1. 程式人生 > >MSSQL 2008、2012儲存過程加密解密

MSSQL 2008、2012儲存過程加密解密

1. 必須在DAC連線SQL Server

不然會報錯:

訊息 208,級別 16,狀態 1,過程 sp_DecryptObject,第 75 行
物件名 'sys.sysobjvalues' 無效。

2. 建立加(解)密過程儲存過程

3. 執行儲存過程

 

用於加密的儲存過程 (sp_EncryptObject) :

Use master
Go
if object_ID('[sp_EncryptObject]') is not null
    Drop Procedure [sp_EncryptObject]
Go
create procedure sp_EncryptObject 
(
    @Object sysname='All'
)
as
/*
    當@Object=All的時候,對所有的函式,儲存過程,檢視和觸發器進行加密
    呼叫方法:
    1. Execute sp_EncryptObject 'All'
    2. Execute sp_EncryptObject 'ObjectName'
*/
begin
    set nocount on
    
    if @Object <>'All'
    begin
        if not exists(select 1 from sys.objects a where a.object_id=object_id(@Object) And a.type in('P','V','TR','FN','IF','TF'))
        begin
            --SQL Server 2008
            raiserror 50001 N'無效的加密物件!加密物件必須是函式,儲存過程,檢視或觸發器。'

            --SQL Server 2012
            --throw 50001, N'無效的加密物件!加密物件必須是函式,儲存過程,檢視或觸發器。',1 

            return
        end
        
        if exists(select 1 from sys.sql_modules a where a.object_id=object_id(@Object) and a.definition is null)
        begin
            --SQL Server 2008
            raiserror 50001 N'物件已經加密!'

            --SQL Server 2012
            --throw 50001, N'物件已經加密!',1  
            return
        end
    end
    
    declare @sql nvarchar(max),@C1 nchar(1),@C2 nchar(1),@type nvarchar(50),@Replace nvarchar(50)
    set @C1=nchar(13)
    set @C2=nchar(10)
    
    
    declare cur_Object 
        cursor for 
            select object_name(a.object_id) As ObjectName,a.definition 
                from sys.sql_modules a  
                    inner join sys.objects b on b.object_id=a.object_id
                        and b.is_ms_shipped=0
                        and not exists(select 1 
                                            from sys.extended_properties x
                                            where x.major_id=b.object_id
                                                and x.minor_id=0
                                                and x.class=1
                                                and x.name='microsoft_database_tools_support'
                                        )
                where b.type in('P','V','TR','FN','IF','TF')
                    and (
[email protected]
 or @Object='All')                     and b.name <>'sp_EncryptObject'                     and a.definition is not null                                     order by Case                              when b.type ='V' then 1                              when b.type ='TR' then 2                             when b.type in('FN','IF','TF') then 3                              else 4 end,b.create_date,b.object_id                      open cur_Object     fetch next from cur_Object into @Object,@sql     while @@fetch_status=0     begin                  Begin Try                                   if objectproperty(object_id(@Object),'ExecIsAfterTrigger')=0 set @Replace='As' ; else set @Replace='For ';                              if (patindex('%'
[email protected]
[email protected][email protected][email protected][email protected]+'%',@sql)>0)             begin                 set @sql=Replace(@sql,@
[email protected]
[email protected][email protected][email protected],@[email protected]+'With Encryption'[email protected][email protected][email protected][email protected][email protected])             end             else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)             begin                  set @sql=Replace(@sql,@[email protected][email protected],@C1+'With Encryption'[email protected][email protected][email protected])             end             else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)             begin                  set @sql=Replace(@sql,@[email protected][email protected],@C2+'With Encryption'[email protected][email protected][email protected])             end             else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)             begin                  set @sql=Replace(@sql,@[email protected][email protected],@C1+'With Encryption'[email protected][email protected][email protected])             end             else if(patindex('%'[email protected][email protected][email protected]+'%',@sql)>0)             begin                  set @sql=Replace(@sql,@[email protected][email protected],@[email protected]+'With Encryption'[email protected][email protected][email protected])             end             else if(patindex('%'[email protected][email protected]+'%',@sql)>0)             begin                  set @sql=Replace(@sql,@[email protected],@C1+'With Encryption'[email protected][email protected])             end             else if(patindex('%'[email protected][email protected]+'%',@sql)>0)             begin                  set @sql=Replace(@sql,@[email protected],@C2+'With Encryption'[email protected][email protected])             end                                  set @type =                 case                      when object_id(@Object,'P')>0 then 'Proc'                     when object_id(@Object,'V')>0 then 'View'                     when object_id(@Object,'TR')>0  then 'Trigger'                     when object_id(@Object,'FN')>0 or object_id(@Object,'IF')>0 or object_id(@Object,'TF')>0 then 'Function'                 end             set @sql=Replace(@sql,'Create '[email protected],'Alter '[email protected])                          Begin Transaction             exec(@sql)                         print N'已完成加密物件('[email protected]+'):'[email protected]                         Commit Transaction                      End Try         Begin Catch             Declare @Error nvarchar(2047)             Set @Error='Object: '[email protected][email protected][email protected]+'Error: '+Error_message()             Rollback Transaction                       print @Error             print @sql            End Catch                              fetch next from cur_Object into @Object,@sql              end          close cur_Object     deallocate cur_Object         end   Go exec sp_ms_marksystemobject 'sp_EncryptObject' --標識為系統物件 go

 

用於解密的儲存過程(sp_DecryptObject):

Use master
Go
if object_ID('[sp_DecryptObject]') is not null
    Drop Procedure [sp_DecryptObject]
Go
create procedure sp_DecryptObject 
(
    @Object sysname,    --要解密的物件名:函式,儲存過程,檢視或觸發器
    @MaxLength int=4000 --評估內容的長度
)
as
set nocount on
/* 1. 解密 */
 
if not exists(select 1 from sys.objects a where a.object_id=object_id(@Object) And a.type in('P','V','TR','FN','IF','TF'))
begin
    --SQL Server 2008
    raiserror 50001 N'無效的物件!要解密的物件必須是函式,儲存過程,檢視或觸發器。'

    --SQL Server 2012
    --throw 50001, N'無效的物件!要解密的物件必須是函式,儲存過程,檢視或觸發器。',1   
    return
end
 
if exists(select 1 from sys.sql_modules a where a.object_id=object_id(@Object) and a.definition is not null)
begin
    --SQL Server 2008
    raiserror 50001 N'物件沒有加密!'

    --SQL Server 2012
    --throw 50001, N'無效的物件!要解密的物件必須是函式,儲存過程,檢視或觸發器。',1 
    return
end
 
declare  @sql nvarchar(max)                --解密出來的SQL語句
        ,@imageval nvarchar(max)        --加密字串
        ,@tmpStr nvarchar(max)            --臨時SQL語句
        ,@tmpStr_imageval nvarchar(max) --臨時SQL語句(加密後)
        ,@type char(2)                    --物件型別('P','V','TR','FN','IF','TF')
        ,@objectID int                    --物件ID
        ,@i int                            --While迴圈使用
        ,@Oject1 nvarchar(1000)
 
set @objectID=object_id(@Object)
set @type=(select a.type from sys.objects a where [email protected])
 
declare @Space4000 nchar(4000)
set @Space4000=replicate('-',4000)
 
/*
@tmpStr 會構造下面的SQL語句
-------------------------------------------------------------------------------
alter trigger Tr_Name on Table_Name with encryption for update as return /**/
alter proc Proc_Name with encryption  as select 1 as col /**/
alter view View_Name with encryption as select 1 as col /**/
alter function Fn_Name() returns int with encryption as begin return(0) end/**/
*/
set @Oject1=quotename(object_schema_name(@objectID))+'.'+quotename(@Object)
set @tmpStr=
        case     
            when @type ='P ' then N'Alter Procedure '[email protected]+' with encryption as select 1 as column1 '
            when @type ='V ' then N'Alter View '[email protected]+' with encryption as select 1 as column1 '
            when @type ='FN' then N'Alter Function '[email protected]+'() returns int with encryption as begin return(0) end '
            when @type ='IF' then N'Alter Function '[email protected]+'() returns table with encryption as return(Select a.name from sys.types a) '
            when @type ='TF' then N'Alter Function '[email protected]+'() returns @t table(name nvarchar(50)) with encryption as begin return end '
            else 'Alter Trigger '[email protected]+'on '+quotename(object_schema_name(@objectID))+'.'+(select Top(1) quotename(object_name(parent_id)) from sys.triggers a where [email protected])+' with encryption for update as return ' 
        end        
 
    
set @[email protected]+'/*'[email protected]
set @i=0
while @i < (ceiling(@MaxLength*1.0/4000)-1)
begin
    set @[email protected]+ @Space4000
    Set @[email protected]+1
end
set @[email protected]+'*/'
 
------------
set @imageval =(select top(1) a.imageval from sys.sysobjvalues a where [email protected] and a.valclass=1)
 
begin tran
exec(@tmpStr)
set @tmpStr_imageval =(select top(1) a.imageval from sys.sysobjvalues a where [email protected] and a.valclass=1)
 
rollback tran
 
-------------
set @tmpStr=stuff(@tmpStr,1,5,'create')
set @sql=''
set @i=1
while @i<= (datalength(@imageval)/2)
begin
    set @[email protected]+isnull(nchar(unicode(substring(@tmpStr,@i,1)) ^ unicode(substring(@tmpStr_imageval,@i,1))^unicode(substring(@imageval,@i,1)) ),'')
    Set @i+=1
end
 
/* 2. 列印 */
 
 
declare @patindex int    
while @sql>''
begin
    
    set @patindex=patindex('%'+char(13)+char(10)+'%',@sql)
    if @patindex >0
    begin
        print substring(@sql,1,@patindex-1)
        set @sql=stuff(@sql,1,@patindex+1,'')
    end    
    else 
    begin
        set @patindex=patindex('%'+char(13)+'%',@sql)
        if @patindex >0
        begin
            print substring(@sql,1,@patindex-1)
            set @sql=stuff(@sql,1,@patindex,'')
        end
        else
        begin
            set @patindex=patindex('%'+char(10)+'%',@sql)
            if @patindex >0
            begin
                print substring(@sql,1,@patindex-1)
                set @sql=stuff(@sql,1,@patindex,'')
            end        
            else
            begin
                print @sql
                set @sql=''
            end    
        end        
    end
        
end
 
Go
exec sp_ms_marksystemobject 'sp_DecryptObject' --標識為系統物件
go