Updated on 2026-09-24 GMT+08:00

Huawei Cloud KMS

Key Management Service is a secure, reliable, and user-friendly key hosting service that helps you easily create and manage keys while ensuring their security. The Huawei Cloud Key Management Service (KMS) protects keys using a Hardware Security Module (HSM), which complies with FIPS 140-2 Level 3 security requirements.

All user keys are protected by the root key within the HSM to prevent key leakage.

When higher security requirements are imposed, the Huawei Cloud KMS can be used for key management.

Enable Huawei Cloud KMS for Key Management

  1. Select Huawei KMS from the Encryption Management Methods dropdown menu.
  2. Select the Enable checkbox on the right.
  3. Click Save.
  4. Click Edit in the Parameter Configuration Area to make it editable.
  5. Enter the integration information for Huawei KMS; the integration information is shown in Table 1.
  6. Click Test to verify whether the entered Huawei KMS integration information is correct.
  7. Click Confirm to save the parameters entered above.
  8. The Huawei KMS management keys are shown in Figure 1; the parameters required for integrating Huawei Key Management are listed in Table 1.

    Figure 1 The key is sourced from Huawei KMS.
    Table 1 Huawei cloud key management parameter guide

    Parameter

    Description

    Access Key

    AK (Access Key ID): Used to identify the user's identity.

    For instructions on how to obtain an Access Key (AK/SK), please refer to the How Do I Obtain an Access Key (AK/SK).

    Encrypted Signature

    SK (Secret Access Key): A key used in conjunction with AK for encrypting and signing requests, ensuring the confidentiality and integrity of the requests.

    For instructions on how to obtain an Access Key (AK/SK), please refer to the How Do I Obtain an Access Key (AK/SK).

    Availability Zone

    Region ID: An availability zone. Please refer to the Data Encryption Workshop KMS.

    Master Key Id

    Key id: Huawei Cloud primary key ID. Please refer to the Viewing Key Details in the Data Encryption Workshop (DEW) for more information.

    Ciphertext key length

    Data key cipher length: The length of the ciphertext key in bytes; the value is 64.

    Random Number length

    Random data length: Must be a multiple of 8; default value is 512 bits.

  • The database encryption system allows only one key management method at a time.
  • When higher security requirements are imposed, Huawei KMS can be used for key management.
  • When using Huawei Cloud KMS, Huawei Cloud KMS manages the keys. When switching key management methods, the original data must first be decrypted, and the existing keys must be available.