語言

SqlColumnEncryptionAzureKeyVaultProvider 類別

定義

實作欄位主金鑰儲存提供者,允許用戶端應用程式在欄位主金鑰儲存在 Microsoft Microsoft Azure Key Vault 時存取資料。

欲了解更多關於 Always Encrypted 的資訊,請參考: https://aka.ms/AlwaysEncrypted。

以憑證儲存提供者加密的欄位加密金鑰,應能被該提供者解密,反之亦然。

加密欄位加密金鑰的信封格式:版本 + keyPathLength + 密文長度 + keyPath + 密文 + 簽名

  • 版本:一個位元組表示格式版本。
  • keyPathLength:keyPath 的長度。
  • 密文長度:密文長度
  • keyPath:用於加密欄位加密金鑰的 keyPath。 這僅用於故障排除,解密時不會驗證。
  • 密文:加密欄位加密金鑰
  • 簽名:整個位元組陣列的簽名。 簽章會在解密欄位加密金鑰前進行驗證。
public ref class SqlColumnEncryptionAzureKeyVaultProvider : Microsoft::Data::SqlClient::SqlColumnEncryptionKeyStoreProvider
public class SqlColumnEncryptionAzureKeyVaultProvider : Microsoft.Data.SqlClient.SqlColumnEncryptionKeyStoreProvider
type SqlColumnEncryptionAzureKeyVaultProvider = class
    inherit SqlColumnEncryptionKeyStoreProvider
Public Class SqlColumnEncryptionAzureKeyVaultProvider
Inherits SqlColumnEncryptionKeyStoreProvider
繼承
SqlColumnEncryptionAzureKeyVaultProvider

備註

欲了解更多資訊,請參閱:使用 Azure Key Vault 提供者

建構函式

名稱 Description
SqlColumnEncryptionAzureKeyVaultProvider(TokenCredential, String)

建構器採用 Token Credential 實作,能提供 OAuth 令牌及受信任端點。

SqlColumnEncryptionAzureKeyVaultProvider(TokenCredential, String[])

建構器採用一個能提供 OAuth 憑證及多個受信任端點陣列的 Token 憑證實作實例。

SqlColumnEncryptionAzureKeyVaultProvider(TokenCredential)

建構器採用能提供 OAuth 令牌的憑證實作。

欄位

名稱 Description
ProviderName

欄位加密金鑰儲存提供者字串

TrustedEndPoints

受信任端點列表

屬性

名稱 Description
ColumnEncryptionKeyCacheTtl

取得或設定解密後的欄加密金鑰在快取中的壽命。 時間跨度結束後,解密後的欄位加密金鑰會被丟棄,並必須重新驗證。

方法

名稱 Description
DecryptColumnEncryptionKey(String, String, Byte[])

此函式使用金鑰路徑指定的非對稱金鑰,並以 RSA 加密演算法解密加密的 CEK。

DecryptColumnEncryptionKeyAsync(String, String, Byte[], CancellationToken)

非同步使用金鑰路徑指定的非對稱金鑰,並以 RSA 加密演算法解密加密後的 CEK。

EncryptColumnEncryptionKey(String, String, Byte[])

此函式使用金鑰路徑指定的非對稱金鑰,並以 RSA 加密演算法加密 CEK。

EncryptColumnEncryptionKeyAsync(String, String, Byte[], CancellationToken)

非同步使用金鑰路徑指定的非對稱金鑰,並以 RSA 加密演算法加密 CEK。

SignColumnMasterKeyMetadata(String, Boolean)

使用由金鑰路徑識別的非對稱金鑰來簽署由(masterKeyPath、allowEnclaveComputations bit、providerName)組成的主金鑰元資料。

SignColumnMasterKeyMetadataAsync(String, Boolean, CancellationToken)

非同步使用由密鑰路徑識別的非對稱金鑰來簽署主金鑰元資料,該資料包含(masterKeyPath、allowEnclaveComputations bit、providerName)。

VerifyColumnMasterKeyMetadata(String, Boolean, Byte[])

使用由金鑰路徑識別的非對稱金鑰來驗證主金鑰的元資料,該資料包含(masterKeyPath、allowEnclaveComputations bit、providerName)。

VerifyColumnMasterKeyMetadataAsync(String, Boolean, Byte[], CancellationToken)

非同步使用由金鑰路徑識別的非對稱金鑰來驗證由(masterKeyPath、allowEnclaveComputations bit、providerName)組成的主金鑰元資料。

適用於