Data Domain Encryption
The purpose of designing an encryption algorithm is to provide a convenient encryption configuration mode, enabling rapid synchronization between the sensitive data discovery results and the encryption configuration.
This enables the automatic application of encryption rules to the sensitive data discovery results – including the identification, confirmation, and preservation of sensitive data versions – without requiring manual configuration of encryption rules for each individual field.
The operating principle involves relational associations, as shown in Figure 1.
The encryption rules are automatically applied to the corresponding field in the target table based on the data domain of the sensitive data.
This module does not support adding new data domains; for instructions on how to add a data domain, please refer to the Discovery Rule – data domains are managed centrally within this module.
New Algorithm
- Logging In to the Database Encryption System the system administrator (sysadmin) account .
- In the left navigation tree, select Rule Management > Data Domain Encryption.
- Select the target data domain, then click the plus icon.
- In the pop-up window, enter the new encryption algorithm parameter information as shown in Figure 2; the description of the new encryption algorithm parameters is provided in Table 1. Click Confirm to save the changes.
Table 1 New encryption algorithm parameter documentation Parameter
Description
Algorithm Name
Please enter the unique identifier name for the encryption algorithm.
Encryption rules
Select or enter the encryption algorithm type. The system comes preconfigured with commonly used algorithms such as SM4 and AES. For additional algorithms, please contact your administrator for configuration. SM4 is a Chinese national symmetric encryption algorithm suitable for large-scale data encryption scenarios.
Keys Name
Select or enter a key identifier. Please choose the appropriate key version based on your specific business requirements; different keys should not be used interchangeably. For production environments, it is recommended to rotate keys periodically.
Default or not
When checked, this algorithm will serve as the default algorithm for data encryption (automatically applied when no specific algorithm is explicitly specified). Only one default algorithm can be configured per encryption rule type.
View/Edit/Delete Algorithm
- View: Select the target encryption algorithm category and then select the target algorithm to view the encryption algorithm details, as shown in Figure 3.
- Edit: Select the target encryption algorithm category, then select the target algorithm; click Edit to modify the encryption algorithm, as shown in Figure 4.
- Delete: Select the target encryption algorithm category, then select the target algorithm; click the trash can icon to delete the encryption algorithm, as shown in Figure 5.
- Encryption algorithms are a critical technical measure for ensuring data security, safeguarding the confidentiality and integrity of data during both transmission and storage. Improper editing or deletion operations can lead to serious security risks and data loss.
- Impact Assessment: Before modifying an encryption algorithm, its impact on existing encrypted data and business processes should be thoroughly evaluated.
- Compatibility: Ensure that the modified algorithm is compatible with all other components of the system, including compatibility with existing hardware and software.
- Security: Assess whether the new algorithm provides sufficient security to prevent potential security vulnerabilities.
- Backup: Before making any edits, back up the current algorithm configuration and related data so that they can be restored if needed.
- Dependency check: Before removing an encryption algorithm, verify whether there are any business processes or data in the system that depend on this algorithm.
- Data risk: Recognize that deletion algorithms may render existing encrypted data unreadable, leading to permanent data loss.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot




