Nyelv

SqlColumnEncryptionCspProvider Class

Definition

The CMK Store provider implementation for using Microsoft CAPI based Cryptographic Service Providers (CSP) with Always Encrypted.

public ref class SqlColumnEncryptionCspProvider : Microsoft::Data::SqlClient::SqlColumnEncryptionKeyStoreProvider
public class SqlColumnEncryptionCspProvider : Microsoft.Data.SqlClient.SqlColumnEncryptionKeyStoreProvider
type SqlColumnEncryptionCspProvider = class
    inherit SqlColumnEncryptionKeyStoreProvider
Public Class SqlColumnEncryptionCspProvider
Inherits SqlColumnEncryptionKeyStoreProvider
Inheritance
SqlColumnEncryptionCspProvider

Remarks

Enables storing Always Encrypted column master key keys in a store, such as a hardware security module (HSM), that supports the Microsoft CAPI based Cryptographic Service Providers (CSP).

Constructors

Name Description
SqlColumnEncryptionCspProvider()

Fields

Name Description
ProviderName

A constant string for the provider name MSSQL_CSP_PROVIDER.

Properties

Name Description
ColumnEncryptionKeyCacheTtl

Gets or sets the lifespan of the decrypted column encryption key in the cache. Once the timespan has elapsed, the decrypted column encryption key is discarded and must be revalidated.

(Inherited from SqlColumnEncryptionKeyStoreProvider)

Methods

Name Description
DecryptColumnEncryptionKey(String, String, Byte[])

Decrypts the given encrypted value using an asymmetric key specified by the key path and algorithm. The key path will be in the format of [ProviderName]/KeyIdentifier and should be an asymmetric key stored in the specified CSP provider. The valid algorithm used to encrypt/decrypt the CEK is RSA_OAEP'.

DecryptColumnEncryptionKeyAsync(String, String, Byte[], CancellationToken)

Asynchronously decrypts the specified encrypted value of a column encryption key. The encrypted value is expected to be encrypted using the column master key with the specified key path and using the specified algorithm.

(Inherited from SqlColumnEncryptionKeyStoreProvider)
EncryptColumnEncryptionKey(String, String, Byte[])

Encrypts the given plain text column encryption key using an asymmetric key specified by the key path and the specified algorithm. The key path will be in the format of [ProviderName]/KeyIdentifier and should be an asymmetric key stored in the specified CSP provider. The valid algorithm used to encrypt/decrypt the CEK is RSA_OAEP.

EncryptColumnEncryptionKeyAsync(String, String, Byte[], CancellationToken)

Asynchronously encrypts a column encryption key using the column master key with the specified key path and using the specified algorithm.

(Inherited from SqlColumnEncryptionKeyStoreProvider)
SignColumnMasterKeyMetadata(String, Boolean)

Throws a NotSupportedException exception in all cases.

SignColumnMasterKeyMetadataAsync(String, Boolean, CancellationToken)

When implemented in a derived class, asynchronously signs the column master key metadata with the column master key referenced by the masterKeyPath parameter.

(Inherited from SqlColumnEncryptionKeyStoreProvider)
VerifyColumnMasterKeyMetadata(String, Boolean, Byte[])

This function must be implemented by the corresponding Key Store providers. This function should use an asymmetric key identified by a key path and sign the masterkey metadata consisting of (masterKeyPath, allowEnclaveComputations, ProviderName).

VerifyColumnMasterKeyMetadataAsync(String, Boolean, Byte[], CancellationToken)

When implemented in a derived class, asynchronously verifies the specified signature is valid for the column master key with the specified key path and the specified enclave behavior. The default implementation returns a faulted task with NotImplementedException.

(Inherited from SqlColumnEncryptionKeyStoreProvider)

Applies to