Skip to main content

Concepts & Architecture

© Pi Soft, 2018-2026 · Tricryption Engine 8.1

This page defines the components of a Tricryption deployment and describes the common data-protection scenarios and the decisions to make before you start developing.

Definitions​

Tricryption​

A three-step encryption process in which data is encrypted using a unique cryptographic key, the key is then encrypted, and finally the link between the data and the key is encrypted. The data, key and link are then stored, remaining encrypted while in storage. Decrypting involves decrypting the link, matching the key to the data, decrypting the key, and then decrypting the data. Protected data can only be decrypted by authorized users performing authorized transactions, so stored data accessed by unauthorized users cannot be decrypted.

Tricryption Engine (Key Server)​

Performs all cryptographic key-management functions (key generation, key exchange, and the encryption and decryption of keys and links) as well as data encryption and decryption. These functions are performed in response to transaction requests received from agents and Remote Engines. The Engine also performs administrative functions such as maintaining backup user authentication information.

Tricryption Agent​

An integration component that transmits cryptographic transaction requests from an application to the Tricryption Engine or a Remote Engine. This SDK provides the agent in C, C++, Java and TypeScript (Node.js) versions for Windows and Linux client applications.

Remote Engine (Desktop Server)​

Transmits cryptographic key requests from a computer to the Tricryption Engine and uses the keys to encrypt and decrypt data stored on the client computer. Use of the Remote Engine is optional and offloads data encryption/decryption from the Tricryption Engine. (The Remote Engine is also marketed as the "Desktop Server", or ds.)

Key ID​

An identifier assigned to an encrypted key.

Tricryption requires a link between the data and the cryptographic key used to encrypt it. A Hidden Link is formed when the Key ID is encrypted. Hidden Links are stored with the encrypted data and act as an encryption receipt: the Hidden Link must accompany a later request for the key to decrypt the data.

Warning: If its Hidden Link is lost, the encrypted data cannot be decrypted and is unrecoverable.

Key Database​

Stores encrypted keys and the Key IDs assigned to them.

Certificate Authority​

As part of a public-key infrastructure, governs the issuance, management and verification of digital certificates used to authenticate identity. A certificate authority is optional and used only to provide trust between Tricryption Engines.

Basic data-protection scenarios​

Protecting information in a relational database​

Use a Tricryption Engine to perform all cryptographic functionality, including key generation, key retrieval, key encryption, link encryption and data encryption. Multiple Tricryption Engines may be used for fault tolerance. The Key Database stores encrypted keys and Key IDs as well as user and trusted-component information. An application server hosts the client applications and a Tricryption Agent, which submits cryptographic requests to a Tricryption Engine, while the target database stores the unencrypted data, encrypted data and Hidden Links.

Protecting information contained in files​

Use a Tricryption Engine to perform key-management functions (key generation, key retrieval, key encryption and link encryption). The Key Database stores encrypted keys, while encrypted files and Hidden Links are stored on client machines. A Remote Engine can be installed on each client machine to transmit key requests to the Tricryption Engine and to encrypt and decrypt data locally. This offloads data encryption/decryption from the Tricryption Engine and reduces network traffic.

Integrating with your application​

For each kind of operation, the application developer is responsible for the following steps:

EncryptionDecryptionAdministration
Create a Tricryption Agent instanceCreate a Tricryption Agent instanceCreate an administration component instance
Connect to the Engine or Remote EngineConnect to the Engine or Remote EngineConnect to the Engine or Remote Engine
Provide credentials for authenticationProvide credentials for authenticationProvide credentials for authentication
Prepare the data to be encryptedPrepare the encrypted data and its Hidden LinkPrepare the necessary data sets
Submit the data to the EngineSubmit the data to the EngineSubmit the administrative request
Close the connectionClose the connectionClose the connection
Store the encrypted data and Hidden LinksStore the decrypted data

Note: Every encryption key request returns a unique Hidden Link. It functions as an encryption receipt and must accompany a later decryption request — see Hidden Link.

Pre-development decisions​

  • Which agent — C, C++, Java or TypeScript? Determined by the type of application that will use the Engine's cryptographic services.
  • Which method of authentication? The system offers username/password (SRP), LDAP, certificate, session token, delegation, Kerberos, and Trusted Components (code-access authentication). Kerberos takes two forms. The Key Server's own channel-bound Kerberos login, GSSAPIAuthentication (AM10): a caller holding a Kerberos ticket logs in over GSS-API, bound to the TLS connection, and is resolved through the directory to an LDAP principal — every agent has it (Kerberos login, Kerberos login, Kerberos login, Kerberos login). And Kerberos as a GSSAPI SASL mechanism under LDAP, for the Key Server's own bind to its directory. There is no separate integrated-Windows authentication (removed by TE81-338).

Note: Determining what needs to be protected should be done as part of a comprehensive enterprise-security study and is beyond the scope of this SDK.