SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 

Protecting the Encryption Keys

By Steve Jones, 2009/09/04

Total article views: 69 | Views in the last 30 days: 4

There was an interesting debate on SQLServerCentral recently after John Magnabosco wrote an editorial about encryption. I had chimed in that I thought adding encryption keys to the things you need to protect was harder than just backing up your data. Someone else disagreed, and we debated the issue back and forth.

It seems to me that it's harder, but I'm really not sure. I think you need a separate backup process, and a more complex recovery process, but perhaps that's not true. Maybe I'm just over-thinking it.  Since it's Friday, I decided this would make a good poll.

Is protecting your encryption keys harder than just making a backup?

I've always thought that a best practice was to keep the keys separate from the data, or in this case, the backup. Which means that I need to have a different media, and preferably a different location. That means it's a whole separate process.

The other thing that seems more complex is that you're want to rotate keys periodically. Otherwise if someone got the key, they could theoretically brute-force the key. I know it's supposed to take years, but it seems that hardware advances are always making this take less time than originally estimated. And what if someone managed to secure the first letter or two? I bet it's crackable in reasonable times.  However if you rotate keys, then the time frames shrink, perhaps too small to be worth the effort.

If you rotate keys, then you need to ensure that somehow you can match up the key with the backup. If I think across time, this seems complicated, but the reality is for DR situations it would be one of two keys (the current and the past). For other situations, like legal issues where you might go back over a year, perhaps it's more complicated.

I'm curious what other people do, or what they think. Is this harder?

Steve Jones


The Voice of the DBA Podcasts

Everyday Jones

The podcast feeds are available at sqlservercentral.mevio.com. Comments are definitely appreciated and wanted, and you can get feeds from there.

You can also follow Steve Jones on Twitter:

Overall RSS Feed: or now on iTunes!

Today's podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

I really appreciate and value feedback on the podcasts. Let us know what you like, don't like, or even send in ideas for the show. If you'd like to comment, post something here. The boss will be sure to read it.

By Steve Jones, 2009/09/04

Total article views: 69 | Views in the last 30 days: 4
Your response
 
 
Related Articles
ARTICLE

Encrypting Data

Encrypting data is the easy part of dealing with encryption and databases. Steve Jones talks about s...

FORUM

sql 2005 encryption

encryption

FORUM
BLOG

SQL Musings - Podcasting

A new video setup is on the way!!!! Actually I'll do a couple podcasts on podcasting over the hol...

FORUM

Podcast Problem

Podcast Problem Blocked by group policy

Tags
editorial    
encryption    
friday poll    
 
Contribute

Free registration required...

To read the rest of this article, and access thousands of other articles, we ask you to register on the site and subscribe to our newsletters.

Login (existing users)

Login

Email:   Password:   Remember me: Forgotten your password?

Register (new users)

Register

Email:   Password:
Confirm:

Subscribing to our newsletters gets you:

  • ALL of our content (thousands of articles, scripts, and forum postings)
  • A daily newsletter (example)
  • A weekly news round up (example)
  • The opportunity to ask and answer questions in our forums
  • A daily Question of the Day to test and help you increase your knowledge of SQL Server.

Steve Jones
Editor, SQLServerCentral.com