Updated on 2026-09-24 GMT+08:00

Encryption Proxy Service

The encrypted proxy service is a database-oriented network reverse proxy. In a database encryption system, when it is necessary to configure data encryption in Proxy mode, the encrypted proxy service must be configured first.

Conversely, when the Application-Plugin mode is selected for data encryption, there is no need to configure an encryption proxy service. The logical architecture of the encryption proxy service is shown in Figure 1.

Figure 1 Encrypted proxy service logical architecture

In an encryption system, once the database encryption/decryption configuration is completed, any content viewed by users when accessing the database directly via SQL statements is ciphertext. Conversely, the encryption proxy service acts as a security barrier; it introduces an additional proxy service port on top of the original database server port to forward requests. Through this mechanism, not only is data encryption/decryption performed, but it is also ensured that the data viewed or manipulated by authorized users always appears as plaintext. The data within the database remains encrypted at all times to safeguard security.

The core responsibility of this module is to configure the connection parameters between the real database service and the proxy service, ensuring the security and accuracy of the data during transmission.

Conceptual Explanation

  • Main Server: The main server is the host on which the encrypted proxy service runs. Depending on the operating environment, the main server can be either a cloud host or a physical host; technically, a single main server can host multiple encrypted proxy services. This depends on factors such as the server's configuration, the degree of parallelism in the application, and the complexity of the application.

The current version does not support configuring multiple main servers.

  • Encryption Proxy Service: The Encryption Proxy Service is a database-oriented network reverse proxy service. It serves as the primary execution unit responsible for data encryption and decryption within the proxy mode.
  • Asset Database: The Asset Database is the database managed within the Asset Database Management Module.

Constraints and Limitations

  • Special note regarding whether to enable SSL: To encrypt non-intrusive bypass traffic, the TLS encrypted channel cannot be used, which may pose security risks.
  • Encrypted proxy functionality; currently unsupported data operation methods:
    • The `SELECT` data type clause that includes the `temp` keyword is not currently supported.
    • `INSERT` is used for batch insertion of data with a self-referential structure; `INSERT` supports nested formatting.
    • Update: The data type supports nested formatting.
    • encrypted fields do not support size comparison operators (e.g.,>, <, ORDER BY, BETWEEN, etc.).
    • Function computations (e.g., AVG, MAX, MIN, SUM, and arithmetic expressions) are not supported.
    • View, trigger, and stored procedure operations are not supported; for equality comparisons ('=') following conditions such as 'WHERE', both fields on either side of the '=' operator must be encrypted, or neither field should be encrypted.
    • Encryption for table or field names containing wildcards is not supported for configuration.

Adding a Main Server

The main server is the host machine that runs the encrypted proxy service; depending on the operating environment, it can be either a cloud-based server or a physical server. Technically, a single main server can support multiple encrypted proxy services—though the exact number depends on factors such as the server's configuration, the degree of parallelism in the business application, and the complexity of the business logic.

The current version does not support multiple main servers; this functionality will be released in a future version. Therefore, adding additional main servers is generally not required at this time.

  1. Log in to the database encryption system using the system administrator (sysadmin) account .
  2. Select Encryption Proxy Service from the left navigation tree.
  3. In the right-hand section, click Add New, as shown in Figure 2.

    Figure 2 Adding a new encrypted proxy server or proxy service

  4. After selecting Add Main Server, configure the corresponding server information in the pop-up window, as shown in Figure 3. For configuring the main server, refer to Table 1 for parameter descriptions.

    Figure 3 Adding a main server
    Table 1 New main server parameter documentation

    Parameter

    Description

    Main Server Name

    Custom string – can be filled in according to business requirements.

    Machine Name

    Custom string – can be filled in according to business requirements.

    Public IP

    This is an optional field; you may enter the public IP address of this host.

    MAC

    This is an optional field; you may enter the MAC address of the host.

Creating a Proxy Service

The Encryption Proxy Service is a reverse proxy service for databases; it serves as the primary execution unit responsible for data encryption/decryption and data masking. This service functions as a virtual database; after configuring the Encryption Proxy Service, the business system's database connection should be directed to this newly added proxy service. As shown in Figure 4, the IP address for the business system's database connection should be changed to the virtual IP address of the Database Encryption Service instance. This virtual IP address can be retrieved from the Database Security Service (DBSS) management console; the port should be set to 2099.

Figure 4 Proxy service instance
  1. Logging In to the Database Encryption System using the system administrator (sysadmin) account.
  2. Select Encryption Proxy Service from the left navigation tree.
  3. In the right-hand area, click Add New, as shown in Figure 5.

    Figure 5 Adding a new encrypted proxy server or proxy service

  4. After selecting Add Proxy Service, configure the attributes for the newly added proxy service in the pop-up window, as shown in Figure 6. The parameter descriptions for configuring proxy services are listed in Table 2.

    Figure 6 Creating a proxy service
    Table 2 New proxy service parameter documentation

    Parameter

    Description

    Main Server

    Select the configured main server using the dropdown menu.

    Proxy Service Name

    Custom string – fill in according to your actual business requirements.

    Port Number

    The port number for the Execution Proxy Service ranges from 2026 to 3036.

    The target database will provide services to applications or O&M tools via this port. For example, if port 2999 is selected, the database connection port for the business system must be changed to 2999.

    Database Type

    Select the required database type – that is, the database type of the remote database.

    For example: if the backend database is MySQL, select MySQL; if the backend database is another type of database, select the corresponding database.

    Data Asset

    Select data assets using the dropdown menu (these assets must have been configured in advance within the Asset Database module). For detailed instructions on configuring an Asset Database, please refer to the Asset Database.

    Remark

    Optional – please provide additional details regarding this agency service.

    Maximum Memory

    The maximum amount of memory that can be allocated by the current proxy service, measured in MB. The maximum allowable memory allocation value cannot exceed the available memory; otherwise, the proxy service cannot be created.

    Available Memory

    The maximum memory available for proxy service allocation across the entire system, measured in MB.

    Maximum Cached Memory

    The percentage of memory allocated to the cache for field information, field encryption rules, parsed SQL statements, and other cached data when assigned to an agent service. This value can be configured between 1 and 50; it depends on the number of fields and whether the system executes a large volume of SQL queries. You may initially set this value to 50 and adjust it later based on your specific business requirements.

  5. Click Confirm to save.

Viewing Proxy Services

When you need to modify an application's use of a proxy service, you should review the relevant information about that proxy service.

  1. Log in to the database encryption system using the system administrator (sysadmin) account.
  2. Select Encryption Proxy Service from the left navigation tree, as shown in Figure 7.

    Figure 7 Encrypted proxy service list

Editing or Deleting a Proxy Service

Adjust the configuration of existing servers to accommodate changing business requirements.

  1. Log in to the database encryption system using the system administrator (sysadmin) account.
  2. Select Encryption Proxy Service from the left navigation tree.
  3. View the server list; click the Edit button in the action column to edit the server, as shown in Figure 8.

    Figure 8 Editing a proxy service

  4. In the pop-up window, edit the proxy server configuration information, as shown in Figure 9.

    Figure 9 Editing the proxy server

  5. After completing the editing, click Confirm to save.
  6. You can also delete the corresponding server information based on your business requirements.
  • Service disruption: Encryption/decryption and data masking operations depend on specific proxy service configurations. Editing or deleting a proxy service while these operations are in progress may cause related service disruptions, affecting the normal operation of the system.
  • Data loss: Encryption and decryption operations involve the processing of sensitive data. If the proxy service is edited or deleted during these operations, it may prevent the relevant data from being correctly decrypted or recovered, leading to data loss.
  • Security Risk: Encryption/decryption and data masking operations involve the processing of sensitive data. If the proxy service is edited or deleted during these operations, it may lead to security vulnerabilities, exposing sensitive data to potential risks.
  • Configuration error: Rule configuration is typically tightly integrated with other parts of the system. Editing or deleting a proxy service while rule configuration is in progress may cause a configuration error that can affect the normal operation of the system.