Skip to content

Store and verify tag for canary encryption #20162

Description

@ccfelius

What happens?

An encrypted canary is stored in the database header of an encrypted file, to check whether the correct key is used to decrypt a database. Currently, we use AES-GCM with a constant IV to en- and decrypt, without storing and checking the tag. This is not NIST-compliant.

To Reproduce

n/a

OS:

MacOS

DuckDB Version:

1.4.2

DuckDB Client:

CLI

Hardware:

n/a

Full Name:

Lotte Felius

Affiliation:

DuckDB Labs

Did you include all relevant configuration (e.g., CPU architecture, Linux distribution) to reproduce the issue?

  • Yes, I have

Did you include all code required to reproduce the issue?

  • Yes, I have

Did you include all relevant data sets for reproducing the issue?

No - Other reason (please specify in the issue body)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions