in reply to Cryptology in the database
There are plenty of articles on database encryption, e.g. Encrypting Data Values in DB2 Universal Database (ibm.com/developerworks) which describes using Column level encryption in the DB2 database. While an interesting read, the article does not touch on key management. The question of where do we store the keys remain unanswered.
I recommend reading the Payment Card Industry Data Security Standard Specification (pcisecuritystandards.org). The PCI DSS Specification outlines a series of principles on how financial institutions are to protect financial data (credit card details etc). Again, there is no definitive implementation, but some of the ideas behind it are interesting (from section 3):
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Cryptology in the database
by patspam (Sexton) on Mar 31, 2008 at 07:01 UTC | |
by ikegami (Patriarch) on Mar 31, 2008 at 07:37 UTC | |
by patspam (Sexton) on Mar 31, 2008 at 09:08 UTC | |
by andreas1234567 (Vicar) on Mar 31, 2008 at 10:28 UTC | |
by jsegal (Friar) on Mar 31, 2008 at 23:23 UTC | |
by andreas1234567 (Vicar) on Mar 31, 2008 at 07:41 UTC | |
by patspam (Sexton) on Mar 31, 2008 at 09:15 UTC | |
by andreas1234567 (Vicar) on Mar 31, 2008 at 12:48 UTC | |
|
Re^2: Cryptology in the database
by stiller (Friar) on Mar 31, 2008 at 08:05 UTC | |
by andreas1234567 (Vicar) on Mar 31, 2008 at 08:21 UTC |