A key that both encrypts and decrypts data, for example AES_256. With cell-level encryption, a certificate protects the key and ENCRYPTBYKEY uses it to encrypt column data.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Symmetric key in context, with comparison tables and the common traps.
Terms in this definition
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - AES
Short for Advanced Encryption Standard, a symmetric cipher. With TDE, the RSA TDE protector wraps an AES-256 data encryption key.
- Column-level encryption
Encrypting values one at a time using a database-held symmetric key and T-SQL functions such as
ENCRYPTBYKEY. Always Encrypted works differently: here, the app itself has to call T-SQL to encrypt and decrypt. - Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- ENCRYPTBYKEY
A T-SQL function that encrypts data using a symmetric key that has already been opened, with an optional authenticator tying the ciphertext to its row. DECRYPTBYKEY does the reverse.
Related terms
- Database master key
A per-database symmetric key that guards that database's certificates, credential secrets and asymmetric keys. You make it with
CREATE MASTER KEY, and the service master key in turn protects it.