DuoKey

Oracle TDE

A master key Oracle never truly holds

DuoKey's PKCS#11 bridge moves Oracle's TDE master key off the database host and into Cockpit. Only master-key operations cross the network; bulk encryption stays local.

Oracle Database

Bulk data stays local, AES-NI

DuoKey PKCS#11

SET KEY, wrap / unwrap

DuoKey Cockpit

Tenant-isolated keystore

Only master-key operations cross the network. The key never resides on the database host.

How it works

Only the master key crosses the network

To Oracle, DuoKey presents itself as an external HSM keystore. The library handles SET KEY and wrap/unwrap only; bulk tablespace encryption stays on the host, accelerated by AES-NI.

Oracle Database

Bulk data stays local, AES-NI

DuoKey PKCS#11

SET KEY, wrap / unwrap

DuoKey Cockpit

Tenant-isolated keystore

Only master-key operations cross the network. The key never resides on the database host.

Engagement

Keep the master key off the database host

See the PKCS#11 bridge running against your own Oracle release, with a live-tested compatibility record, not a general compatibility promise.

Request a demo

Parlons des décisions qui comptent pour votre programme de sécurité.

Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.