A financial institution is designing a new customer-facing web application that will handle sensitive personal and financial data. The application will leverage Azure App Service for hosting and Azure SQL Database for data storage. The security architect needs to implement a solution that ensures all data, both at rest and in transit, within the Azure SQL Database is encrypted, and that the encryption keys are managed outside the database itself, with strict access controls. Furthermore, the solution must minimize changes to the application code for encryption/decryption operations. Which Azure service should the architect recommend to meet these requirements?
- AAzure SQL Always Encrypted with secure enclaves
- BAzure Disk Encryption
- CAzure Storage Service Encryption
- DTransparent Data Encryption (TDE)
Show answer & explanationAnswer & explanation
Correct answer: A. Azure SQL Always Encrypted with secure enclaves
Azure SQL Always Encrypted with secure enclaves allows sensitive data to be encrypted on the client side and remain encrypted while processed on the server side within a secure enclave, meeting the requirement for encryption both at rest and in transit. The keys are managed by the client application, outside the database, and it minimizes application code changes.
Why the other options are wrong
- B. Azure Disk Encryption encrypts the entire disk where the database files reside, but it does not encrypt data within the database itself or manage keys separately from the database engine.
- C. Azure Storage Service Encryption encrypts the underlying storage where Azure SQL Database files are stored, but it does not provide column-level encryption or external key management for data within the database.
- D. Transparent Data Encryption (TDE) encrypts the entire database data and log files at rest but decrypts data for processing in memory, and keys are managed within Azure SQL Database.
Azure SQL Always Encrypted with secure enclaves
A feature in Azure SQL Database that encrypts sensitive data inside client applications and never reveals the encryption keys to the database engine, even when processing data within a secure enclave.
- Data remains encrypted in client applications, in transit, at rest, and even during computation within secure enclaves.
- Encryption keys are managed outside the database.
- Minimizes changes to application code for encryption/decryption.
Memory trick: Always Encrypted ensures SQL data is a secret, even to the server, protected by enclaves and external keys.