| Nome: | Descrição: | Tamanho: | Formato: | |
|---|---|---|---|---|
| 4.3 MB | Adobe PDF |
Autores
Orientador(es)
Resumo(s)
A crescente digitalização dos processos empresariais tornou os sistemas de gestão de bases de dados um dos principais alvos de ataques informáticos. A funcionalidade Transparent Data Encryption (TDE) do Oracle Database, disponível desde a versão 10g Release 2, permite cifrar automaticamente os ficheiros de dados e os ficheiros de registo (redo logs), respondendo a requisitos de proteção definidos por normas como o Regulamento Geral sobre a Proteção de Dados (RGPD), o Payment Card Industry Data Security Standard (PCI-DSS) e a diretiva NIS 2. Apesar da sua maturidade, persistem dúvidas quanto ao impacto no desempenho e à eficácia operacional desta funcionalidade na versão 19c, atualmente predominante nos ambientes empresariais.
Esta dissertação avalia, num ambiente laboratorial controlado, os efeitos da ativação da TDE em métricas como utilização do processador, memória, latência e operações de entrada e saída, comparando cenários com e sem encriptação. A abordagem segue um desenho quase experimental, com recurso a cargas de trabalho transacionais e analíticas geradas pela ferramenta SwingBench e a uma monitorização detalhada do sistema. Os resultados pretendem clarificar os custos, benefícios e boas práticas associados à utilização da TDE, fornecendo evidência empírica que apoie decisões informadas sobre a sua adoção em arquiteturas empresariais.
Escalating reliance on data intensive workloads has turned database management systems into critical assets and prominent targets for cyberattacks. Transparent Data Encryption (TDE), a native feature of the Oracle Database, encrypts datafiles and redo log files transparently and is increasingly adopted to meet the security requirements established by the General Data Protection Regulation (GDPR), the Payment Card Industry Data Security Standard (PCI DSS) and the NIS 2 Directive. Despite its maturity, empirical evidence quantifying the operational cost of enabling TDE in the current Oracle 19c release remains limited, particularly in configurations that take advantage of modern cryptographic optimisations and hardware acceleration. This dissertation presents a quasi experimental study that quantifies the performance impact and compliance benefits of TDE. Two identical Oracle 19c environments, one with TDE enabled and another without encryption, are subjected to transactional and analytical workloads generated by the SwingBench toolkit. Key system level metrics including processor utilisation, memory consumption, input output throughput and latency are captured through Automatic Workload Repository reports and operating system monitors. Audit trails and key management logs are mapped to GDPR and PCI DSS controls to assess the contribution of TDE to regulatory compliance. The results clarify the balance between security and performance and provide practical guidance for administrators intending to deploy TDE as part of a defence in depth strategy.
Escalating reliance on data intensive workloads has turned database management systems into critical assets and prominent targets for cyberattacks. Transparent Data Encryption (TDE), a native feature of the Oracle Database, encrypts datafiles and redo log files transparently and is increasingly adopted to meet the security requirements established by the General Data Protection Regulation (GDPR), the Payment Card Industry Data Security Standard (PCI DSS) and the NIS 2 Directive. Despite its maturity, empirical evidence quantifying the operational cost of enabling TDE in the current Oracle 19c release remains limited, particularly in configurations that take advantage of modern cryptographic optimisations and hardware acceleration. This dissertation presents a quasi experimental study that quantifies the performance impact and compliance benefits of TDE. Two identical Oracle 19c environments, one with TDE enabled and another without encryption, are subjected to transactional and analytical workloads generated by the SwingBench toolkit. Key system level metrics including processor utilisation, memory consumption, input output throughput and latency are captured through Automatic Workload Repository reports and operating system monitors. Audit trails and key management logs are mapped to GDPR and PCI DSS controls to assess the contribution of TDE to regulatory compliance. The results clarify the balance between security and performance and provide practical guidance for administrators intending to deploy TDE as part of a defence in depth strategy.
Descrição
Palavras-chave
Transparent Data Encryption Oracle Database encriptação desempenho proteção de dados RGPD.
