Oracle透明数据加密:数据泵文件导出

不带加密的数据泵导出

先给hr用户赋予DATA_PUMP_DIR的读写权限:

sql 复制代码
SQL> grant read, write on directory DATA_PUMP_DIR to hr;

Grant succeeded.

expdp导出配置文件:

bash 复制代码
$ cat exp.par
DIRECTORY=DATA_PUMP_DIR
DUMPFILE=dataonly.dmp
CONTENT=DATA_ONLY

导出:

bash 复制代码
$ expdp hr/Welcome1@orclpdb1 parfile=exp.par

Export: Release 19.0.0.0.0 - Production on Thu Jul 11 01:27:32 2024
Version 19.16.0.0.0

Copyright (c) 1982, 2019, Oracle and/or its affiliates.  All rights reserved.

UDE-28002: operation generated ORACLE error 28002
ORA-28002: the password will expire within 7 days

Connected to: Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production
Starting "HR"."SYS_EXPORT_SCHEMA_01":  hr/********@orclpdb1 parfile=exp.par
Processing object type SCHEMA_EXPORT/TABLE/TABLE_DATA
. . exported "HR"."EMPLOYEES"                            17.08 KB     107 rows
. . exported "HR"."LOCATIONS"                            8.437 KB      23 rows
. . exported "HR"."DBTOOLS$EXECUTION_HISTORY"            8.398 KB       1 rows
. . exported "HR"."JOB_HISTORY"                          7.195 KB      10 rows
. . exported "HR"."JOBS"                                 7.109 KB      19 rows
. . exported "HR"."DEPARTMENTS"                          7.125 KB      27 rows
. . exported "HR"."COUNTRIES"                            6.367 KB      25 rows
. . exported "HR"."REGIONS"                              5.546 KB       4 rows
Master table "HR"."SYS_EXPORT_SCHEMA_01" successfully loaded/unloaded
******************************************************************************
Dump file set for HR.SYS_EXPORT_SCHEMA_01 is:
  /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp
Job "HR"."SYS_EXPORT_SCHEMA_01" successfully completed at Thu Jul 11 01:27:36 2024 elapsed 0 00:00:04

文件大小:

bash 复制代码
$ ls -l dataonly.dmp
-rw-r-----. 1 oracle dba 360448 Jul 11 01:50 dataonly.dmp

搜索敏感文字,如电话的区号:

bash 复制代码
$ strings /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp|grep -i "650\."|sort|uniq
650.121.1234
650.121.1834
650.121.2004
650.121.2019
650.121.2034
650.121.2874
650.121.2994
650.121.8009
650.123.1234
650.123.2234
650.123.3234
650.123.4234
650.123.5234
650.124.1214
650.124.1224
650.124.1334
650.124.1434
650.124.5234
650.124.6234
650.124.7234
650.124.8234
650.127.1634
650.127.1734
650.127.1834
650.127.1934
650.501.1876
650.501.2876
650.501.3876
650.501.4876
650.505.1876
650.505.2876
650.505.3876
650.505.4876
650.507.9811
650.507.9822
650.507.9833
650.507.9844
650.507.9876
650.507.9877
650.507.9878
650.507.9879
650.509.1876
650.509.2876
650.509.3876
650.509.4876

带加密的数据泵导出

带加密的配置文件:

bash 复制代码
$ cat exp.par
DIRECTORY=DATA_PUMP_DIR
DUMPFILE=dataonly.dmp
CONTENT=DATA_ONLY
ENCRYPTION=DATA_ONLY

加密导出:

bash 复制代码
[oracle@instance-20231220-1113-19c-iaas tde]$ expdp hr/Welcome1@orclpdb1 parfile=exp.par

Export: Release 19.0.0.0.0 - Production on Thu Jul 11 01:44:20 2024
Version 19.16.0.0.0

Copyright (c) 1982, 2019, Oracle and/or its affiliates.  All rights reserved.

UDE-28002: operation generated ORACLE error 28002
ORA-28002: the password will expire within 7 days

Connected to: Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production
Starting "HR"."SYS_EXPORT_SCHEMA_01":  hr/********@orclpdb1 parfile=exp.par
Processing object type SCHEMA_EXPORT/TABLE/TABLE_DATA
. . exported "HR"."EMPLOYEES"                            17.09 KB     107 rows
. . exported "HR"."LOCATIONS"                            8.445 KB      23 rows
. . exported "HR"."DBTOOLS$EXECUTION_HISTORY"            8.406 KB       1 rows
. . exported "HR"."JOB_HISTORY"                          7.203 KB      10 rows
. . exported "HR"."JOBS"                                 7.117 KB      19 rows
. . exported "HR"."DEPARTMENTS"                          7.132 KB      27 rows
. . exported "HR"."COUNTRIES"                            6.375 KB      25 rows
. . exported "HR"."REGIONS"                              5.554 KB       4 rows
Master table "HR"."SYS_EXPORT_SCHEMA_01" successfully loaded/unloaded
******************************************************************************
Dump file set for HR.SYS_EXPORT_SCHEMA_01 is:
  /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp
Job "HR"."SYS_EXPORT_SCHEMA_01" successfully completed at Thu Jul 11 01:44:38 2024 elapsed 0 00:00:16

没有输出了:

bash 复制代码
$ strings /u01/app/oracle/admin/ORCL/dpdump/0CE9C0F43A7F3441E06500001702E44D/dataonly.dmp|grep -i "650\."|sort|uniq

加密后的文件大小:

sql 复制代码
$ ls -l dataonly.dmp
-rw-r-----. 1 oracle dba 360448 Jul 11 01:44 dataonly.dmp

文件大小没有变化。

参考

相关推荐
数据库小组2 小时前
Oracle 上云 / 替代场景下,NineData 完成到 PostgreSQL 的低风险迁移
大数据·数据库·mysql·postgresql·oracle·数据一致性·数据库迁移
jnrjian5 小时前
expdp 指定的表分区 其实指定where 条件也可以
oracle
IT邦德5 小时前
Oracle 26ai 图数据库
数据库·oracle
果果燕6 小时前
SQLite3数据库学习笔记1
数据库·sql·oracle
jnrjian6 小时前
Oracle 收缩8TB 磁盘空间遇到的问题
数据库·oracle
Ricky_Theseus6 小时前
SQL数据控制9动词
数据库·sql·oracle
jnrjian15 小时前
Oracle 历史重启时间 Alert.log
oracle
spencer_tseng1 天前
ORA-00911: invalid character
oracle·ora-00911
寒风暖哥1 天前
Oracle视图查询返回空数据集的分析
oracle·c#
汤愈韬1 天前
BGP知识点解析
网络协议·网络安全·security