FINDING · EVALUATION

In PostgreSQL benchmarks, FPE-encrypted account-balance fields (libfte P-DD scheme, regex `\-[0-9]{9}`) reduce throughput by only 0.8% for complex mixed-transaction workloads (USUUI) and only 1.1% for SELECT-only workloads, relative to conventional authenticated encryption. Per-query latency for FPE versus authenticated encryption is identical across all five tested query types.

From 2014-luchaup-libfteLibFTE: A Toolkit for Constructing Practical, Format-Abiding Encryption Schemes · §7.1, Tables 8–9 · 2014 · USENIX Security Symposium

Implications

Tags

censors
generic
defenses
format-transform

Extracted by claude-sonnet-4-6 — review before relying.