Overview
DuoKey SQL EKM Overview
External key management for Microsoft SQL Server Transparent Data Encryption
What is SQL EKM?
DuoKey SQL EKM (Extensible Key Management) is a comprehensive solution that enables Microsoft SQL Server to use external key management for Transparent Data Encryption (TDE). This integration provides enhanced security by storing encryption keys outside the database, giving organizations greater control over their data protection.
Key Sovereignty
Full control over your encryption keys, stored in the vault you select for this app - a DuoKey-managed software vault, MPC-based backend, or a supported third-party HSM
Enhanced Security
Keys stored separately from database infrastructure for defense-in-depth
Seamless Integration
Native SQL Server EKM support with transparent encryption/decryption
Compliance Ready
Meets GDPR, HIPAA, PCI-DSS, and other regulatory requirements
EKM is an Enterprise-tier feature, available in SQL Server Enterprise and Developer editions on Windows (SQL Server 2016 and later). Standard, Express, and LocalDB editions do not support EKM. Azure SQL Managed Instance and SQL Server on Linux cannot load a custom Windows EKM provider and are not supported.
Architecture
DuoKey SQL EKM provides a seamless bridge between SQL Server's native TDE capabilities and external key management through a cryptographic provider DLL.
SQL Server
DuoKey Cloud
System Components
| Component | Location | Description |
|---|---|---|
| DuoKey Cloud Platform | Cloud | Central key management service backed by the vault selected for the app (software vault, MPC-based, or HSM) |
| DuoKey EKM Provider | SQL Server | Cryptographic provider DLL (DuoKeyCryptoProvider.dll) |
| SQL Server TDE | SQL Server | Native Transparent Data Encryption engine |
| Asymmetric Key | master database | RSA key protecting the DEK (RSA_2048, RSA_3072, or RSA_4096 - selected when the app is created) |
| Database Encryption Key | User database | AES-256 key encrypting data files |
Encryption Hierarchy
SQL Server TDE with DuoKey EKM uses a multi-layer encryption hierarchy. Each layer protects the layer below it, with the Master Encryption Key (MEK) in DuoKey serving as the root of trust.
DuoKey Cloud Platform
Master Encryption Key (MEK)
MPC ProtectedSQL Server (master database)
Asymmetric Key (EKM)
RSA-2048User Database
Database Encryption Key (DEK)
AES-256Data Files
.mdf, .ndf, .ldf
Encrypted at RestThis hierarchy ensures that even if database files are stolen, they cannot be decrypted without access to the DuoKey platform where the MEK resides.
Key Features
Transparent Data Encryption
Encrypt databases at rest without application changes.
External Key Storage
Keys stored securely in the vault backing your SQL EKM app - software vault, MPC-based, or HSM.
Key Rotation Support
Seamlessly rotate encryption keys without downtime.
Multi-Server Support
Deploy across multiple SQL Server instances.
Backup & Restore
Encrypted backups work across any configured server.
Audit & Compliance
Comprehensive logging for all key operations.
System Requirements
SQL Server
- SQL Server 2016 or later
- Enterprise or Developer edition
- EKM must be enabled
Operating System
- Windows Server 2012 R2+
- Windows 10/11 (dev only)
- 64-bit architecture
Network
- HTTPS to DuoKey platform
- Port 443 outbound
- TLS 1.2 or higher
Prerequisites
- DuoKey platform account
- SQL EKM app created
- Administrator privileges
Only SQL Server Enterprise and Developer editions on Windows support Extensible Key Management. Standard, Express, and LocalDB editions do not, and EKM is not available on Azure SQL Managed Instance or SQL Server on Linux.
Getting Started
Ready to implement SQL EKM? Follow these guides:
Create App
Set up DuoKey app
Install
Install EKM provider
Configure
Configure SQL Server
Encrypt
Enable TDE
See the Quick Start Guide for a complete walkthrough.