Data masking#
Data masking is the process of applying a mask on data to hide sensitive information and replace it with new data or scrubbed data.
Data masking divides into two categories:
Static Data Masking vs. Dynamic Data Masking:
Static Data Masking |
Dynamic Data Masking |
|---|---|
Happens on a physical copy of the database |
Happens on the original database |
Original data not retrievable |
Original data intact |
Mask occurs at the storage level |
Mask occurs on-the-fly at query time |
All users have access to the same masked data |
Mask varies based on user permission |
In Querona both data masking techniques are available, yet are implemented slightly differently than in a database server. Dynamic data masking is applied on the fly, per calling identity. Static data masking happens when a view is materialized to a store reached through a connection marked untrusted: the values written there are replaced with pseudonymized ones, while queries answered through Querona still return the original data. It is not applied to every materialization - see Data Security for what has to be configured.