Open Closed

Medical Data Encryption Strategy and Implementation (S3 Files & PostgreSQL) in ABP Framework #10694


User avatar
0
vmquang95 created

Hi

Our team is currently building a medical data storage and management application using the ABP Framework. Given the highly sensitive nature of our domain, our data is primarily stored in two locations:

  • Physical Files: Stored via S3 (MinIO).
  • Relational Database: Stored in PostgreSQL.

Core Security Objectives:

  • Data Confidentiality: Ensure absolute security for Personally Identifiable Information (PII) at rest (Data at Rest).
  • Centralized Key Management: Ensure the lifecycle of encryption keys is strictly and securely managed, isolated from the application logic.

To achieve these goals, I would like to ask ABP for advice on the best practices and implementation strategies for data encryption within the ABP ecosystem for the following two issues:


Issue 1: Physical File Encryption (XML Files on S3/MinIO)

Our system currently stores medical records as XML files via S3 (MinIO).

  • ABP Modules/Packages: Does ABP provide any built-in modules, packages, or integrations (e.g., intercepting the BLOB Storing module) that support transparent encryption/decryption of these files before uploading them to S3?
  • Architecture Flow: What should the standard encryption/decryption flow look like to optimize performance?
  • Algorithms: Which encryption algorithms are recommended for this specific use case?
  • Key Management: How should we securely manage, store, and rotate encryption keys for this file system?

Issue 2: Field-Level Data Encryption in PostgreSQL

Our PostgreSQL database contains highly sensitive patient information such as: National ID/Health Insurance Numbers, Full Names, Addresses, Medical History, etc.

  • ABP Support Mechanisms: To what extent does the framework support encrypting these properties? (e.g., using EF Core Value Converters, or does ABP have specific Data Masking/Encryption features?).
  • Tokenization vs. Encryption: What built-in mechanisms does ABP offer regarding Encryption vs. Tokenization? What are the standard algorithms used?
  • Architecture Flow: How does the read/write flow work for encrypted data fields, especially when performing querying/searching operations on them?
  • Key Management: Similar to the file system, how should we set up the management of Master Keys or Data Encryption Keys (DEK) for the database in ABP?

I would greatly appreciate any real-world experience, insights, keywords, or related documentation you could share. Thank you!

Markdown supported.
Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)

4 Answer(s)
  • User Avatar
    0
    AI-Bot created
    Support Team ABP Agent
    • ABP does not provide a built-in “transparent encryption” module for Blob Storing providers (S3/MinIO) or a built-in field-level encryption feature for EF Core entities that automatically encrypts/decrypts selected columns.
    • What ABP does provide (and you can safely build on) is:
      • IStringEncryptionService for encrypting/decrypting strings (ABP implementation uses AES; documented as AES/CBC) and configuration via AbpStringEncryptionOptions.
      • ASP.NET Core Data Protection APIs (usable in ABP like any ASP.NET Core app) for application-level data protection (cookies, tokens, etc.).

    Issue 1 — Encrypting XML files stored in S3/MinIO (ABP Blob Storing)

    Recommended ABP-style approach (application-level envelope encryption)

    1. Generate a per-file DEK (data encryption key) (random 256-bit).
    2. Encrypt the XML with AES (prefer AEAD like AES-GCM in your own implementation; ABP’s IStringEncryptionService is AES/CBC and string-focused).
    3. Store the encrypted file bytes in S3/MinIO using ABP Blob Storing as usual.
    4. Encrypt (“wrap”) the DEK with a master key managed outside the app (KMS/HSM/Vault), and store the wrapped DEK + metadata (algorithm, key id, version) alongside the blob (e.g., blob metadata or a DB table).

    Where to plug this in ABP

    • Keep ABP Blob Storing provider (MinIO/S3) unchanged.
    • Implement a small service layer such as IEncryptedBlobStore that:
      • Takes a stream/bytes
      • Encrypts + uploads through ABP IBlobContainer
      • Downloads + decrypts on read

    This avoids forking ABP Blob Storing and keeps encryption logic isolated.

    Performance flow (streaming)

    • Upload: stream XML → encrypt stream on-the-fly → upload encrypted stream to MinIO.
    • Download: download encrypted stream → decrypt stream on-the-fly → consume plaintext stream.
    • Avoid loading full XML into memory; use streaming crypto.

    Algorithms

    • ABP’s documented string encryption is AES (CBC) via IStringEncryptionService, but for file encryption best practice is AEAD (e.g., AES-GCM) with a random nonce per object + authentication tag. (ABP does not ship a file-encryption abstraction; you implement this with .NET cryptography.)

    Key management / rotation

    • ABP itself doesn’t provide centralized KMS. Typical production pattern:
    • Master key in external KMS/HSM/Vault (never in appsettings).
    • DEKs are generated per file (or per tenant/bucket partition) and wrapped by KMS.
    • Rotation: rotate master key in KMS; re-wrap DEKs lazily or via background job.

    Issue 2 — Field-level encryption in PostgreSQL (EF Core)

    ABP support mechanisms

    • ABP does not have a built-in “encrypt these entity properties” feature.
    • ABP does provide IStringEncryptionService which you can use to implement field encryption yourself (e.g., EF Core ValueConverter, or domain setters/getters).

    Practical implementation pattern (EF Core ValueConverter)

    • Create a ValueConverter<string,string> that uses IStringEncryptionService.Encrypt/Decrypt.
    • Apply it to sensitive properties in OnModelCreating.

    Important operational consequence:

    • Queries/search: encrypted columns are generally not searchable by plaintext criteria (e.g., Where(x => x.NationalId == "…")) unless you:
      • search by an additional deterministic index (e.g., keyed hash column), or
      • use database-native encryption/search approaches. ABP doesn’t provide built-in tokenization/searchable encryption.

    Tokenization vs encryption in ABP

    • ABP has no built-in tokenization feature for domain data.
    • ABP’s provided primitive here is string encryption (IStringEncryptionService, AES-based) and ASP.NET Core data protection; anything beyond that (token vault, format-preserving tokenization, searchable encryption) is custom/external.

    Key management for DB encryption

    • Same as files: keep master keys outside the app (KMS/Vault/etc.).
    • ABP’s AbpStringEncryptionOptions requires consistent parameters across instances; you should load secrets from a centralized secret manager (example ABP community article shows AWS Secrets Manager integration).

    Sources

    • https://abp.io/docs/latest/framework/infrastructure/string-encryption
    • https://abp.io/community/articles/37uqhdwz
    • https://learn.microsoft.com/en-us/aspnet/core/security/data-protection/introduction
    • https://abp.io/community/articles/3dcblyix

    This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    Hi,

    A quick note on this topic — ABP framework itself doesn't ship a built-in module for blob/file encryption or entity field-level encryption. Both need to be implemented by the developer, combining ABP's primitives with platform or library features. Below are a few common directions people typically take, which may help you choose what fits your project best.

    File encryption (S3/MinIO): Most teams rely on the storage layer's own server-side encryption (SSE-KMS / SSE-C). MinIO and S3 both support this. Master keys live in an external KMS (AWS KMS, Azure Key Vault, HashiCorp Vault), and encryption happens transparently. This is generally simpler and performs better than wrapping IBlobContainer with custom streaming AES in the application layer.

    If you really need application-level encryption, you can wrap IBlobContainer with a streaming AES-GCM layer (per-file DEK + master key wrap pattern), but rolling your own envelope encryption is non-trivial.

    Field-level encryption (PostgreSQL): A few options worth considering:

    • Database-level TDE with customer-managed keys — Azure Database for PostgreSQL Flexible Server and AWS RDS for PostgreSQL both support this. The DB handles everything; the app stays unchanged. Usually the simplest path for compliance.
    • EF Core ValueConverter + IStringEncryptionService — works for basic column-level encryption. The EF Core docs do include a caution about rolling your own encryption here, and ValueConverter can't access DbContext or session state, which makes per-tenant key derivation tricky.
    • PostgreSQL pgcrypto extension — SQL-level encryption/decryption functions.

    Encrypted columns aren't directly searchable by plaintext. The common pattern is a separate blind-index column (HMAC of the value) for equality lookups.

    Key management: ABP doesn't ship a dedicated KMS abstraction, but AbpStringEncryptionOptions reads from IConfiguration, so AWS Secrets Manager / Azure Key Vault / HashiCorp Vault can be plugged in via the standard .NET configuration providers. ASP.NET Core Data Protection APIs are mainly designed for short-lived secrets (cookies, tokens), so I wouldn't recommend them for long-term storage of medical data.

    Related ABP article: I wrote a piece some time ago covering the encryption mechanisms ABP uses internally — IStringEncryptionService (AES), Identity password hashing (PBKDF2 / HMAC-SHA512), and OpenIddict signing/encryption credentials. It may help as background: https://abp.io/community/articles/encryption-and-decryption-in-abp-framework-37uqhdwz

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    vmquang95 created

    Thank you so much for the detailed and insightful response!

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    : )

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.