SQL Server on Azure Virtual Machines by Louis Davidson Allan Hirt Joey D’Antoni Anthony

SQL Server on Azure Virtual Machines by Louis Davidson Allan Hirt Joey D’Antoni Anthony

Author:Louis Davidson, Allan Hirt, Joey D’Antoni, Anthony
Language: eng
Format: epub
Publisher: Packt Publishing Pvt. Ltd.
Published: 2020-06-02T00:00:00+00:00


Always Encrypted

While TDE is designed to meet the requirements of encryption at rest, administrators and users who have access to the database have full access to the unencrypted data, where it can be consumed and potentially exported in a tool such as Excel. Additionally, with any other encryption solution, such as SQL Server's cell-level encryption, database administrators have access to the encryption keys.

Always Encrypted changes this paradigm—the encryption key for the encrypted data is accessed in the client application and never in the database server. The administrators have no access to the encryption key, and therefore no access to the unencrypted values. Having a key management process, such as AKV, enables enhanced separation of duties to prevent this administrator access. In addition to AKV, options include Windows Certificate Store on a client machine, or a hardware security module.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.