ALE
ALE FAQ
Quick answers to questions that come up repeatedly when discussing Application Level Encryption in general, independent of any particular framework.
- What's an IV, and why does it matter?
- What's a hash, and how is that different from encryption?
- Why do I need to HMAC data to make it searchable?
- Why do I need to HMAC data to enforce a unique constraint?
- What's the difference between key rotation and rekeying?
- Why would a key ever need to rotate?
- Why can there be only one active encryption key at a time, but potentially many active HMAC keys?
- If HMACs don't carry a reference to their own key, how does rekeying know what to rekey?
- What is HMAC tokenization / derived-value search?
- What's a tenant?