Jump to content

Transparent data encryption

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Pradameinhoff (talk | contribs) at 16:13, 23 January 2009 (Initial draft of article). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.
(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

Transparent Data Encryption (often abbreviated to TDE) is a technology employed by both Microsoft and Oracle to encrypt database content. TDE offers encryption at a column, table, and tablespace level. TDE solves the problem of protecting data at rest, encrypting databases both on the hard drive and consequently on backup media. Enterprises typically employ TDE to solve compliance issues such as PCI DSS.

Microsoft offers TDE as part of its Microsoft SQL Server 2008. Oracle requires the Advanced Security Option for Oracle 10g and 11g to enable TDE. Keys for TDE can be stored in a hardware security module to manage keys across servers, protect keys with hardware, and introduce a separation of duties.

See also

Organizations offering TDE-enabled databases

  • Microsoft - Microsoft SQL Server 2008
  • Oracle - Advanced Security Option for Oracle 10g and 11g

Organizations offering HSMs for TDE

  • Thales - Thales (formerly nCipher)