Updated on 2026-09-24 GMT+08:00

Database Encryption Introduction

Features and Functions

Database Encryption is a data security solution designed specifically to encrypt sensitive data (e.g., personal information) stored within databases and to provide integrity protection. It is primarily used to meet data security and compliance requirements, such as data security protection and Commercial Cryptography Assessment and Modification.

System Main Features:

  • High security: A single product provides five layers of protection – including Prevention of Unauthorized Disk Removal, prevention of data file theft, Prevention of Data File Peeking and Theft, prevention of SQL-based data retrieval by third-party service personnel, and prevention of SQL-based data retrieval by super administrators.
  • Meet encryption compliance requirements: satisfy the high-risk item requirements under the Application and Data Security category for encryption-related system modifications.
  • Simple to use: Encrypt data and prevent tampering with just a few straightforward configuration steps.

The main system functions are as follows:

  • Data Transparent Encryption/Decryption: Supports column-level transparent encryption/decryption for databases – meaning applications do not require any complex code modifications; simply configuring through the database encryption product's management console enables rapid deployment of data encryption/decryption, ensuring data security during both transmission and storage.
  • Data integrity protection: Supports column-level database integrity validation to prevent important data from being tampered with or corrupted. Similar to data encryption, data integrity protection requires no code modification – it can be implemented simply through configuration.
  • Dynamic Data Masking (Beta): The system supports dynamic data masking for sensitive data; based on configured masking rules, it masks plaintext data for display, ensuring the security of data display and query processes.
  • Sensitive Data Discovery: Automates the identification of sensitive data using automated or semi-automated methods, facilitating the rapid detection of sensitive data that requires encryption.
  • Encryption Management: The system supports multiple encryption algorithms depending on the version; these can be flexibly selected according to user requirements, and the system can be integrated with an External Key Management Service (KMS) to meet diverse security needs.

Through these features, the database encryption system effectively protects sensitive data, meets compliance requirements, and provides robust security safeguards for the organization's core confidential information stored within the database.

Product Logical Architecture

The logical architecture of the database encryption system is depicted in Figure 1; its core capabilities consist of three layers, specifically:

Figure 1 Database encryption system logical architecture
  • Asset Database Layer: Refers to various databases managed by the database encryption system. These managed databases are referred to as the Asset Database within this system.
  • Technical Support Layer: This refers to the two key technologies implemented in the database encryption system, encompassing two implementation modes – the Application-Plugin mode and the Proxy mode. While the functionalities provided by these two technologies are similar, each has distinct characteristics; for a detailed description of these characteristics, please refer to the sections on theApplication-plugin Pattern and Proxy Pattern.
  • Capability Output Layer: The Capability Output Layer comprises two types of core functions.
    • Column-level storage encryption and data integrity verification.
    • Sensitive data identification and dynamic desensitization.

Application-plugin Pattern

The Application-Plugin pattern enables data encryption during write operations and data decryption or masking during read operations by deploying plugins within an application. This technique is also known in the industry as aspect-oriented programming or Application Layer Encryption (ALE). Taking the encryption/decryption process as an example, the logical architecture of the Application-Plugin pattern is illustrated in Figure 2.

Figure 2 Plugin mode logical architecture
  • Key components:
    • Database Encryption System: The Database Encryption System is managed via a Web-based management console (this console serves as a web-based administration interface provided by the Database Encryption System). The fields to be encrypted, the encryption algorithm to be used, and the source of the encryption key are all configured and managed through the Encryption Console.
    • Database: A database is the database used by a business system to store data. A database under the management of a database encryption system is referred to as an Asset Database within the system.
    • Business systems: Refers to various business systems already in use by users, such as Customer Relationship Management (CRM), ERP, customer loyalty program management systems, student record management systems, and other business systems.
    • Encryption Plugin: The Encryption Plugin is a Jar file generated and downloaded from the Database Encryption System Management Console, after configuring the data encryption settings via the Web Management Console. This Jar file is then deployed onto the business system.
    • Existing data encryption: This refers to the scenario where historically generated data already exists in the database in plaintext format before a database encryption system is deployed; such data must be encrypted using the existing data encryption function.
  • Plugin Mode – Applicable scenarios:
    • The business system is developed using Java; the Java version must be 17 or later.
    • The business system experiences high concurrency levels.
  • service restrictions:
    • Non-Java applications are not suitable for the application plugin pattern.
    • When the database contains stored procedures or functions that perform computations on sensitive data, please contact Technical Support or your database UDF team to modify the stored procedures or functions.

Proxy Pattern

The Proxy pattern involves deploying a network proxy server between the application system and the database to encrypt data during write operations or decrypt/mask data during read operations. The logical architecture of the Network Proxy pattern is illustrated in Figure 3.

Figure 3 Network proxy mode logical architecture

As shown in Figure 3, the network proxy pattern involves deploying a network proxy server between the application system and the database.

  • Key components:
    • Database Encryption System: The Database Encryption System is managed via a Web-based management console (this console serves as a web-based administration interface provided by the Database Encryption System). The fields to be encrypted, the encryption algorithm to be used, and the source of the encryption key are all configured and managed through the Encryption Console.
    • Database: A database is the database used by a business system to store data. A database under the management of a database encryption system is referred to as an Asset Database within the system.
    • Business systems: Refers to various business systems already in use by users, such as Customer Relationship Management (CRM), ERP, customer loyalty program management systems, student record management systems, and other business systems.
    • Network proxy server: A network proxy server is a physical or cloud-based server that runs a database encryption system and a proxy service.
    • Proxy Service: The Proxy Service is a reverse proxy service created on a network proxy server using a database encryption system; it runs on the network proxy server. This service is used to retrieve SQL statements written to the database and to encrypt or decrypt the sensitive data involved in those statements.
    • Existing data encryption: This refers to the scenario where historically generated data already exists in the database in plaintext format before a database encryption system is deployed; such data must be encrypted using the existing data encryption function.
  • Proxy Pattern Use Cases:
    • Business systems are those designed using programming languages such as Java, C/C++, PHP, or Python.
    • The business system does not experience high concurrency.
  • Proxy Pattern Usage Restrictions:
    • The Proxy Pattern is heavily dependent on the database version; please refer to the Support and Compatibility List before use.
    • The current version of the Proxy Pattern does not support clustering or high availability (HA); therefore, it should be used with caution in environments requiring high availability. HA and clustering features will be released in future versions.
    • When a database contains stored procedures or functions that perform computations on sensitive data, the recommended solution is to contact technical support or the database UDF team and modify the stored procedures or functions accordingly.

Algorithm Support

The system supports data encryption and integrity verification, meeting the evaluation requirements for initiatives such as the Classified Protection and Graded Protection, as well as the key data storage confidentiality and integrity assurance requirements specified in commercial cryptography evaluation frameworks.

  • Encryption algorithm: SM4 (Chinese Commercial Cryptography Algorithm).
  • Integrity verification algorithm: SM3-HMAC algorithm.

Applicable Scenarios

  • Data storage security, database exfiltration prevention, and network sniffing prevention: The database encryption system is widely applicable across various sectors—including government agencies, education, finance, healthcare, e-commerce, and internal enterprise data security management. In these scenarios, the system enables the encrypted storage and transmission of sensitive data, ensuring that data is stored in ciphertext form within the database. When the data masking function is activated, the system also supports data masking during external display, data analysis, or third-party sharing, thereby preventing data leakage.
  • Compliance Requirements: Alignment with National Regulatory Requirements: The system supports multiple encryption algorithms and strictly complies with the requirements stipulated in laws and regulations such as the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law. Through data encryption and anonymization technologies, the system effectively protects personal information and critical data, ensuring the compliance of all data processing activities.
  • Commercial Cryptography Compliance Upgrade: Supports the migration of legacy systems to support China Standard Cryptography (CSC) standards. The system employs application plugins or a transparent network proxy to encrypt data; this approach involves low implementation costs and high migration efficiency, enables seamless integration with legacy systems, meets the requirements for encrypted storage and integrity verification of critical data during the CSC migration process, and eliminates the need for large-scale system architecture refactoring.
  • Prevents large-scale theft of sensitive data by third-party service personnel or system operations and maintenance staff. This solution effectively safeguards against massive theft or tampering of sensitive data by on-site third-party maintenance personnel as well as internal employees with high-level data access privileges—particularly in highly competitive industries such as educational training, medical aesthetics, ophthalmology, and high-end healthcare.