On-the-Fly AES256 Decryption/Encryption for Trusted Cloud SQL DBS: Position Statement
Sushil Jajodia, Witold Litwin, Thomas Schwarz · 2016
We propose the client-side AES256 encryption for a cloud SQL DB. We trust the safety of the cloud DBS run-time values, e.g., through a moving target defense. The client may send AES key(s) with the query. These become run-time values for on-the-fly decryption of ciphertext into plaintext for query evaluation. The DBS clears all these values at the query end at latest. The scheme functionally offers all capabilities of a plaintext SQL DBS. It appears the first generally practical for an encrypted cloud SQL DB. An implementation often sufficient in practice should be easy.