A startup is building a new mobile application that stores user profiles and preferences in an Azure Cosmos DB database. The application developers want to implement encryption for specific sensitive fields within the JSON documents, such as email addresses and phone numbers, before the data is sent to Cosmos DB. This encryption should be handled by the client application, and the database should only ever receive and store the encrypted values. Keys for this encryption will be managed in Azure Key Vault. Which encryption approach should the security architect recommend?
- AApplication-Level Encryption (Client-Side Encryption)
- BAzure Cosmos DB Server-Side Encryption
- CTransparent Data Encryption (TDE) for Cosmos DB
- DAzure Disk Encryption for Cosmos DB
Show answer & explanationAnswer & explanation
Correct answer: A. Application-Level Encryption (Client-Side Encryption)
Application-level encryption (also known as client-side encryption) directly addresses the requirement for the client application to encrypt specific fields before sending them to the database. This ensures that Cosmos DB only ever stores encrypted values, and the encryption keys are managed by the application, typically leveraging a service like Azure Key Vault.
Why the other options are wrong
- B. Azure Cosmos DB Server-Side Encryption encrypts data at rest, but the service itself handles encryption/decryption, meaning the data is plaintext within the service's memory during operations.
- C. Transparent Data Encryption (TDE) is typically associated with relational databases like Azure SQL Database and encrypts entire data files at rest, not specific fields within a NoSQL document, nor does it operate client-side.
- D. Azure Disk Encryption is for virtual machine disks and not directly applicable to a PaaS service like Azure Cosmos DB's internal storage.
Application-Level Encryption (Client-Side Encryption)
Application-level encryption, or client-side encryption, involves encrypting sensitive data fields within an application before the data is sent to the database. The database then stores only the encrypted ciphertext, and decryption occurs only within the client application.
- Ensures data is encrypted before it reaches the database.
- Database never sees plaintext data or encryption keys.
- Provides granular control over which fields are encrypted.
- Requires application code changes to handle encryption/decryption.
Memory trick: Client-side encryption means the 'secret' stays secret from the start.