instructions. When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the steps of the data processing method in the method embodiment shown in FIG. 7 . The apparatus embodiment described above is merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one location or distributed across multiple network units. Some or all of the modules can be selected according to actual needs to achieve the objectives of the present embodiment. Persons skilled in the art can understand and implement the present embodiment without inventive effort. Through the description of the above embodiments, persons skilled in the art can clearly understand that each embodiment can be implemented by adding a necessary general-purpose hardware platform, or can also be implemented through a combination of hardware and software. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a computer product. The present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The present disclosure is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable device to produce a machine, such that execution of the instructions by the processor of the computer or other programmable device generates means for implementing the functions specified in one or more processes in the flowcharts and / or one or more blocks in the block diagrams. These computer program instructions can also be stored in a computer-readable memory capable of directing the computer or other programmable device to operate in a specific manner, such that the instructions stored in the computer-readable memory generate an article of manufacture including instruction means that implement the functions specified in one or more processes in the flowcharts and / or one or more blocks in the block diagrams.These computer program instructions can also be loaded onto a computer or other programmable device, causing the computer or other programmable device to execute a series of operational steps to produce a computer-implemented process. The instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more flow charts and / or one or more blocks in a block diagram. In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory. O Memory is an example of computer-readable media. Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can implement information storage using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmitting medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves. Finally, it should be noted that the above embodiments are merely illustrative of the technical solutions of the present disclosure and are not intended to limit the present disclosure. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they may modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein with equivalents. However, such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present disclosure.
Claims
Claims 1. A fully encrypted database system, comprising: A security control module, which is set in the trusted area corresponding to the fully encrypted database, is used to obtain a data processing request, decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine for processing; wherein, the data processing request includes sensitive data after encryption processing; the data processing engine is communicatively connected to the security control module and is set in the trusted area corresponding to the fully encrypted database, and is used to process the decrypted processing request to obtain a data processing result.
2. The system according to claim 1, wherein the system further comprises: A database access module communicatively connected to the security control module and a client, the database access module is used to: obtain an original processing request through the client; When the original processing request includes sensitive data, encrypt the sensitive data to obtain a data processing request; send the data processing request to the security control module.
3. The system according to claim 2, wherein When the database access module encrypts the sensitive data to obtain a data processing request, the database access module is used to: obtain a main key corresponding to the original processing request and a random value for encrypting the sensitive data; generate a data encryption key based on the main key and the random value; use the data encryption key to encrypt the sensitive data to obtain a data processing request.
4. The system according to claim 3, wherein, When the original processing request is a first type of operation and maintenance request, the main key corresponding to the original processing request is a null value, wherein the first type of operation and maintenance request is used to implement operation and maintenance operations independent of user data, and the user data is stored in the fully encrypted database; when the original processing request is a second type of operation and maintenance request, the main key corresponding to the original processing request is a non-null value, wherein the second type of operation and maintenance request is used to implement operation and maintenance operations related to user data.
5. The system according to claim 3 or 4, wherein The database access module is further used to: obtain a public key for encrypting and transmitting the main key; use the public key to encrypt the main key to obtain an encrypted main key; send the encrypted main key to the security control module, so that the security control module processes the encrypted main key based on the private key corresponding to the public key to obtain the main key, and uses the main key to decrypt the data processing request.
6. The system according to any one of claims 3-5, wherein The data processing engine is further configured to send the data processing result to the security control module after obtaining the data processing result; the security control module is further configured to generate an encryption key when the data processing result includes sensitive data, encrypt the data processing result by using the encryption key to obtain an encrypted processing result, and send the encrypted processing result and the random value to the database access module, wherein the encryption key is determined by the random value and the master key corresponding to the data processing request; the database access module is configured to decrypt the encrypted processing result based on the random value to obtain a decrypted processing result, and send the decrypted processing result to the client.
7. The system according to any one of claims 1-6, wherein After the security control module obtains the data processing request, the security control module is further configured to: Obtain a user identity identifier corresponding to the data processing request; based on the user identity identifier, determine whether the user of the data processing request is an authorized user; When the user is an authorized user, encrypt the data processing request by using the master key corresponding to the user identity identifier, so that the client can obtain a plaintext data processing result that meets the expected requirements; When the user is an unauthorized user, encrypt the data processing request by using a master key that has no corresponding relationship with the user identity identifier, so that the client cannot obtain a plaintext data processing result that meets the expected requirements.
8. The system according to claim 7, wherein When the security control module determines whether the user of the data processing request is an authorized user based on the user identity identifier, the security control module is configured to: detect whether the user identity identifier corresponds to a master key; when the user identity identifier does not correspond to a master key, determine that the user is an unauthorized user; when the user identity identifier corresponds to a master key, determine whether the user of the data processing request is an authorized user based on the master key and the registered master key.
9. The system according to claim 7 or 8, wherein After the user is an authorized user, the security control module is further configured to: determine the access permission of the user based on the user identity identifier; based on the access permission, determine whether the user has access permission to the data corresponding to the data processing request; when having access permission, allow encrypting the data processing request by using the master key corresponding to the user identity identifier; When not having access permission, prohibit encrypting the data processing request by using the master key corresponding to the user identity identifier.
10. The system according to any one of claims 1-9, wherein, The security control module and the data processing engine are located in the database kernel, and the database kernel is located in the trusted area; or, the data processing engine is located in the database kernel, the security control module is located outside the database kernel and is communicatively connected to the database kernel, and the database kernel is located in the trusted area.
11. The system according to any one of claims 1-9, wherein The security control module is further configured to: obtain a data writing request corresponding to the ciphertext metadata, where the ciphertext metadata includes at least one of the following for implementing encrypted data processing operations: encryption rule information for identifying sensitive data, user identity verification codes, and encryption algorithm parameters, and the ciphertext metadata is stored in a metadata database; determine the user signature information corresponding to the data writing request; based on the user signature information, identify whether the data writing request is a legitimate request; when the data writing request is a legitimate request, allow the ciphertext metadata to be stored in the metadata database based on the data writing request; when the data writing request is an illegal request, prohibit the ciphertext metadata from being stored in the metadata database based on the data writing request.
12. A data processing method is applied to a fully homomorphic encryption database system. The fully homomorphic encryption database system includes a security control module and a data processing engine that are communicatively connected, and both the security control module and the data processing engine are located in a trusted area corresponding to the fully homomorphic encryption database. The method includes: The security control module obtains a data processing request, where the data processing request includes sensitive data that has been encrypted. The security control module decrypts the data processing request to obtain a decrypted processing request, and sends the decrypted processing request to a data processing engine for processing. The data processing engine processes the decrypted processing request to obtain a data processing result.
13. A data processing method is applied to a security control module. The security control module is communicatively connected to a data processing engine, and both the security control module and the data processing engine are located in a trusted area corresponding to a fully encrypted database. The method includes: Obtain a data processing request, where the data processing request includes sensitive data that has been encrypted. Decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
14. A security control device, the security control device is communicatively connected to a data processing engine, and both the security control device and the data processing engine are located in a trusted area corresponding to a fully encrypted database; The security control device includes: A second obtaining module, configured to obtain a data processing request, where the data processing request includes sensitive data that has been encrypted. A second processing module, configured to decrypt the data processing request to obtain a decrypted processing request, and send the decrypted processing request to a data processing engine for processing, so that the data processing engine processes the decrypted processing request to obtain a data processing result.
15. An electronic device, comprising: A memory and a processor; where the memory is used to store one or more computer instructions, and when the one or more computer instructions are executed by the processor, the method described in claim 12 or 13 above is implemented.
16. A computer storage medium for storing a computer program, where the computer program, when executed by a computer, implements the method described in claim 12 or 13 above.
17. A computer program product, comprising: A computer program, when executed by a processor of an electronic device, causes the processor to execute the method described in claim 12 or 13 above.
Citation Information
Patent Citations
Encrypted database system and method and device for realizing encrypted database system
CN112699399A
Data encryption system and method, data processing method and device and electronic equipment
CN112995109A
Database operation method and system, storage medium and computer terminal
CN114637743A
Soft and hard adaptive collaborative query execution method based on secret database
CN115203235A