CHAPTER13Database Encryption

Many people think security is encryption and encryption is security. Encrypt it and it is secure, where “it” applies to anything and everything. This is a fallacy. Encryption is a critical element to security, but it plays different roles in different situations. For networks, encryption is a major part of the overall security. With databases, encryption is another layer of security defense, and you have to use it wisely; otherwise, you risk a zero increase in overall security and possibly a decrease in performance, usability, and accessibility; worst of all, you create a false sense of security.

This chapter evaluates the use of database encryption with Oracle’s new DBMS_CRYPTO package. This package, which replaces ...

