Re: how do I protect/encrypt sensitive data in a database?

From: Date: Sun, 25 Jun 2000 10:28:49 +0000
Subject: Re: how do I protect/encrypt sensitive data in a database?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-2965@lists.php.net to get a copy of this message
Hi You could use the native encryption calls in MySQL (checkout www.mysql.com). I believe (but not certain!) you need the crypt() system function in place on the host - so MySQL needs to be installed on a Unix box. From the manual: ENCODE(str,pass_str) Encrypt str using pass_str as the password. To decrypt the result, use DECODE(). The results is a binary string. If you want to save it in a column, use a BLOB column type. DECODE(crypt_str,pass_str) Descrypts the encrypted string crypt_str using pass_str as the password. crypt_str should be a string returned from ENCODE(). Cheers Julian ----- Original Message ----- From: "Daevid Vincent" <DayWalker@TheMatrix.com> To: <php-general@lists.php.net> Sent: Sunday, June 25, 2000 2:57 AM Subject: [PHP-GENERAL] how do I protect/encrypt sensitive data in a database? > I want to write a stock option accounting system using mySQL, but a big > problem I'm encountering from the start is how to make sure that NOBODY can > know who's options are what and how many and all that. > > At first I figured I'd just do something like this: > create an 'employee_table' with the ID being the primary key and a random 10 > digit INT (so it's hard to guess -- similar to a bank account number) then > I'd create another 'option_table' and that would store all info per a single > option grant (date, number, price, notes, etc..) along with the ID mentioned > above. > > That would give me a way of linking people and options together. However, I > thought I could then just "ENCODE()" and "DECODE()" all the fields as I > wrote/read them, but I notice in the docs > (http://www.mysql.com/php/manual.php3?section=Miscellaneous_functions) that > they work on strings only. > > So the problem becomes, how can I encrypt all the important fields of the > database so that anyone, even root can't go in and start perusing/linking up > who has what? Working with strings will sort of defeat the purpose of having > fields -- no indexes, no specific function calls (like DATE stuff). > > Ideally, I'd like to encode all the fields with the user's password as the > key (which is encrypted with PASSWORD()) since that's a one way encryption > it'll work out good, then they can also change their password and I can > 're-encode' all the data at that point as well. > > Another thing is that for now, I'll be using PHP and the web interface, but > I may like to switch it over to a Java applet with JDBC once it's working, > so the solution (again, ideally) should be as generic/portable as > possible -- however beggars can't be choosers so for now I'll take what I > can get until a better solution comes along. > > There has to be a secure way of doing this type of thing in a database > right? How do people like E-Trade and Hospitals and stuff protect records of > their customers/clients? > > daevid.com > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#2965) next »