ArticleClover
 Home | Login | Register Now! | Submit Article | Latest Articles | Contact Us RSS
ArticleClover » Computer-and-technology

SQL Server Encryption
Words: 521 | Date: Tue, 31 Aug 2010


Transparent data encryption (TDE) is a new encryption feature introduced in Microsoft SQL Server 2008. It is designed to provide protection for the entire database at rest without affecting existing applications.

Extensible Key Management (EKM) is another new feature in SQL Server 2008. It enables parts of the cryptographic key hierarchy to be managed by an external source such as Hardware Security Module (HSM), referred to as a cryptographic provider. Encryption and decryption operations using these keys are handled by the cryptographic provider. This allows for flexibility and choice in cryptographic providers as well as common key management. TDE supports asymmetric keys that are provisioned by EKM. No other form of asymmetric key is supported by TDE and database certificates cannot currently be provisioned through EKM. EKM is supported for cell-level encryption through symmetric and asymmetric keys. It is highly recommended that you use EKM with both database- and cell-level encryption for more comprehensive key management and hardware-based cryptography (if available through the HSM).

Extensible Key Management (EKM) enables you to manage your encryption keys via an external provider. Extensible Key Management enables third-party vendors to implement solutions that store keys in a device such as a smart card, USB device, or a hardware security module (HSM). Encryption is the process of obfuscating data by the use of a key or password. This can make the data useless without the corresponding decryption key or password.

Introduction to Extensible Key Management : Some high-security databases use thousands of keys, and you must employ a system to store, retire, and regenerate these keys. Furthermore, you should store these keys separately from the data to improve security.

SQL Server 2008 provides Extensible Key Management, which exposes encryption functionality for use by third-party vendors. These solutions work seamlessly with databases in SQL Server 2005 and SQL Server 2008, and provide enterprise-wide, dedicated key management. This moves the key-management workload from SQL Server to a dedicated key-management system. Extensible Key Management enables key storage in a device such as a smart card or USB drive.

Extensible Key Management in SQL Server 2008 also supports the use of HSMs to provide the physical separation of keys from data. This improves security because the data remains protected even if it is stolen, because the keys are in a separate physical location.

Enabling Extensible Key Management :

Extensible Key Management is switched off by default. You can use the sp_configure stored procedure to enable it.

The following code example shows how to enable Extensible Key Management.

sp_configure 'show advanced', 1 GO RECONFIGURE GO sp_configure 'EKM provider enabled', 1 GO RECONFIGURE GO

To summarize, SQL Server 2008 Extensible Key Management provides the following benefits:

An additional authorization check that enables separation of duties between database administration and key management Improved performance through hardware-based encryption/decryption rather than software-based encryption/decryption External encryption key generation Physical separation of data and keys Encryption key retrieval External encryption key retention and encryption key rotation Easier encryption key recovery Manageable encryption key distribution Secure encryption key disposal


This is DBATAG, worked as SQL Server Production DBA in one of the Top MNCs for TEN years. I am Microsoft Certified DBA (MCDBA) since 2001 as well as IT Professional DBA, Developer and Business Intelligence (MCITP) in 2005 and upgraded to SQL Server 2008 too. Thanks DBATAG, http://sqlserver-training.com

Article Source: Article Directory | Author Dbatag Dbatag | Cheap WebHosting




Bookmark
digg delicious googlecombookmarks stumbleupon propellercom redditcom simpycom mister-wongcom mixxcom mywebyahoocom myjeevesaskcom furlnet blinklistcom technoraticom myspacecom facebookcom twittercom
More Articles
* Saas Outsourcing – For Efficient Project Delivery
* Should You Retrieve Deleted Text to Verify Signs of Cheating?
* Registry Error Tool Review - Regcure
* How Can I Use a Reverse Phone Lookup to Discover Who Owns a Certain Phone Number?
* How does property Tax calculator Help?
* How Using Voice-overs in Flash Videos Improves Viewer Engagement
* The Concept Of Blue Ray Releases
* Are You Getting Tired of Squinting?
* Types of Projects Adobe InDesign is Best Used For
* Use This Reverse Cell Phone Search To Discover Who Owns Any Phone Number!
* How Can I Run a Background Check on Someone? Here's the Easiest Way!
* Printer Toner
* External Devices Pose Network Security Challenges
* Document Generation in Microsoft Office
* Enjoying The Best of Your Vaction Trip With Photoshop
* Web development – Variety of points to be covered
* Best Camera Phone
* Common Problems With The Red Light Camera Detector
* How Can A Reseller Guarantee Call Accounting Service Levels?
* Do You Know How to Retrieve Deleted Text From a Nokia TDMA Cellular Device?
* Web Design - Learn How to Make it Easy
* How to Get a Free iPad Online
* More Freedom on a Pockect Size Digital Camera, S90
* Convert Your TIFF, JPEG & PDF Files online 24x7 And Then Edit
* Anti-Glare Film Increases Visibility


 

Search for Content:

Advanced Search


Categories
*Arts and Entertainment
*Automotive
*Business
*Communications
*Computer and Technology
*Fashion and Beauty
*Finance and Investment
*Food and Beverages
*Health and Fitness
*Home and Family
*Internet Business
*News and Society
*Pets and Animals
*Recreation and Sports
*Reference and Education
*Self Improvement
*Shopping and Reviews
*Travel and Leisure
*Writing and Speaking


Now Trending
iconsierra lamar
iconhouse finale
iconfacebook stock
iconspacex
iconokc thunder
iconstan van gundy
iconaroldis chapman
iconcory booker
iconandrew bynum
iconoklahoma city thunder
iconlakers
iconacl
iconbill stewart
iconmade in america
iconelon musk
iconthe master
iconkellen winslow
iconanchorman 2
iconbar refaeli
iconmemorial day
sikiş film izle