Local Management
When keys are managed using the local management approach, the key database encryption system within the system is generated and stored.
Local management is the default key management method.
Enable Local Management
- Select Local Management from the Encryption Management Methods dropdown menu.
- Select the Enable Or Not checkbox on the right.
- Click Save. Local management is shown in Figure 1; the parameter descriptions for local management are provided in Table 1.
Table 1 Key management parameter description Parameter
Description
Encryption Management Methods
Select the dense-pipe method:
- Local Management
- Huawei KMS
When a different density management method is selected, the parameter configuration area will display the parameters specific to that particular density management method.
Enabled or not
Whether to enable the left-side selected key method.
- When the left-side Secure Management Mode is set to Local Management, selecting the checkbox enables Local Management; if the checkbox is not selected, it indicates that the Local Management mode is not enabled. The Local Management mode is the default key management mode; therefore, the checkbox is initially selected.
- When the left-side encryption management method is set to Huawei KMS, selecting the checkbox indicates that Huawei KMS is enabled; if the checkbox is not selected, it indicates that the Huawei KMS encryption management method is not enabled. The Local Management method is the default key management method; in this case, the checkbox is initially selected.
Key Rotation of KEK
Supports automatic KEK key rotation on a weekly or monthly basis; alternatively, you can manually update the key by clicking Manual Key Update.
- Month: Rotates once every x month; where x represents the configured cycle.
- Week: Rotate every x week; where x represents the configured cycle.
- The database encryption system allows only one key management method at a time.
- When higher security requirements are imposed, Huawei KMS can be used for key management.
- When using Huawei Cloud KMS, Huawei Cloud KMS manages the keys. When switching key management methods, the original data must first be decrypted, and the existing keys must be available.
- Using Huawei Cloud KMS incurs charges; for specific pricing details, please refer to the Data Encryption Workshop Billing Description.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
