Always Encrypted with secure enclaves in Azure SQL Database preview

Published Feb 01 2021 02:15 PM 9,389 Views
Microsoft

Moving to the cloud has clear economic benefits: cost savings, productivity gains, scalability, and agility, to name a few. However, many organizations keep sensitive data out of the public cloud due to regulations or to remain in full control, and thus they are missing out on those benefits.

 

Keep control of your data

Always Encrypted allows you to store your most sensitive data in the public cloud without giving up the control. With Always Encrypted, your data gets transparently encrypted and decrypted outside of the database (inside the client application) using keys that are never revealed to the database system. As a result, administrators, including cloud operators, cannot see the data or the keys in plaintext. For example, a DBA can query a table holding sensitive data or an OS admin can read the memory of the database system process, but all they can access is encrypted data, not plaintext.


Confidential computing

Client-side encryption typically makes it impossible for the database system to perform any computations on encrypted data, which makes it extremely costly to deploy. To work around it, you need to refactor your apps to perform computations outside of the database, which is often impractical.

 

Always Encrypted addresses this challenge with confidential computing – the ability to process queries on encrypted data without exposing the data in the clear to admins.


Secure enclaves open new possibilities
Until now, Always Encrypted has supported confidential computing with deterministic encryption, which enables simple point lookup searches and equality joins on encrypted data within the database system.


Now in preview in Azure SQL Database, Always Encrypted with secure enclaves takes confidential computing to the next level. A secure enclave is a protected region of memory within the SQL database engine process. It acts as a trusted execution environment for processing sensitive data inside the database engine. A secure enclave appears as an opaque box for the rest of the database engine process and other processes on the hosting machine. There is no way to view any data or code inside the enclave from the outside, even with a debugger. Therefore, during query processing, the secure enclave can safely decrypt sensitive data and perform rich computations on the plaintext.

 

 

ae-data-flow.png

Always Encrypted with secure enclaves provides two key benefits:

  • Rich confidential queries, including pattern matching (LIKE) and range comparisons. These new capabilities make it possible to protect a much broader set of sensitive information (names, address, phone numbers, sensitive numerical data) without painful compromises.
  • In-place encryption – allowing cryptographic operations inside the secure enclave, to eliminate the need to move the data outside of the database for initial encryption or key rotation.

In Azure SQL Database, Always Encrypted uses Intel Software Guard Extensions (Intel SGX) enclaves - a hardware technology supported in databases that use the new DC-series hardware generation, now also in preview. Selecting DC-series for your database places it on the hardware equipped with Intel SGX, which is a prerequisite for enabling Always Encrypted with secure enclaves.


With this release, Azure SQL Database joins the growing family of Azure confidential computing services, including confidential virtual machines, confidential containers, confidential machine learning, and confidential IoT edge devices.


Customers who are already using secure enclaves
Here are some examples of customers who are already using Always Encrypted with secure enclaves in Azure SQL Database.


Royal Bank of Canada 

"Our project focuses on working with different partners to bring more value to respective customers by exchanging encrypted data wherein no person, process or system can see each other’s data. Always Encrypted with secure enclaves in Azure SQL Database provides us the framework for managing encrypted data and running queries on top of them, while minimizing work on our end. By leveraging Always Encrypted that helps ensure that RBC and Microsoft don’t have access to customer data, we can create a new platform to provide services that we couldn’t offer before." — Eddy Ortiz, VP of Solution Acceleration and Innovation, Royal Bank of Canada

 

Financial Fabric 

"Always Encrypted with secure enclaves enables the DataHub service from Financial Fabric to meet the strictest of Financial Services Industry data security requirements where PII data remains encrypted throughout its life cycle. Financial calculations on sensitive data are computed completely within the secure "walls" of the enclave giving banks, hedge funds and investors control so that their unencrypted PII data and related computations stay within the secure enclave." — Paul A. Stirpe Ph.D., Chief Technology Officer, Financial Fabric

 

Next steps
For more information and to get started with Always Encrypted with secure enclaves, see:

1 Comment
Occasional Visitor

I have been working with Secure Enclaves on Azure SQL and have seen dramatic improvements in the speed of encryption versus Always Encrypted without Secure Enclaves.  I am working on tables with hundreds of millions of rows and performance is critical.  

%3CLINGO-SUB%20id%3D%22lingo-sub-2051544%22%20slang%3D%22en-US%22%3EAlways%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%20preview%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2051544%22%20slang%3D%22en-US%22%3E%3CP%3EMoving%20to%20the%20cloud%20has%20clear%20economic%20benefits%3A%20cost%20savings%2C%20productivity%20gains%2C%20scalability%2C%20and%20agility%2C%20to%20name%20a%20few.%20However%2C%20many%20organizations%20keep%20sensitive%20data%20out%20of%20the%20public%20cloud%20due%20to%20regulations%20or%20to%20remain%20in%20full%20control%2C%20and%20thus%20they%20are%20missing%20out%20on%20those%20benefits.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%225%22%3EKeep%20control%20of%20your%20data%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3EAlways%20Encrypted%20allows%20you%20to%20store%20your%20most%20sensitive%20data%20in%20the%20public%20cloud%20without%20giving%20up%20the%20control.%20With%20Always%20Encrypted%2C%20your%20data%20gets%20transparently%20encrypted%20and%20decrypted%20outside%20of%20the%20database%20(inside%20the%20client%20application)%20using%20keys%20that%20are%20never%20revealed%20to%20the%20database%20system.%20As%20a%20result%2C%20administrators%2C%20including%20cloud%20operators%2C%20cannot%20see%20the%20data%20or%20the%20keys%20in%20plaintext.%20For%20example%2C%20a%20DBA%20can%20query%20a%20table%20holding%20sensitive%20data%20or%20an%20OS%20admin%20can%20read%20the%20memory%20of%20the%20database%20system%20process%2C%20but%20all%20they%20can%20access%20is%20encrypted%20data%2C%20not%20plaintext.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CFONT%20size%3D%225%22%3EConfidential%20computing%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3EClient-side%20encryption%20typically%20makes%20it%20impossible%20for%20the%20database%20system%20to%20perform%20any%20computations%20on%20encrypted%20data%2C%20which%20makes%20it%20extremely%20costly%20to%20deploy.%20To%20work%20around%20it%2C%20you%20need%20to%20refactor%20your%20apps%20to%20perform%20computations%20outside%20of%20the%20database%2C%20which%20is%20often%20impractical.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlways%20Encrypted%20addresses%20this%20challenge%20with%20confidential%20computing%20%E2%80%93%20the%20ability%20to%20process%20queries%20on%20encrypted%20data%20without%20exposing%20the%20data%20in%20the%20clear%20to%20admins.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CFONT%20size%3D%225%22%3ESecure%20enclaves%20open%20new%20possibilities%3C%2FFONT%3E%3CBR%20%2F%3EUntil%20now%2C%20Always%20Encrypted%20has%20supported%20confidential%20computing%20with%20deterministic%20encryption%2C%20which%20enables%20simple%20point%20lookup%20searches%20and%20equality%20joins%20on%20encrypted%20data%20within%20the%20database%20system.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3ENow%20in%20preview%20in%20Azure%20SQL%20Database%2C%20%3CSTRONG%3EAlways%20Encrypted%20with%20secure%20enclaves%3C%2FSTRONG%3E%20takes%20confidential%20computing%20to%20the%20next%20level.%20A%20secure%20enclave%20is%20a%20protected%20region%20of%20memory%20within%20the%20SQL%20database%20engine%20process.%20It%20acts%20as%20a%20trusted%20execution%20environment%20for%20processing%20sensitive%20data%20inside%20the%20database%20engine.%20A%20secure%20enclave%20appears%20as%20an%20opaque%20box%20for%20the%20rest%20of%20the%20database%20engine%20process%20and%20other%20processes%20on%20the%20hosting%20machine.%20There%20is%20no%20way%20to%20view%20any%20data%20or%20code%20inside%20the%20enclave%20from%20the%20outside%2C%20even%20with%20a%20debugger.%20Therefore%2C%20during%20query%20processing%2C%20the%20secure%20enclave%20can%20safely%20decrypt%20sensitive%20data%20and%20perform%20rich%20computations%20on%20the%20plaintext.%20%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22ae-data-flow.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F246816i84966E5ED687F1F3%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22ae-data-flow.png%22%20alt%3D%22ae-data-flow.png%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3EAlways%20Encrypted%20with%20secure%20enclaves%20provides%20two%20key%20benefits%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3ERich%20confidential%20queries%3C%2FSTRONG%3E%2C%20including%20pattern%20matching%20(LIKE)%20and%20range%20comparisons.%20These%20new%20capabilities%20make%20it%20possible%20to%20protect%20a%20much%20broader%20set%20of%20sensitive%20information%20(names%2C%20address%2C%20phone%20numbers%2C%20sensitive%20numerical%20data)%20without%20painful%20compromises.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EIn-place%20encryption%3C%2FSTRONG%3E%20%E2%80%93%20allowing%20cryptographic%20operations%20inside%20the%20secure%20enclave%2C%20to%20eliminate%20the%20need%20to%20move%20the%20data%20outside%20of%20the%20database%20for%20initial%20encryption%20or%20key%20rotation.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EIn%20Azure%20SQL%20Database%2C%20Always%20Encrypted%20uses%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FIntelBlog%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EIntel%20Software%20Guard%20Extensions%20(Intel%20SGX)%3C%2FA%3E%20enclaves%20-%20a%20hardware%20technology%20supported%20in%20databases%20that%20use%20the%20new%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fazure-sql%2Fdatabase%2Fservice-tiers-vcore%23dc-series%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EDC-series%3C%2FA%3E%20hardware%20generation%2C%20now%20also%20in%20preview.%20Selecting%20DC-series%20for%20your%20database%20places%20it%20on%20the%20hardware%20equipped%20with%20Intel%20SGX%2C%20which%20is%20a%20prerequisite%20for%20enabling%20Always%20Encrypted%20with%20secure%20enclaves.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EWith%20this%20release%2C%20Azure%20SQL%20Database%20joins%20the%20growing%20family%20of%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzureCC%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20confidential%20computing%20services%3C%2FA%3E%2C%20including%20confidential%20virtual%20machines%2C%20confidential%20containers%2C%20confidential%20machine%20learning%2C%20and%20confidential%20IoT%20edge%20devices.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CFONT%20size%3D%225%22%3ECustomers%20who%20are%20already%20using%20secure%20enclaves%3C%2FFONT%3E%3CBR%20%2F%3EHere%20are%20some%20examples%20of%20customers%20who%20are%20already%20using%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.rbcroyalbank.com%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ERoyal%20Bank%20of%20Canada%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CEM%3E%22Our%20project%20focuses%20on%20working%20with%20different%20partners%20to%20bring%20more%20value%20to%20respective%20customers%20by%20exchanging%20encrypted%20data%20wherein%20no%20person%2C%20process%20or%20system%20can%20see%20each%20other%E2%80%99s%20data.%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%20provides%20us%20the%20framework%20for%20managing%20encrypted%20data%20and%20running%20queries%20on%20top%20of%20them%2C%20while%20minimizing%20work%20on%20our%20end.%20By%20leveraging%20Always%20Encrypted%20that%20helps%20ensure%20that%20RBC%20and%20Microsoft%20don%E2%80%99t%20have%20access%20to%20customer%20data%2C%20we%20can%20create%20a%20new%20platform%20to%20provide%20services%20that%20we%20couldn%E2%80%99t%20offer%20before.%22%26nbsp%3B%E2%80%94%26nbsp%3B%3C%2FEM%3E%3CEM%3EEddy%20Ortiz%2C%20VP%20of%20Solution%20Acceleration%20and%20Innovation%2C%20Royal%20Bank%20of%20Canada%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.financialfabric.com%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EFinancial%20Fabric%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CEM%3E%22Always%20Encrypted%20with%20secure%20enclaves%20enables%20the%20DataHub%20service%20from%20Financial%20Fabric%20to%20meet%20the%20strictest%20of%20Financial%20Services%20Industry%20data%20security%20requirements%20where%20PII%20data%20remains%20encrypted%20throughout%20its%20life%20cycle.%20Financial%20calculations%20on%20sensitive%20data%20are%20computed%20completely%20within%20the%20secure%20%22walls%22%20of%20the%20enclave%20giving%20banks%2C%20hedge%20funds%20and%20investors%20control%20so%20that%20their%20unencrypted%20PII%20data%20and%20related%20computations%20stay%20within%20the%20secure%20enclave.%22%20%E2%80%94%20Paul%20A.%20Stirpe%20Ph.D.%2C%20Chief%20Technology%20Officer%2C%20Financial%20Fabric%3CBR%20%2F%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%225%22%3ENext%20steps%3C%2FFONT%3E%3CBR%20%2F%3EFor%20more%20information%20and%20to%20get%20started%20with%20Always%20Encrypted%20with%20secure%20enclaves%2C%20see%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAlwaysEncryptedEnclavesAzureSQLDB%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAlways%20Encrypted%20with%20secure%20enclaves%20-%20documentation%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAlwaysEncryptedEnclavesAzureSQLDBTutorial%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ETutorial%3A%20Getting%20started%20with%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fwww.youtube.com%252Fwatch%253Fv%253Dtp-eawkI_GM%2526t%253D394s%26amp%3Bdata%3D04%257C01%257Cjaszymas%2540microsoft.com%257C0095febfc57c47c7e6b708d8c31e13ad%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637473881227710831%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DcFtDF8Bb%252Fz8U%252B4X0VS0hycutYhshdGaiaxwGywxSybk%253D%26amp%3Breserved%3D0%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EData%20Exposed%20video%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAlwaysEncryptedEnclavesSQLDBWebinar%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EA%20webinar%20including%20a%20deep%20dive%20on%20Always%20Encrypted%20with%20secure%20enclaves%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2051544%22%20slang%3D%22en-US%22%3E%3CP%3EAlways%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%20leverages%20Intel%20SGX%20to%20enable%20in-place%20encryption%20and%20rich%20confidential%20queries.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2051544%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20SQL%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2451440%22%20slang%3D%22en-US%22%3ERe%3A%20Always%20Encrypted%20with%20secure%20enclaves%20in%20Azure%20SQL%20Database%20preview%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2451440%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20been%20working%20with%20Secure%20Enclaves%20on%20Azure%20SQL%20and%20have%20seen%20dramatic%20improvements%20in%20the%20speed%20of%20encryption%20versus%20Always%20Encrypted%20without%20Secure%20Enclaves.%26nbsp%3B%20I%20am%20working%20on%20tables%20with%20hundreds%20of%20millions%20of%20rows%20and%20performance%20is%20critical.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎Feb 01 2021 02:14 PM
Updated by: