Updated on 2026-07-07 GMT+08:00

Introduction

Database encryption and access control is a security solution that safeguards sensitive data through encryption, utilizing gateway proxy technology.

As a proxy encryption gateway, the system is deployed between the database and client applications. Any access must pass through the gateway to implement data encryption and access control. Figure 1 shows the system networking scenario.

Figure 1 Networking mode

Encrypting Data

The system supports data encryption and integrity verification, meeting the evaluation requirements of graded protection and sub-protection as well as the evaluation requirements of storage data integrity and confidentiality assurance in the application and security evaluation of commercial cryptographic systems.

  • Encryption algorithm: AES
  • Integrity check algorithm: AES-GCM

Access Control

The system has an access authorization mechanism independent of the database. Authorized users can access encrypted data, but unauthorized users cannot access encrypted data. This effectively prevents administrators from accessing the database without authorization and hackers from dragging the database.

The system allows system administrators, security administrators, and audit administrators to manage separation of permissions, enhancing database security and compliance.

Applications

Database encryption and access control can meet compliance requirements as well as sensitive database data protection requirements.

Meet the compliance requirements of national assessment.

The application system processes data based on user permissions. For legacy systems (the old system cannot be upgraded or reconstructed) and personal privacy protection issues required by the Cybersecurity Law are not considered during development, it is too complex to change the code, data privacy protection depends on external technologies.

Database encryption and access control can implement database encryption and comply with various laws and regulations.

Meet the requirements for protecting sensitive database data.

Database encryption and access control can effectively prevent data leakage caused by the leakage of high-privilege accounts and passwords of database administrators, such as DBAs. In addition, the system can prevent database files from being downloaded or copied due to external APT attacks or improper internal management, meeting sensitive data protection requirements of databases.

Functions

This section describes the main functions and related sections of database encryption and access control.

Table 1 Functions

Function

Description

Reference

Asset management

You can add, delete, modify, and query database assets; test data source connectivity; and configure database read/write isolation, encryption mode, return value, and account permission check.

Adding Data Assets

Sensitive data discovery

You can scan for sensitive data, manage sensitive data types, and manage sensitive data industry templates.

Sensitive Data Discovery

Business test

You can perform service simulation tests to verify encryption and decryption. You can also connect to the network before encryption to analyze service SQL traffic, locate SQL statements that may fail to be executed after encryption, and generate analysis reports.

Simulated Encryption Test, Simulated Decryption Test, and Service Test and Analysis

Data encryption

The data encryption module manages encryption and decryption tasks, authorizes client and database users to restrict user access, views and downloads encryption logs, rolls back table structures, manages encryption tables, and downloads bypass plug-ins.

Data Encryption and Decryption

Dynamic data masking

A masking algorithm can be configured for sensitive data to dynamically mask plaintext data.

Dynamic Data Masking

Key management

This feature supports a three-tier key hierarchy, key source configuration, periodic Data Signing Key (DSK) rotation, KMS integration, as well as key record tracking and searching.

Initializing a Key and Key Management

Platform management

In the platform management module, you can configure network interfaces (NICs) and routes, upgrade the system, back up and restore configuration data, audit application access logs, and manage security passwords.

Platform Management

System management

  • In the system management module, you can manage platform users, organizational units, user roles, and account reviews. You can also check and manage system notifications.
  • You can monitor device status, manage devices, analyze the utilization of system kernels, CPUs, and storage, perform system upgrades, and configure system security settings.

System Management

Log management

You can view and search for logs of all operations in the system.

Viewing System Operation Logs