語言

SqlColumnEncryptionCngProvider 類別

定義

CMK Store 提供者實作,用於使用 Microsoft 密碼學 API:下一代 (CNG) Always Encrypted。

public ref class SqlColumnEncryptionCngProvider : Microsoft::Data::SqlClient::SqlColumnEncryptionKeyStoreProvider
public class SqlColumnEncryptionCngProvider : Microsoft.Data.SqlClient.SqlColumnEncryptionKeyStoreProvider
type SqlColumnEncryptionCngProvider = class
    inherit SqlColumnEncryptionKeyStoreProvider
Public Class SqlColumnEncryptionCngProvider
Inherits SqlColumnEncryptionKeyStoreProvider
繼承
SqlColumnEncryptionCngProvider

備註

允許將 Always Encrypted 欄位主金鑰儲存在支援 Microsoft Cryptography API: Next Generation(CNG)的硬體安全模組(HSM)中。

建構函式

名稱 Description
SqlColumnEncryptionCngProvider()

CMK Store 提供者實作,用於使用 Microsoft 密碼學 API:下一代 (CNG) Always Encrypted。

欄位

名稱 Description
ProviderName

提供者名稱 MSSQL_CNG_STORE>的一個恆定字串。

屬性

名稱 Description
ColumnEncryptionKeyCacheTtl

取得或設定解密後的欄加密金鑰在快取中的壽命。 時間跨度結束後,解密後的欄位加密金鑰會被丟棄,並必須重新驗證。

(繼承來源 SqlColumnEncryptionKeyStoreProvider)

方法

名稱 Description
DecryptColumnEncryptionKey(String, String, Byte[])

利用由金鑰路徑指定的非對稱金鑰及指定演算法解密給定的加密值。 金鑰路徑格式為 , [ProviderName]/KeyIdentifier 且應為儲存在指定 CNG 金鑰儲存提供者中的非對稱金鑰。 用於加密/解密 CEK 的有效演算法為 RSA_OAEP。

DecryptColumnEncryptionKeyAsync(String, String, Byte[], CancellationToken)

非同步解密欄位加密金鑰的指定加密值。 加密後的值預期會使用欄位主金鑰、指定的金鑰路徑及指定的演算法進行加密。

(繼承來源 SqlColumnEncryptionKeyStoreProvider)
EncryptColumnEncryptionKey(String, String, Byte[])

利用由金鑰路徑與演算法指定的非對稱金鑰加密給定的明文欄位加密金鑰。 金鑰路徑格式為 , [ProviderName]/KeyIdentifier 且應為儲存在指定 CNG 金鑰儲存提供者中的非對稱金鑰。 用於加密/解密 CEK 的有效演算法為 RSA_OAEP。

EncryptColumnEncryptionKeyAsync(String, String, Byte[], CancellationToken)

非同步地使用欄位主金鑰、指定金鑰路徑及演算法加密欄位加密金鑰。

(繼承來源 SqlColumnEncryptionKeyStoreProvider)
SignColumnMasterKeyMetadata(String, Boolean)

在所有情況下都會投 NotSupportedException 出例外。

SignColumnMasterKeyMetadataAsync(String, Boolean, CancellationToken)

當在衍生類別中實作時,非同步地以參數參考 masterKeyPath 的欄位主鍵元資料簽署。

(繼承來源 SqlColumnEncryptionKeyStoreProvider)
VerifyColumnMasterKeyMetadata(String, Boolean, Byte[])

此函式必須由對應的金鑰儲存提供者實作。 此函式應使用由金鑰路徑識別的非對稱金鑰,並驗證由(masterKeyPath、allowEnclaveComputations、providerName)組成的主金鑰元資料。

VerifyColumnMasterKeyMetadataAsync(String, Boolean, Byte[], CancellationToken)

當在衍生類別中實作時,非同步驗證指定的簽章是否適用於欄位主金鑰、指定金鑰路徑及指定 enclave 行為。 預設實作會回傳一個錯誤任務,為 NotImplementedException。

(繼承來源 SqlColumnEncryptionKeyStoreProvider)

適用於