Skip to content
_CORE
AI & Agentic Systems Core Information Systems Cloud & Platform Engineering Data Platform & Integration Security & Compliance QA, Testing & Observability IoT, Automation & Robotics Mobile & Digital Banking & Finance Insurance Public Administration Defense & Security Healthcare Energy & Utilities Telco & Media Manufacturing Logistics & E-commerce Retail & Loyalty
References Technologies Blog Know-how Tools
About Collaboration Careers
CS EN DE
Let's talk

Encryption at Rest — Encrypting Stored Data

15. 11. 2023 1 min read intermediate

Šifrování at rest chrání data proti fyzickému přístupu k disku nebo databázi. Compliance requirement i zdravý rozum.

Vrstvy šifrování

  • Full Disk Encryption: LUKS, BitLocker, FileVault
  • File/Volume: dm-crypt, VeraCrypt
  • Database: TDE (Transparent Data Encryption)
  • Application-level: Šifrování v kódu před uložením
  • Cloud: AWS KMS, Azure Key Vault, GCP KMS

LUKS — Linux

Encryption at Rest — Encrypting Stored Data

cryptsetup luksFormat /dev/sdb cryptsetup luksOpen /dev/sdb encrypted_disk mkfs.ext4 /dev/mapper/encrypted_disk

Application-level

from cryptography.fernet import Fernet key = Fernet.generate_key() # Uložit v KMS! f = Fernet(key) encrypted = f.encrypt(b”citliva data”) decrypted = f.decrypt(encrypted)

Key Takeaway

Šifrujte data na všech vrstvách — disk, databáze, aplikace. Klíče v KMS, nikdy vedle dat.

securityencryptionaeskms
Share:

CORE SYSTEMS team

We build core systems and AI agents that keep operations running. 15 years of experience with enterprise IT.