Issues in Data Encryption
Posted in 2011
Topics: Security, Permissions & Auditing
Hi I am encrypting data of a field. The encryption functions always returns different output against same data and same key. I mean whenever i execute the encryption function for some specific data , it always returns a different output during each execution, where as the data and key that i use in the encryption function is same during each execution. If I run the encryption function thrice with same data and key, in these three executions, the output for each execution will be different each time. Is there any way that the encryption function returns same output during each execution ? Is there any method available in informix to secure the encryption key for security purposes.
On Mon, May 30, 2011 at 10:08, ANEES AHMAD <aanees@i2cinc.com> wrote: > I am encrypting data of a field. The encryption functions always returns > different output against same data and same key. I mean whenever i execute > the > encryption function for some specific data , it always returns a different > output during each execution, where as the data and key that i use in the > encryption function is same during each execution. If I run the encryption > function thrice with same data and key, in these three executions, the > output > for each execution will be different each time. > > Is there any way that the encryption function returns same output during > each > execution? > It would be a big bug if ENCRYPT_AES() or ENCRYPT_TDES() did return the same value twice. They are intentionally designed to be the ultimate in 'variant procedures' -- same inputs, different outputs each time. If you start getting duplicates significantly before 2**56 repeats of the same inputs, please let me know. The source of the variability is a random IV or initialization vector. It is designed to ensure that you cannot casually tell whether the same information is encrypted several times > Is there any method available in informix to secure the encryption key for > security purposes. > What are your requirements? Yes, there are ways. No, they are not necessarily easy. Ultimately, AFAICT, it always comes back to 'how do you protect one master key'. Protecting the keys is fearsomely difficult; the majority of problems with encrypted information being retrieved by the unauthorized arise because the keys were not adequately protected. -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." --0016e647630670dda304a489c445