Data Encryption Service Selection
Overview
Cryptography is the discipline dedicated to securing information. It relies on algorithms to protect data confidentiality, integrity, authenticity, and non-repudiation. It plays a vital role in digital communications, ensuring that information is not accessed or tampered with by unauthorized parties during transmission, storage, and use. With the advent of the AI era, cryptography provides a fundamental layer of data security for both enterprises and individuals.
Huawei Cloud delivers comprehensive cryptographic solutions to help you construct secure and resilient information security architectures. Utilizing Huawei Cloud Data Encryption Workshop (DEW), you can seamlessly implement robust security capabilities, including data encryption, identity authentication, and digital signatures. You can gain enterprise-grade security assurances without requiring deep expertise in cryptographic theory. It provides Key Management Service (KMS) for key management, Key Pair Service (KPS) for SSH key pair management, Cloud Secret Management Service (CSMS) for secret management, and Dedicated HSM (DHSM) for dedicated encryption. To correctly use cryptographic technologies, you need to have an in-depth understanding of cryptography, as well as knowledge of security design, secure coding, and security management.
This document can help you quickly choose Huawei Cloud cryptographic services based on service scenarios, security control, compliance requirements, and cost budget.
Scenario
Select Huawei Cloud cryptographic services based on your specific conditions, data security requirements, compliance regulations, and operation preferences. There are multiple services for your choice. The following table lists the details.
| Service | Function | Application | Feature | Advantage |
|---|---|---|---|---|
| KMS | Provides secure key management, including creating, managing, rotating, and protecting encryption keys. | Used when you need to manage encryption keys. Multiple cryptographic algorithms are supported. | It is integrated with multiple Huawei Cloud Services, such as Object Storage Service (OBS), Elastic Volume Service (EVS), and Relational Database Service (RDS). It features full hosting and high availability (HA), and supports SM series cryptographic algorithms. | Extensive service integration Regulatory compliance Easy to use |
| KPS | Provides SSH key pair management, including generating, importing, and exporting key pairs. | Used when you need to manage SSH key pairs for secure login to ECSs. | Easy to use and supports multiple OSs. | Reinforced login security Regulatory compliance |
| CSMS | CSMS allows you to create, retrieve, update, and delete secrets in a unified manner throughout the secret lifecycle. It can help you eliminate risks incurred by hardcoding, plaintext configuration, and permission abuse. | Used when you need to centrally manage sensitive secrets such as database passwords, keys, and AKs/SKs. It implements comprehensive security O&M, including automatic rotation, dynamic calling, permission control, and compliance audit. | Automatic rotation, fine-grained permissions, secure storage, and full-link audit. | Secret encryption Secure secret retrieval Centralized secret management Secret change notification Secure secret calling |
| DHSM | Provides customers with independent cryptographic resources and customized services to meet specific service and security requirements. |
| Physical isolation, SM series cryptographic algorithm certification, and full control of keys by users. | Cloud applicable Elastic scaling Security management Permission authentication Reliability Security compliance Wide application |
| CPCS | A one-stop cryptographic service management platform is provided. Cluster deployment is supported. |
| Compliance, pooling, elasticity, and enterprise-level cryptographic service platform. | Automated deployment Cluster isolation Situation awareness Diversified encryption scenarios |
Selecting Cloud Services
To properly select Huawei Cloud cryptographic services, you need to clarify your security, operations, and compliance requirements. There are multiple services for various scenarios, including key management, data encryption, and secure communication. To select services that meet your organization's security goals and operations process requirements, you need to evaluate your requirements based on the following key criteria: applications, control and flexibility requirements, compliance specifications, cost factors, and integration requirements with Huawei Cloud services.
See the following table for service scenarios.
| Service | Requirement | Recommended Service |
|---|---|---|
| Key management | Hosted keys, easy to use, and low cost | KMS |
| SSH key pairs and ECS login keys | KPS | |
| Exclusive use of hardware security modules (HSMs) and full control of keys | DHSM | |
| Compliance with SM series cryptographic algorithms and a unified cryptographic platform | CPCS | |
| Data encryption | Transparent encryption for cloud services (such as OBS, RDS, and EVS) | KMS |
| Client-side and application-layer encryption | KMS + Huawei Cloud encryption SDK | |
| High-security hardware encryption | DHSM | |
| Secret and sensitive information management | Hosting of sensitive information such as database passwords and API keys | CSMS |
| Automatic secret rotation, audit, and leak prevention | CSMS | |
| Compliance and strong supervision | DJCP (MLPS), cryptography test, finance, and government compliance | CPCS + DHSM + KMS |
| SM series cryptographic algorithms and State Cryptography Administration (SCA) authentication | CPCS + DHSM + KMS |
See the following table for service applications.
| Scenario | DHSM | KMS | KPS | CSMS |
|---|---|---|---|---|
| Cloud service encryption Storage services that are integrated with OBS, EVS, Virtual Block Service (VBS), and Image Management Service (IMS) for encryption. | × | ✓ Recommended | × | × |
| Customized application encryption Encryption of upper-layer applications by calling APIs. | ✓ Recommended | ✓ Recommended | × | × |
| High-performance encryption and decryption Meet cryptographic computing requirements in a range of industry applications, such as identity authentication, data protection, and SSL uninstallation. | ✓ Recommended | × | × | × |
| Financial cryptography Cryptographic calculation in financial systems, such as card issuing systems and point of sale (POS) systems. | ✓ Recommended | × | × | × |
| Host login A user can log in to a server through private key authentication instead of password authentication. | × | × | ✓ Recommended | × |
| Application secret storage/rotation Storage and automatic rotation of database/application secrets. | × | × | × | ✓ Recommended |
Using Cloud Services
The preceding describes usages of Huawei Cloud cryptographic services. We will further illustrate the working principles of these services. The following provides references, usage guides, and other links to help you quickly get started.
| Service | Link |
|---|---|
| KMS |
|
| KPS |
|
| CSMS |
|
| DHSM |
|
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot