Field-level encryption: choosing the layer that has to hold
Encryption at rest protects the storage medium. It does not protect the running application, and it does not limit which records a compromised service account can read. Field-level encryption moves the protection boundary upward: selected values are encrypted before they reach the database, so a dump of the table shows ciphertext for those columns only.
Envelope encryption in practice
The standard pattern uses a data encryption key (DEK) to encrypt each record and a key encryption key (KEK) held in a key management service to wrap that DEK. NIST SP 800-57 Part 1 Revision 5 describes the key states and cryptoperiods that keep this scheme manageable, including the point at which a key must be retired. Storing the wrapped DEK beside the ciphertext lets the application decrypt one record without holding a master key for the whole process lifetime.
What breaks first
- Search. Ciphertext cannot be compared for equality or ordered without leakage. Deterministic encryption allows equality lookups and leaks frequency; order-revealing encryption leaks ordering. Both are deliberate trade-offs that belong in the design document.
- Indexes. A column encrypted in the application cannot use the database's index for range queries. The usual answers are a blind index over a normalised value, or moving the query to a service that holds the keys.
- Key custody. Application-level encryption does not stop a live SQL injection from reading decrypted values, because the process that answers the query also holds the key material.
- Rotation. Rotating the KEK is cheap when only wrapped DEKs are rewritten. Rotating a DEK requires re-encryption or a key-version field on every record.
Choosing the layer
Encrypt at the layer that owns the trust boundary. When the database administrator sits outside the trust boundary, application-level encryption is the only control that helps. When the threat is a stolen disk or a lost backup tape, the storage layer is enough and far cheaper. Record which attacker the control excludes. A control whose excluded attacker is not written down tends to be described later as covering more than it does.
References
- NIST SP 800-57 Part 1 Revision 5, Recommendation for Key Management
- NIST SP 800-38D, Recommendation for Block Cipher Modes of Operation: GCM and GMAC
- NIST SP 800-38G, Recommendation for Block Cipher Modes of Operation: Format-Preserving Encryption
- OWASP Cryptographic Storage Cheat Sheet
Top comments (0)