Short for Advanced Encryption Standard, a symmetric cipher. With TDE, the RSA TDE protector wraps an AES-256 data encryption key.
Also called Advanced Encryption Standard.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AZ-802MD-102DP-800
Each book explains AES in context, with comparison tables and the common traps.
Terms in this definition
- Transparent Data Encryption
At-rest encryption of database files and nothing more; any user able to query the database still reads the data in plaintext.
- RSA
Public-key encryption algorithm. For storage customer-managed keys, RSA and RSA-HSM keys of 2048, 3072 or 4096 bits are accepted; a SQL TDE protector cannot use 4096 bits.
- TDE protector
The key that encrypts (wraps) the TDE data encryption key: an asymmetric RSA key the customer manages and keeps in Key Vault or Managed HSM.
- DEK
The symmetric AES key that actually encrypts the data; a protector, for example the TDE protector, wraps it in turn.
Related terms
- msDS-SupportedEncryptionTypes
A bitmask attribute on an account recording which Kerberos encryption types, for example AES or RC4, it can handle. When it is left empty, the KDC uses the domain's default instead.
- RC4
Weak and being retired in favour of AES. Accounts lacking an explicit Kerberos encryption type have defaulted to AES-SHA1 since November 2022, and Windows Server 2025 KDCs refuse to issue RC4 TGTs.
- Symmetric key
A key that both encrypts and decrypts data, for example AES_256. With cell-level encryption, a certificate protects the key and ENCRYPTBYKEY uses it to encrypt column data.