Skip to main content

Cryptographic Mechanisms

The DuoKey PKCS#11 library exposes a standard set of Cryptoki mechanisms. This page describes the mechanisms relevant to Oracle TDE, the key sizes involved, and — importantly — which mechanism Oracle TDE must use on the master-key wrap path.

Oracle TDE uses the AES path only

Oracle TDE exercises only the AES key-generation and wrap / unwrap (encrypt / decrypt) mechanisms. The library is a general-purpose Cryptoki provider and also advertises RSA and EC mechanisms for other DuoKey integrations, but Oracle TDE never drives them for the master key. The TDE master encryption key is always AES-256.

Overview​

Cryptoki mechanisms
Symmetric (used by Oracle TDE)
AES-CBC / AES-CBC-PADLength-preserving key wrap
AES key generation256-bit master key
Other mechanisms (not used by Oracle TDE)
AES-GCMAuthenticated envelope
RSA-OAEP / RSA key pairs
ECC key pairs

Oracle TDE drives only the symmetric AES path; the library advertises other mechanisms for non-TDE integrations.

Symmetric Encryption​

AES-CBC and AES-CBC-PAD — the Oracle TDE wrap mechanism​

PKCS#11 mechanisms: CKM_AES_CBC, CKM_AES_CBC_PAD

For the Oracle TDE master-key path, the tablespace and table keys are wrapped and unwrapped under the master key using a length-preserving AES-CBC / AES-CBC-PAD mechanism. This is the mechanism Oracle TDE relies on, and it must be length-preserving.

Why length preservation matters:

Oracle's SET KEY operation expects the unwrapped key to be exactly the size it was when wrapped. AES-CBC (with block-aligned input) and AES-CBC-PAD preserve the key size, so the stored key blob round-trips correctly.

Do not use an expanding envelope on the TDE path

An expanding AES-GCM envelope — which appends an IV and an authentication tag — changes the length of the stored key blob. On the Oracle TDE wrap path this corrupts Oracle's stored tablespace key and triggers:

ORA-00600: internal error code, arguments: [kcbtse_populate_tbskey_1]

The authenticated AES-GCM envelope mode is offered only as a fallback for non-TDE callers that store opaque blobs. It must never be selected for Oracle TDE.

Characteristics:

  • Block size: 128 bits (16 bytes)
  • IV: required initialization vector
  • Padding: CKM_AES_CBC_PAD applies PKCS#7 padding automatically; CKM_AES_CBC expects block-aligned input
  • Operations: single-part only (C_Encrypt / C_Decrypt); the multi-part C_EncryptUpdate / C_EncryptFinal forms are not implemented and return CKR_FUNCTION_NOT_SUPPORTED — Oracle TDE's master-key operations are single-part by construction, so this is not a limitation in practice

AES-GCM (not used by Oracle TDE)​

PKCS#11 mechanism: CKM_AES_GCM

AES-GCM is an authenticated encryption mode providing confidentiality and integrity (with an IV, optional additional authenticated data, and an authentication tag). Because it expands the ciphertext, it is unsuitable for the Oracle TDE key-wrap path (see the caution above) and is reserved as a fallback for non-TDE callers only.

Key Generation​

AES Key Generation​

PKCS#11 mechanism: CKM_AES_KEY_GEN

Supported key sizes:

  • 128 bits (16 bytes)
  • 192 bits (24 bytes)
  • 256 bits (32 bytes) — used by Oracle TDE

Oracle TDE usage:

  • Master encryption key (MEK): 256-bit AES key. Oracle's master encryption keys are always AES-256.
  • Table and tablespace keys: generated by Oracle and wrapped under the master key using AES-CBC-PAD.

RSA and ECC key generation (not used by Oracle TDE)​

The library also advertises CKM_RSA_PKCS_KEY_PAIR_GEN (2048 / 3072 / 4096-bit) and CKM_EC_KEY_PAIR_GEN (P-256 / P-384 / P-521) for other DuoKey integrations. Oracle TDE does not use RSA or ECC for the master key.

Oracle TDE Usage Summary​

TDE operationMechanismNotes
Master key generationCKM_AES_KEY_GEN256-bit, CKA_LABEL such as TDE-MASTER-<date>; wrap/unwrap enabled
Table key wrap / unwrapCKM_AES_CBC_PADLength-preserving; wraps the table encryption key under the master key
Tablespace key wrap / unwrapCKM_AES_CBC_PADLength-preserving; wraps the tablespace key under the master key

The master-key bytes are sensitive: C_GetAttributeValue never returns CKA_VALUE (it is refused with CKR_ATTRIBUTE_SENSITIVE), so master-key material never leaves the backend keystore.

Security Considerations​

Key sizes​

  • AES: 256 bits is the Oracle TDE default and the recommended choice.

IV management​

  • Use a fresh, random IV for each wrap operation.
  • Match IV length to the AES block size (16 bytes).
  • Store the IV alongside the wrapped key.
  • Never reuse an IV with the same key.

Performance Considerations​

  • Bulk tablespace data is encrypted locally on the database host and is hardware-accelerated by the CPU's AES-NI instructions — it does not cross the network.
  • Master-key operations (generate, wrap, unwrap) are small and infrequent; only these travel to DuoKey Cockpit.
  • Object handles are cached per session to avoid repeated lookups.

Any throughput figures quoted elsewhere are indicative targets, not benchmarked guarantees.

Next Steps​