Matomo

Quick migration to field level encryption of governmental data | Cossack Labs
Case studies
Quick migration to field level encryption of governmental data

Quick migration to field level encryption of governmental data

2020 Service platform GovTech Finance
Quick migration to field level encryption of governmental data

Overview

Industry

  • GovTech
  • Finance
  • Service platform

Technology stack

  • Java, PHP (~60 apps)
  • React, Angular
  • MySQL cluster
  • huge on-prem deployment

Regulations

  • Governmental regulations for working with sensitive government-owned data
  • SOX, CCPA, CPRA
  • PCI DSS

Challenges

[01]

Flexible data access policy.

Different applications should have different access policies to the same instances / databases.

[02]

Scalable key management.

In a constrained environment, managing millions of key and additional infrastructure components is a problem.

[03]

Tight timelines.

Acra users had to deliver proof of security value within 12 weeks.

[04]

Zero code changes.

[REDACTED] has over 60 applications that operate on sensitive data and must be protected without significant interventions in the application code.

Technology requirements

Technology requirements

Integrate encryption without changing the application code

As [REDACTED] has over 60 applications (external APIs and internal apps), the data security changes should require minimal application code changes.

FIPS 140-2 compliant cryptography

The cryptographic module should be FIPS 140-2 compliant.

Large scale infrastructure

The customer operates a large MySQL deployment with many instances and different policies for each instance. Acra should provide fine-grained access control for existing applications.

ETL optimization

Ingest, transform and encrypt large amounts of data via ETL gateway.

Our approach

Security design to reflect exact use cases

We outlined the architecture that would ideally meet the Customer’s needs aligned with constraints. We designed and implemented configurations as security policies, designed a key lifecycle that minimizes key load and stores remaining keys in a simpler datastore.

Modeling and testing the environment

After the design phase, we built a test environment with implemented data security controls and configurations. Together with [REDACTED] engineers, we tested this environment with comparable load, data volume, and complexity. Based on test results, the network and security configurations were fine-tuned.

Building a migration pipeline

Having proven business value and designed the end solution, we built a migration flow to bring service disruption to a bare minimum.
Our approach

Solution

Acra database security suite used for quick migration to protect sensitive data.

Key features:

Data access policy:

FIPS 140-2:

Results and outcomes

Cossack Labs' solution allowed the Customer to integrate field level encryption and data masking quickly without risking to lose its governmental customers.

Acra’s flexibility (using AcraServer as SQL proxy, and AcraTranslator as encryption API service) allowed to blend into constrained architecture without the need to re-engineer and rewrite existing customer applications. The resulting solution was measured, optimised and acceptable from a performance perspective. The introduced delay was no more than 3..6% within most application requests.

The Customer has met financial and governmental requirements for protecting sensitive data, and timely delivered the solution, which opened more doors in the regulated domain.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days