Re: how do I protect/encrypt sensitive data in a database?
| From: | Julian Morcinek | Date: | Sun, 25 Jun 2000 10:28:49 +0000 |
| Subject: | Re: how do I protect/encrypt sensitive data in a database? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2965@lists.php.net to get a copy of this message | ||
Hi
You could use the native encryption calls in MySQL (checkout www.mysql.com).
I believe (but not certain!) you need the crypt() system function in place
on the host - so MySQL needs to be installed on a Unix box.
From the manual:
ENCODE(str,pass_str)
Encrypt str using pass_str as the password. To decrypt the result, use
DECODE(). The results is a binary string. If you want to save it in a
column, use a BLOB column type.
DECODE(crypt_str,pass_str)
Descrypts the encrypted string crypt_str using pass_str as the password.
crypt_str should be a string returned from ENCODE().
Cheers
Julian
----- Original Message -----
From: "Daevid Vincent" <DayWalker@TheMatrix.com>
To: <php-general@lists.php.net>
Sent: Sunday, June 25, 2000 2:57 AM
Subject: [PHP-GENERAL] how do I protect/encrypt sensitive data in a
database?
> I want to write a stock option accounting system using mySQL, but a big
> problem I'm encountering from the start is how to make sure that NOBODY
can
> know who's options are what and how many and all that.
>
> At first I figured I'd just do something like this:
> create an 'employee_table' with the ID being the primary key and a random
10
> digit INT (so it's hard to guess -- similar to a bank account number) then
> I'd create another 'option_table' and that would store all info per a
single
> option grant (date, number, price, notes, etc..) along with the ID
mentioned
> above.
>
> That would give me a way of linking people and options together. However,
I
> thought I could then just "ENCODE()" and "DECODE()" all the fields as I
> wrote/read them, but I notice in the docs
> (http://www.mysql.com/php/manual.php3?section=Miscellaneous_functions)
that
> they work on strings only.
>
> So the problem becomes, how can I encrypt all the important fields of the
> database so that anyone, even root can't go in and start perusing/linking
up
> who has what? Working with strings will sort of defeat the purpose of
having
> fields -- no indexes, no specific function calls (like DATE stuff).
>
> Ideally, I'd like to encode all the fields with the user's password as the
> key (which is encrypted with PASSWORD()) since that's a one way encryption
> it'll work out good, then they can also change their password and I can
> 're-encode' all the data at that point as well.
>
> Another thing is that for now, I'll be using PHP and the web interface,
but
> I may like to switch it over to a Java applet with JDBC once it's working,
> so the solution (again, ideally) should be as generic/portable as
> possible -- however beggars can't be choosers so for now I'll take what I
> can get until a better solution comes along.
>
> There has to be a secure way of doing this type of thing in a database
> right? How do people like E-Trade and Hospitals and stuff protect records
of
> their customers/clients?
>
> daevid.com
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>