Huawei Cloud KMS
Key Management Service is a secure, reliable, and user-friendly key hosting service that helps you easily create and manage keys while ensuring their security. The Huawei Cloud Key Management Service (KMS) protects keys using a Hardware Security Module (HSM), which complies with FIPS 140-2 Level 3 security requirements.
All user keys are protected by the root key within the HSM to prevent key leakage.
When higher security requirements are imposed, the Huawei Cloud KMS can be used for key management.
Enable Huawei Cloud KMS for Key Management
- Select Huawei KMS from the Encryption Management Methods dropdown menu.
- Select the Enable checkbox on the right.
- Click Save.
- Click Edit in the Parameter Configuration Area to make it editable.
- Enter the integration information for Huawei KMS; the integration information is shown in Table 1.
- Click Test to verify whether the entered Huawei KMS integration information is correct.
- Click Confirm to save the parameters entered above.
- The Huawei KMS management keys are shown in Figure 1; the parameters required for integrating Huawei Key Management are listed in Table 1.
Table 1 Huawei cloud key management parameter guide Parameter
Description
Access Key
AK (Access Key ID): Used to identify the user's identity.
For instructions on how to obtain an Access Key (AK/SK), please refer to the How Do I Obtain an Access Key (AK/SK).
Encrypted Signature
SK (Secret Access Key): A key used in conjunction with AK for encrypting and signing requests, ensuring the confidentiality and integrity of the requests.
For instructions on how to obtain an Access Key (AK/SK), please refer to the How Do I Obtain an Access Key (AK/SK).
Availability Zone
Region ID: An availability zone. Please refer to the Data Encryption Workshop KMS.
Master Key Id
Key id: Huawei Cloud primary key ID. Please refer to the Viewing Key Details in the Data Encryption Workshop (DEW) for more information.
Ciphertext key length
Data key cipher length: The length of the ciphertext key in bytes; the value is 64.
Random Number length
Random data length: Must be a multiple of 8; default value is 512 bits.
- The database encryption system allows only one key management method at a time.
- When higher security requirements are imposed, Huawei KMS can be used for key management.
- When using Huawei Cloud KMS, Huawei Cloud KMS manages the keys. When switching key management methods, the original data must first be decrypted, and the existing keys must be available.
- Using Huawei Cloud KMS incurs charges; for specific pricing details, please refer to the Data Encryption Workshop Billing Description.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
