Updated on 2026-09-24 GMT+08:00

Local Management

When keys are managed using the local management approach, the key database encryption system within the system is generated and stored.

Local management is the default key management method.

Enable Local Management

  1. Select Local Management from the Encryption Management Methods dropdown menu.
  2. Select the Enable Or Not checkbox on the right.
  3. Click Save. Local management is shown in Figure 1; the parameter descriptions for local management are provided in Table 1.

    Figure 1 Key local management
    Table 1 Key management parameter description

    Parameter

    Description

    Encryption Management Methods

    Select the dense-pipe method:

    • Local Management
    • Huawei KMS

    When a different density management method is selected, the parameter configuration area will display the parameters specific to that particular density management method.

    Enabled or not

    Whether to enable the left-side selected key method.

    • When the left-side Secure Management Mode is set to Local Management, selecting the checkbox enables Local Management; if the checkbox is not selected, it indicates that the Local Management mode is not enabled. The Local Management mode is the default key management mode; therefore, the checkbox is initially selected.
    • When the left-side encryption management method is set to Huawei KMS, selecting the checkbox indicates that Huawei KMS is enabled; if the checkbox is not selected, it indicates that the Huawei KMS encryption management method is not enabled. The Local Management method is the default key management method; in this case, the checkbox is initially selected.

    Key Rotation of KEK

    Supports automatic KEK key rotation on a weekly or monthly basis; alternatively, you can manually update the key by clicking Manual Key Update.

    • Month: Rotates once every x month; where x represents the configured cycle.
    • Week: Rotate every x week; where x represents the configured cycle.

  • The database encryption system allows only one key management method at a time.
  • When higher security requirements are imposed, Huawei KMS can be used for key management.
  • When using Huawei Cloud KMS, Huawei Cloud KMS manages the keys. When switching key management methods, the original data must first be decrypted, and the existing keys must be available.