On-Demand Encryption of Data
You can use the DBMS_CRYPTO PL/SQL package to perform on-demand encryption of data.
-
About On-Demand Encryption of Data
To perform on-demand encryption of data, you use theDBMS_CRYPTOPL/SQL package. -
Security Problems That Encryption Does Not Solve
While there are many good reasons to encrypt data, there are many reasons not to encrypt data. -
Data Encryption Challenges
In cases where encryption can provide additional security, there are some associated technical challenges. -
Data Encryption Storage with the DBMS_CRYPTO Package
TheDBMS_CRYPTOpackage enables you to perform on-demand encryption and decryption of stored data. -
Asymmetric Key Operations with the DBMS_CRYPTO Package
TheDBMS_CRYPTOpackage provides four functions that enable you to perform asymmetric key operations for encryption, decryption, signing, and verification. -
Examples of Using the Data Encryption API
Examples of using the data encryption API include using theDBMS_CRYPTO.SQLprocedure, encrypting AES 256-bit data, and encrypting BLOB data.
About On-Demand Encryption of Data
To perform on-demand encryption of data, you use the DBMS_CRYPTO PL/SQL package.
This package enables you to encrypt and decrypt stored data. You can use the DBMS_CRYPTO functions and procedures with PL/SQL programs that run network communications. This package supports industry-standard encryption and hashing algorithms, including the Advanced Encryption Standard (AES) encryption algorithm. AES has been approved by the National Institute of Standards and Technology (NIST) to replace the Data Encryption Standard (DES).
In most cases, you should use TDE to encrypt data. If you want to encrypt data at rest, then you should use TDE.
There are several use cases for the manual encryption of data, using the DBMS_CRYPTO PL/SQL package:
-
Manual encryption enables you to encrypt data at the point of data collection, and then keep this data encrypted in all other layers in the database.
-
Manual encryption is useful in cases where your database may retrieve information that had already been encrypted in another source outside the database. The
DBMS_CRYPTOcan use the encryption key to decrypt the data and then present it in an unencrypted format. -
Manual encryption is also useful for scenarios in which you must hash passwords, protect extremely sensitive data, and use data signatures.
Disadvantages to performing on-demand encryption of data include the following:
-
Indexes will be irrelevant or can have performance issues.
-
Decrypting each row can result in a performance overhead.
Related Topics