Updated on 2026-07-07 GMT+08:00

Key Management

Key management is used to configure and integrate various types of encryption devices.

Managing Keys

  1. Logging In to the Database Encryption System using the system administrator sysadmin account.
  2. In the left navigation tree, select Rule Management > Key Management to set up the secret channel KEK key rotation. The parameter descriptions are shown in Table 1. You can choose whether to enable secret channel KEK key rotation. On the page, you can choose to manage the key locally or use Huawei Cloud KMS.

    Figure 1 Key management page
    Table 1 Table1 Key management page parameter description

    Parameter

    Description

    Encryption Management Method

    You can choose local management or Huawei KMS.

    Enabled or Not

    The platform can only select one encryption method; switching encryption rules requires changing the encryption method accordingly.

    Key Rotation of KEK

    You can choose to perform automatic KEK key rotation on a weekly or monthly basis; or manually click the button to update the key.

    Figure 2 Huawei KMS configuration page
    Table 2 Table2 Key management page parameter description

    Parameter

    Description

    Access Key

    ak: Access key that identifies the user.

    Encryption Signature

    sk: Used to encrypt and sign the access key for identity verification.

    Availability Zone

    regionid: An available zone.

    Master Key ID

    keyid: Huawei Cloud Master Key ID.

    Ciphertext Key Length

    datakeycipherlength: Ciphertext key byte length, set to 64.

    Random Number Length

    randomdatalength: Value is a multiple of 8; the default is 512 bits.

  3. Click Save to save the settings.