Re: Database Encryption
Posted in 2006
Topics: Performance & Tuning, Security, Permissions & Auditing
"Obnoxio The Clown" <obnoxio@serendipita.com> wrote in message news:mailman.395.1151597436.19084.informix-list@iiug.org... > > Campbell, John \\(GE Cons Fin\\) said: >> Any impact to performance? > > Yes, plus it makes indexing pointless (on encrypted columns). Why?
Neil Truby said: > > "Obnoxio The Clown" <obnoxio@serendipita.com> wrote in message > news:mailman.395.1151597436.19084.informix-list@iiug.org... >> >> Campbell, John \\(GE Cons Fin\\) said: >>> Any impact to performance? >> >> Yes, plus it makes indexing pointless (on encrypted columns). > > Why? Do you know anything about encryption? :o) -- Bye now, Obnoxio "... no bill is required as no value was provided." -- Christine Normile
Neil Truby wrote: > "Obnoxio The Clown" <obnoxio@serendipita.com> wrote in message > news:mailman.395.1151597436.19084.informix-list@iiug.org... >> Campbell, John \\(GE Cons Fin\\) said: >>> Any impact to performance? >> Yes, plus it makes indexing pointless (on encrypted columns). > > Why? > > Neil, Encryption uses a key which is not part of the actually encrypted data, but which is used to transform the bits in the encrypted value of the plain-text representation of the data. For the same data if you use a different key, then you get different encrypted values. Indexes are used for great than and less than as well as equality. You can never use encrypted columns for less than or greater than on the encrypted data itself. You can use equality on the encrypted data, but only if the same key is used to encrypt all of the data. If you are using the same key to encrypt all of the data, then why encrypt?