RE: [Proposal] Table-level Transparent Data Encryption (TDE) and Key Management Service (KMS)

From: "Moon, Insung" <Moon_Insung_i3(at)lab(dot)ntt(dot)co(dot)jp>
To: "'Aleksander Alekseev'" <a(dot)alekseev(at)postgrespro(dot)ru>
Cc: <pgsql-hackers(at)postgresql(dot)org>
Subject: RE: [Proposal] Table-level Transparent Data Encryption (TDE) and Key Management Service (KMS)
Date: 2018-07-03 11:18:42
Message-ID: 006401d412bf$9988cd40$cc9a67c0$@lab.ntt.co.jp
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Dear Aleksander Alekseev.

> -----Original Message-----
> From: Aleksander Alekseev [mailto:a(dot)alekseev(at)postgrespro(dot)ru]
> Sent: Thursday, May 31, 2018 10:33 PM
> To: Moon, Insung
> Cc: pgsql-hackers(at)postgresql(dot)org
> Subject: Re: [Proposal] Table-level Transparent Data Encryption (TDE) and Key Management Service (KMS)
>
> Hello Moon,
>
> I promised to email links to the articles I mentioned during your talk on the PGCon Unconference to this thread. Here
> they are:
>
> * http://cryptowiki.net/index.php?title=Order-preserving_encryption
> * https://en.wikipedia.org/wiki/Homomorphic_encryption
>
> Also I realized that I was wrong regarding encryption of the indexes since they will be encrypted on the block level the
> same way the heap will be.

Sorry. I did not explain correctly in PGCon.
Yes. this idea is encrypting at the block level as you said, there is probably not a big problem with index encryption.
I will testing with PoC later an Index Encryption.

Thank you and Best regards.
Moon.

>
> --
> Best regards,
> Aleksander Alekseev

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Moon, Insung 2018-07-03 11:21:38 RE: [Proposal] Table-level Transparent Data Encryption (TDE) and Key Management Service (KMS)
Previous Message Moon, Insung 2018-07-03 11:17:48 RE: [Proposal] Table-level Transparent Data Encryption (TDE) and Key Management Service (KMS)