---
name: power-iaas-Integrate_hpcs
title: Integrating Power Virtual Server with IBM Cloud Key Management Services
description: 'IBM provides two Cloud key management services that integrate with Power Virtual Server workloads:'
last-updated: 2024-12-03
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/power-iaas?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Integrating Power Virtual Server with IBM Cloud Key Management Services
{: #integrate-hpcs}

---



IBM Power Virtual Server in [IBM data center]{: tag-blue}


IBM Power Virtual Server Private Cloud in [Client location]{: tag-red}


---

[Client location]{: tag-red}To integrate IBM&reg; Power&reg; Virtual Server with IBM Cloud key management services, establish a connection from your virtual machine to IBM Cloud.
{: note}

IBM provides two Cloud key management services that integrate with Power Virtual Server workloads:
{: shortdesc}

1. [IBM Cloud® Hyper Protect Crypto Services (HPCS)](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-overview&format=markdown) is a dedicated key management service and hardware security module (HSM) based on IBM Cloud. You can integrate HPCS with Power Virtual Server to securely store and protect encryption key information for AIX and Linux.
2. [IBM Key Protect](https://cloud.ibm.com/docs/key-protect?topic=key-protect-about&format=markdown) is a full-service multi-tenant encryption solution that allows data to be secured and stored in IBM Cloud™ with the envelope encryption techniques. You can integrate Key Protect with Power Virtual Server to securely store and protect encryption key information for AIX and Linux.

## Using Hyper Protect Crypto Services (HPCS) and Key Protect for AIX
{: #AIX-hpcs}

HPCS and Key Protect are supported by AIX 7.3 TL1 for AIX logical volume encryption.
{: note}

Power-AIX integration for PKCS11/TDE integration for Oracle or Db2 workloads is not available currently. No impact to the volume-level encryption for AIX, Power-Linux with HPCS.
{: important}

You can use Power Virtual Server to integrate with HPCS and Key Protect to use encryption on AIX file systems with `keysvrmgr` and `hdcryptmgr` command.

The `keysvrmgr` command manages the Object Data Manager (ODM) database entries that are associated with the encryption key server when the logical or physical volume uses the key server key-protection method for encryption. For more information, see [keysvrmgr Command](https://www.ibm.com/docs/en/aix/7.3?topic=k-keysvrmgr-command){: external}.

The `hdcryptmgr` command helps to manage the cryptographic management of logical volumes (LV) and physical volumes (PV). For more information, see [hdcryptmgr Command](https://www.ibm.com/docs/en/aix/7.3?topic=h-hdcryptmgr-command){: external}.

## Using Hyper Protect Crypto Services (HPCS) or Key Protect for Linux
{: #Linux-hpcs}

You can use Power Virtual Server to integrate with HPCS or Key Protect to protect Linux Unified Key set up (LUKS) encryption keys from being compromised. Either key management service can act as the single point of control to enable or disable access to data across the enterprise. It is done by successively wrapping encryption keys, with the ultimate control being a master key that resides in a hardware security module (HSM).

For more information, see [Protect LUKS encryption keys with IBM Cloud Hyper Protect Crypto Services and Key Protect](https://developer.ibm.com/tutorials/protect-luks-encryption-keys-with-ibm-cloud-hyper-protect-crypto-services/){: external}.

## Additional support for configuring Hyper Protect Crypto Services or Key Protect
{: #support-hpcs}

For any additional information and assistance on HPCS or Key Protect for AIX or Linux, [contact IBM](mailto:zaas.client.acceleration@ibm.com).