tencent cloud

TencentDB for SQL Server

Release Notes and Announcements
Release Notes
Product Announcements
User Guide
Product Introduction
Overview
Product Architecture
Strengths
Use Cases
Regions and AZs
Major Version Lifecycle Explanation
Features and Differences
Instance Types
Instance Specifications
Storage Types
Common Concepts
Network Environment
License Statement
Purchase Guide
Billing Overview
Product Pricing
Purchase Methods
Renewal Instructions
Payment Overdue
Refund
From Pay-as-You-Go to Monthly Subscription
Instance Adjustment Fees Description
Local Backup Space Billing
Cross-Region Backup Billing
Viewing Bill Details
Getting Started
Creating TencentDB for SQL Server Instance
Connecting to TencentDB for SQL Server Instance
Managing TencentDB for SQL Server Instance
Operation Guide
Constraints and Limits
Usage Specifications and Suggestions
Maintaining Instance
Adjusting Instance Configuration
Read-Only Instance
Network and Security
Account Management
Database Management
Data Security
Parameter Configuration
Monitoring and Alarms
Backup and Restoration 
Log Management
Publish-Subscribe
SSIS
Data Migration (New)
Data Migration (Legacy)
Data Synchronization (DTS) 
Practical Tutorial
TencentDB for SQL Server Methods for Regular Maintenance
TencentDB for SQL Server Optimization of Slow SQL
How to Better Use Tempdb
Cross-Account Backup Restoration
Creating VPC for TencentDB for SQL Server
Connecting Kingdee K/3 WISE to TencentDB for SQL Server
Account Permissions and Permission Control
Enabling and Disabling the CDC Feature
Shrinking a Database
API Documentation
History
Introduction
API Category
Making API Requests
Sales and fee related APIs
Instance Management related APIs
Operation and maintenance management related APIs
Network management related APIs
Account management related APIs
Database management related APIs
Security group management related APIs
Data security encryption related APIs
Parameter configuration related APIs
Extended Event related APIs
Log management related APIs
Read only instance management related APIs
Publish and subscribe related APIs
Backup related APIs
Rollback related APIs
Data migration (cold standby migration) related APIs
SQL Server Integration Services (SSIS) related APIs
Data migration (DTS old version) related APIs
Data Types
Error Codes
FAQs
Overview
Model Selection
Pricing and Selection
Connection and Network
Account and Permission
Backup and Rollback
Data Migration
Publish/Subscribe
Read-Only Instance
Version and Architecture Upgrade
Disk Space and Specification Adjustment
Monitoring and Alarms
Log-Related
Parameter Modification
Features
Performance, Space, and Memory-Related FAQs
Service Agreement
Service Level Agreement
Terms of Service
Performance Evaluation
Performance Test Report
Glossary
Contact Us

Disk Encryption

PDF
フォーカスモード
フォントサイズ
最終更新日: 2025-05-19 16:50:34
This document describes the disk encryption feature of TencentDB for SQL Server.

Feature Overview

Disk encryption is a technology used to protect the security of data stored on disks (including cloud disks). It prevents unauthorized access and data leakage by encrypting the data on disks. TencentDB for SQL Server provides the disk encryption feature. When data stored on disks needs to be encrypted and protected to meet security or compliance requirements, you can enable the disk encryption feature to effectively protect data security. Enabling the disk encryption feature will not affect your business, and no transformation is required for applications.

Support

Supported region of this feature: Shanghai.
Supported database versions of this feature: SQL Server 2019/2022 Enterprise.
Supported instance architectures and types of this feature: Architectures: single-node, two-node, and multi-node; types: primary instance and read-only instance. Business intelligence servers are not supported.
Supported storage types of this feature: cloud disks of the following types: Premium Disk, Cloud SSD, Balanced SSD, and Enhanced SSD.
Note:
Users who satisfy all the above conditions can apply for whitelisting and use the disk encryption feature. Disk encryption is not supported in other regions or for other versions. You can submit a ticket for application if needed.

Key

After the disk encryption feature is enabled, the privacy of data is effectively protected by using the infrastructure provided by Tencent Cloud Key Management Service (KMS). Tencent Cloud uses the industry-standard AES-256 algorithm and data keys to encrypt your data on cloud disks. The system will automatically create a customer master key (CMK) specially used for cloud disk data encryption in your corresponding region of KMS when you use disk encryption for the first time. The key is unique and is stored on KMS protected under strict physical and logical security controls.

Billing Instructions

Currently, disk encryption is a free feature. Data read/write and storage on cloud disks will not incur fees.

Note

This feature can only be enabled when an instance is created. It cannot be enabled after an instance is created.
This feature cannot be disabled once it is enabled.
The Disk Encryption field is displayed on the details page only for instances with the disk encryption feature enabled.
This feature currently only supports using keys provided by Tencent Cloud. User-defined keys are not supported.

Enabling Disk Encryption

2. Select Premium Disk, Cloud SSD, Balanced SSD, or Enhanced SSD for the storage type field.
3. Click the button next to Disk Encryption and retain the default option Provided by Tencent Cloud for Key Source.

Note:
For the complete steps to create an instance, see Creating TencentDB for SQL Server Instance.

Viewing the Disk Encryption Status

1. Log in to the SQL Server Console.
2. Select a region and in the instance list, click the Instance ID or Manage in the Operation column for the target instance.
3. In the instance information area on the right side of the Instance Details page, you can view the Disk Encryption field to check whether the disk encryption feature is enabled for an instance.

If the Disk Encryption field is displayed and the encryption status is on, the disk encryption feature is enabled for this instance. The second-generation encryption technology ENCRYPT_V2 is used, featuring higher efficiency and better performance.
If the Disk Encryption field is not displayed, the disk encryption feature is not enabled for this instance.

Related APIs

API
Description
This API is used to create a read-only instance (cloud disk).
This API is used to create a Basic Edition instance (cloud disk).
This API is used to create a highly available instance (cloud disk).
This API is used to query attributes of an instance.

ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック