Cryptographic Mechanisms
The DuoKey PKCS#11 library exposes a standard set of Cryptoki mechanisms. This page describes the mechanisms relevant to Oracle TDE, the key sizes involved, and — importantly — which mechanism Oracle TDE must use on the master-key wrap path.
Oracle TDE exercises only the AES key-generation and wrap / unwrap (encrypt / decrypt) mechanisms. The library is a general-purpose Cryptoki provider and also advertises RSA and EC mechanisms for other DuoKey integrations, but Oracle TDE never drives them for the master key. The TDE master encryption key is always AES-256.
Overview
Oracle TDE drives only the symmetric AES path; the library advertises other mechanisms for non-TDE integrations.
Symmetric Encryption
AES-CBC and AES-CBC-PAD — the Oracle TDE wrap mechanism
PKCS#11 mechanisms: CKM_AES_CBC, CKM_AES_CBC_PAD
For the Oracle TDE master-key path, the tablespace and table keys are wrapped and unwrapped under the master key using a length-preserving AES-CBC / AES-CBC-PAD mechanism. This is the mechanism Oracle TDE relies on, and it must be length-preserving.
Why length preservation matters:
Oracle's SET KEY operation expects the unwrapped key to be exactly the size it was when wrapped. AES-CBC (with block-aligned input) and AES-CBC-PAD preserve the key size, so the stored key blob round-trips correctly.
An expanding AES-GCM envelope — which appends an IV and an authentication tag — changes the length of the stored key blob. On the Oracle TDE wrap path this corrupts Oracle's stored tablespace key and triggers:
ORA-00600: internal error code, arguments: [kcbtse_populate_tbskey_1]
The authenticated AES-GCM envelope mode is offered only as a fallback for non-TDE callers that store opaque blobs. It must never be selected for Oracle TDE.
Characteristics:
- Block size: 128 bits (16 bytes)
- IV: required initialization vector
- Padding:
CKM_AES_CBC_PADapplies PKCS#7 padding automatically;CKM_AES_CBCexpects block-aligned input - Operations: single-part only (
C_Encrypt/C_Decrypt); the multi-partC_EncryptUpdate/C_EncryptFinalforms are not implemented and returnCKR_FUNCTION_NOT_SUPPORTED— Oracle TDE's master-key operations are single-part by construction, so this is not a limitation in practice
AES-GCM (not used by Oracle TDE)
PKCS#11 mechanism: CKM_AES_GCM
AES-GCM is an authenticated encryption mode providing confidentiality and integrity (with an IV, optional additional authenticated data, and an authentication tag). Because it expands the ciphertext, it is unsuitable for the Oracle TDE key-wrap path (see the caution above) and is reserved as a fallback for non-TDE callers only.
Key Generation
AES Key Generation
PKCS#11 mechanism: CKM_AES_KEY_GEN
Supported key sizes:
- 128 bits (16 bytes)
- 192 bits (24 bytes)
- 256 bits (32 bytes) — used by Oracle TDE
Oracle TDE usage:
- Master encryption key (MEK): 256-bit AES key. Oracle's master encryption keys are always AES-256.
- Table and tablespace keys: generated by Oracle and wrapped under the master key using AES-CBC-PAD.
RSA and ECC key generation (not used by Oracle TDE)
The library also advertises CKM_RSA_PKCS_KEY_PAIR_GEN (2048 / 3072 / 4096-bit) and CKM_EC_KEY_PAIR_GEN (P-256 / P-384 / P-521) for other DuoKey integrations. Oracle TDE does not use RSA or ECC for the master key.
Oracle TDE Usage Summary
| TDE operation | Mechanism | Notes |
|---|---|---|
| Master key generation | CKM_AES_KEY_GEN | 256-bit, CKA_LABEL such as TDE-MASTER-<date>; wrap/unwrap enabled |
| Table key wrap / unwrap | CKM_AES_CBC_PAD | Length-preserving; wraps the table encryption key under the master key |
| Tablespace key wrap / unwrap | CKM_AES_CBC_PAD | Length-preserving; wraps the tablespace key under the master key |
The master-key bytes are sensitive: C_GetAttributeValue never returns CKA_VALUE (it is refused with CKR_ATTRIBUTE_SENSITIVE), so master-key material never leaves the backend keystore.
Security Considerations
Key sizes
- AES: 256 bits is the Oracle TDE default and the recommended choice.
IV management
- Use a fresh, random IV for each wrap operation.
- Match IV length to the AES block size (16 bytes).
- Store the IV alongside the wrapped key.
- Never reuse an IV with the same key.
Performance Considerations
- Bulk tablespace data is encrypted locally on the database host and is hardware-accelerated by the CPU's AES-NI instructions — it does not cross the network.
- Master-key operations (generate, wrap, unwrap) are small and infrequent; only these travel to DuoKey Cockpit.
- Object handles are cached per session to avoid repeated lookups.
Any throughput figures quoted elsewhere are indicative targets, not benchmarked guarantees.
Next Steps
- PKCS#11 Interface Layer → - See how mechanisms are surfaced to Oracle
- Communication Flow → - Understand operation flow
- Configuration → - Learn how the provider is configured