DBSEC data security products and services
lower the data breach risks,prevent sensitive data from being threatened,and meet the requirements of laws and regulations
Data Security Products Series
DBSEC Database Encryption System (DES)
Product Overview
DBSEC Database Encryption System (DES) is a database security product based on transperant database communication encryption technology, provides multiple functions such as sensitive data encrypted storage, access control Consolidation, application access security control, users commutative monitoring, etc.
Based on two core mechanisms, the encryption storage mechanism on the bottom layer and the independent privileges control mechanism, DES prevents the data breaches result by plaintext storage, the external intrusion for the purpose of stealing sensitive data, the data abuse of internal high privilege users, the direct data decryption through bypass the legal application system, and solves data breaches problems at “the last kilometer”.
DES provides various encryption methods, such as column encryption, table encryption, table space encryption for different use scenarios and security requirements. Combined with the patented core technologies, such as transparent encryption and decryption, ciphertext indexing and so on, DES features excellent adaptation and practicability, and achieves the high security of data, the complete trasperant of application, and high-efficiency access of encryption.
DES currently supports windows, AIX, Linux, Solaris and many other platforms, supports a variety of international mainstream databases such as Oracle, MSSQL, Mysql, etc., and domestic databases such as DM. DES provides many highly available deployment patterns, in which DES can be deployed as master, slave, emergency and so on, to meet the various deployment demandings of users. Its encryption and decryption algorithms are in accordance with national encryption standards, and it is compatible with a variety of international commercial algorithms. DES provides extensible encryption devices and encryption algorithm interfaces, can work with various encryption cards and machines. DES goes for government, education, military, confidential, electricity and many other industries, and compliance with the laws and regulations in national Classified Cybersecurity Protection law, Grading Protection law, Military Confidential regulations, etc.
Product Values
Prevent Data Breaches Result by Plaintext Storage
The loss of data file, log file and backup file who are stored unencrypted in the bottom layer of database may bring data branches risks. Take Oracle as an example, there are many software in the market that can directly analyze the plaintext stored data file, and output clear and structured data, such as Aul and MyDul.
DES ensures the data security fundamentally by storage encryption function. So the data is unreadable even after reverse data analysis.
Prevent External Intrusion for the Purpose of Stealing Sensitive Data
Database is a large scale system with high complexity. Take Oracle as an example, it reported more than 1,000 kinds of security vulnerabilities, and it is still in increasing. Once attackers exploit these database vulnerabilities, they get sensitive data easily.
DES strengthens the verification of user password, provides idependent password management and ciphertext control system. So even attackers break the database privilege control system, they still can not access to the sensitive data.
Prevent the Illegal Data Access of Legal Users
The legal database user’s username and password of application system usually exposed to a third-party due to human factor or poor management. Then the third-party can steal the data in patches through commands and management tools.
DES has capability to protect application security, can bind the legal database users with application systems, after that, users can access to the ciphertext data through the specific application system, but can’t by any other ways such as the commands.
Prevent Data Stealing of Internal High Privilege Users
Limited by export policies, superusers (represent by sys, sysdba and sa) originally have the privileges of data access and data authorization in the database systems on C2 security level. And in large enterprises or government bodies, besides system administrator, some database users (represent by data analyst, programmer and service outsourcing personnel) can also access to sensitive data. These sensitive data access privileges has nothing to do with business that bring great risks of data breaches. The built-in encryption and decryption technologies of database can not slove the problems of high-privilege users access to sensitive data fundamentally.
DES provides a privilege separation mechanism, with three kinds of privileges in it who monitors each other, effectively splits the privileges of privileged users. It adds the user type: security administrator (DSA). Without the authorization of DSA, even DBA can not access to the ciphertext data. And it adds the user type: audit administrator (DAA), who audits and traces the authorization of DSA.
Product Advantages
Transperant Data Encryption
DES supports the encryption algorithm that required by national password management organizations, and also supports internaltional mainstream encryption algorithms. It provides column, table and table space encryption configurations for databases, ensures sensitive data stored in ciphertext. DES encrypts the data files, also the log files and index files, to strengthen the security of storage.
The meaning of transperant data encryption: firstly, it is transperant for application system and operation tools, which means users and developers needn’t change their application system, the existed backup and recovery operation behaviors; furthermore, it displays the plaintext data for those who have the access privilege of encrypted data, and the encryption and decryption process are complete transperant for users.
Data Query with High Efficiency
After data encryption, DES can also provide index capability for the encrypted data, to keep the efficient access capability of databases.
Through the index technology of encrypted data, DES breaks the limitations of using modified encryption and network equipment encryption in ciphertext index query. DES ensures the high security of index data, and at the same time provides the query capability of encrypted data. Some operations on the encrypted columns can also use the index, such as equal to, greater than, less than, and like.
Access Control Consolidation
DES adds the user type: Data Security Administrator (DSA). DSA is independent from the DBA, and they work together to strengthen the access control of sensitive fields, to achieve the real accordance of responsibility and privilege. DBA controls the general access control of common fields, and DSA controls the creation, masking and encryption access privilege of sensitive data.
Based on the encryption storage, DES performs the access control on database users on force by the independent password management system and privilege control mechanism. It prevent efficiently the illegal access of high privilege users to sensitive datas. So even the high privilege users such as sys, sysdba or sa, can’t access to the encrypted data without the authorization of DES.
Application Identity Security
DES provides encryption data access control based on the roles, IP address and time range, and can identify the applications. DES binds the legal users with application systems, after that, a user can access to the ciphertext data through the specific application system, but can’t by any other ways such as the commands, management tools.
DES judges the abstract value and connect random seeds of application programs and systems, ensures the application identity lable is unforgeable, and the legal connection is non-replayable.
High Usability and Easy to Maintain
DES provides high-usability supports and abnormal troubleshooting capability based on its technologies of data integrated storage, RAC support, double hot standby, emergency mode, Multi-process redundancy, trasnperant trouble switch, data error neglect, backup recovery, etc.
DES is with high stability, reliability and productization. It provides graphical management interface, makes itself easy to use. DES can be installed and deployed within half an hour, and its security can be strengthened (data encryption protection) within a day. DES has rapidly and accurately intergrated decryption capability, to ensure the application system can be operated normally after the decryption.