Encryption configurations and patterns
Summarize
Summary of Encryption configurations and patterns
Edge Encryption enables ServiceNow customers to protect sensitive data by encrypting individual fields and tokenizing strings using encryption configurations and patterns. It supports AES 128-bit encryption by default, with optional AES 256-bit encryption if the Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy files are installed.
Show less
Encryption configurations
Customers can apply different encryption types to secure fields, each offering varying levels of security and functionality:
- Standard encryption: Produces a different encrypted value each time even if the original value is the same, offering the highest security. However, fields encrypted this way cannot be sorted, filtered, or grouped.
- Equality-preserving encryption: Produces consistent encrypted values for identical inputs, enabling equality comparisons and grouping. Note that existing unencrypted data may cause grouping inconsistencies.
- Order-preserving encryption: Supports sorting, equality filtering, and grouping by using tokens and encryption. This requires a MySQL proxy database. If the proxy database is down, some sorting and grouping features may not work correctly until a token repair job is run once the database is restored.
These encryption types are available with AES 128-bit and AES 256-bit keys, listed from most to least secure as: standard AES 256, standard AES 128, equality-preserving AES 256, equality-preserving AES 128, order-preserving AES 256, and order-preserving AES 128.
Encryption patterns
Encryption patterns allow tokenization of sensitive data found within strings based on pattern matching (e.g., social security numbers, credit card numbers). When activated, the Edge Encryption proxy server detects matching strings in requests, replaces them with tokens in ServiceNow, and stores the clear text in the proxy database.
Encryption patterns supplement encryption configurations by securing sensitive data outside of defined encrypted fields.
Important considerations
- The use of order-preserving encryption or encryption patterns requires a MySQL proxy database within your network to store clear text values securely.
- Since clear text data is stored in the proxy database, it is critical to secure and regularly back up this database.
With Edge Encryption, you can encrypt fields and tokenize strings.
Encryption configurations
You can encrypt individual fields using encryption configurations. Edge Encryption supports AES 128-bit encryption keys. If the Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy files are installed, Edge Encryption supports AES 256-bit encryption keys for each encryption type. Edge Encryption supports the following types of encryption configurations.
- Standard encryption
- The encrypted value of a field is different each time the field is encrypted, even when the field value remains the same. Standard encryption is the most robust form of encryption. Fields using standard encryption cannot be sorted, grouped by, or filtered on.
- Equality-preserving encryption
- The encrypted value of a field is the same when the field value remains
the same. Supports equality comparisons and group by operations on a
field.Note:When equality-preserving encryption is selected for a field that already contains data, performing a group by action on the field may not group fields with the same value if one is encrypted and the other is not.
- Order-preserving encryption
- Uses tokens and encryption to secure data in your proxy database.
Supports equality comparisons, group by operations, and the ability to
sort data. The order preserving encryption type is only supported if
there is a MySQL database configured for the Edge Encryption proxy
server.Note:When using order-preserving encryption and the proxy database is down, updates can be made to fields using order-preserving encryption. However, the sort order will not be correct when trying to sort data based on those fields. Groups also will not work as expected. When the proxy database is again operational, schedule an order token repair job to repair missing tokens.
| Encryption type | Description |
|---|---|
| Standard AES 256 | Fields cannot be filtered, sorted, or compared. |
| Standard AES 128 | Fields cannot be filtered, sorted, or compared. |
| Equality preserving AES 256 | Fields can be filtered using equality comparisons. |
| Equality preserving AES 128 | Fields can be filtered using equality comparisons. |
| Order preserving AES 256 | Fields can be sorted and equality comparison filtering can be used. Requires the use of a MySQL database in your network. |
| Order preserving AES 128 | Fields can be sorted and equality comparison filtering can be used. Requires the use of a MySQL database in your network. |
Encryption Patterns
You can secure sensitive data found in strings using encryption patterns. Once an encryption pattern is stored and activated, the Edge Encryption proxy server identifies strings that match the pattern in requests. Once located, the clear text string is stored in the proxy database and replaced on the instance with a token. Use encryption patterns to tokenize strings that match regular patterns such as social security and credit card numbers. While we recommend that encryption configurations be the primary method of encryption, use encryption patterns as a supplement to locate and secure sensitive information found outside of encrypted fields.