Using Key Protect

Business Automation Content Services on Cloud supports IBM® Key Protect for the lifecycle management of encryption keys that are used in IBM Cloud services or client-built applications.

Key Protect provides roots of trust (RoT), backed by a hardware security module (HSM). For more information about Key Protect, see the corresponding entry in the IBM Cloud Catalog External link opens a new window or tab.

If Key Protect is enabled on your subscription, the Content Platform Engine domain master key and the content encryption key for the pre-provisioned storage area are automatically generated and saved to your Key Protect service instance. Review the following guidelines about the master key and content encryption key:
  • Do not rotate or delete the domain master key. This key is used to encrypt Content Platform Engine user credentials, user name, and passwords for various purposes that include access to external services and devices.
  • Do not delete your existing content encryption keys. These keys are used to encrypt and decrypt your content when it is stored or retrieved. Missing content encryption keys cause content encryption, decryption, and retrieval to fail.
  • Lock the service ID and API key that are associated with your Key Protect service instance. This action helps ensure that you don't accidentally delete your service ID or API key.
  • As a best practice, generate a new content encryption key regularly. For more information about generating a new content encryption key, see Encrypting content External link opens a new window or tab.