Encrypting existing databases with zero downtime and zero storage overhead
Systems, methods are provided for encrypting, decrypting, re-encrypting an existing database with neither downtime nor storage overhead. Create a list of tables to be processed. Identify status of each table by an indicator in a database catalog. Store a second status in each data page. Select a table to process from list of tables. Issue a table lock against the selected table. Select a configurable number of data pages to process during the duration of the table lock. Following the processing, flush the data pages to storage. If there are no more data pages to encrypt for the selected table, remove the selected table from the list of tables to be processed. Release the table lock. If there are more data pages to process in the selected table, and there are waiters for the selected table, release the table lock; select another table from the list of tables to process.
1 . A method comprising:
creating a list of tables to be encrypted, wherein a status of a table to be encrypted is identified by an indicator in a database catalog, and a second status is stored in each data page;
selecting a table to encrypt from the list of tables, wherein a table lock is issued against the selected table to encrypt;
selecting a configurable number of data pages to encrypt during a duration of the table lock;
flushing the configurable number of data pages to storage following the processing encrypting of the configurable number of data pages;
based on there being no more data pages to encrypt for the selected table, removing the selected table from the list of tables to be encrypted and releasing the table lock.
2 . The method of claim 1 , wherein the list of tables is preserved in permanent storage between system activations.
3 . The method of claim 1 , wherein encrypting the table comprises encrypting the configurable number of data pages.
4 . The method of claim 1 , wherein encrypting the table comprises decrypting the selected table.
5 . The method of claim 1 , wherein encrypting the table comprises re-encrypting the selected table by re-encrypting the configurable number of data pages.
6 . The method of claim 1 , wherein the table to encrypt is selected based on data pages belonging to the table not being in a database buffer pool.
7 . The method of claim 1 , further comprising:
based on there being more data pages to encrypt in the selected table, and there being waiters to access the selected table, releasing the table lock; and
select another table from the list of tables to encrypt.
8 . A computer program product, the computer program product comprising one or more computer-readable storage media having program code embodied therewith, the program code, when executed by a processor of a computer to perform a method, the method comprising:
creating a list of tables to be encrypted, wherein a status of a table to be encrypted is identified by an indicator in a database catalog, and a second status is stored in each data page;
selecting a table to encrypt from the list of tables, wherein a table lock is issued against the selected table to encrypt;
selecting a configurable number of data pages to encrypt during a duration of the table lock;
flushing the configurable number of data pages to storage following the encrypting of the configurable number of data pages;
based on there being no more data pages to encrypt for the selected table, removing the selected table from the list of tables to be encrypted and releasing the table lock.
9 . The computer program product of claim 8 , wherein the list of tables is preserved in permanent storage between system activations.
10 . The computer program product of claim 8 , wherein encrypting the table comprises encrypting the configurable number of data pages.
11 . The computer program product of claim 8 , wherein encrypting the table comprises decrypting the selected table.
12 . The computer program product of claim 8 , wherein encrypting the table comprises re-encrypting the selected table by re-encrypting the configurable number of data pages.
13 . The computer program product of claim 8 , wherein the table to encrypt is selected based on data pages belonging to the table not being in a database buffer pool.
14 . A computer system the computer system, comprising:
one or more processors;
a memory coupled to at least one of the processors;
a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform actions of:
creating a list of tables to be encrypted, wherein a status of a table to be encrypted is identified by an indicator in a database catalog, and a second status is stored in each data page;
selecting a table to encrypt from the list of tables, wherein a table lock is issued against the selected table to encrypt;
selecting a configurable number of data pages to encrypt during a duration of the table lock;
flushing the configurable number of data pages to storage following the encrypting of the configurable number of data pages;
based on there being no more data pages to encrypt for the selected table, removing the selected table from the list of tables to be encrypted and releasing the table lock.
15 . The computer system of claim 14 , wherein the list of tables is preserved in permanent storage between system activations.
16 . The computer system of claim 14 , wherein encrypting the table comprises encrypting the configurable number of data pages.
17 . The computer system of claim 14 , wherein encrypting the table comprises decrypting the selected table.
18 . The computer system of claim 14 , wherein encrypting the table comprises re-encrypting the selected table by re-encrypting the configurable number of data pages.
19 . The computer system of claim 14 , wherein the table to encrypt is selected based on data pages belonging to the table not being in a database buffer pool.
20 . The computer system of claim 14 , further comprising:
based on there being more data pages to encrypt in the selected table, and there being waiters to access the selected table, releasing the table lock; and
selecting another table from the list of tables to encrypt.