Oracle透明数据加密:数据泵文件导出

不带加密的数据泵导出

先给hr用户赋予DATA_PUMP_DIR的读写权限:

sql 复制代码
SQL> grant read, write on directory DATA_PUMP_DIR to hr;

Grant succeeded.

expdp导出配置文件:

bash 复制代码
$ cat exp.par
DIRECTORY=DATA_PUMP_DIR
DUMPFILE=dataonly.dmp
CONTENT=DATA_ONLY

导出:

bash 复制代码
$ expdp hr/Welcome1@orclpdb1 parfile=exp.par

Export: Release 19.0.0.0.0 - Production on Thu Jul 11 01:27:32 2024
Version 19.16.0.0.0

Copyright (c) 1982, 2019, Oracle and/or its affiliates.  All rights reserved.

UDE-28002: operation generated ORACLE error 28002
ORA-28002: the password will expire within 7 days

Connected to: Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production
Starting "HR"."SYS_EXPORT_SCHEMA_01":  hr/********@orclpdb1 parfile=exp.par
Processing object type SCHEMA_EXPORT/TABLE/TABLE_DATA
. . exported "HR"."EMPLOYEES"                            17.08 KB     107 rows
. . exported "HR"."LOCATIONS"                            8.437 KB      23 rows
. . exported "HR"."DBTOOLS$EXECUTION_HISTORY"            8.398 KB       1 rows
. . exported "HR"."JOB_HISTORY"                          7.195 KB      10 rows
. . exported "HR"."JOBS"                                 7.109 KB      19 rows
. . exported "HR"."DEPARTMENTS"                          7.125 KB      27 rows
. . exported "HR"."COUNTRIES"                            6.367 KB      25 rows
. . exported "HR"."REGIONS"                              5.546 KB       4 rows
Master table "HR"."SYS_EXPORT_SCHEMA_01" successfully loaded/unloaded
******************************************************************************
Dump file set for HR.SYS_EXPORT_SCHEMA_01 is:
  /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp
Job "HR"."SYS_EXPORT_SCHEMA_01" successfully completed at Thu Jul 11 01:27:36 2024 elapsed 0 00:00:04

文件大小:

bash 复制代码
$ ls -l dataonly.dmp
-rw-r-----. 1 oracle dba 360448 Jul 11 01:50 dataonly.dmp

搜索敏感文字,如电话的区号:

bash 复制代码
$ strings /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp|grep -i "650\."|sort|uniq
650.121.1234
650.121.1834
650.121.2004
650.121.2019
650.121.2034
650.121.2874
650.121.2994
650.121.8009
650.123.1234
650.123.2234
650.123.3234
650.123.4234
650.123.5234
650.124.1214
650.124.1224
650.124.1334
650.124.1434
650.124.5234
650.124.6234
650.124.7234
650.124.8234
650.127.1634
650.127.1734
650.127.1834
650.127.1934
650.501.1876
650.501.2876
650.501.3876
650.501.4876
650.505.1876
650.505.2876
650.505.3876
650.505.4876
650.507.9811
650.507.9822
650.507.9833
650.507.9844
650.507.9876
650.507.9877
650.507.9878
650.507.9879
650.509.1876
650.509.2876
650.509.3876
650.509.4876

带加密的数据泵导出

带加密的配置文件:

bash 复制代码
$ cat exp.par
DIRECTORY=DATA_PUMP_DIR
DUMPFILE=dataonly.dmp
CONTENT=DATA_ONLY
ENCRYPTION=DATA_ONLY

加密导出:

bash 复制代码
[oracle@instance-20231220-1113-19c-iaas tde]$ expdp hr/Welcome1@orclpdb1 parfile=exp.par

Export: Release 19.0.0.0.0 - Production on Thu Jul 11 01:44:20 2024
Version 19.16.0.0.0

Copyright (c) 1982, 2019, Oracle and/or its affiliates.  All rights reserved.

UDE-28002: operation generated ORACLE error 28002
ORA-28002: the password will expire within 7 days

Connected to: Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production
Starting "HR"."SYS_EXPORT_SCHEMA_01":  hr/********@orclpdb1 parfile=exp.par
Processing object type SCHEMA_EXPORT/TABLE/TABLE_DATA
. . exported "HR"."EMPLOYEES"                            17.09 KB     107 rows
. . exported "HR"."LOCATIONS"                            8.445 KB      23 rows
. . exported "HR"."DBTOOLS$EXECUTION_HISTORY"            8.406 KB       1 rows
. . exported "HR"."JOB_HISTORY"                          7.203 KB      10 rows
. . exported "HR"."JOBS"                                 7.117 KB      19 rows
. . exported "HR"."DEPARTMENTS"                          7.132 KB      27 rows
. . exported "HR"."COUNTRIES"                            6.375 KB      25 rows
. . exported "HR"."REGIONS"                              5.554 KB       4 rows
Master table "HR"."SYS_EXPORT_SCHEMA_01" successfully loaded/unloaded
******************************************************************************
Dump file set for HR.SYS_EXPORT_SCHEMA_01 is:
  /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp
Job "HR"."SYS_EXPORT_SCHEMA_01" successfully completed at Thu Jul 11 01:44:38 2024 elapsed 0 00:00:16

没有输出了:

bash 复制代码
$ strings /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp|grep -i "650\."|sort|uniq

加密后的文件大小:

sql 复制代码
$ ls -l dataonly.dmp
-rw-r-----. 1 oracle dba 360448 Jul 11 01:44 dataonly.dmp

文件大小没有变化。

参考

相关推荐
文牧之16 分钟前
Oracle 的 SEC_CASE_SENSITIVE_LOGON 参数
运维·数据库·oracle
NineData1 小时前
NineData云原生智能数据管理平台新功能发布|2025年5月版
数据库·云原生·oracle·devops·ninedata
不会编程的猫星人1 小时前
Oracle杀进程注意事项
数据库·microsoft·oracle
GUIQU.1 小时前
【Oracle】安装单实例
数据库·oracle
Lx3522 小时前
UNION ALL与UNION的性能差异及选择技巧
sql·mysql·oracle
GUIQU.3 小时前
【Oracle】存储过程
数据库·oracle
爱可生开源社区3 小时前
SQLShift 重大更新:Oracle→PostgreSQL 存储过程转换功能上线!
数据库·postgresql·oracle
TDengine (老段)15 小时前
TDengine 集群容错与灾备
大数据·运维·数据库·oracle·时序数据库·tdengine·涛思数据
风景_fengjing18 小时前
ORACLE 缺失 OracleDBConsoleorcl服务导致https://xxx:port/em 不能访问
oracle
徐sir(徐慧阳)1 天前
Dataguard switchover遇到ORA-19809和ORA-19804报错的问题处理
服务器·数据库·oracle·dataguard