Updated on 2024-05-06 GMT+08:00

What Is DEW?

DEW

Data is the core asset of an enterprise. Each enterprise has its core sensitive data, which needs to be encrypted and protected from breach.

Data Encryption Workshop (DEW) is a cloud data encryption service. It provides services such as Key Management Service (KMS), , Key Pair Service (KPS), and Cloud Secret Management Service (CSMS). DEW secures your data and keys, as well as simplifies key management. DEW uses hardware security modules (HSMs) to protect the security of your keys and can be integrated with multiple Huawei Cloud services. Additionally, DEW enables you to develop customized encryption applications.

Figure 1 DEW subservices
Table 1 Service overview

Service

Description

Reference

Key Management Service

(KMS)

KMS is a secure, reliable, and easy-to-use service for managing your keys on the cloud. It helps you easily create, manage, and protect keys.

KMS uses hardware security modules (HSMs) to protect keys. HSM meets the FIPS 140-2 Level 3 security requirements. It helps you create and manage keys. All keys are protected by root keys in HSMs to avoid key leakage.

Key Types

Cloud Secret Management Service

(CSMS)

CSMS is a secure, reliable, and easy-to-use secret hosting service.

Users or applications can use CSMS to create, retrieve, update, and delete credentials in a unified manner throughout the secret lifecycle. CSMS can help you eliminate risks incurred by hardcoding, plaintext configuration, and permission abuse.

Creating a Secret

Key Pair Service

(KPS)

KPS is a secure, reliable, and easy-to-use cloud service designed to manage and protect your SSH key pairs (key pairs for short).

KPS uses HSMs to generate true random numbers which are then used to produce key pairs. In addition, it adopts a complete and reliable key pair management solution to help users create, import, and manage key pairs with ease. The public key of a generated key pair is stored in KPS while the private key can be downloaded and saved separately, which ensures the privacy and security of the key pair.

Creating a Key Pair

Dedicated Hardware Security Module

(Dedicated HSM)

Dedicated HSM enables data encryption on the cloud, specifically, encrypting and decrypting data, verifying signature, generating keys, and storing keys.

Dedicated HSM provides encryption hardware, guaranteeing data security and integrity on Elastic Cloud Servers (ECSs) and meeting compliance requirements. Dedicated HSM offers you a secure and reliable management for the keys generated by your instances, and uses multiple algorithms for data encryption and decryption.

Dedicated HSM