Encryption Proxy Service
The encrypted proxy service is a database-oriented network reverse proxy. In a database encryption system, when it is necessary to configure data encryption in Proxy mode, the encrypted proxy service must be configured first.
Conversely, when the Application-Plugin mode is selected for data encryption, there is no need to configure an encryption proxy service. The logical architecture of the encryption proxy service is shown in Figure 1.
In an encryption system, once the database encryption/decryption configuration is completed, any content viewed by users when accessing the database directly via SQL statements is ciphertext. Conversely, the encryption proxy service acts as a security barrier; it introduces an additional proxy service port on top of the original database server port to forward requests. Through this mechanism, not only is data encryption/decryption performed, but it is also ensured that the data viewed or manipulated by authorized users always appears as plaintext. The data within the database remains encrypted at all times to safeguard security.
The core responsibility of this module is to configure the connection parameters between the real database service and the proxy service, ensuring the security and accuracy of the data during transmission.
Conceptual Explanation
- Main Server: The main server is the host on which the encrypted proxy service runs. Depending on the operating environment, the main server can be either a cloud host or a physical host; technically, a single main server can host multiple encrypted proxy services. This depends on factors such as the server's configuration, the degree of parallelism in the application, and the complexity of the application.
The current version does not support configuring multiple main servers.
- Encryption Proxy Service: The Encryption Proxy Service is a database-oriented network reverse proxy service. It serves as the primary execution unit responsible for data encryption and decryption within the proxy mode.
- Asset Database: The Asset Database is the database managed within the Asset Database Management Module.
Constraints and Limitations
- Special note regarding whether to enable SSL: To encrypt non-intrusive bypass traffic, the TLS encrypted channel cannot be used, which may pose security risks.
- Encrypted proxy functionality; currently unsupported data operation methods:
- The `SELECT` data type clause that includes the `temp` keyword is not currently supported.
- `INSERT` is used for batch insertion of data with a self-referential structure; `INSERT` supports nested formatting.
- Update: The data type supports nested formatting.
- encrypted fields do not support size comparison operators (e.g.,>, <, ORDER BY, BETWEEN, etc.).
- Function computations (e.g., AVG, MAX, MIN, SUM, and arithmetic expressions) are not supported.
- View, trigger, and stored procedure operations are not supported; for equality comparisons ('=') following conditions such as 'WHERE', both fields on either side of the '=' operator must be encrypted, or neither field should be encrypted.
- Encryption for table or field names containing wildcards is not supported for configuration.
Adding a Main Server
The main server is the host machine that runs the encrypted proxy service; depending on the operating environment, it can be either a cloud-based server or a physical server. Technically, a single main server can support multiple encrypted proxy services—though the exact number depends on factors such as the server's configuration, the degree of parallelism in the business application, and the complexity of the business logic.
The current version does not support multiple main servers; this functionality will be released in a future version. Therefore, adding additional main servers is generally not required at this time.
- Log in to the database encryption system using the system administrator (sysadmin) account .
- Select Encryption Proxy Service from the left navigation tree.
- In the right-hand section, click Add New, as shown in Figure 2.
- After selecting Add Main Server, configure the corresponding server information in the pop-up window, as shown in Figure 3. For configuring the main server, refer to Table 1 for parameter descriptions.
Table 1 New main server parameter documentation Parameter
Description
Main Server Name
Custom string – can be filled in according to business requirements.
Machine Name
Custom string – can be filled in according to business requirements.
Public IP
This is an optional field; you may enter the public IP address of this host.
MAC
This is an optional field; you may enter the MAC address of the host.
Creating a Proxy Service
The Encryption Proxy Service is a reverse proxy service for databases; it serves as the primary execution unit responsible for data encryption/decryption and data masking. This service functions as a virtual database; after configuring the Encryption Proxy Service, the business system's database connection should be directed to this newly added proxy service. As shown in Figure 4, the IP address for the business system's database connection should be changed to the virtual IP address of the Database Encryption Service instance. This virtual IP address can be retrieved from the Database Security Service (DBSS) management console; the port should be set to 2099.
- Logging In to the Database Encryption System using the system administrator (sysadmin) account.
- Select Encryption Proxy Service from the left navigation tree.
- In the right-hand area, click Add New, as shown in Figure 5.
- After selecting Add Proxy Service, configure the attributes for the newly added proxy service in the pop-up window, as shown in Figure 6. The parameter descriptions for configuring proxy services are listed in Table 2.
Table 2 New proxy service parameter documentation Parameter
Description
Main Server
Select the configured main server using the dropdown menu.
Proxy Service Name
Custom string – fill in according to your actual business requirements.
Port Number
The port number for the Execution Proxy Service ranges from 2026 to 3036.
The target database will provide services to applications or O&M tools via this port. For example, if port 2999 is selected, the database connection port for the business system must be changed to 2999.
Database Type
Select the required database type – that is, the database type of the remote database.
For example: if the backend database is MySQL, select MySQL; if the backend database is another type of database, select the corresponding database.
Data Asset
Select data assets using the dropdown menu (these assets must have been configured in advance within the Asset Database module). For detailed instructions on configuring an Asset Database, please refer to the Asset Database.
Remark
Optional – please provide additional details regarding this agency service.
Maximum Memory
The maximum amount of memory that can be allocated by the current proxy service, measured in MB. The maximum allowable memory allocation value cannot exceed the available memory; otherwise, the proxy service cannot be created.
Available Memory
The maximum memory available for proxy service allocation across the entire system, measured in MB.
Maximum Cached Memory
The percentage of memory allocated to the cache for field information, field encryption rules, parsed SQL statements, and other cached data when assigned to an agent service. This value can be configured between 1 and 50; it depends on the number of fields and whether the system executes a large volume of SQL queries. You may initially set this value to 50 and adjust it later based on your specific business requirements.
- Click Confirm to save.
Viewing Proxy Services
When you need to modify an application's use of a proxy service, you should review the relevant information about that proxy service.
- Log in to the database encryption system using the system administrator (sysadmin) account.
- Select Encryption Proxy Service from the left navigation tree, as shown in Figure 7.
Editing or Deleting a Proxy Service
Adjust the configuration of existing servers to accommodate changing business requirements.
- Log in to the database encryption system using the system administrator (sysadmin) account.
- Select Encryption Proxy Service from the left navigation tree.
- View the server list; click the Edit button in the action column to edit the server, as shown in Figure 8.
- In the pop-up window, edit the proxy server configuration information, as shown in Figure 9.
- After completing the editing, click Confirm to save.
- You can also delete the corresponding server information based on your business requirements.
- Service disruption: Encryption/decryption and data masking operations depend on specific proxy service configurations. Editing or deleting a proxy service while these operations are in progress may cause related service disruptions, affecting the normal operation of the system.
- Data loss: Encryption and decryption operations involve the processing of sensitive data. If the proxy service is edited or deleted during these operations, it may prevent the relevant data from being correctly decrypted or recovered, leading to data loss.
- Security Risk: Encryption/decryption and data masking operations involve the processing of sensitive data. If the proxy service is edited or deleted during these operations, it may lead to security vulnerabilities, exposing sensitive data to potential risks.
- Configuration error: Rule configuration is typically tightly integrated with other parts of the system. Editing or deleting a proxy service while rule configuration is in progress may cause a configuration error that can affect the normal operation of the system.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot








