From: Carl Youngblood Date: 2004-07-10T10:11:02+09:00 Subject: Re: Secure Database Systems Sarah, at this point I think you should read the book(s) I mentioned. As I said earlier, every RDBMS I know of will allow you to do the things that Wayner talks about in TRANSLUCENT DATABASES. It's all up to you as the programmer to decide how you want to encrypt or obfuscate the different fields. On Sat, 10 Jul 2004 09:42:30 +0900, Sarah Tanembaum wrote: > Thanks Carl. > > The goal is to be able to control down to a field level most efficiently. If > the only trade of for good security is performance, I can live by that BUT > not functionality. It should be transparent and ONLY the authorized user can > view the field in cleartext. > > Ideally, if somehow I can rest the responsibility to the owner of the > information(user configurable) whether its the whole record or part of the > record(some fields are read-only public, some fields read-write for > restricted group, and some are for the owner eyes only), then I can think of > other security prevention without sacrifying usability. > > Does any of the opensource/commercial (object or relational) DBMS support > field level control? Personally, I prefer the database be the custodian of > this sensitive data, rather than the programming/scriptiong language > controlling the business logic. Is this make any sense?