how do I protect/encrypt sensitive data in a database?

From: Date: Sun, 25 Jun 2000 01:57:11 +0000
Subject: how do I protect/encrypt sensitive data in a database?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-2941@lists.php.net to get a copy of this message
I want to write a stock option accounting system using mySQL, but a big problem I'm encountering from the start is how to make sure that NOBODY can know who's options are what and how many and all that. At first I figured I'd just do something like this: create an 'employee_table' with the ID being the primary key and a random 10 digit INT (so it's hard to guess -- similar to a bank account number) then I'd create another 'option_table' and that would store all info per a single option grant (date, number, price, notes, etc..) along with the ID mentioned above. That would give me a way of linking people and options together. However, I thought I could then just "ENCODE()" and "DECODE()" all the fields as I wrote/read them, but I notice in the docs (http://www.mysql.com/php/manual.php3?section=Miscellaneous_functions) that they work on strings only. So the problem becomes, how can I encrypt all the important fields of the database so that anyone, even root can't go in and start perusing/linking up who has what? Working with strings will sort of defeat the purpose of having fields -- no indexes, no specific function calls (like DATE stuff). Ideally, I'd like to encode all the fields with the user's password as the key (which is encrypted with PASSWORD()) since that's a one way encryption it'll work out good, then they can also change their password and I can 're-encode' all the data at that point as well. Another thing is that for now, I'll be using PHP and the web interface, but I may like to switch it over to a Java applet with JDBC once it's working, so the solution (again, ideally) should be as generic/portable as possible -- however beggars can't be choosers so for now I'll take what I can get until a better solution comes along. There has to be a secure way of doing this type of thing in a database right? How do people like E-Trade and Hospitals and stuff protect records of their customers/clients? daevid.com

« previous php.general (#2941) next »