DEV Community

StarkMan
StarkMan

Posted on

Field-level encryption: choosing the layer that has to hold

Field-level encryption: choosing the layer that has to hold

Encryption at rest protects the storage medium. It does not protect the running application, and it does not limit which records a compromised service account can read. Field-level encryption moves the protection boundary upward: selected values are encrypted before they reach the database, so a dump of the table shows ciphertext for those columns only.

Envelope encryption in practice

The standard pattern uses a data encryption key (DEK) to encrypt each record and a key encryption key (KEK) held in a key management service to wrap that DEK. NIST SP 800-57 Part 1 Revision 5 describes the key states and cryptoperiods that keep this scheme manageable, including the point at which a key must be retired. Storing the wrapped DEK beside the ciphertext lets the application decrypt one record without holding a master key for the whole process lifetime.

What breaks first

  • Search. Ciphertext cannot be compared for equality or ordered without leakage. Deterministic encryption allows equality lookups and leaks frequency; order-revealing encryption leaks ordering. Both are deliberate trade-offs that belong in the design document.
  • Indexes. A column encrypted in the application cannot use the database's index for range queries. The usual answers are a blind index over a normalised value, or moving the query to a service that holds the keys.
  • Key custody. Application-level encryption does not stop a live SQL injection from reading decrypted values, because the process that answers the query also holds the key material.
  • Rotation. Rotating the KEK is cheap when only wrapped DEKs are rewritten. Rotating a DEK requires re-encryption or a key-version field on every record.

Choosing the layer

Encrypt at the layer that owns the trust boundary. When the database administrator sits outside the trust boundary, application-level encryption is the only control that helps. When the threat is a stolen disk or a lost backup tape, the storage layer is enough and far cheaper. Record which attacker the control excludes. A control whose excluded attacker is not written down tends to be described later as covering more than it does.

References

  • NIST SP 800-57 Part 1 Revision 5, Recommendation for Key Management
  • NIST SP 800-38D, Recommendation for Block Cipher Modes of Operation: GCM and GMAC
  • NIST SP 800-38G, Recommendation for Block Cipher Modes of Operation: Format-Preserving Encryption
  • OWASP Cryptographic Storage Cheat Sheet

Top comments (0)