Skip to main content

Overview

encrypted dataSQL ServerTDE / cell encryption (EKM)wrap / unwrapkey controlDuoKey Cockpityour key (EKM)vault APIVault / HSMkey never exportedRevoke the key → instant lockout
SQL Server keeps the data; DuoKey keeps the key. You stay in control — revoke the key and the data goes dark, everywhere.
Applies to:
SQL Server 2016+Windows Server 2012 R2+Windows onlyEnterprise / Developer

What is SQL EKM?​

DuoKey SQL EKM (Extensible Key Management) is a comprehensive solution that enables Microsoft SQL Server to use external key management for Transparent Data Encryption (TDE). This integration provides enhanced security by storing encryption keys outside the database, giving organizations greater control over their data protection.

Key Sovereignty

Full control over your encryption keys, stored in the vault you select for this app - a DuoKey-managed software vault, MPC-based backend, or a supported third-party HSM

Enhanced Security

Keys stored separately from database infrastructure for defense-in-depth

Seamless Integration

Native SQL Server EKM support with transparent encryption/decryption

Compliance Ready

Meets GDPR, HIPAA, PCI-DSS, and other regulatory requirements

Note

EKM is an Enterprise-tier feature, available in SQL Server Enterprise and Developer editions on Windows (SQL Server 2016 and later). Standard, Express, and LocalDB editions do not support EKM. Azure SQL Managed Instance and SQL Server on Linux cannot load a custom Windows EKM provider and are not supported.

Architecture​

DuoKey SQL EKM provides a seamless bridge between SQL Server's native TDE capabilities and external key management through a cryptographic provider DLL.

SQL Server

TDE Engine
EKM ProviderDuoKeyCryptoProvider.dll
HTTPS 443
▶

DuoKey Cloud

Key Vault
MPC HSMFIPS 140-2 Level 3

System Components​

ComponentLocationDescription
DuoKey Cloud PlatformCloudCentral key management service backed by the vault selected for the app (software vault, MPC-based, or HSM)
DuoKey EKM ProviderSQL ServerCryptographic provider DLL (DuoKeyCryptoProvider.dll)
SQL Server TDESQL ServerNative Transparent Data Encryption engine
Asymmetric Keymaster databaseRSA key protecting the DEK (RSA_2048, RSA_3072, or RSA_4096 - selected when the app is created)
Database Encryption KeyUser databaseAES-256 key encrypting data files

Encryption Hierarchy​

SQL Server TDE with DuoKey EKM uses a multi-layer encryption hierarchy. Each layer protects the layer below it, with the Master Encryption Key (MEK) in DuoKey serving as the root of trust.

DuoKey Cloud Platform

Master Encryption Key (MEK)

MPC Protected
Protects

SQL Server (master database)

Asymmetric Key (EKM)

RSA-2048
Protects

User Database

Database Encryption Key (DEK)

AES-256
Encrypts

Data Files

.mdf, .ndf, .ldf

Encrypted at Rest
Tip

This hierarchy ensures that even if database files are stolen, they cannot be decrypted without access to the DuoKey platform where the MEK resides.

Key Features​

Transparent Data Encryption

Encrypt databases at rest without application changes.

External Key Storage

Keys stored securely in the vault backing your SQL EKM app - software vault, MPC-based, or HSM.

Key Rotation Support

Seamlessly rotate encryption keys without downtime.

Multi-Server Support

Deploy across multiple SQL Server instances.

Backup & Restore

Encrypted backups work across any configured server.

Audit & Compliance

Comprehensive logging for all key operations.

System Requirements​

SQL Server

  • SQL Server 2016 or later
  • Enterprise or Developer edition
  • EKM must be enabled

Operating System

  • Windows Server 2012 R2+
  • Windows 10/11 (dev only)
  • 64-bit architecture

Network

  • HTTPS to DuoKey platform
  • Port 443 outbound
  • TLS 1.2 or higher

Prerequisites

  • DuoKey platform account
  • SQL EKM app created
  • Administrator privileges
Caution

Only SQL Server Enterprise and Developer editions on Windows support Extensible Key Management. Standard, Express, and LocalDB editions do not, and EKM is not available on Azure SQL Managed Instance or SQL Server on Linux.

Getting Started​

Ready to implement SQL EKM? Follow these guides:

Tip

See the Quick Start Guide for a complete walkthrough.