Encryption algorithms
Protecting sensitive data with FIPS-compliant libraries
The data masking product IRI FieldShield And the data management platform IRI Voracity, which includes FieldShield, can encrypt data in tables and files at the column (field) level with a selection of proven algorithms:
Algorithm | Application |
AES-128, AES-256, | In accordance with NSA Suite B-level security, IRI's 128- and 256-bit Advanced Encryption Standard (AES) are implemented in FieldShield and CellShield (as well as CoSort and FirstImpression). Produce either standard ciphertext or wide and format-preserving encryption resultsFPE), which preserve the original appearance of the column value. Use your own passphrase string, file, or environment variable as an encryption key. The cipher contains printable characters for processing and representation and, in the case of FPE, retains the original format of the data. |
GPG | Asymmetric encryption and decryption routines allow users to find and utilize public key keychain files on central servers. IRI's GPG implementation is PGP compatible. |
3DES | Symmetric encryption and decryption routines allow users to find and utilize public key keychain files on central servers, EBC, and OpenSSL implementations. |
SSL | IRI uses the OpenSSL FIPS Object Module for AES and 3DES to comply with the FIPS 140-2 computer security standard under the NIST Cryptographic Module Validation Program. |
User-defined | Support for custom, field-level transformations in FieldShield or Voracity also means you can specify your own encryption codes, an alternative encryption library, or other field protection features. So, if you prefer Twofish or any other algorithm, use it. |
Solutions
When working with PII in tables or flat files, use IRI FieldShield – or the SortCL-program in the IRI CoSort Product or in the IRI Voracity-Platform – to replace this data with secure but realistic dummy outputs, which are stored in DB tables or external datasets, so-called Set files, are saved. If you need to do the same with ranges in Excel, use IRI CellShield, or for unstructured data sources IRI DarkShield. They support:
|
Recoverable pseudonymization |
Specify a lookup set where real and fake names are either pre-filled or randomly assigned. Use the recovery set to restore the original names. |
|
Irreversible pseudonymization |
Select random replacement names for the original value from a set file containing real or fake names. This way, the original name value has no automatic basis for recovery. |
Set the pseudonym method used in your output fields in simple 4GL job scripts, or use the Pseudonymization dialog in the masking dialogs of FieldShield-GUI or the DarkShield Assistant in the same Eclipse™ IDE or in CellShield, which also supports pseudonymized lookup replacements of values in Excel.
Pseudonymization is just one method by which FieldShield can identify information in a dataset. It can also pseudonymize other Functions combine data security at the field level.
Do you need test names?
In addition to pseudonymization and other masking of production data, there is a standalone solution for creating secure but realistic first and last names of genders (or other nouns). IRI RowGen uses the same metadata as FieldShield (and SortCL) to create and format pseudonyms for use as test data values (or in formatted test data destinations).
RowGen is particularly necessary to provide anonymous yet realistic test data when production data is unavailable or insufficient. RowGen builds structurally and referentially correct test data into database, file, and report targets. Note that RowGen is also included in Voracity.
Related solutions
Instructions
Other resources