Tamper-Evident Logging
Any logs stored in the database can potentially be altered by a malicious user who gains access. To mitigate this risk, Kron PAM implements a tamper-evident mechanism that makes it possible to detect and identify any changes made to log records. This mechanism ensures that any unauthorized alteration can be reliably detected.
All log types are stored in the database and are secured using hashing and encryption. Each log record is processed with the SHA-256 hashing algorithm to generate a unique hash value. The hash value, together with its timestamp, is encrypted with a customer-specific encryption key and stored in the database alongside the original log record. Records are audited periodically. Kron PAM recalculates the stored data's hash value and compares it to the previously stored encrypted hash. If the values match, the record is verified as unchanged. If they differ, this discrepancy indicates tampering. Through this design, the system provides a verifiable audit trail where log integrity can be continuously validated.
Beyond this tamper-evident mechanism, Kron PAM also enforces strict communication and access control policies to protect the database itself. Internal applications communicate with the database exclusively over TLS-encrypted connections, ensuring that all data transmitted between components is protected against interception or modification in transit. Additionally, database access is blocked by default for any resources other than authorized internal applications. This layered approach ensures that while the hashing mechanism verifies the integrity of logs, the secure communication and access controls minimize opportunities for unauthorized access to the database.