
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
Chandrabhan Singh1, Mrs. Arifa Khan2
1Master of Technology, Computer Science and Engineering, Lucknow Institute of Technology, Lucknow, India 2Assistant Professor, Department of Computer Science and Engineering, Lucknow Institute of Technology, Lucknow, India
Abstract - The rapid digital transformation of enterprise systems has intensified the need for robust data protection mechanisms withinapplicationpersistence layers. Inmodern .NETecosystems,EntityFrameworkCore(EFCore)servesasa widelyadoptedObject–RelationalMapping(ORM)framework that abstracts database interactions, yet introduces unique security considerations at the data persistence level. This reviewcriticallyexaminesexistingapproachestosecure data persistence in enterprise .NET systems, with particular emphasisondynamicencryptionstrategiesintegratedwithEF Core. The paper synthesizes research on application-level encryption, database-native encryption mechanisms, cryptographic key management models, and runtime policy enforcementtechniques.Itsystematicallycategorizesexisting solutions based on encryption granularity, integration architecture, scalability, compliance alignment, and performanceoverhead.Furthermore,thereviewevaluatesthe roleofEFCorefeaturessuchasvalueconverters,interceptors, and middleware pipelines in implementing transparent and adaptive encryption workflows. Key challenges identified include secure key rotation, multi-tenant isolation, performance trade-offs, and limitations in current ORM-level security abstractions. By consolidating dispersed literature across enterprise security, cryptography, and .NET architectural practices, this review provides a structured taxonomyofsecurepersistencestrategiesandoutlines future researchdirectionstowardadaptive,policy-drivenencryption frameworks for enterprise-grade applications.
Key Words: Entity Framework Core; Secure Data Persistence; Dynamic Encryption; Enterprise .NET Systems; Cryptographic Key Management
Enterprise information systems increasingly operate in distributed, cloud-native, and compliance-regulated environments, where data confidentiality, integrity, and availability are critical operational requirements. As organizations rely on data-driven decision-making and digitalservicedelivery,thepersistencelayerofapplications has become a strategic security boundary. Within the Microsoft ecosystem, Entity Framework Core (EF Core) functions as a primary Object–Relational Mapping (ORM) technologythatmediatesinteractionsbetweenapplication
logic and relational databases. While EF Core enhances developer productivity and abstraction, it also introduces architecturalconsiderationsregardingsecuredatahandling, encryption integration, and runtime enforcement of protection policies. This section contextualizes the importanceofsecurepersistenceinenterprise.NETsystems andestablishestheobjectivesofthisreview.
Enterprise applications routinely process sensitive data, includingpersonallyidentifiableinformation(PII),financial records, healthcare data, and proprietary intellectual property.Theexposureofsuchdatacanresultinfinancial losses, reputational damage, and regulatory penalties. Industry analyses consistently show that data breaches frequently originate from misconfigurations, inadequate encryptioncontrols,andinsufficientaccessmanagementat theapplicationlayer(Verizon,2023).
Modern regulatory frameworks such as the General Data ProtectionRegulation(GDPR)andISO/IEC27001emphasize encryption, access governance, and accountability mechanismsasfoundationalcontrols(EuropeanParliament andCouncil,2016).Inthiscontext,application-levelsecurity cannotrelysolelyonperimeterdefenses;instead,secure-bydesign persistence mechanisms are required to enforce confidentiality and integrity directly within software architectures. Consequently, encryption strategies embeddedwithinpersistenceworkflowshaveemergedasa focalpointinsecureenterprisesoftwareengineering.
Persistenceframeworksabstractthecomplexityofdatabase communicationandenabledeveloperstointeractwithdata throughobject-orientedparadigms.EFCore,developedby Microsoft as a lightweight, cross-platform ORM, supports LINQ-based querying, change tracking, migrations, and extensibility through interceptors and value converters (Microsoft,2023).

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
EFCoreoperatesthroughalayeredarchitecturecomprising theDbContext,changetracker,querypipeline,anddatabase provider abstractions. While this abstraction enhances productivity and maintainability, it also centralizes data transformationprocesses,makingtheORMlayerastrategic insertionpointforencryptionlogic.Featuressuchasvalue convertersallowtransformationofpropertyvaluesbefore database persistence, while interceptors enable runtime inspection and modification of commands. These extensibility points provide technical opportunities for implementingdynamicencryptionpolicieswithoutaltering underlyingdatabaseschemas.
Thepersistencelayerisexposedtomultipleattackvectors, including SQL injection, unauthorized access, credential leakage,insiderthreats,anddatabaseexfiltration.Although ORMsmitigatecertaininjectionrisksthroughparameterized queries,misconfiguredrawSQLexecutionorimproperdata handlingmaystillintroducevulnerabilities(OWASP,2021).
Beyond injection attacks, data-at-rest remains vulnerable when encryption is absent or improperly managed. Database-level mechanisms such as Transparent Data Encryption (TDE) protect storage media but do not necessarily mitigate threats from privileged insiders or compromisedapplicationservers(NIST,2020).Moreover, cloud-baseddeploymentsintroduceadditionalrisksrelated to multi-tenancy, shared infrastructure, and key managementservices.Theserealitiesunderscoretheneed forlayeredencryptionstrategiesthatintegratedirectlywith the application persistence workflow rather than relying exclusivelyoninfrastructure-levelsafeguards.
This review aims to systematically examine secure data persistence strategies applicable to EF Core-based enterprise systems, with particular emphasis on dynamic encryptionmechanisms.Theobjectivesarethreefold:
To categorize existing encryption approaches across database-levelandapplication-levelimplementations;
To evaluate integration patterns leveraging EF Core extensibilityfeatures;and
To identify limitations and research gaps in adaptive keymanagementandruntimepolicyenforcement.
Thescopeofthereviewencompassespeer-reviewedstudies, industrial guidelines, cryptographic standards, and bestpractice frameworks relevant to enterprise .NET security. Ratherthanproposinganovelencryptionmodel,thispaper
synthesizes existing knowledge to provide a structured taxonomy and critical assessment of secure persistence strategies suitable for high-assurance enterprise environments.
A rigorous and transparent methodology is essential to ensurecredibility,reproducibility,andscholarlyvalidityin an SCI-indexed review paper. This section outlines the systematicapproachadoptedtoidentify,screen,categorize, andevaluateliteraturerelevanttosecuredatapersistence and dynamic encryption within Entity Framework Core–basedenterprise.NETsystems.Themethodologyalignswith established systematic review principles in software engineeringandinformationsecurityresearch(Kitchenham andCharters,2007).
Theliteraturesearchwasconductedusingmajorscientific andtechnicaldatabasestoensurecomprehensivecoverage. PrimarysourcesincludedIEEEXplore,ACMDigitalLibrary, SpringerLink, ScienceDirect (Elsevier), and Scopus. Complementaryindustryandstandardsdocumentationwas sourced from Microsoft Learn, NIST publications, and OWASP repositories to capture applied and regulatory perspectives.
The temporal scope primarily covered publications from 2012to2024,reflectingtheperiodofsignificantadoptionof EF Core and modern encryption frameworks. Earlier foundationalworksoncryptographyanddatabasesecurity wereincludedselectivelywheretheoreticallyrelevant.
SearchstringswereconstructedusingBooleancombinations of keywords such as: “Entity Framework Core”, “ORM security”, “application-level encryption”, “dynamic encryption”, “database security”, “key management”, and “enterprise .NET systems”. Keyword refinement followed iterativescreeningtoreduceirrelevantresultsandimprove thematicalignment.Thestructuredsearchapproachreduces selection bias and enhances replicability (Petersen et al., 2015).
Explicit inclusion and exclusion criteria were applied to maintainacademicrigorandthematicrelevance.
Inclusion criteria comprised:
Peer-reviewedjournalarticles,conferenceproceedings, andrecognizedtechnicalstandards.
Studies addressing encryption in application layers, ORM-levelsecurity,databaseencryptionmechanisms, orkeymanagementsystems.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
Publicationspresentingarchitecturalmodels,empirical evaluations, or systematic analyses related to enterprisepersistencesecurity.
Exclusion criteria included:
Non-technical opinion articles, blog posts without empiricalorarchitecturalgrounding.
Studies focused solely on network-layer encryption (e.g., TLS) without relevance to persistence mechanisms.
Duplicatesorpaperslackingmethodologicalclarity.
The screening process followed a staged evaluation title review, abstract screening, and full-text assessment to ensurethematiccoherenceandeliminateredundancy.Such multi-stage filtering aligns with evidence-based software engineeringpractices(Breretonetal.,2007).
2.3 Categorization Strategy (Themes, Techniques, Frameworks)
To synthesize heterogeneous findings, a structured taxonomywasdeveloped.Thecategorizationwasperformed through thematic coding and comparative abstraction. Literaturewasgroupedintothreeprincipaldomains:
Encryption Layer Classification – database-level encryption (e.g., TDE), column-level encryption, and application-levelencryptionintegratedwithORMs.
Integration Techniques – EF Corevalueconverters, interceptors, middleware pipelines, and external key vaultintegration.
Security Governance Frameworks –standards-based controls(e.g.,NIST,ISO27001),regulatorycompliance considerations, and secure development lifecycle practices.
This classification approach facilitates cross-study comparisonwhilepreservingcontextualnuance.Thematic synthesis methods commonly used in systematic reviews enable consolidation of technical diversity into coherent analyticalclusters(Snyder,2019).
Securedatapersistenceinenterprise.NETsystemsrequires an interdisciplinary understanding of ORM architecture, databaseinteractionmodels,andappliedcryptography.This section establishes the technical foundations necessary to evaluate encryption strategies within Entity Framework Core (EF Core). It contextualizes EF Core’s architectural properties, persistence-layer risks, and the cryptographic mechanismsthatunderpinsecurestoragepractices.
EntityFrameworkCore(EFCore)isalightweight,extensible, and cross-platform Object–Relational Mapping (ORM) frameworkdevelopedbyMicrosoftfor.NETapplications.It abstracts relational database interactions through objectoriented constructs, enabling developers to work with domain entities rather than raw SQL queries. EF Core supports multiple database providers and integrates seamlessly with modern architectural patterns such as dependencyinjectionandmicroservices-baseddeployment (Microsoft,2023).
The architecture of EF Core is structured around the DbContext, which acts as a unit-of-work and repository abstraction. It incorporates a change tracker for state management, a query translation pipeline for converting LINQ expressions into SQL, and provider-specific components for database communication. This layered design allows extensibility via interceptors and value converters,whichcantransformdatabeforeitispersisted orretrieved.Sucharchitecturalinsertionpointsarecritical when embedding encryption logic within the persistence workflow,astheyenabletransparentdatatransformation withoutmodifyingdatabaseschemas.
3.1.2
ORM, LINQ Queries, Migrations, Extensibility
EF Core’s ORM capabilities automate object mapping betweendomainmodelsandrelationaltables.LINQ-based queryingenablestype-safequerycompositionthatreduces injection risks through parameterized SQL generation. Migration support facilitates schema evolution in a controlledandversionedmanner.Additionally,extensibility features such as middleware integration, logging hooks, and interception APIs allow developers to implement cross-cutting concerns including auditing and encryption policies. ORM abstractions have been shown to improve maintainability and security consistency in enterprise applications when properly configured (Bauer and King, 2018).
3.1.3 Storage Models (Code-First, Database-First, ModelFirst)
EF Coresupportsmultipledevelopmentparadigms.Inthe Code-First approach, entity classes define the database schema through migrations. Database-First reverses this process by scaffolding entity models from an existing schema. Model-First, though less common in EF Core compared to earlier EF versions, uses conceptual design tools to generate schemas. Each approach carries implicationsforencryptionintegration.Forexample,CodeFirstworkflowsallowencryptionattributestobeembedded directly in domain models, whereas Database-First
© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page582

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
approaches may require schema-level adaptation to accommodate encrypted columns. The chosen model influences flexibility and governance within enterprise environments.
Enterprise systems operate in distributed infrastructures, often integrating web APIs, cloud services, identity management frameworks, and heterogeneous databases. The persistence layer acts as a convergence point for sensitivetransactionalandanalyticaldata.Consequently,its design directly affects data integrity, compliance posture, andoperationalresilience.
3.2.1
Conventionalpersistencemechanismsencounterchallenges related to scalability, concurrency control, transaction consistency,andschemaevolution.Asenterpriseworkloads increase, maintaining ACID properties while supporting distributed architectures becomes complex. Moreover, abstractionlayersmayconcealinefficientqueries,leadingto performance bottlenecks.Froma governanceperspective, ensuringconsistentapplicationofsecuritycontrolsacross microservices and multi-tenant deployments remains a persistentissueinenterprisesystems(Fowler,2018).
3.2.2
Persistence layers are susceptible to injection attacks, misconfiguredaccesspermissions,credential leakage,and insider misuse. Although modern ORMs mitigate classical SQLinjectionthroughparameterizedqueries,improperuse ofrawSQLordynamicqueryconcatenationcanreintroduce vulnerabilities (OWASP, 2021). Additionally, insufficient access control at the database level may permit unauthorizedprivilegeescalation.Configurationleaks such as exposed connection strings or embedded credentials further expand the attack surface. Industry analyses consistentlyidentifyapplication-layerweaknessesasleading contributorstodatabreaches,underscoringthenecessityfor layeredsecuritycontrols(Verizon,2023).
Encryptionformsthefoundationalmechanismforprotecting sensitivedatawithinpersistenceworkflows.Itseffectiveness dependsnotonlyonalgorithmicstrengthbutalsooncorrect integration,keymanagementdiscipline,andalignmentwith thesystem’sthreatmodel.
Symmetricencryptionalgorithms,suchasAES,useasingle shared key for both encryption and decryption, offering computational efficiency suitable for high-volume data storage.Asymmetricencryptionemployspublic–privatekey pairsandistypicallyusedforsecurekeyexchangeordigital signatures rather than bulk data encryption. Hybrid encryption models combine both approaches to balance efficiency and security guarantees (Stallings, 2017). In persistence scenarios, symmetric cryptography is predominantly applied to encrypt data-at-rest, while asymmetricmechanismsprotectkeydistributionchannels.
The strength of encryption systems depends heavily on securekeymanagement.Keygeneration,storage,rotation, and revocation processes must be governed by strict controls to prevent compromise. Modern enterprise architectures frequently rely on centralized key management services such as hardware security modules (HSMs) or cloud-based vaults. Periodic key rotation mitigates the risk of long-term exposure and aligns with best-practicerecommendationsincryptographicgovernance standards(NIST,2020).Failureinkeylifecyclemanagement cannullifyotherwiserobustencryptionimplementations.
3.3.3
A comprehensive security design distinguishes between data-at-rest,data-in-transit,anddata-in-use.Encryptionat restprotectsstoreddatabasefilesfromunauthorizedaccess. Encryption in transit, commonly implemented via TLS, securescommunicationchannelsbetweenapplicationand database servers. Data-in-use protection remains more complex,asdecrypteddataresidestemporarilyinmemory during processing. Advanced techniques such as secure enclavesandconfidentialcomputingaimtoreduceexposure inthisstate.Effectivepersistencesecurityrequiresmapping encryptionstrategiestothespecificthreatmodelrelevantto thedeploymentcontext(Shostack,2014).
TheliteratureonsecuredatapersistencespansORM-level safeguards, database-native encryption mechanisms, application-layer cryptographic enforcement, and governance standards. Existing work reflects a layered security philosophy, emphasizing defense-in-depth across application,database,andinfrastructuretiers.Thissection categorizes and critically compares these approaches, focusingontheirapplicabilitytoEntityFrameworkCore(EF Core)withinenterprise.NETsystems.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
ORM-level security research emphasizes minimizing injection risks, enforcing consistent access policies, and embeddingsecuritycontrolsdirectlywithintheapplication abstraction layer. By positioning the ORM as a policy enforcement point, developers can implement uniform securitylogicindependentofdatabasevendorcapabilities.
4.1.1
Secure coding practices in EF Core primarily involve disciplineduseofDbContext,avoidanceofunsaferawSQL concatenation,andadherencetorepositoryorunit-of-work patterns to centralize persistence logic. Strong typing via LINQreducesexposuretomalformedqueriesandsupports parameterizedcommandgeneration.Architecturalpatterns suchasdomain-drivendesignfurtherencapsulatesensitive datatransformations,reducingaccidentalleakage.Empirical studies in software security engineering indicate that framework-level consistency significantly lowers defect densityindata-accesslayers(McGraw,2006).
4.1.2
Although ORMsmitigatetraditional SQLinjectionthrough parameter binding, misuse of dynamic queries or string interpolation may reintroduce vulnerabilities. Security analysesdemonstratethatinjectionflawsremainprevalent inapplicationsthatbypassORMsafeguardsforperformance orflexibilityreasons(Halfond,ViegasandOrso,2006).EF Core’s query pipeline inherently parameterizes LINQ expressions,butdefensivemeasuressuchasinputvalidation and strict separation of data and command logic remain essential.OWASPguidanceemphasizesvalidationandleastprivilege database access to complement ORM-level protections(OWASP,2021).
AuditingmechanismsimplementedviaEFCoreinterceptors enable logging of entity state transitions and query execution. Such capabilities support accountability and forensic traceability. Role-based and claims-based authorization models, integrated through ASP.NET Core identity frameworks, extend security enforcement to persistence operations. Research on application-layer authorizationunderscoresthatfine-grainedaccesscontrolat thedata-accessboundaryimprovesresilienceagainstinsider misuse(Sandhuetal.,1996).
Encryptionstrategiesforpersistencecanbecategorizedby the layer at which cryptographic transformation occurs: database-nativemechanismsorapplication-levelencryption. Comparative studies highlight trade-offs between transparency,performance,andthreatcoverage.
TransparentDataEncryption(TDE)encryptsdatabasefiles at rest without requiring application changes. It mitigates risksassociatedwithphysicalmediatheftorunauthorized fileaccessbutdoesnotprotectagainstprivilegeddatabase administrators or compromised application servers. Column-levelencryptionprovidesfinergranularitybutmay complicate indexing and query optimization. Analyses of databaseencryptionmodelsshowthatinfrastructure-level approachesprimarilyaddressstorage-layerthreatsrather thanapplication-layerexposures(Oracle,2020).
Application-level encryption occurs before data is transmitted to the database, typically using symmetric cryptographicalgorithms.Thismodelenhancesprotection against insider threats and database compromise, as encryptedvaluesremainopaquetodatabaseadministrators. However, it introduces performance overhead and complicates search operations on encrypted columns. Research on secure application architectures notes that application-layerencryptionprovidesstrongerend-to-end guarantees when integrated with disciplined key management(Fischer-Hübner,2001).
Dynamicencryptionreferstocontext-awareorpolicy-driven encryption that adapts at runtime based on metadata, sensitivity classification, or tenant-specific requirements. Emergingstudiesexploreruntimepolicyenforcementusing interception layers and centralized key vaults. Secure key lifecycle governance including rotation, revocation, and segregation is consistently identified as critical to maintaining confidentiality guarantees (NIST, 2020). Comparativereviewssuggestthatdynamicencryptionoffers enhanced flexibility but requires careful performance benchmarkingandrobustpolicyorchestration.
SecurityenhancementsinEFCoreoftenleveragethird-party librariesorcustommiddleware.Thesetoolsextendbaseline ORM capabilities by automating encryption, auditing, or complianceenforcement.
Several open-source and commercial libraries provide attribute-based encryption, automatic property transformation,orintegrationwithcloudkeymanagement services. Such packages typically utilize EF Core value converters or command interceptors to apply encryption transparently. While these tools reduce implementation complexity, they vary in maturity, documentation quality,

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
andcryptographicrobustness.Criticalevaluationofthirdpartysecuritylibrariesemphasizestheimportanceofpeer review and alignment with established cryptographic standards(Gutmann,2004).
4.3.2 Comparison of Extension Capabilities (Configurability, Performance, Supported Scenarios)
Comparative analysis of available extensions reveals variability across three dimensions: configurability (finegrained policy definition), performance overhead (encryption latency and indexing impact), and scenario coverage(multi-tenant,cloud-native,hybriddeployments). Lightweight attribute-driven encryption offers ease of integration but limited runtime adaptability, whereas interceptor-basedframeworksprovidegreaterflexibilityat the cost of increased architectural complexity. Systematic mapping approaches highlight that performance benchmarkingremainsunderreportedinmanyORM-level encryptionstudies(Petersenetal.,2015).
4.4 Enterprise Use Cases
Securepersistencemechanismsmustalignwithenterprise deploymentpatterns,particularlymulti-tenantarchitectures andcloud-nativeinfrastructures.
4.4.1
Multi-tenantsystemsrequirelogicalisolationofdataacross tenantswhilemaintainingsharedinfrastructureefficiency. Encryption strategies may involve tenant-specific keys to prevent cross-tenant exposure. Research on SaaS security modelsdemonstratesthattenant-isolatedkeymanagement significantlystrengthensconfidentialitybutintroduceskeyscalingchallenges(ChongandCarraro,2006).
4.4.2 Cloud Deployments (Azure SQL, AWS RDS, Containerized Environments)
Cloud environments integrate managed database services with built-in encryption and key management features. AzureSQLandAWSRDSprovideTDEandintegrationwith cloud key vaults, supporting centralized governance. Containerizedmicroservicesfurthercomplicatepersistence securityduetodynamicscalingandephemeralworkloads. Cloudsecurityanalysesemphasizethesharedresponsibility model,whereinapplication-layerencryptioncomplements provider-managedcontrols(AmazonWebServices,2023).
4.5 Standards and Best Practices
Security standards provide normative guidance for implementing and evaluating persistence protection mechanisms.
OWASPrecommendsdefense-in-depthstrategies,including parameterized queries, secure credential storage, and encryption of sensitive data fields. Its secure coding guidelineshighlightORMconfigurationdisciplineandinput validationasfoundationalcontrolsinpreventinginjection vulnerabilities(OWASP,2021).
on
NISTpublicationsoutlinecryptographicalgorithmselection, key management lifecycle practices, and access control requirements for federal information systems. These guidelinesserveasauthoritativereferencesforencryption strength, key rotation policies, and compliance validation (NIST,2020).
4.5.3 Corporate Security Frameworks and Compliance Regimes
RegulatoryframeworkssuchasGDPRmandateappropriate technicalandorganizationalmeasurestosafeguardpersonal data, explicitly referencing encryption and pseudonymization techniques (European Parliament and Council, 2016). ISO/IEC 27001 further establishes information security management systems (ISMS) that institutionalizeriskassessment,controlimplementation,and continuous monitoring. These standards shape enterprise encryption strategies by linking technical safeguards to governanceaccountabilitystructures.
This section synthesizes the reviewed literature into a structured analytical assessment of secure persistence mechanisms applicable to Entity Framework Core (EF Core)–based enterprise systems. Rather than reiterating individual studies, the discussion consolidates patterns, contrasts architectural models, and identifies unresolved challenges.Theevaluationintegratessecurityengineering principles with enterprise software architecture considerations to provide a balanced comparative perspective.
Thereviewedliteraturecanbesystematicallyclassifiedinto three principal categories based on the layer at which encryptionandsecurityenforcementareimplemented.
Infrastructure-centric models include database-native mechanismssuchasTransparentDataEncryption(TDE)and managedkeyservicesintegratedatthestoragelayer.These approaches primarily address threats involving physical mediacompromiseorunauthorizedfileaccess.Theyrequire

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
minimal application modification but provide limited protection against privileged insiders or compromised applicationservers.Suchmodelsalignwithbaselinesecurity controls commonly recommended in enterprise security frameworks(Oracle,2020).
5.1.2
Application-level encryption performs cryptographic transformationbeforedataispersisted,oftenthroughORM extensionpointssuchasvalueconvertersorinterceptors. This approach enhances confidentiality guarantees by ensuring that stored values remain encrypted even if database-level access controls fail. However, it increases architectural complexity and computational overhead. Research in secure software engineering emphasizes that embedding encryption within the application layer strengthens defense-in-depth strategies but demands disciplinedkeygovernance(McGraw,2006).
Hybrid models combine database-level safeguards with application-driven encryption and centralized key management. Dynamic encryption frameworks introduce context-aware logic, enabling runtime selection of encryption policies based on data classification or tenant requirements.Theseadaptivestrategiesalignwithmodern zero-trust principles but require advanced orchestration mechanismsandmetadatagovernance(Roseetal.,2020).
5.2 Evaluation Criteria (Security Properties, Scalability, Performance Overhead)
To ensure consistent comparison, three major evaluation dimensionsweresynthesizedfromtheliterature.
5.2.1 Security Properties
Security strength is assessed based on confidentiality robustness,resistancetoinsiderthreats,keyisolation,and compliance alignment. Infrastructure-only encryption provides strong protection for data-at-rest but does not inherently mitigate application-layer compromise. Application-level encryption enhances end-to-end confidentiality, especially when integrated with strict key lifecycle controls. Cryptographic governance standards emphasizesecurekeygeneration,rotation,andrevocationas determinantsofoverallsystemassurance(NIST,2020).
5.2.2 Scalability
Scalability considerations include the ability to support multi-tenantenvironments,distributedmicroservices,and cloud-native deployments. Infrastructure-level encryption scales efficiently due to database engine optimization. Conversely, application-layer encryption may introduce bottlenecks under high transaction throughput if not
carefullyoptimized.Distributedsystemsresearchhighlights thatscalabilitymustbeevaluatedalongsideconsistencyand latencytrade-offs(Coulourisetal.,2012).
5.2.3
Encryption operations incur computational cost, affecting query latency and indexing efficiency. Column-level or application-drivenencryptioncanimpairsearchabilityand sorting unless specialized indexing techniques are implemented. Performance benchmarking studies in cryptographicsystemsindicatethatsymmetricencryption remains efficient for bulk data processing, but cumulative overheadbecomessignificantinhigh-frequencytransaction systems (Stallings, 2017). Consequently, performance–security trade-offs must be quantitatively assessed in enterprisecontexts.
A comparative synthesis reveals distinct advantages and limitationsacrosscategories.
Infrastructure-centricencryptionofferseaseofdeployment and minimal development effort. It integrates seamlessly with managed cloud services and aligns well with compliancerequirements.However,itsprotectionscopeis restrictedtostorage-levelthreats.
Application-level encryption provides stronger logical isolation and protection against database compromise. It enablesfine-grainedcontroloversensitivefieldsandtenantspecific encryption keys. Nevertheless, it increases developmentcomplexity,maycomplicatequeryoperations, andnecessitatesrobustkeymanagementframeworks.
Hybrid approaches combine complementary strengths by layeringinfrastructuresafeguardswithapplication-driven controls. While they provide comprehensive defense-indepth, they also introduce operational complexity and require careful coordination between development and securityteams.
Comparativesecurityanalysesconsistentlydemonstratethat no single approach offers universal protection; instead, layered integration tailored to the threat model yields optimalresilience(Shostack,2014).
Despiteprogressinencryptionintegration,severalresearch andimplementationgapsremainevident.
First, automated and seamless key rotation within ORMintegrated encryption frameworks is insufficiently addressed. Many implementations assume static keys or

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
manual rotation processes, which conflict with modern cryptographicgovernancerecommendations.
Second, runtime adaptability where encryption policies adjust dynamically based on contextual risk or data classification remains underdeveloped in EF Core ecosystems.Currentsolutionsoftenrelyonstaticattributebasedconfigurationsratherthanpolicy-drivenengines.
Third, limited empirical benchmarking data exists comparing performance overhead across dynamic encryption techniques in large-scale enterprise deployments. The absence of standardized evaluation frameworksrestrictsobjectiveassessment.
Finally, integration of confidential computing paradigms with ORM-level encryption strategies has not been comprehensivelyexplored.Asenterprisestransitiontoward zero-trust architectures, future research must address adaptive encryption orchestration, scalable key lifecycle automation,andformalsecurityvalidationmodels(Roseet al.,2020).
Dynamic encryption represents an advanced evolution of application-layer security, emphasizing adaptive, policydrivenprotectionmechanismsintegratedwithinpersistence frameworks.In thecontext ofEntityFramework Core (EF Core), dynamic encryption leverages extensibility points suchasinterceptors,valueconverters,andmiddleware to enforcecontext-awarecryptographictransformationsduring runtime.Thissectionsynthesizesexistingscholarshipand industry practices to examine conceptual foundations, technicalimplementations,andgovernanceimplications.
Dynamic encryption extends beyond static, hard-coded cryptographic configurations by enabling runtime adaptability based on metadata, tenant context, or data classificationlevels.Italignswithzero-trustanddata-centric securityparadigms,whereprotectionpoliciesareenforced irrespectiveofinfrastructuretrustboundaries.
In enterprise environments, dynamic encryption refers to encryptionmechanismsthatadjustcryptographicbehavior according to contextual triggers such as user role, data sensitivity label, regulatory domain, or deployment environment.Ratherthanuniformlyencryptingpredefined columns, dynamic systems evaluate metadata and apply encryptionselectivelyatruntime. Thisapproachsupports granular governance and adaptive risk management strategies consistent with zero-trust architectural models (Roseetal.,2020).
Within EF Core, dynamic encryption may involve interceptingSaveChanges()operationsorqueryexecution pipelines to apply transformation logic dynamically. Such runtime flexibility enables policy evolution without requiringstructuraldatabasemodifications.
6.1.2
Staticencryptionschemesoftenstrugglewithmulti-tenant systems, regulatory variability across jurisdictions, and evolving compliance requirements. Dynamic encryption addressestheselimitationsbyenablingtenant-specifickeys, conditionalencryptionpolicies,andruntimereconfiguration. It also mitigates risks associated with insider threats by enforcingcontextualkeysegregation.Securityengineering researchindicatesthatadaptivecontrolsaremoreresilient againstevolvingattacksurfacescomparedtostaticrulesets (Shostack,2014).
The literature identifies several technical strategies for implementing dynamic encryption within application persistencelayers.Theseapproachesvaryinconfigurability, complexity,andruntimeoverhead.
Metadata-drivenmodelsassociateencryptionrequirements with entity attributes, annotations, or configuration descriptors. For example, custom attributes applied to EF Coreentitypropertiesmaysignalthatspecificfieldsrequire encryption. Policy engines interpret metadata during runtime and enforce cryptographic transformations accordingly.Thisstrategyalignswithmodel-drivensecurity principles, where declarative specifications govern enforcementlogic(Basin,DoserandLodderstedt,2006).
Runtime enforcement mechanisms typically utilize dependency injection, middleware pipelines, and interception APIs provided by .NET and EF Core. Interceptorsallowinspectionandmodificationofdatabase commands before execution, enabling encryption or decryption logic to be applied transparently. Middleware components can coordinate policy evaluation and key retrievalbeforepersistenceoperationsarecommitted.
Policy-basedsecuritymodelsemphasizecentralgovernance ofauthorizationandencryptionrules,ensuringconsistent enforcementacrossservices(Hu,KuhnandFerraiolo,2015). In distributed enterprise systems, runtime adaptability improves alignment with compliance frameworks and tenant-specificrequirements.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
EF Core provides command interceptors, connection interceptors,andvalueconvertersthatfacilitateencryption integration. Value converters transform property values duringpersistence,whereascommandinterceptorsoperate attheSQLgenerationstage.Theinterception-basedmodel supports cross-cutting concerns without tightly coupling encryptionlogictodomainentities.
Architecturalanalysesofinterceptionframeworkshighlight the importance of minimizing side effects and ensuring threadsafetyinhigh-concurrencyenvironments(Gammaet al.,1994).Whencorrectlyimplemented,interception-based encryption can achieve transparency while preserving domain-layerabstraction.
6.3
Effective dynamic encryption depends fundamentally on secure and scalable key management. Cryptographic robustness is undermined if key lifecycle processes lack rigororisolation.
6.3.1
Localkeystoragemechanisms,suchasconfiguration-based secret storage or on-premise hardware security modules (HSMs), provide direct control but increase operational responsibility. They may be suitable for tightly controlled enterpriseenvironmentsbutrequirerobustaccesscontrol andauditingmeasures.
Externalized key management services centralize governanceandfacilitateautomatedrotation,auditing,and revocation. Security standards emphasize separation of duties between application logic and cryptographic key custodianship to reduce insider threat exposure (NIST, 2020). External key services typically enhance scalability andregulatorycompliancealignment.
6.3.2 Cloud-Native Key Vaults (Azure Key Vault, AWS KMS)
Cloud-nativekeyvaultsolutionssuchasAzureKeyVaultand AWS Key Management Service (KMS) provide managed cryptographic operations, centralized policy enforcement, andintegrationwithidentitymanagementsystems.These servicesenablesecurekeystorage,automatedrotation,and role-basedaccesscontrol.
Cloud security frameworks highlight the shared responsibility model, under which application developers remain accountable for correct key usage while providers ensureinfrastructure-levelsecuritycontrols(AmazonWeb Services,2023).IntegrationofEFCoreencryptionlogicwith cloud-native vault APIs supports scalable and compliant dynamicencryptionarchitectures.
Integration patterns determine how encryption logic is embedded within enterprise .NET architectures. Effective integrationmustbalancetransparency,maintainability,and performance.
MiddlewareinASP.NETCoreprovidesacentralizedpipeline forhandlingcross-cuttingconcernssuchasauthentication and logging. Encryption-related preprocessing can occur before persistence operations are invoked. EF Core interceptorscomplementmiddlewarebyenablinglow-level command transformation. Combining both approaches supportslayeredenforcementandmodulardesign.
Layered architecture principles suggest that cross-cutting concernsshouldbeencapsulatedinreusablecomponentsto reduce coupling and improve maintainability (Fowler, 2018).
Transparentencryptionensuresthatdomainlogicremains unaware of cryptographic operations. By abstracting encryption behind repository interfaces or interceptors, applications preserve clean separation of concerns. Transparency enhances maintainability and reduces developererrorrates.
However,transparentworkflowsmustensuredeterministic behaviorforindexingandqueryingwhenencryptedfields require search functionality. Research on encrypted database systems indicates that searchable encryption techniques may partially address this limitation but introduceadditionalcomplexity(Popaetal.,2011).
Dynamicencryptionintroducescomputationaloverheaddue to encryption, decryption, and key retrieval operations. Performance impact varies depending on encryption granularity, algorithm choice, and concurrency levels. Symmetric cryptographic algorithms offer efficient throughput,yetcumulativelatencymaybecomesignificant underhightransactionvolumes.
Distributed systems theory underscores that security enhancementsoftentradeoffagainstlatencyandscalability, requiring careful benchmarking and architectural optimization (Koulouris et al., 2012). Therefore, performance evaluation must accompany security design decisions.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
Robust encryption integration requires systematic validation. Fuzz testing evaluates resilience against malformed inputs and unexpected runtime conditions. Penetration testing assesses exploitability of injection vulnerabilities, key exposure risks, and misconfiguration weaknesses.
Securedevelopment lifecyclemodelsadvocateintegrating dynamictestingandthreatmodelingintopersistence-layer designtoidentifyweaknessesbeforedeployment(McGraw, 2006).Continuoussecurityassessmentisparticularlycritical inadaptiveencryptionframeworkswhereruntimepolicies evolve.
Thisreviewsystematicallyexaminedsecuredatapersistence strategieswithinEntityFrameworkCore–basedenterprise .NET systems, with particular emphasis on dynamic encryption mechanisms. The analysis demonstrates that securepersistencecannotrelysolelyoninfrastructure-level protectionssuchasTransparentDataEncryption;rather,a layered security architecture integrating application-level encryption,ORMinterceptionmechanisms,andcentralized key management provides stronger confidentiality guarantees.EFCore’sextensibilityfeatures suchasvalue converters,interceptors,andmiddlewareintegration offer practicalinsertionpointsforimplementingadaptive,policydriven encryption without disrupting domain-layer abstractions.
Comparative synthesis reveals that infrastructure-centric approaches provide scalability and ease of deployment, while application-layer encryption enhances resilience against insider threats and database compromise. Hybrid models, especially those incorporating cloud-native key vaultsandautomatedkeyrotation,alignmostcloselywith zero-trustandcompliance-drivenenterprisearchitectures. However,performanceoverhead,encryption-awarequery limitations, and governance complexity remain critical designconsiderations.
Overall,theliteratureunderscoresthatdynamicencryption strategies represent a promising direction for enterprisegrade secure persistence, particularly in multi-tenant and cloud-native environments. Future advancements should focus on automated policy orchestration, scalable key lifecycle management, and standardized benchmarking frameworks to strengthen both theoretical rigor and practicalapplicability.
This review is limited by its reliance on publicly available academic publications, technical documentation, and
industrystandards,whichmaynotfullycaptureproprietary enterpriseimplementations.Empiricalbenchmarkingdata acrosslarge-scaleEFCoredeploymentsremainslimitedin the literature, constraining quantitative comparison of performance impacts. Additionally, rapidly evolving cloud security services and .NET framework updates may introducenewcapabilitiesnotcomprehensivelyreflectedin current studies. The review adopts a qualitative synthesis approachratherthanmeta-analyticstatisticalevaluationdue to heterogeneity in methodologies and reporting formats. Finally, while the analysis integrates cryptographic governanceperspectives,itdoesnotexperimentallyvalidate specificencryptionconfigurations,andthereforefocuseson conceptual and architectural evaluation rather than implementation-levelperformancetesting.
1. Amazon Web Services (2023) AWS Key Management ServiceBestPractices.AWSWhitepaper.
2. Basin, D., Doser, J. and Lodderstedt, T. (2006) ‘Model driven security: From UML models to access control infrastructures’, ACM Transactions on Software EngineeringandMethodology,15(1),pp.39–91.
3. Bauer,C.andKing,G.(2018)HibernateinActionand ORMArchitecturePrinciples.ManningPublications.
4. Brereton,P.,Kitchenham,B.A.,Budgen, D.,Turner,M. and Khalil, M. (2007) ‘Lessons from applying the systematic literature review process within the softwareengineeringdomain’,JournalofSystemsand Software,80(4),pp.571–583.
5. Chong,F.andCarraro,G.(2006)ArchitectureStrategies forCatchingtheLongTail.MicrosoftCorporation.
6. Coulouris, G., Dollimore, J., Kindberg, T. and Blair, G. (2012)DistributedSystems:ConceptsandDesign.5th edn.Addison-Wesley.
7. European Parliament and Council (2016) Regulation (EU)2016/679(GeneralDataProtectionRegulation). OfficialJournaloftheEuropeanUnion.
8. Fischer-Hübner, S. (2001) IT-Security and Privacy: Design and Use of Privacy-Enhancing Security Mechanisms.Springer.
9. Fowler, M. (2018) Patterns of Enterprise Application Architecture.Addison-Wesley.
10. Gamma,E.,Helm,R.,Johnson,R.andVlissides,J.(1994) DesignPatterns:ElementsofReusableObject-Oriented Software.Addison-Wesley.
11. Gutmann,P.(2004)EngineeringSecurity.Universityof Auckland.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
12. Halfond, W.G., Viegas, J. and Orso, A. (2006) ‘A classification of SQL-injection attacks and countermeasures’, Proceedings of the IEEE International Symposium on Secure Software Engineering.
13. Hu,V.C.,Kuhn,D.R.andFerraiolo,D.F.(2015)AttributeBasedAccessControl.NationalInstituteofStandards andTechnology.
14. Kitchenham,B.andCharters,S.(2007)Guidelinesfor PerformingSystematicLiteratureReviewsinSoftware Engineering.EBSETechnicalReport.
15. McGraw,G.(2006)SoftwareSecurity:BuildingSecurity In.Addison-Wesley.
16. Microsoft (2023) Entity Framework Core Documentation.MicrosoftLearn.
17. NIST (2020) Security and Privacy Controls for Information Systems and Organizations (SP 800-53 Rev.5).NationalInstituteofStandardsandTechnology.
18. Oracle (2020) Oracle Database Advanced Security Guide.OracleCorporation.
19. OWASP(2021)OWASPTop10:TheTenMostCritical WebApplicationSecurityRisks.OpenWebApplication SecurityProject.
20. Petersen, K., Vakkalanka, S. and Kuzniarz, L. (2015) ‘Guidelinesforconductingsystematicmappingstudies in software engineering’, Information and Software Technology,64,pp.1–18.
21. Popa, R.A., Redfield, C.M.S., Zeldovich, N. and Balakrishnan, H. (2011) ‘CryptDB: Protecting confidentiality with encrypted query processing’, Proceedings of the ACM Symposium on Operating SystemsPrinciples,pp.85–100.
22. Rose,S.,Borchert,O.,Mitchell,S.andConnelly,S.(2020) Zero Trust Architecture (SP 800-207). National InstituteofStandardsandTechnology.
23. Sandhu,R.,Coyne,E.J.,Feinstein,H.L.andYouman,C.E. (1996) ‘Role-based access control models’, IEEE Computer,29(2),pp.38–47.
24. Shostack, A. (2014) Threat Modeling: Designing for Security.Wiley.
25. Snyder, H. (2019) ‘Literature review as a research methodology:Anoverviewandguidelines’,Journalof BusinessResearch,104,pp.333–339.
26. Stallings, W. (2017) Cryptography and Network Security:PrinciplesandPractice.Pearson.
27. Verizon (2023) Data Breach Investigations Report. VerizonEnterpriseSolutions.
28. Bertino,E.andSandhu,R.(2005)‘Databasesecurity Concepts, approaches, and challenges’, IEEE Transactions on Dependable and Secure Computing, 2(1),pp.2–19.
29. Boneh,D.andShoup,V.(2020)AGraduateCoursein Applied Cryptography. Draft version. Stanford University.
30. Damiani,E.,DeCapitanidiVimercati,S.,Paraboschi,S. andSamarati,P.(2003)‘Balancingconfidentialityand efficiencyinuntrustedrelationalDBMSs’,Proceedings of the ACM Conference on Computer and CommunicationsSecurity,pp.93–102.
31. Ferraiolo,D.,Kuhn,D.R.andChandramouli,R.(2003) Role-BasedAccessControl.ArtechHouse.
32. Garrison,W.C.andShull,A.H.(2011)‘Enterprisecloud computingsecurityconsiderations’,Proceedingsofthe IEEEInternationalConferenceonGreenComputingand Communications,pp.19–26.
33. Hacigümüs,H., Iyer,B., Li,C. andMehrotra, S.(2002) ‘Executing SQL over encrypted data in the databaseservice-provider model’, Proceedings of the ACM SIGMODInternational Conference on Management of Data,pp.216–227.
34. Katz,J.andLindell,Y.(2014)IntroductiontoModern Cryptography.2ndedn.CRCPress.
35. Krebs, B. (2014) Spam Nation: The Inside Story of Organized Cybercrime. Sourcebooks. (Relevant for threatlandscapecontext)
36. Leavitt,N.(2010)‘WillNoSQLdatabasesliveuptotheir promise?’,Computer,43(2),pp.12–14.
37. Mykletun, E., Narasimha, M. and Tsudik, G. (2006) ‘Authenticationandintegrityinoutsourceddatabases’, ACMTransactionsonStorage,2(2),pp.107–138.
38. Popa, R.A. and Zeldovich, N. (2012) ‘Multi-key searchableencryption’,IACRCryptologyePrintArchive, 2012,pp.1–23.
39. Sabt, M., Achemlal, M. and Bouabdallah, A. (2015) ‘Trustedexecutionenvironment:Whatitis,andwhatit isnot’,ProceedingsoftheIEEETrustComConference, pp.57–64.
40. Samarati, P. and De Capitani di Vimercati, S. (2001) ‘Dataprotectioninoutsourceddatabases’,Proceedings of the ACM Workshop on Computer Security Architecture,pp.1–10.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072
41. Smith, S.W. and Marchesini, J. (2007) The Craft of SystemSecurity.Addison-Wesley.
42. Tang, Q.,Bringer, J., Chabanne, H. and Pointcheval,D. (2012) ‘Privacy-preserving data processing in cloud computing’, Proceedings of the International Conference on Information Security Practice and Experience,pp.1–15.
43. Zissis, D. and Lekkas, D. (2012) ‘Addressing cloud computing security issues’, Future Generation ComputerSystems,28(3),pp.583–592.