Encrypted data administrationSource:
Encrypted data administration; functions for setting up, adding users, etc.
data_admin_init(path_data, path_user = NULL, quiet = FALSE) data_admin_authorise( path_data = NULL, hash = NULL, path_user = NULL, yes = FALSE, quiet = FALSE ) data_admin_list_requests(path_data = NULL) data_admin_list_keys(path_data = NULL)
Path to the data set. We will store a bunch of things in a hidden directory within this path. By default in most functions we will search down the tree until we find the .cyphr directory
Path to the directory with your ssh key. Usually this can be omitted.
Suppress printing of informative messages.
A vector of hashes to add. If provided, each hash can be the binary or string representation of the hash to add. Or omit to add each request.
Skip the confirmation prompt? If any request is declined then the function will throw an error on exit.
data_admin_init initialises the system; it will create a
data key if it does not exist and authorise you. If it already
exists and you do not have access it will throw an error.
data_admin_authorise authorises a key by creating a key to
the data that the user can use in conjunction with their personal
data_admin_list_requests lists current requests.
data_admin_list_keys lists known keys that can access the
data. Note that this is not secure; keys not listed here
may still be able to access the data (if a key was authorised and
moved elsewhere for example). Conversely, if the user has deleted
or changed their key they will not be able to access the data
despite the key being listed here.
# The workflow here does not really lend itself to an example, # please see the vignette instead. # First we need a set of user ssh keys. In a non example # environment your personal ssh keys will probably work well, but # hopefully they are password protected so cannot be used in # examples. The password = FALSE argument is only for testing, # and should not be used for data that you care about. path_ssh_key <- tempfile() cyphr::ssh_keygen(path_ssh_key, password = FALSE) # Initialise the data directory, using this key path. Ordinarily # the path_user argument would not be needed because we would be # using your user ssh keys: path_data <- tempfile() dir.create(path_data, FALSE, TRUE) cyphr::data_admin_init(path_data, path_user = path_ssh_key) #> Generating data key #> Authorising ourselves #> Adding key 4f:4f:4e:5c:b9:ef:8e:c5:2c:6f:7e:9f:30:9c:3a:fa:a3:4f:7a:58:11:78:2a:b9:06:53:ca:f1:81:66:a6:36 #> user: root #> host: a07fc6233936 #> date: 2022-06-20 13:44:46 #> Verifying # Now you can get the data key key <- cyphr::data_key(path_data, path_user = path_ssh_key) # And encrypt things with it cyphr::encrypt_string("hello", key) #>  67 44 ed 1a 62 8d 8e 83 04 3f 9e 07 35 cd 4e d4 43 35 bd 67 63 25 0f 20 ac #>  95 18 08 ca 98 33 40 f2 fe 84 53 07 57 78 6a 83 00 30 84 ef # See the vignette for more details. This is not the best medium # to explore this. # Cleanup unlink(path_ssh_key, recursive = TRUE) unlink(path_data, recursive = TRUE)