The problem
Oracle's own wallet file is still a local secret
A TDE master key stored on the database host is one host compromise from being read.
Oracle's default TDE keystore is a file on the same server as the data it protects. A local admin, a stolen backup, or a compromised host can reach the wallet and the data behind it. Separating the master key from the database host is the actual control, not an optional hardening step.
Wallet on the host
The default keystore sits on the same machine as the encrypted data.
No independent custody
Whoever administers the database can also reach the master key.
Version drift
Keystore configuration and SQL grammar change across Oracle releases, silently.
Compliance gap
DORA, PCI DSS and HIPAA reviewers increasingly ask where the TDE master key actually lives.
How it works
Only the master key crosses the network
To Oracle, DuoKey presents itself as an external HSM keystore. The library handles SET KEY and wrap/unwrap only; bulk tablespace encryption stays on the host, accelerated by AES-NI.
Oracle Database
Bulk data stays local, AES-NI
DuoKey PKCS#11
SET KEY, wrap / unwrap
DuoKey Cockpit
Tenant-isolated keystore
Only master-key operations cross the network. The key never resides on the database host.
Proof in practice
Where teams deploy this
Engagement
Keep the master key off the database host
See the PKCS#11 bridge running against your own Oracle release, with a live-tested compatibility record, not a general compatibility promise.
Request a demoDiscuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.