Database Encryption

Product Overview

Unisys Database Encryption is designed to protect sensitive data in databases from unauthorized access and tampering. Database Encryption enables you to encrypt data at the field level. Encryption is transparent to applications. Database Encryption provides security against a broader range of threats than disk encryption; plus it prevents an MCP or Windows application from directly reading the files that make up a database. In general, it prevents any kind of tool that can read files from a disk from accessing the data in clear text.

In addition, it provides more granular control over who can access decrypted data—by role, by user id, or by privilege.

You can encrypt DMSII data using AES-256 encryption. Encrypting your data prevents access of the data that is in clear text. Database Encryption is available at the field level for alpha, numeric, real, and group data. You can set it at the global or data set default, at the structure level, or for selected items in a data set.

Note: Encrypted key data items are not supported.

You can encrypt indexed sequential sets spanning fixed format standard data sets. You can use encrypted sets to perform searches for equality. You can rekey a database to meet regulatory requirements or because a key has been compromised. This capability/product includes enhancements to the ALGOL and COBOL85 compilers, to Security Center, and to MCP cryptography (also known as SECURE-TRANSPORT).

Configuration Information

The Database Encryption product uses architectural changes that are only available on these systems:

  • Libra 43xx/63xx/83xx and FS600 (will require a firmware update available in late 2017)

  • ClearPath Software Series MCP Bronze, MCP Silver, MCP Developer Studio, and Financial Server (will require a firmware update available in late 2017).

  • Future server and software series products

Product Information

Refer to the following documents for more information:

  • Enterprise Database Server for ClearPath MCP Data And Structure Definition Language (DASDL) Programming Reference Manual (8600 0213)

  • Enterprise Database Server for ClearPath MCP Utilities Operations Guide (8600 0759)