Sensitive user data in the company's database needs to be encrypted into a binary ciphertext stored in the mysqlblob type field, and it is found that it is difficult to ensure the uniqueness of user data, because it seems that blob fields cannot be directly used for logical operations, and the ciphertext in the table cannot be fully read and decrypted again... sensitive user data in the company's database needs to be encrypted into a binary ciphertext stored in the mysql blob type field. it is found that it is difficult to ensure the uniqueness of user data, because it seems that blob fields cannot be directly used for logical operations, and the ciphertext in the table cannot be fully read and decrypted before logical operations.
Reply content:
Sensitive user data in the company's database needs to be encrypted into a binary ciphertext stored in the mysql blob type field. it is found that it is difficult to ensure the uniqueness of user data, because it seems that blob fields cannot be directly used for logical operations, and the ciphertext in the table cannot be fully read and decrypted before logical operations.
Cache ciphertext md5 based on user ID
I think we should do this:
-
Add new data to perform md5 hash on plaintext before encryption, and then save a hash value (encrypted blob also needs to be stored)
-
For some data, you need to find a time to decrypt all the md5 files, and then store the hash value.
In this way, you can determine the uniqueness of the hash value.
Md5 is not recommended for ciphertext unless you can ensure that the same plaintext is always generated after encryption. However, ciphertext will at least be affected by the key. after the key is changed, the ciphertext will definitely change... besides, some encryption methods have random initial vectors, and the ciphertext encrypted each time is different.
Direct mysql built-in method hex ()