Encryption Keys Stored in FIPS 140-2 Compliant HSM for OCI (Gen 2) Environments

To satisfy the requirement of encryption key storage in Hardware Security Module (HSM) in OCI (Gen 2) environments, all master keys including the following are stored in Federal Information Processing Standard (FIPS) 140-2 compliant HSM:

  • Transparent Data Encryption (TDE) master key for database encryption
  • Block Volume Encryption master key for file system encryption
  • Object Storage Encryption master key for encryption of artifact snapshots