The key that encrypts (wraps) the TDE data encryption key: an asymmetric RSA key the customer manages and keeps in Key Vault or Managed HSM.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains TDE protector in context, with comparison tables and the common traps.
Terms in this definition
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Transparent Data Encryption
At-rest encryption of database files and nothing more; any user able to query the database still reads the data in plaintext.
- DEK
The symmetric AES key that actually encrypts the data; a protector, for example the TDE protector, wraps it in turn.
- RSA
Public-key encryption algorithm. For storage customer-managed keys, RSA and RSA-HSM keys of 2048, 3072 or 4096 bits are accepted; a SQL TDE protector cannot use 4096 bits.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Managed HSM
Pool of FIPS-validated hardware security modules in Azure Key Vault, dedicated to a single tenant, able to store customer-managed encryption keys such as a TDE protector.
Related terms
- AES
Short for Advanced Encryption Standard, a symmetric cipher. With TDE, the RSA TDE protector wraps an AES-256 data encryption key.
- BYOK
Customer-managed key approach where the key lives in your own Key Vault, serving for instance as the TDE protector or as a storage account's encryption key.
- EKM
A provider model that lets SQL Server use symmetric or asymmetric keys kept somewhere else, such as Azure Key Vault. That is what makes a customer-managed key possible as the TDE protector.
- wrapKey / unwrapKey
Operations in Key Vault for encrypting and decrypting one key with another. Together with get, they are the access-policy permissions required by the identity behind a CMK or TDE protector.