Re: Performance of column level encryption
Posted in 2007
I have used Informix's encryption. Carsten is correct, using encryption you will incur some overhead. You really don't tell us much about your application. You say you have to encrypt a couple of columns but you don't really give us a use case or a rough example of your application. So its impossible to say how large of a performance hit you'll take. Relatively speaking, any database will have a performance hit due to encryption and depending on the algorithm, the amount of the hit will vary. Now if you want encryption but don't want to incur a performance hit, you could always go with a hardware based solution and then write a UDR to handle the encryption. Note that depending on the hardware, the cost ($$$$) and performance will vary. Plus you'll also have to deal with key management. Using IDS 10, I wrote a simple security app where I tracked user information and authentication passwords so I did field level encryption on the password column where the key was the password being stored. (Simple enough, and easy to maintain.) HTH -G >From: Carsten Haese <carsten@uniqsys.com> >>On Mon, 2007-07-30 at 22:33 +0000, mohitanchlia@gmail.com wrote: > > Version: IDS 10 > > > > We have need to encrypt few columns of the database. One of the > > options I looked at was encryption functions provided by informix. > > But, when I asked some of the consultant they told us that Informix > > has performance issues in using their encryption functions. They > > recommend to NOT use informix's encryption function. I wanted to know > > if this is the case, and if yes, then is it going to be improved in > > next versions of IDS. > >I haven't used column-level encryption myself yet, so please take the >following advice with a grain of salt. > >*ANY* encryption mechanism will impact performance, because you're >asking the computer to do more work than it would do without encryption. >If you must encrypt, you have no choice about incurring this performance >hit. Your only choice is whether this performance hit is incurred on the >client(s) or on the server, if client and server are actually physically >different computers. > >The advantage of doing encryption on the server is that the >functionality is built-in, and I would imagine that the smart guys over >in Lenexa are using state-of-the-art implementations of state-of-the-art >algorithms. I don't know if the same could be said for whatever you >choose to bolt on to the client side. (I can't help but wonder what your >consultant recommends instead.) The only advantage of doing the work >client-side is that the workload is distributed across multiple CPUs. > >I suggest you actually run performance tests of no encryption versus >server-side encryption versus client-side encryption. *If* you can't get >satisfactory performance, *then* ask for speedup suggestions. Until >then, anything else is pure speculation and premature optimization. > >Hope this helps, > >-- >Carsten Haese >http://informixdb.sourceforge.net > > >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ http://liveearth.msn.com