- 21 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Sensitive data encryption
- Mis à jour le 21 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
By default, OneSpan Authentication Server encrypts security-sensitive data using an embedded key. This encryption can be strengthened by adding a custom key via the Administration Web Interface. The sensitive data key is derived from the embedded and the custom keys and is used to protect sensitive data attributes in the data store.
For new installations of OneSpan Authentication Server, AES-128 is used. Upgraded installations using previously supported algorithms may continue to use the legacy algorithms.
All OneSpan Authentication Server instances MUST share the same encryption settings.
Encryption settings must be set before you import any authenticator. If you change the encryption settings later, all authenticator records become invalidated, and require deleting and re-importing. For more information, see Exporting and importing encryption settings.
Various data attributes are encrypted in the data store (see Table: Encrypted data columns).