Re: Transparent column encryption
От
Mark Dilger
Тема
Re: Transparent column encryption
Дата
Msg-id
39414634-723D-43E4-9EC6-7E955201733C@enterprisedb.com
Ответ на
Re: Transparent column encryption (Peter Eisentraut)
Список
Дерево обсуждения
Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Bruce Momjian <bruce@momjian.us>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Masahiko Sawada <sawada.mshk@gmail.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Mark Woodward <woodwardm@google.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jehan-Guillaume de Rorthais <jgdr@dalibo.com>
Re: Transparent column encryption Frédéric Yhuel <frederic.yhuel@dalibo.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jehan-Guillaume de Rorthais <jgdr@dalibo.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Justin Pryzby <pryzby@telsasoft.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Mark Dilger <mark.dilger@enterprisedb.com>
Re: Transparent column encryption Mark Dilger <mark.dilger@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <jchampion@timescale.com>
Re: Transparent column encryption vignesh C <vignesh21@gmail.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Mark Dilger <mark.dilger@enterprisedb.com>
Re: Transparent column encryption Mark Dilger <mark.dilger@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Andres Freund <andres@anarazel.de>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Stephen Frost <sfrost@snowman.net>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter@eisentraut.org>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Dave Cramer <davecramer@postgres.rocks>
Re: Transparent column encryption Jelte Fennema-Nio <postgres@jeltef.nl>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Jelte Fennema-Nio <postgres@jeltef.nl>
Re: Transparent column encryption Peter Eisentraut <peter@eisentraut.org>
Re: Transparent column encryption Jelte Fennema-Nio <postgres@jeltef.nl>
Re: Transparent column encryption Mark Dilger <mark.dilger@enterprisedb.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Robert Haas <robertmhaas@gmail.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Greg Stark <stark@mit.edu>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <pchampion@vmware.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <pchampion@vmware.com>
Re: Transparent column encryption Tomas Vondra <tomas.vondra@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <pchampion@vmware.com>
Re: Transparent column encryption Tomas Vondra <tomas.vondra@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <pchampion@vmware.com>
Re: Transparent column encryption Tomas Vondra <tomas.vondra@enterprisedb.com>
Re: Transparent column encryption Jacob Champion <pchampion@vmware.com>
Re: Transparent column encryption Peter Eisentraut <peter.eisentraut@enterprisedb.com>
> On Dec 31, 2022, at 6:17 AM, Peter Eisentraut wrote:
>
> Another update, with some merge conflicts resolved.
Hi Peter, thanks for the patch!
I wonder if logical replication could be made to work more easily with this feature. Specifically, subscribers of encrypted columns will need the encrypted column encryption key (CEK) and the name of the column master key (CMD) as exists on the publisher, but getting access to that is not automated as far as I can see. It doesn't come through automatically as part of a subscription, and publisher's can't publish the pg_catalog tables where the keys are kept (because publishing system tables is not supported.) Is it reasonable to make available the CEK and CMK to subscribers in an automated fashion, to facilitate setting up logical replication with less manual distribution of key information? Is this already done, and I'm just not recognizing that you've done it?
Can we do anything about the attack vector wherein a malicious DBA simply copies the encrypted datum from one row to another? Imagine the DBA Alice wants to murder a hospital patient Bob by removing the fact that Bob is deathly allergic to latex. She cannot modify the Bob's encrypted and authenticated record, but she can easily update Bob's record with the encrypted record of a different patient Charlie. Likewise, if she want's Bob to pay Charlie's bill, she can replace Charlie's encrypted credit card number with Bob's, and once Bob is dead, he won't dispute the charges.
An encrypted-and-authenticated column value should be connected with its row in some way that Alice cannot circumvent. In the patch as you have it written, the client application can include row information in the patient record (specifically, the patient's name, ssn, etc) and verify when any patient record is retrieved that this information matches. But that's hardly "transparent" to the client. It's something all clients will have to do, and easy to forget to do in some code path. Also, for encrypted fixed-width columns, it is not an option. So it seems the client needs to "salt" (maybe not the right term for what I have in mind) the encryption with some relevant other columns, and that's something the libpq client would need to understand, and something the patch's syntax needs to support. Something like:
CREATE TABLE patient_records (
-- Cryptographically connected to the encrypted record
patient_id BIGINT NOT NULL,
patient_ssn CHAR(11),
-- The encrypted record
patient_record TEXT ENCRYPTED WITH (column_encryption_key = cek1,
column_encryption_salt = (patient_id, patient_ssn)),
-- Extra stuff, not cryptographically connected to anything
next_of_kin TEXT,
phone_number BIGINT,
...
);
I have not selected any algorithms that include such "salt"ing (again, maybe the wrong word) because I'm just trying to discuss the general feature, not get into the weeds about which cryptographic algorithm to select.
Thoughts?
—
Mark Dilger
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company
В списке pgsql-hackers по дате отправления
От: Ted Yu
Дата:
От: Andres Freund
Дата: