إنتقل إلى المحتوى الرئيسي
ينطبق على:
DuoKey PKCS#11 LibraryOracle TDEDuoKey Cockpit

The DuoKey PKCS#11 library is a software implementation of the PKCS#11 (Cryptoki) standard that connects Oracle Database TDE to the DuoKey Cockpit platform. It presents a standard Cryptoki surface to Oracle and, for each master-key operation, forwards the request over HTTPS to Cockpit, which performs the operation against the tenant keystore. The design is organized into clean layers that each own a specific responsibility.

Master-key path only

Oracle uses the library for the TDE master-key path only — opening the keystore, SET KEY, and wrapping / unwrapping the tablespace and table keys under the master key. Bulk tablespace data encryption stays local on the database host, hardware-accelerated by AES-NI. Only the small master-key operations cross the network.

High-Level Architecture​

Oracle Database issues standard PKCS#11 calls; the library forwards the master-key operations over HTTPS to DuoKey Cockpit, which performs them against the tenant keystore. In production this keystore is backed by a Securosys HSM; a DuoKey software keystore is used in development. Master-key material never leaves the platform.

Oracle Database

Oracle Database

مع TDE

محفظة TDE

مفاتيح DEK مشفّرة

ewallet.p12
طلب KEK · PKCS#11
DuoKey PKCS#11 Provider

PKCS#11 Library

libdke_pkcs11.so

التهيئة

pkcs11.toml

بيانات الاعتماد
استدعاء API · HTTPS (TLS 1.2+)
DuoKey Cockpit API

Cockpit API

نقطة نهاية REST

المصادقة

access_guid (Bearer)

المفاتيح الرئيسية · وصول آمن
DuoKey KMS

KMS Service

المفاتيح الرئيسية

MPC Storage

FIPS 140-2 L3

موزّع
Layered by design

Each layer is independent and replaceable — Oracle compatibility, Cockpit communication, and key management are cleanly separated, so a change in one layer never ripples into the others.

Key Components​

Data Flow​

A typical open-keystore → provision master key → wrap tablespace key sequence flows through every layer, from Oracle down to the backend keystore and back. Note that only the master-key operations travel to Cockpit — the tablespace bulk data is encrypted locally under the (unwrapped) tablespace key.

Data flow
1 - Initialize
Oracle: C_Initialize()
read pkcs11.toml, establish connection
SDK to CockpitHTTPS handshake (access_token bearer credential)
ready — CKR_OK
Initialized
2 - Provision master key
Oracle: C_GenerateKey(AES-256 master key)
provision master key
Cockpit: generate key
Keystore (HSM): generate keykey reference
key created, map id to handle
Oracle receives key handle
3 - Wrap tablespace key
Oracle: C_Encrypt(handle, tablespace key)
wrap request (AES-CBC-PAD)
Cockpit: wrap under master key
Keystore (HSM): wrapwrapped key
wrapped key returned
Oracle receives wrapped tablespace key

Only the master-key operations travel to Cockpit; tablespace bulk data is encrypted locally under the unwrapped tablespace key.

Benefits of This Architecture​

Separation of Concerns

Each layer owns one responsibility: the PKCS#11 layer handles Oracle compatibility, the SDK layer handles Cockpit communication, and Cockpit handles key management.

Scalability

Supports multiple concurrent Oracle sessions, multiple database instances, and high-throughput operations — bulk data crypto stays local, so only master-key calls cross the network.

Security

Master-key material never leaves the keystore, transport is TLS-encrypted, access is bearer-token authenticated, and every operation is audit-logged in the Cockpit.

Flexibility

A Securosys HSM or DuoKey software keystore behind the same interface, simple file-plus-env configuration, and container-based deployment.

Keys stay in the platform

Across every layer, the TDE master key is generated, stored, and used inside the DuoKey Cockpit keystore (a Securosys HSM in production). The library only ever exchanges object handles and wrapped keys — never raw master-key material.

Next Steps​