Shaping the Future of China's Database: Building a New Ecosystem for Secure and Trusted Intelligent Data Storage
At the 25th China International Software Expo · China Database Industry Summit, Academician Shen Changxiang of the Chinese Academy of Engineering delivered a keynote speech titled “Creating a New Ecosystem for Secure and Trusted Intelligent Data Storage” at the main forum. He addressed data security and cybersecurity assurance issues in the new era of data as a factor of production, and called on domestic database enterprises to build database products based on trusted architectures to ensure the secure and healthy development of China's digital economy.
Academician Shen stressed: The 20th National Congress of the Communist Party of China proposed “accelerating the building of a cyber power and a digital China.” Amid the wave of digital transformation, the Internet of Everything means cyberattacks will extend from digital space to physical space, posing severe challenges to cybersecurity. We must effectively counter the intimidation of those who seek to monopolize cyberspace and build a strong line of cyber defense.
Big data is characterized by multi-source heterogeneity, unstructured formats, low value density, and rapid processing. As massive data becomes further concentrated and information technology advances, information security has become a bottleneck for the rapid development of big data. For example, the WannaCry ransomware attack in 2017 swept across more than 150 countries; in 2018 a ransomware intrusion forced TSMC to suspend operations at three manufacturing sites; and in 2021 Colonial Pipeline, the largest refined oil pipeline operator in the United States, was hit by a ransomware attack and had to shut down its fuel supply network along the U.S. East Coast.
Academician Shen pointed out that cybersecurity risks originate from inherent vulnerabilities: the Turing machine model lacks an offensive/defensive design philosophy, the von Neumann architecture lacks protective components, and engineering applications lack security services. Secure and trusted products and services, on the other hand, perform dynamic, comprehensive, end-to-end protection in parallel with computation and calculation. This ensures that the logical combination required to complete computing tasks is not tampered with or destroyed, thereby achieving the expected computing goals—analogous to the human body’s immunity ensuring health.
Therefore, in accordance with national cybersecurity laws, strategies, and the requirements of the Classified Protection of Cybersecurity regime, we must innovate in foundational principles, core technologies, and engineering applications, and use secure and trusted network products and services to build a digital economy assurance system with proactive immune protection. This achieves the “Six No’s” protection effect: attackers cannot get in, unauthorized parties cannot obtain critical information, stolen confidential information cannot be read, systems and information cannot be altered, systems cannot be paralyzed, and attack behaviors cannot be denied.
Among these, building a trusted-architecture database becomes an important pillar of “a new type of critical infrastructure security and trusted management and control system.” The encryption driver (on the participating side) manages encapsulated keys, encrypts sensitive data, and parses and modifies SQL statements and other complex operations. The encrypted key trusted channel transmits the CEK (Client Encryption Key) based on a trusted channel; order-preserving encryption (OPE) and Trusted Execution Environment (TEE) use operator-level isolation to significantly reduce security risks.
In addition, the Cybersecurity Classified Protection 2.0 standard and the regulations on the protection of critical information infrastructure also require that priority be given to purchasing fully secure and trusted products and services to build a critical infrastructure security assurance system. On October 28, 2020, the National Demonstration Base for Classified Protection 2.0 and Trusted Computing 3.0 was officially inaugurated. Academician Shen believes that domestic CPUs with a parallel trusted computing architecture, embedded trusted chip motherboards, and product devices based on Trusted Computing 3.0 technology are undergoing continuous iterative evolution. A complete Trusted Computing 3.0 industrial chain will create a huge new industrial space and promote the transformation of the industrial ecosystem.
Finally, Academician Shen emphasized that we must seize the commanding heights of core technologies such as database software, persist in independent innovation, and accelerate the transformation and development of domestic databases toward trusted architectures. Through end-to-end management and control with equal emphasis on technology and management, we can safeguard the security of China's independent information systems, thereby ensuring the healthy development of China's digital economy.