Re: Column Encryption
Posted in 1995
> Subject: Column Encryption > Date: 27 Jan 1995 04:53:35 GMT > Reply-To: Michael L. Gonzales <76543.2600@CompuServe.COM> > Organization: The Focus Group, Ltd. > > I need a method to take entered data (passwords), encrypt the > value, and store the value in a column. Obviously, I would need > to decipher the stored value for future validations. The purpose > of this is to merely keep any individual from scanning the > database for passwords. > > Any recommendations on encrypting data? > > Mike. Within the past couple of weeks, someone posted a very nice encryption / decryption routine to c.d.i. I saved it somewhere; now if I could only find it! However, I consider it poor security to store passwords in a format that can be deciphered. For password verification it is enough, and better security, to encrypt the newly entered password and then compare the encrypted form to the stored encrypted form. This is in contrast to your suggestion of deciphering the stored password and comparing the passwords in clear-text format. I have used variations on the following password encryption algorithm in several languages: DEFINE cypher INTEGER { other definitions as needed } LET cypher = 0 FOR j = 1 to LENGTH ( password_text ) LET cypher = cypher * 7 + ord ( password_text[j] ) + 3 IF cypher > 32767 THEN { these three lines are optional } LET cypher = cypher - 32767 END IF END FOR Especially with the optional lines, this is a "lossy" algorithm, meaning that information is lost, so that encrypted values cannot be decrypted uniquely. The chance of two different passwords colliding to the same encrypted value and giving a false validation can be reduced by increasing 32767 to some larger value. A disadvantage to doing this in 4GL is that 4GL does not have an ord function. However, I include one below for your use. Regards, Alan ___________________________ ______________________| R. Alan Popiel |__________________________ \\ Internet: | Martin Marietta, SLS | / \\ alan@den.mmc.com | P.O. Box 179, M/S 3810 | Std disclaimers apply. / )Voice: | Denver, CO 80201-0179 USA | ( / 303-977-9998 |___________________________| (But you knew that!) \\ /________________________) (____________________________\\ ----------- begin included source code --------------- /* function: ord - return numeric ASCII code for character * author: Alan Popiel * date: 27 Oct 1993 * * ord() returns the numeric value of the ASCII code for the first character * of the string passed to it by an Informix 4GL routine. * * usage: * CALL ord(str) RETURNING number * LET number = ord(str) * * CALL argument: * str -- 4GL character string, normally of length 1. If length is greater * than 1, the the code for the first character is returned. * * RETURNING argument: * integer number -- numeric value of the ASCII code; * Note: negative values are returned for ASCII codes > 127. To fix this: * IF number < 0 THEN * LET number = number + 256 * END IF */ int ord(nargs) int nargs; { char str[513]; /* Input from stack: Allow for long strings. */ /* Pop calling argument from the stack. */ popquote( str, sizeof(str) ); /* Push return argument to the stack. */ retint( (unsigned)str[0] ); /* ASCII code of first character. */ return(1); /* Number of arguments pushed. */ } ------------ end included source code ----------------