Always Encrypted with secure enclaves now generally available in Azure SQL Database

Published Jul 14 2021 09:10 AM 1,723 Views
Microsoft

Always Encrypted helps you prevent the exfiltration of sensitive data by rogue DBAs, admins, and cloud operators. Your data gets transparently encrypted and decrypted on the client side and it is never revealed in plaintext in the database system.

 

Always Encrypted with secure enclaves extends Always Encrypted by allowing sensitive data to be decrypted within a server-side trusted execution environment, called a secure enclave - a protected region of memory within the database system process, which appears as a black box to the database system and other processes on the hosting machine. There is no way to view any data or code inside the enclave from the outside. Thus, the enclave can safely perform computations on plaintext data within the database system.

 

ae-data-flow.png

 

Always Encrypted with secure enclaves, now generally available in Azure SQL Database, provides two main benefits: in-place encryption and rich confidential queries.

 

In-place encryption

Without secure enclaves, setting up Always Encrypted can be challenging – since the database system has, by design, no access to cryptographic keys, encrypting a column requires data to be moved and encrypted outside of the database. As a result, the encryption process can take a long time and is prone to network errors. And, if you need to re-encrypt your column later, for example to rotate the column encryption key or to change the type of encryption, you will face the same challenges again.

 

With a secure enclave available inside your database system, there is no need to move your data for cryptographic operations. Since the enclave is trusted, a client driver within your application or a tool, such as Azure Data Studio or SQL Server Management Studio, can securely share the keys with the enclave for the duration of cryptographic operations. The enclave can encrypt or re-encrypt columns in-place. This typically results in a dramatic reduction of time needed to perform such operations. 

UWM_logo.jpg

United Wholesale Mortgage is one of the customers benefiting from in-place encryption:

Our project involves protecting sensitive financial information stored in large tables, with hundreds of millions of rows. The performance of encrypting such large data sets is critical. With secure enclaves we have seen dramatic improvements in the speed of encryption, compared to Always Encrypted not using enclaves. Encrypting columns in a table with over 700 million rows used to take days. Now, with secure enclaves supporting in-place encryption, the time is reduced to 5 hours. - Erick Wittrock, Cloud Engineer, United Wholesale Mortgage.

 

Rich confidential queries

Most client-side encryption technologies allow no operations on protected data within a database server. Always Encrypted (without secure enclaves) supports only one operation on encrypted columns: equality comparison. Many applications, however, require richer data processing. For example, personally identifiable information (PII), such as people names, addresses, national identification numbers, or credit card numbers often require pattern matching or sorting. If you want to protect your data from malicious admins and perform such computations without enclaves, the only option is to move the data to the client-side and process it within your application. However, this approach does not scale to large data sets and requires extensive application changes.

 

Always Encrypted with secure enclaves enables pattern matching, range comparisons, sorting, and more on encrypted columns, allowing you to use the database system for what it’s designed for: querying your data. There is no need for refactor your apps and expensive data movement.

rbc logo.jpg

Royal Bank of Canada is an example of a customer who is already leveraging the power of rich confidential computations provided by Always Encrypted with secure enclaves:

Our project focuses on working with different partners to bring more value to respective customers by exchanging encrypted data wherein no person, process or system can see each other’s data. Always Encrypted with secure enclaves in Azure SQL Database provides us the framework for managing encrypted data and running queries on top of them, while minimizing work on our end. By leveraging Always Encrypted that helps ensure that RBC and Microsoft don’t have access to customer data, we can create a new platform to provide services that we couldn’t offer before. — Eddy Ortiz, VP of Solution Acceleration and Innovation, Royal Bank of Canada

You can learn more about RBC’s application here.

 

Next steps

For more information and to get started with Always Encrypted with secure enclaves in Azure SQL Database, see:

To learn about other confidential computing technologies and services in Azure, see Azure confidential computing documentation.

%3CLINGO-SUB%20id%3D%22lingo-sub-2544476%22%20slang%3D%22en-US%22%3EAlways%20Encrypted%20with%20secure%20enclaves%20now%20generally%20available%20in%20Azure%20SQL%20Database%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2544476%22%20slang%3D%22en-US%22%3E%3CP%3EAlways%20Encrypted%20helps%20you%20prevent%20the%20exfiltration%20of%20sensitive%20data%20by%20rogue%20DBAs%2C%20admins%2C%20and%20cloud%20operators.%20Your%20data%20gets%20transparently%20encrypted%20and%20decrypted%20on%20the%20client%20side%20and%20it%20is%20never%20revealed%20in%20plaintext%20in%20the%20database%20system.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAlways%20Encrypted%20with%20secure%20enclaves%3C%2FSTRONG%3E%20extends%20Always%20Encrypted%20by%20allowing%20sensitive%20data%20to%20be%20decrypted%20within%20a%20server-side%20trusted%20execution%20environment%2C%20called%20a%20secure%20enclave%20-%20a%20protected%20region%20of%20memory%20within%20the%20database%20system%20process%2C%20which%20appears%20as%20a%20black%20box%20to%20the%20database%20system%20and%20other%20processes%20on%20the%20hosting%20machine.%20There%20is%20no%20way%20to%20view%20any%20data%20or%20code%20inside%20the%20enclave%20from%20the%20outside.%20Thus%2C%20the%20enclave%20can%20safely%20perform%20computations%20on%20plaintext%20data%20within%20the%20database%20system.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22ae-data-flow.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F295514i8F9268CD1C7EAAEB%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22ae-data-flow.png%22%20alt%3D%22ae-data-flow.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlways%20Encrypted%20with%20secure%20enclaves%2C%20now%20generally%20available%20in%20Azure%20SQL%20Database%2C%20provides%20two%20main%20benefits%3A%20in-place%20encryption%20and%20rich%20confidential%20queries.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--410628756%22%20id%3D%22toc-hId--410628754%22%3EIn-place%20encryption%3C%2FH2%3E%0A%3CP%3EWithout%20secure%20enclaves%2C%20setting%20up%20Always%20Encrypted%20can%20be%20challenging%20%E2%80%93%20since%20the%20database%20system%20has%2C%20by%20design%2C%20no%20access%20to%20cryptographic%20keys%2C%20encrypting%20a%20column%20requires%20data%20to%20be%20moved%20and%20encrypted%20outside%20of%20the%20database.%20As%20a%20result%2C%20the%20encryption%20process%20can%20take%20a%20long%20time%20and%20is%20prone%20to%20network%20errors.%20And%2C%20if%20you%20need%20to%20re-encrypt%20your%20column%20later%2C%20for%20example%20to%20rotate%20the%20column%20encryption%20key%20or%20to%20change%20the%20type%20of%20encryption%2C%20you%20will%20face%20the%20same%20challenges%20again.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWith%20a%20secure%20enclave%20available%20inside%20your%20database%20system%2C%20there%20is%20no%20need%20to%20move%20your%20data%20for%20cryptographic%20operations.%20Since%20the%20enclave%20is%20trusted%2C%20a%20client%20driver%20within%20your%20application%20or%20a%20tool%2C%20such%20as%20Azure%20Data%20Studio%20or%20SQL%20Server%20Management%20Studio%2C%20can%20securely%20share%20the%20keys%20with%20the%20enclave%20for%20the%20duration%20of%20cryptographic%20operations.%20The%20enclave%20can%20encrypt%20or%20re-encrypt%20columns%20in-place.%20This%20typically%20results%20in%20a%20dramatic%20reduction%20of%20time%20needed%20to%20perform%20such%20operations.%26nbsp%3B%3C%2FP%3E%0A%3CTABLE%20style%3D%22border-style%3A%20none%3B%20width%3A%20100%25%3B%22%20border%3D%221%22%20width%3D%22100%25%22%3E%0A%3CTBODY%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2250%25%22%20style%3D%22width%3A%205%25%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22UWM_logo.jpg%22%20style%3D%22width%3A%20800px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F296137iD6D6718C9E863CA5%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22UWM_logo.jpg%22%20alt%3D%22UWM_logo.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FTD%3E%0A%3CTD%20width%3D%2250%25%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.uwm.com%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EUnited%20Wholesale%20Mortgage%3C%2FA%3E%26nbsp%3Bis%20one%20of%20the%20customers%20benefiting%20from%20in-place%20encryption%3A%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CEM%3EOur%20project%20involves%20protecting%20sensitive%20financial%20information%20stored%20in%20large%20tables%2C%20with%20hundreds%20of%20millions%20of%20rows.%20The%20performance%20of%20encrypting%20such%20large%20data%20sets%20is%20critical.%20With%20secure%20enclaves%20we%20have%20seen%20dramatic%20improvements%20in%20the%20speed%20of%20encryption%2C%20compared%20to%20Always%20Encrypted%20not%20using%20enclaves.%20Encrypting%20columns%20in%20a%20table%20with%20over%20700%20million%20rows%20used%20to%20take%20days.%20Now%2C%20with%20secure%20enclaves%20supporting%20in-place%20encryption%2C%20the%20time%20is%20reduced%20to%205%20hours.%20-%26nbsp%3BErick%20Wittrock%2C%20Cloud%20Engineer%2C%20United%20Wholesale%20Mortgage.%3C%2FEM%3E%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3C%2FTBODY%3E%0A%3C%2FTABLE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-2076884077%22%20id%3D%22toc-hId-2076884079%22%3ERich%20confidential%20queries%3C%2FH2%3E%0A%3CP%3EMost%20client-side%20encryption%20technologies%20allow%20no%20operations%20on%20protected%20data%20within%20a%20database%20server.%20Always%20Encrypted%20(without%20secure%20enclaves)%20supports%20only%20one%20operation%20on%20encrypted%20columns%3A%20equality%20comparison.%20Many%20applications%2C%20however%2C%20require%20richer%20data%20processing.%20For%20example%2C%20personally%20identifiable%20information%20(PII)%2C%20such%20as%20people%20names%2C%20addresses%2C%20national%20identification%20numbers%2C%20or%20credit%20card%20numbers%20often%20require%20pattern%20matching%20or%20sorting.%20If%20you%20want%20to%20protect%20your%20data%20from%20malicious%20admins%20and%20perform%20such%20computations%20without%20enclaves%2C%20the%20only%20option%20is%20to%20move%20the%20data%20to%20the%20client-side%20and%20process%20it%20within%20your%20application.%20However%2C%20this%20approach%20does%20not%20scale%20to%20large%20data%20sets%20and%20requires%20extensive%20application%20changes.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlways%20Encrypted%20with%20secure%20enclaves%20enables%20pattern%20matching%2C%20range%20comparisons%2C%20sorting%2C%20and%20more%20on%20encrypted%20columns%2C%20allowing%20you%20to%20use%20the%20database%20system%20for%20what%20it%E2%80%99s%20designed%20for%3A%20querying%20your%20data.%20There%20is%20no%20need%20for%20refactor%20your%20apps%20and%20expensive%20data%20movement.%3C%2FP%3E%0A%3CTABLE%20style%3D%22border-style%3A%20none%3B%20width%3A%20100%25%3B%22%20border%3D%221%22%20width%3D%22100%25%22%3E%0A%3CTBODY%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2250%25%22%20style%3D%22width%3A%205%25%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22rbc%20logo.jpg%22%20style%3D%22width%3A%20158px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F295834i02B40954957746E3%2Fimage-dimensions%2F158x158%3Fv%3Dv2%22%20width%3D%22158%22%20height%3D%22158%22%20role%3D%22button%22%20title%3D%22rbc%20logo.jpg%22%20alt%3D%22rbc%20logo.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FTD%3E%0A%3CTD%20width%3D%2250%25%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.rbcroyalbank.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ERoyal%20Bank%20of%20Canada%3C%2FA%3E%26nbsp%3Bis%20an%20example%20of%20a%20customer%20who%20is%20already%20leveraging%20the%20power%20of%20rich%20confidential%20computations%20provided%20by%20Always%20Encrypted%20with%20secure%20enclaves%3A%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CEM%3EOur%20project%20focuses%20on%20working%20with%20different%20partners%20to%20bring%20more%20value%20to%20respective%20customers%20by%20exchanging%20encrypted%20data%20wherein%20no%20person%2C%20process%20or%20system%20can%20see%20each%20other%E2%80%99s%20data.%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%20provides%20us%20the%20framework%20for%20managing%20encrypted%20data%20and%20running%20queries%20on%20top%20of%20them%2C%20while%20minimizing%20work%20on%20our%20end.%20By%20leveraging%20Always%20Encrypted%20that%20helps%20ensure%20that%20RBC%20and%20Microsoft%20don%E2%80%99t%20have%20access%20to%20customer%20data%2C%20we%20can%20create%20a%20new%20platform%20to%20provide%20services%20that%20we%20couldn%E2%80%99t%20offer%20before.%20%E2%80%94%26nbsp%3BEddy%20Ortiz%2C%20VP%20of%20Solution%20Acceleration%20and%20Innovation%2C%20Royal%20Bank%20of%20Canada%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EYou%20can%20learn%20more%20about%20RBC%E2%80%99s%20application%20%3CA%20href%3D%22https%3A%2F%2Fcustomers.microsoft.com%2Fen-us%2Fstory%2F1356341973555285762-royalbankofcanada-banking-capital-markets-azure%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3C%2FTBODY%3E%0A%3C%2FTABLE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-269429614%22%20id%3D%22toc-hId-269429616%22%3ENext%20steps%3C%2FH2%3E%0A%3CP%3EFor%20more%20information%20and%20to%20get%20started%20with%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%2C%20see%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAlwaysEncryptedEnclavesAzureSQLDB%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAlways%20Encrypted%20with%20secure%20enclaves%20-%20documentation%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAlwaysEncryptedEnclavesAzureSQLDBTutorial%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ETutorial%3A%20Getting%20started%20with%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fmicrosoft%2Fsql-server-samples%2Ftree%2Fmaster%2Fsamples%2Ffeatures%2Fsecurity%2Falways-encrypted-with-secure-enclaves%2Fazure-sql-database%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EGitHub%20demo%2Fsample%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F69PrhWQorEM%3Ft%3D4522%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EInside%20Azure%20Datacenter%20Architecture%20with%20Mark%20Russinovich%20(video)%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FXuoJwjOZPZw%3Ft%3D1716%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EData%20Exposed%20episode%20(video%3C%2FA%3E%3CU%3E)%3C%2FU%3E%3CU%3E%3C%2FU%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20data-unlink%3D%22true%22%3ETo%20learn%20about%20other%20confidential%20computing%20technologies%20and%20services%20in%20Azure%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Faccdocs%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20confidential%20computing%20documentation%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2544476%22%20slang%3D%22en-US%22%3E%3CP%3EAlways%20Encrypted%20with%20secure%20enclaves%20now%20generally%20available%20in%20Azure%20SQL%20Database.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2544476%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EUpdates%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Co-Authors
Version history
Last update:
‎Nov 02 2021 01:10 PM
Updated by: