We use traditional envelope encryption on a highly normalized base. At the end, only a few sensitive columns on a few sensitive tables get encrypted.
It’s kind of like a sparse matrix of encrypted vs. plain data, and works great for our scenario.
It’s kind of like a sparse matrix of encrypted vs. plain data, and works great for our scenario.
I’m sure is not the most secure schema in the world, but it makes retrieval fast and most analytics can be worked out with dynamic query building, while making the db a scrambled mess for those with partial access.
I guess you could call it “Security by insanity.”