Access a secure, application-friendly, and cloud-based key management solution.

IBM Db2 on Cloud now offers integration with IBM Key Protect—accessible through the Db2 on Cloud console—so you can upload, change, and manage private encryption keys in one place. Key Protect is a cloud-based security service that provides lifecycle management for encryption keys that are used in IBM Cloud or customer-built applications. Key Protect provides roots of trust (RoT) backed by a hardware security module (HSM).

How it works

With the Key Protect service, Db2 on Cloud will provide your business control over its keys. Db2 on Cloud will use the keys in Key Protect to encrypt the password used to open the local key store. The password for the local key store will be encrypted using the key protect key. Whenever the key store needs to be opened, the encrypted password in the stash file will be decrypted by making the REST calls to the Key Protect API. 

Control encrypted data in the cloud

Import your own root of trust encryption keys (CRKs) into Key Protect using the Key Protect API to wrap and unwrap the keys associated with your data resources.

Cloud-based HSM protection

Your keys are wrapped in other encrypted keys protected by a cloud-based HSM. The HSMs are at FIPS-140-2 Level 2. All programmatic interfaces are secured by TLS and mutual authentication. Deleted keys and data under those deleted keys are never recovered.

Application independence

Key Protect’s APIs generate, store, retrieve, and manage keys independent of your application’s logic. This enables you to create applications that encrypt data in custom databases or use encrypted block storage in an application-specific format.

Get started

It’s as easy as 1-2-3:

  1. Create or import a key in the Key Protect service on IBM Cloud.
  2. Grant a service authorization for the Db2 service instance to access the Key Protect service instance.
  3. On the Db2 console, select the key to be used and gain complete control.

Key features

  1. Complete self-service options to manage your keys in the IBM Cloud UI or through the Key Protect API, to grant/revoke access service authorization on the IBM Cloud UI, and to select/change the key on the Db2 console.
  2. Key rotation per your security schedule.
  3. Full access to the Key Protect service after migrating your instance to resource groups.

Start using Key Protect through the Db2 on Cloud console today. You can manage a single key or millions of keys.

Visit the Key Protect service page to learn more about how you can more effectively manage your encrypted keys through the cloud.

More from Analytics

IBM acquires StreamSets, a leading real-time data integration company

3 min read - We are thrilled to announce that IBM has acquired StreamSets, a real-time data integration company specializing in streaming structured, unstructured and semistructured data across hybrid multicloud environments. Acquired from Software AG along with webMethods, this strategic acquisition expands IBM's already robust data integration capabilities, helping to solidify our position as a leader in the data integration market and enhancing IBM Data Fabric’s delivery of secure, high-quality data for artificial intelligence (AI).  According to a Forrester study conducted on behalf of…

Fine-tune your data lineage tracking with descriptive lineage

4 min read - Data lineage is the discipline of understanding how data flows through your organization: where it comes from, where it goes, and what happens to it along the way. Often used in support of regulatory compliance, data governance and technical impact analysis, data lineage answers these questions and more.  Whenever anyone talks about data lineage and how to achieve it, the spotlight tends to shine on automation. This is expected, as automating the process of calculating and establishing lineage is crucial to…

Reimagine data sharing with IBM Data Product Hub

3 min read - We are excited to announce the launch of IBM® Data Product Hub, a modern data sharing solution designed to accelerate data-driven outcomes across your organization. Today, we're making this product generally available to our clients across the world, following its announcement at the IBM Think conference in May 2024. Data sharing has become the lifeblood of modern organizations, fueling growth and driving innovation. But traditional approaches to data sharing can often be a bottleneck constricting the seamless sharing of data.…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters