MSSQL 2008、2012儲存過程加密解密
阿新 • • 發佈:2019-01-10
1. 必須在DAC連線SQL Server
不然會報錯:
訊息 208,級別 16,狀態 1,過程 sp_DecryptObject,第 75 行
物件名 'sys.sysobjvalues' 無效。
2. 建立加(解)密過程儲存過程
3. 執行儲存過程
用於加密的儲存過程 (sp_EncryptObject) :
Use master
Go
if object_ID('[sp_EncryptObject]') is not null
Drop Procedure [sp_EncryptObject]
Go
create procedure sp_EncryptObject
(
@Object sysname='All'
)
as
/*
當@Object=All的時候,對所有的函式,儲存過程,檢視和觸發器進行加密
呼叫方法:
1. Execute sp_EncryptObject 'All'
2. Execute sp_EncryptObject 'ObjectName'
*/
begin
set nocount on
if @Object <>'All'
begin
if not exists(select 1 from sys.objects a where a.object_id=object_id(@Object) And a.type in('P','V','TR','FN','IF','TF'))
begin
--SQL Server 2008
raiserror 50001 N'無效的加密物件!加密物件必須是函式,儲存過程,檢視或觸發器。'
--SQL Server 2012
--throw 50001, N'無效的加密物件!加密物件必須是函式,儲存過程,檢視或觸發器。',1
return
end
if exists(select 1 from sys.sql_modules a where a.object_id=object_id(@Object) and a.definition is null)
begin
--SQL Server 2008
raiserror 50001 N'物件已經加密!'
--SQL Server 2012
--throw 50001, N'物件已經加密!',1
return
end
end
declare @sql nvarchar(max),@C1 nchar(1),@C2 nchar(1),@type nvarchar(50),@Replace nvarchar(50)
set @C1=nchar(13)
set @C2=nchar(10)
declare cur_Object
cursor for
select object_name(a.object_id) As ObjectName,a.definition
from sys.sql_modules a
inner join sys.objects b on b.object_id=a.object_id
and b.is_ms_shipped=0
and not exists(select 1
from sys.extended_properties x
where x.major_id=b.object_id
and x.minor_id=0
and x.class=1
and x.name='microsoft_database_tools_support'
)
where b.type in('P','V','TR','FN','IF','TF')
and ( [email protected] or @Object='All')
and b.name <>'sp_EncryptObject'
and a.definition is not null
order by Case
when b.type ='V' then 1
when b.type ='TR' then 2
when b.type in('FN','IF','TF') then 3
else 4 end,b.create_date,b.object_id
open cur_Object
fetch next from cur_Object into @Object,@sql
while @@fetch_status=0
begin
Begin Try
if objectproperty(object_id(@Object),'ExecIsAfterTrigger')=0 set @Replace='As' ; else set @Replace='For ';
if (patindex('%' [email protected][email protected][email protected][email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@ [email protected][email protected][email protected][email protected],@[email protected]+'With Encryption'[email protected][email protected][email protected][email protected][email protected])
end
else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@[email protected][email protected],@C1+'With Encryption'[email protected][email protected][email protected])
end
else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@[email protected][email protected],@C2+'With Encryption'[email protected][email protected][email protected])
end
else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@[email protected][email protected],@C1+'With Encryption'[email protected][email protected][email protected])
end
else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@[email protected][email protected],@[email protected]+'With Encryption'[email protected][email protected][email protected])
end
else if(patindex('%'[email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@[email protected],@C1+'With Encryption'[email protected][email protected])
end
else if(patindex('%'[email protected][email protected]+'%',@sql)>0)
begin
set @sql=Replace(@sql,@[email protected],@C2+'With Encryption'[email protected][email protected])
end
set @type =
case
when object_id(@Object,'P')>0 then 'Proc'
when object_id(@Object,'V')>0 then 'View'
when object_id(@Object,'TR')>0 then 'Trigger'
when object_id(@Object,'FN')>0 or object_id(@Object,'IF')>0 or object_id(@Object,'TF')>0 then 'Function'
end
set @sql=Replace(@sql,'Create '[email protected],'Alter '[email protected])
Begin Transaction
exec(@sql)
print N'已完成加密物件('[email protected]+'):'[email protected]
Commit Transaction
End Try
Begin Catch
Declare @Error nvarchar(2047)
Set @Error='Object: '[email protected][email protected][email protected]+'Error: '+Error_message()
Rollback Transaction
print @Error
print @sql
End Catch
fetch next from cur_Object into @Object,@sql
end
close cur_Object
deallocate cur_Object
end
Go
exec sp_ms_marksystemobject 'sp_EncryptObject' --標識為系統物件
go
用於解密的儲存過程(sp_DecryptObject):
Use master
Go
if object_ID('[sp_DecryptObject]') is not null
Drop Procedure [sp_DecryptObject]
Go
create procedure sp_DecryptObject
(
@Object sysname, --要解密的物件名:函式,儲存過程,檢視或觸發器
@MaxLength int=4000 --評估內容的長度
)
as
set nocount on
/* 1. 解密 */
if not exists(select 1 from sys.objects a where a.object_id=object_id(@Object) And a.type in('P','V','TR','FN','IF','TF'))
begin
--SQL Server 2008
raiserror 50001 N'無效的物件!要解密的物件必須是函式,儲存過程,檢視或觸發器。'
--SQL Server 2012
--throw 50001, N'無效的物件!要解密的物件必須是函式,儲存過程,檢視或觸發器。',1
return
end
if exists(select 1 from sys.sql_modules a where a.object_id=object_id(@Object) and a.definition is not null)
begin
--SQL Server 2008
raiserror 50001 N'物件沒有加密!'
--SQL Server 2012
--throw 50001, N'無效的物件!要解密的物件必須是函式,儲存過程,檢視或觸發器。',1
return
end
declare @sql nvarchar(max) --解密出來的SQL語句
,@imageval nvarchar(max) --加密字串
,@tmpStr nvarchar(max) --臨時SQL語句
,@tmpStr_imageval nvarchar(max) --臨時SQL語句(加密後)
,@type char(2) --物件型別('P','V','TR','FN','IF','TF')
,@objectID int --物件ID
,@i int --While迴圈使用
,@Oject1 nvarchar(1000)
set @objectID=object_id(@Object)
set @type=(select a.type from sys.objects a where [email protected])
declare @Space4000 nchar(4000)
set @Space4000=replicate('-',4000)
/*
@tmpStr 會構造下面的SQL語句
-------------------------------------------------------------------------------
alter trigger Tr_Name on Table_Name with encryption for update as return /**/
alter proc Proc_Name with encryption as select 1 as col /**/
alter view View_Name with encryption as select 1 as col /**/
alter function Fn_Name() returns int with encryption as begin return(0) end/**/
*/
set @Oject1=quotename(object_schema_name(@objectID))+'.'+quotename(@Object)
set @tmpStr=
case
when @type ='P ' then N'Alter Procedure '[email protected]+' with encryption as select 1 as column1 '
when @type ='V ' then N'Alter View '[email protected]+' with encryption as select 1 as column1 '
when @type ='FN' then N'Alter Function '[email protected]+'() returns int with encryption as begin return(0) end '
when @type ='IF' then N'Alter Function '[email protected]+'() returns table with encryption as return(Select a.name from sys.types a) '
when @type ='TF' then N'Alter Function '[email protected]+'() returns @t table(name nvarchar(50)) with encryption as begin return end '
else 'Alter Trigger '[email protected]+'on '+quotename(object_schema_name(@objectID))+'.'+(select Top(1) quotename(object_name(parent_id)) from sys.triggers a where [email protected])+' with encryption for update as return '
end
set @[email protected]+'/*'[email protected]
set @i=0
while @i < (ceiling(@MaxLength*1.0/4000)-1)
begin
set @[email protected]+ @Space4000
Set @[email protected]+1
end
set @[email protected]+'*/'
------------
set @imageval =(select top(1) a.imageval from sys.sysobjvalues a where [email protected] and a.valclass=1)
begin tran
exec(@tmpStr)
set @tmpStr_imageval =(select top(1) a.imageval from sys.sysobjvalues a where [email protected] and a.valclass=1)
rollback tran
-------------
set @tmpStr=stuff(@tmpStr,1,5,'create')
set @sql=''
set @i=1
while @i<= (datalength(@imageval)/2)
begin
set @[email protected]+isnull(nchar(unicode(substring(@tmpStr,@i,1)) ^ unicode(substring(@tmpStr_imageval,@i,1))^unicode(substring(@imageval,@i,1)) ),'')
Set @i+=1
end
/* 2. 列印 */
declare @patindex int
while @sql>''
begin
set @patindex=patindex('%'+char(13)+char(10)+'%',@sql)
if @patindex >0
begin
print substring(@sql,1,@patindex-1)
set @sql=stuff(@sql,1,@patindex+1,'')
end
else
begin
set @patindex=patindex('%'+char(13)+'%',@sql)
if @patindex >0
begin
print substring(@sql,1,@patindex-1)
set @sql=stuff(@sql,1,@patindex,'')
end
else
begin
set @patindex=patindex('%'+char(10)+'%',@sql)
if @patindex >0
begin
print substring(@sql,1,@patindex-1)
set @sql=stuff(@sql,1,@patindex,'')
end
else
begin
print @sql
set @sql=''
end
end
end
end
Go
exec sp_ms_marksystemobject 'sp_DecryptObject' --標識為系統物件
go