Encryption
Posted in 2014
Mark asked whether Informix 11.70/12.x can do whole-table encryption, as a bank client wanted it; he believed only column-level encryption existed. Respondents confirmed that: Informix encryption is column-level only, with drawbacks (application must manage keys, encrypted values can silently expand and corrupt data in non-ANSI databases, and encrypted columns can't be usefully indexed since the same value encrypts differently each time). The recommended answer was transparent data-at-rest encryption via IBM Guardium Encryption Expert (from Vormetric), which encrypts files/devices at the OS level with no database or application changes — put the table in its own dbspace and encrypt those files. It reportedly has no Informix version restrictions (unlike Guardium activity monitoring, which has version caveats).
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Security, Permissions & Auditing
anyone able to provide a quick breakdown of encryption in versions 11.70 and 12.x ? Our client is looking for complete "table level" encryption; to the best of my knowledge IDS only supports encryption at the column level. Thanks, Mark
What do they mean by table level encryption? Are they aware of all the consequences of encrypting lots of data? -- Regards Spokey > On 21 Aug 2014, at 16:41, "MARK JALKIEWICZ" <mark.jalkiewicz@verizon.net> wrote: > > anyone able to provide a quick breakdown of encryption in versions 11.70 and > 12.x ? > > Our client is looking for complete "table level" encryption; to the best of my > knowledge IDS only supports encryption at the column level. > > Thanks, > > Mark > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
it's a bank, a major one at that. Paranoia trumps all. Mark
Would Data At Rest encryption satisfy the requirement? Encrypting an entire table would render it near unusable. -- Regards Spokey > On 21 Aug 2014, at 16:51, "MARK JALKIEWICZ" <mark.jalkiewicz@verizon.net> wrote: > > it's a bank, a major one at that. Paranoia trumps all. > > Mark > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Been there... usually in the end they give it up and use "risk mitigating
measures" as they are called in PCI and other regulations. Let's see...
Informix as you say can only encrypt data at column level and that has some
issues:
1- You need the application to handle the key (unless you do very weird
things like obtaining the key from a keystore using some Java inside a
sysdbopen() procedure that validates the origin etc.). But to be more
secure, the application would have to do that, and many times that "can't
be changed"
2- We have a terrible problem... because the encryption may (and will)
"enlarge" the data in a manner that isn't 100% known at definition time,
and because we INSERT anyway without error in non ANSI databases, we may
end up corrupting data... and being encrypted it becomes 100% useless...
There are feature request to allow this behavior change, but either our
customers don't care, or they don't shout loud enough... This should be a
trivial fix as we already do it for ANSI databases
3- The encrypted columns can't be indexed.... I've been told this doesn't
happen for example on DB2 on z/OS, because value X encrypted using key Y
will always give value Z. So if you just want to use equality matches you
can encrypt X and search for Z... this will use an index on Z. But in
Informix a value X encrypted with key Y will give value Z now, Z1 the next
time and so on...
IBM resells a wonderful product for transparent data encryption. We call it
Guardium Encryption Expert.... originally it's from a company called
Vormetric. It's not expensive and works at the OS level.... it works with
raw devices and cooked files. It has an option for integration with
database (db2 and Informix at least) backup utilities.
This will encrypt the datafiles in a transparent way for the (authorized)
layers. The authorization is provided to a process/user/timeframe mask...
"informix using oninit..."
It makes sure the data can only be accessd through the "natural" means. It
does not prevent against DBA abuse, but you have native audit (or Guardium
DAM) for that.
The product is very easy to use, and as far as I'm told, has very little
overhead in the latest versions (some is explected of course).
if you just want to encrypt a table put it on a specific dbspace and
encrypt just those datafiles. No changes in the database or application.
For informix encryption, if you want to do it transparently.... you need
the application to set the encryption password at the session level and
then mess around with views... and triggers. But you're going to meet the
issues above.
HTH
Regards
On Thu, Aug 21, 2014 at 4:51 PM, MARK JALKIEWICZ <
mark.jalkiewicz@verizon.net> wrote:
> it's a bank, a major one at that. Paranoia trumps all.
>
> Mark
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--20cf303bf57636d42905012714cb
Fernando, Regarding Guardium , are there any restrictions on the IDS version? All I can find on the web shows Gaurdium as an "add on" option for Version 12.x We are either thinking about staying with the current version (11.50.FC8) until we upgrade to 11.70/12.x sometimes within the next year. Many thanks, Mark
No... "This" Guardium doesn't care about the layers above.... it's absolutely transparent to either the database or the filesystems... And the "other" Guardium, which is used for DAM - Database Activity Monitoring it supports all current supported versions of Informix (although in some configurations you'll need Guardium V9.1 (if you use IDS 11.7.FC5 (I think) or above... The breaking piece is the maximum SQL statement size change we did... in some platforms (big/little endian?) it breaks the protocol analyzer inside guardium, leading it to think our SQL packets have 0 bytes :) Regards. On Thu, Aug 21, 2014 at 7:06 PM, MARK JALKIEWICZ < mark.jalkiewicz@verizon.net> wrote: > Fernando, > > Regarding Guardium , are there any restrictions on the IDS version? All I > can > find on the web shows Gaurdium as an "add on" option for Version 12.x We > are > either thinking about staying with the current version (11.50.FC8) until we > upgrade to 11.70/12.x sometimes within the next year. > > Many thanks, > > Mark > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a11c2d676a0634f0501288124
Fernando, Once again , thanks. Mark
No restrictions for guardian encryption Sent from my iPhone > On Aug 21, 2014, at 1:06 PM, MARK JALKIEWICZ <mark.jalkiewicz@verizon.net>= wrote: >=20 > Fernando,=20 >=20 > Regarding Guardium , are there any restrictions on the IDS version? All I c= an=20 > find on the web shows Gaurdium as an "add on" option for Version 12.x We a= re=20 > either thinking about staying with the current version (11.50.FC8) until w= e=20 > upgrade to 11.70/12.x sometimes within the next year.=20 >=20 > Many thanks,=20 >=20 > Mark=20 >=20 >=20 > **************************************************************************= *****=20 > Forum Note: Use "Reply" to post a response in the discussion forum.=20 >=20