1 Overview
Note:
This feature is only available for customers in the Oracle UK Sovereign Cloud (OC4) who have purchased the license for Oracle Primavera Cloud Service, BYOK for United Kingdom Sovereign Cloud.Bring Your Own Key (BYOK) lets you use and manage your own encryption keys to secure data in Oracle Primavera Cloud environments.
By default, Oracle Primavera Cloud encrypts customer data at rest using Oracle-managed encryption keys. BYOK allows eligible customers to replace Oracle-managed keys with customer-managed keys while Oracle continues to manage the Primavera Cloud service.
With BYOK, your organization maintains ownership and lifecycle management of the encryption keys used to protect supported Primavera Cloud resources. You create, disable, and delete the keys in your OCI tenancy according to your organization's security and compliance requirements.
Benefits of BYOK
BYOK helps organizations:
-
Maintain full control of encryption keys used to protect Primavera Cloud data.
-
Meet internal security, governance, and regulatory requirements.
-
Manage key lifecycle operations, including re-keying and retirement.
-
Use Oracle Cloud Infrastructure Vault to securely store and manage encryption keys.
-
Continue using Oracle-managed Primavera Cloud services while retaining control of encryption keys.
- Oracle does not require customers to manually share encryption key OCIDs. Oracle securely discovers the required resources through OCI IAM policies and defined tags.
Prerequisite
The customer tenancy must be in same regions (primary and disaster recovery) as the Oracle Primavera Cloud tenancy.
Setting up BYOK
The BYOK configuration process involves the following steps:
- Submit a Service Request to Enable BYOK.
- Oracle prepares your Primavera Cloud environment and provides you with the information required to configure your environment in the Service Request.
- Create a Tag Namespace and Tag Key Definitions
- Create Keys
- Create Policies
- Verify the Vault Replica Exists
- Update the Service Request with the Vault OCID
Your encryption keys remain in your OCI tenancy throughout this process. Oracle accesses the keys only through tightly scoped OCI Identity and Access Management (IAM) policies that you configure.