Help Center/ Security Decisions/ Decision Guides/ Data Encryption Service Selection
Updated on 2026-08-17 GMT+08:00

Data Encryption Service Selection

Overview

Cryptography is the discipline dedicated to securing information. It relies on algorithms to protect data confidentiality, integrity, authenticity, and non-repudiation. It plays a vital role in digital communications, ensuring that information is not accessed or tampered with by unauthorized parties during transmission, storage, and use. With the advent of the AI era, cryptography provides a fundamental layer of data security for both enterprises and individuals.

Huawei Cloud delivers comprehensive cryptographic solutions to help you construct secure and resilient information security architectures. Utilizing Huawei Cloud Data Encryption Workshop (DEW), you can seamlessly implement robust security capabilities, including data encryption, identity authentication, and digital signatures. You can gain enterprise-grade security assurances without requiring deep expertise in cryptographic theory. It provides Key Management Service (KMS) for key management, Key Pair Service (KPS) for SSH key pair management, Cloud Secret Management Service (CSMS) for secret management, and Dedicated HSM (DHSM) for dedicated encryption. To correctly use cryptographic technologies, you need to have an in-depth understanding of cryptography, as well as knowledge of security design, secure coding, and security management.

This document can help you quickly choose Huawei Cloud cryptographic services based on service scenarios, security control, compliance requirements, and cost budget.

Scenario

Select Huawei Cloud cryptographic services based on your specific conditions, data security requirements, compliance regulations, and operation preferences. There are multiple services for your choice. The following table lists the details.

Table 1 Service scenarios

Service

Function

Application

Feature

Advantage

KMS

Provides secure key management, including creating, managing, rotating, and protecting encryption keys.

Used when you need to manage encryption keys. Multiple cryptographic algorithms are supported.

It is integrated with multiple Huawei Cloud Services, such as Object Storage Service (OBS), Elastic Volume Service (EVS), and Relational Database Service (RDS). It features full hosting and high availability (HA), and supports SM series cryptographic algorithms.

Extensive service integration

Regulatory compliance

Easy to use

KPS

Provides SSH key pair management, including generating, importing, and exporting key pairs.

Used when you need to manage SSH key pairs for secure login to ECSs.

Easy to use and supports multiple OSs.

Reinforced login security

Regulatory compliance

CSMS

CSMS allows you to create, retrieve, update, and delete secrets in a unified manner throughout the secret lifecycle. It can help you eliminate risks incurred by hardcoding, plaintext configuration, and permission abuse.

Used when you need to centrally manage sensitive secrets such as database passwords, keys, and AKs/SKs. It implements comprehensive security O&M, including automatic rotation, dynamic calling, permission control, and compliance audit.

Automatic rotation, fine-grained permissions, secure storage, and full-link audit.

Secret encryption

Secure secret retrieval

Centralized secret management

Secret change notification

Secure secret calling

DHSM

Provides customers with independent cryptographic resources and customized services to meet specific service and security requirements.

  • Used for scenarios that require high data security and performance, such as financial payment, electronic signature, and securities services.
  • Applicable to enterprises and organizations that meet regulatory compliance requirements.

Physical isolation, SM series cryptographic algorithm certification, and full control of keys by users.

Cloud applicable

Elastic scaling

Security management

Permission authentication

Reliability

Security compliance

Wide application

CPCS

A one-stop cryptographic service management platform is provided. Cluster deployment is supported.

  • Applicable to enterprises and organizations that require multiple cryptographic services and need to pass the cryptography test quickly.
  • Used for scenarios that require multiple cryptographic services, such as electronic contracts, electronic invoices, and electronic medical records.

Compliance, pooling, elasticity, and enterprise-level cryptographic service platform.

Automated deployment

Cluster isolation

Situation awareness

Diversified encryption scenarios

Selecting Cloud Services

To properly select Huawei Cloud cryptographic services, you need to clarify your security, operations, and compliance requirements. There are multiple services for various scenarios, including key management, data encryption, and secure communication. To select services that meet your organization's security goals and operations process requirements, you need to evaluate your requirements based on the following key criteria: applications, control and flexibility requirements, compliance specifications, cost factors, and integration requirements with Huawei Cloud services.

See the following table for service scenarios.

Table 2 Applications

Service

Requirement

Recommended Service

Key management

Hosted keys, easy to use, and low cost

KMS

SSH key pairs and ECS login keys

KPS

Exclusive use of hardware security modules (HSMs) and full control of keys

DHSM

Compliance with SM series cryptographic algorithms and a unified cryptographic platform

CPCS

Data encryption

Transparent encryption for cloud services (such as OBS, RDS, and EVS)

KMS

Client-side and application-layer encryption

KMS + Huawei Cloud encryption SDK

High-security hardware encryption

DHSM

Secret and sensitive information management

Hosting of sensitive information such as database passwords and API keys

CSMS

Automatic secret rotation, audit, and leak prevention

CSMS

Compliance and strong supervision

DJCP (MLPS), cryptography test, finance, and government compliance

CPCS + DHSM + KMS

SM series cryptographic algorithms and State Cryptography Administration (SCA) authentication

CPCS + DHSM + KMS

See the following table for service applications.

Table 3 Service applications

Scenario

DHSM

KMS

KPS

CSMS

Cloud service encryption

Storage services that are integrated with OBS, EVS, Virtual Block Service (VBS), and Image Management Service (IMS) for encryption.

×

✓ Recommended

×

×

Customized application encryption

Encryption of upper-layer applications by calling APIs.

✓ Recommended

✓ Recommended

×

×

High-performance encryption and decryption

Meet cryptographic computing requirements in a range of industry applications, such as identity authentication, data protection, and SSL uninstallation.

✓ Recommended

×

×

×

Financial cryptography

Cryptographic calculation in financial systems, such as card issuing systems and point of sale (POS) systems.

✓ Recommended

×

×

×

Host login

A user can log in to a server through private key authentication instead of password authentication.

×

×

✓ Recommended

×

Application secret storage/rotation

Storage and automatic rotation of database/application secrets.

×

×

×

✓ Recommended

Using Cloud Services

The preceding describes usages of Huawei Cloud cryptographic services. We will further illustrate the working principles of these services. The following provides references, usage guides, and other links to help you quickly get started.

Table 4 Helpful links

Service

Link

KMS

KPS

CSMS

DHSM