For Oracle Database TDE on Linux or Windows, see Oracle Database TDE.
What you’ll build
- A CryptoHub Oracle Database TDE service and a client endpoint for the database server.
- The Futurex PKCS #11 library installed in the location where Oracle Database finds hardware security module (HSM) libraries.
- An Oracle database that uses CryptoHub as its HSM key store. The TDE master encryption key is created on CryptoHub and does not leave it.
- An auto-login configuration that opens the HSM key store when the database starts, without an operator.
- An encrypted column and an encrypted tablespace that prove the database encrypts data with the CryptoHub key.
How it works
Oracle TDE uses a two-tier key model:- TDE master encryption key: CryptoHub creates and stores this key. Oracle Database gives it a label that starts with
ORACLE.TDE.HSM.MK. - Table and tablespace keys: Oracle Database creates these keys and stores them in the database, encrypted by the master encryption key.
- Deploy the Oracle Database TDE service in CryptoHub and create a client endpoint for the database server.
- Install the Futurex PKCS #11 library and the endpoint configuration on the Solaris server.
- Point Oracle Database at the HSM key store.
- Open the HSM key store and create the TDE master encryption key on CryptoHub.
- Configure auto-login so the key store opens when the database starts.
- Encrypt data and verify that access depends on CryptoHub.
Why this integration uses PKCS #11
Oracle Database connects to an HSM key store through a PKCS #11 library that the HSM vendor supplies. Oracle Database loads the library from a fixed directory,/opt/oracle/extapi/64/hsm/. The Futurex PKCS #11 library connects to the CryptoHub Host API over mutual TLS, and it uses the credentials in the endpoint bundle. You do not add any CryptoHub connection details to Oracle Database.
The Futurex PKCS #11 library build must match the platform. Oracle Database 19c on Solaris SPARC is a 64-bit SPARC V9 process, so it can load only the 64-bit SPARC build of the library. Linux and Windows builds do not work on this platform.

