Field-level encryption: choosing the layer that has to hold
Field-level encryption: choosing the layer that has to hold Encryption at rest protects the storage medium. It does not protect the running application, and it does not limit which records a compromised service account can read. Field-level encryption moves the protection boundary upward: selected values are encrypted before they reach the database, so a dump of the table shows ciphertext for those columns only. The standard pattern uses a data encryption key (DEK) to encrypt each record and a key encryption key (KEK) held in a key management service to wrap that DEK. NIST SP 800-57 Part 1 Rev
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in