how do I protect/encrypt sensitive data in a database?
| From: | Daevid Vincent | Date: | Sun, 25 Jun 2000 01:57:11 +0000 |
| Subject: | how do I protect/encrypt sensitive data in a database? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2941@lists.php.net to get a copy of this message | ||
I want to write a stock option accounting system using mySQL, but a big
problem I'm encountering from the start is how to make sure that NOBODY can
know who's options are what and how many and all that.
At first I figured I'd just do something like this:
create an 'employee_table' with the ID being the primary key and a random 10
digit INT (so it's hard to guess -- similar to a bank account number) then
I'd create another 'option_table' and that would store all info per a single
option grant (date, number, price, notes, etc..) along with the ID mentioned
above.
That would give me a way of linking people and options together. However, I
thought I could then just "ENCODE()" and "DECODE()" all the fields as I
wrote/read them, but I notice in the docs
(http://www.mysql.com/php/manual.php3?section=Miscellaneous_functions) that
they work on strings only.
So the problem becomes, how can I encrypt all the important fields of the
database so that anyone, even root can't go in and start perusing/linking up
who has what? Working with strings will sort of defeat the purpose of having
fields -- no indexes, no specific function calls (like DATE stuff).
Ideally, I'd like to encode all the fields with the user's password as the
key (which is encrypted with PASSWORD()) since that's a one way encryption
it'll work out good, then they can also change their password and I can
're-encode' all the data at that point as well.
Another thing is that for now, I'll be using PHP and the web interface, but
I may like to switch it over to a Java applet with JDBC once it's working,
so the solution (again, ideally) should be as generic/portable as
possible -- however beggars can't be choosers so for now I'll take what I
can get until a better solution comes along.
There has to be a secure way of doing this type of thing in a database
right? How do people like E-Trade and Hospitals and stuff protect records of
their customers/clients?
daevid.com