A relational database system for encryption of individual data elements comprising
a encryption devices of at least two different types, the types being tamper-proof
hardware and software implemented. The encryption processes of the system are of
at least two different security levels, differing in the type of encryption device
holding the process keys for at least one of the process key categories and also
differing in which type of device executing the algorithm of the process. Each
data element to be protected is assigned an attribute indicating the usage of encryption
process of a certain security level.