Are customer-managed encryption keys supported?

Are customer-managed encryption keys supported?

Gemini saidOCI fully supports Customer-Managed Keys (CMK). While Oracle-managed keys are the default, the OCI Vault service gives you the ability to create, rotate, and control your own encryption keys for a wide range of services.

As of 2026, here are the three ways you can manage your own keys in OCI:

1. OCI Vault (Standard CMK)

This is the most common approach. You create a master encryption key inside an OCI Vault.

  • Control: You control the lifecycle of the key (creation, rotation, and deletion).

  • Integration: These keys can be used to encrypt Block Volumes, Object Storage buckets, and databases (including Autonomous and Base Database services).

  • Storage Options:

    • HSM-Protected: Keys are stored in FIPS 140-2 Level 3 Hardware Security Modules. This is a paid service (~$0.53 per key version/month).

    • Software-Protected: Keys are stored on disk but managed by you. These are free of cost.

2. Bring Your Own Key (BYOK)

If your compliance policy requires that the "entropy" (the random material) of the key must be generated outside the cloud, you can use BYOK.

  • How it works: You generate the key material in your own on-premises HSM or specialized software (like OpenSSL), wrap it securely, and then import it into OCI Vault.

  • The Benefit: Oracle never sees the unencrypted key material during the transfer, ensuring you are the sole source of the "root" of that key.

3. External Key Management (HYOK)

For organizations with the strictest "Sovereignty" requirements, OCI offers External Key Management Service (EKMS), often referred to as "Hold Your Own Key."

  • The Architecture: Your data stays in OCI, but the encryption keys physically reside in an HSM in your own data center (or a third-party manager like Thales).

  • The Ultimate Kill Switch: If you lose your connection or intentionally revoke access at your local site, the data in the cloud immediately becomes unreadable. Oracle has no way to bypass this.


Comparison of Key Ownership Models

Feature

Important Tip: The "Deletion Delay"

When you manage your own keys, you have the power to delete them. To prevent accidental data loss, OCI enforces a minimum 7-day waiting period before a key is permanently deleted. During this window, you can cancel the deletion if you realize a critical database still needs that key to boot.

Looking for servers Rental ?

Call Our Expert :


  • (call for rental enquiries)

Email us :