Field Encryption/Decryption
Remediate data breaches. Comply with privacy regulations.
Challenges
Encryption is one of the best ways to protect personally identifiable information (PII) and other sensitive data. However, implementation or modification can be costly, tedious, and not targeted. And beyond application, algorithm, and encryption key management decisions, there are considerations like authentication and tokenization, format preservation, and referential integrity.
Standalone, data-centric PII encryption solutions that support multiple table and flat file formats (.txt, .csv, .sam, .dat, .xml, .ldif, etc.) and Internet of Things– and cover other data streams are rare. Most data masking solutions that can encrypt more than a single database are limited in their scope and functionality or are otherwise very expensive.
In the meantime, hardware-based encryption and applications that protect entire networks, machines, databases, hard drives, or files are inefficient and overloaded. They restrict access to everything, while only sensitive areas need protection. And when decryption occurs, everything is revealed at once.
Solutions
Software products both in IRI Voracity-platform as well as in the IRI Data Privacy Suite prevent the impact of data breaches by protecting PII at the field level across multiple data sources. IRI FieldShield and the SortCL program in Voracity or IRI CoSort includes all 3DES, AES, FIPS compliant OpenSSL, and GPG encryption and decryption libraries. IRI CellShield for Excel also includes several compatible ones.
You also offer a wide range of other features and methods for static data masking (SDM) and dynamic data masking (DDM) – and enable your own – as part of a comprehensive Data loss prevention (DLP) Strategy.
Consider these benefits:
Function | Flexibility | Efficiency | Security |
Granularity | Encrypt only the sensitive data. Leave the remaining fields in the table or file untouched and be otherwise operational. | The incremental computational overhead of field encryption is low; no resources are wasted protecting non-sensitive data. | Field encryption keys and libraries can align with your role-based access control framework. |
Choice | Leverage IRI's built-in field-level security features together with your own simultaneously. Customize the mix of data privacy features based on your data and your business rules. | Apply safeguards in the same batch (and I/O pass), both during data transformation and reporting. This is more efficient and protects PII in new data sources. | An XML audit trail checks who protected data, when, where, and how. Remember that you must be able to demonstrate regulatory compliance. |
Interoperability | Use the same metadata for IRI RowGen, to generate test data when you cannot access the actual DB/file source(s). | Profile, correct, validate, and manage data and orders together in the same product and in the same Eclipse IDEIRI Workbench). | Encrypted data is independent of hardware, databases, and file formats. The fields are secure until decrypted. |
Learn more about IRI's unique powerful field encryption features for data privacy and compliance:
Related solutions