首页Home 产品Product 解决方案Solutions 关于我们About 联系我们Contact
申请演示Request Demo
HUKEY / PRODUCT / SPEC-01
产品Product

一体化密钥、证书与密钥安全管理平台A unified platform for secrets, certificate & key security

六大核心模块,覆盖机密从生成、存储、分发到轮换、吊销与审计的全生命周期,基于开源项目 OpenBao 构建。Six core modules spanning generation, storage, distribution, rotation, revocation, and audit — built on the open-source OpenBao project.

首页Home/产品Product

动态密钥引擎Dynamic Secrets Engine

01 · 按需生成,租约到期自动吊销Generated on demand, revoked on lease expiry

摆脱静态、长期有效的数据库密码和云访问密钥。HuKey 按需为应用生成短期凭据,并在租约到期后自动吊销,从根本上缩小凭据暴露窗口。Move beyond static, long-lived database passwords and cloud access keys. HuKey issues short-lived credentials on demand and automatically revokes them when their lease expires — shrinking the exposure window at the source.

数据库动态凭据Database Dynamic Credentials支持 MySQL、PostgreSQL、Oracle 等主流数据库的按需账号生成On-demand account provisioning for MySQL, PostgreSQL, Oracle, and more
云平台密钥Cloud Platform Keys为云服务商 IAM 角色生成限时访问密钥Time-boxed access keys for cloud provider IAM roles
租约与自动吊销Lease & Auto-Revocation每个密钥绑定租约(TTL),到期自动失效,支持批量吊销Every secret carries a TTL lease that auto-expires, with bulk revocation support

证书全生命周期与 PKICertificate Lifecycle & PKI

02 · 多级 CA,自动签发与轮换Multi-tier CA, automated issuance & rotation

内置多级证书颁发机构(根 CA / 中间 CA),并可对接公共 CA 完成外部证书的统一签发与续期,从申请到吊销全流程线上化、自动化,让"证书过期导致的凌晨告警"成为历史。A built-in multi-tier certificate authority (root and intermediate CAs) can also connect to public CAs for unified issuance and renewal of externally-trusted certificates — automating the entire path from request to revocation and making 3am certificate-expiry pages a thing of the past.

多级 CA 体系Multi-Tier CA Hierarchy支持根 CA 与多级中间 CA,隔离签发权限Root and intermediate CAs isolate issuance authority
自动化签发Automated Issuance兼容 ACME 协议,配合自动化工具实现证书自动申请与部署ACME-compatible, enabling automated request and deployment
到期预警与轮换Expiry Alerts & Rotation证书到期前自动预警并触发轮换流程,避免服务中断Automatic pre-expiry alerts trigger rotation workflows
公共 CA 自动续期Public CA Auto-Renewal对接 DigiCert 等公共 CA,基于 ACMEv2 协议实现外部证书自动申请与续期Connects to public CAs such as DigiCert via the ACMEv2 protocol for automated request and renewal of externally-trusted certificates
证书清单与到期提醒Certificate Inventory & Expiry Notification自动发现并集中管理内外部证书清单,临近到期主动推送提醒Automatically discovers and centrally tracks internal and external certificates, with proactive alerts as renewal windows approach

加密即服务Encryption as a Service

03 · 调用 API 即可加解密与签名Encrypt, sign & verify via a simple API

应用只需调用 API 即可完成加解密、签名与验签,无需在业务代码中处理密钥,敏感数据全程不落地明文。Applications call a simple API to encrypt, decrypt, sign, and verify — without ever handling raw key material in business code. Sensitive data never touches plaintext at rest.

国密与国际算法National & International Algorithms支持 SM2/SM3/SM4 与 RSA/AES/ECC 等主流算法Supports SM2/SM3/SM4 alongside RSA/AES/ECC
信封加密Envelope Encryption数据密钥由主密钥保护,降低密钥暴露面Data keys are protected by a master key, minimizing exposure
密钥版本管理Key Versioning支持密钥轮换与多版本共存,平滑过渡不中断业务Rotation with multiple concurrent versions for zero-downtime transitions

统一身份与访问控制Unified Identity & Access

04 · 最小权限,精细化授权Least privilege, fine-grained authorization

统一管理人、服务与设备身份,基于最小权限原则精细化控制每一次访问,消除身份蔓延带来的权限盲区。Unify identities for people, services, and devices, and enforce least-privilege access down to the individual request — closing the blind spots created by identity sprawl.

多身份源集成Multi-Source Identity对接 LDAP/AD、OIDC 与云平台身份体系Integrates with LDAP/AD, OIDC, and cloud-native identity systems
精细化 ACL 策略Fine-Grained ACL基于路径、方法与命名空间的细粒度授权Path-, method-, and namespace-level authorization
命名空间隔离Namespace Isolation多租户 / 多部门环境下的策略与数据隔离Policy and data isolation across multi-tenant environments

轮换与自动化Rotation & Automation

05 · 融入 CI/CD 与运维体系Integrated into CI/CD and ops tooling

将密钥与证书轮换从人工操作变为可编排的自动化流程,融入现有 CI/CD 与运维体系,降低人为失误风险。Turn key and certificate rotation from a manual chore into an orchestrated automated workflow, integrated with existing CI/CD and operations tooling.

定时与事件驱动轮换Scheduled & Event-Driven Rotation支持基于时间或触发条件的自动轮换策略Time-based or trigger-based automated rotation policies
API & CLI提供 REST API、CLI 与 Terraform Provider,便于集成REST API, CLI, and Terraform provider for easy integration
Webhook 通知Webhook Notifications轮换、吊销等关键事件可推送至企业协作工具与邮件Push key events like rotation and revocation to enterprise chat and email

审计与合规Audit & Compliance

06 · 不可篡改的完整审计链路A tamper-evident, end-to-end audit trail

记录每一次访问、变更与吊销行为,形成不可篡改的审计链路,支撑合规检查与事后追溯。Every access, change, and revocation is logged into a tamper-evident audit trail, supporting compliance checks and forensic investigation.

全量操作审计Full Operation Audit记录请求方、操作时间、目标路径与结果Logs requester, timestamp, target path, and result
日志转发Log Forwarding支持转发至 SIEM / 日志平台,统一安全运营Forward logs to SIEM / log platforms for unified security operations
合规报表Compliance Reporting生成满足等级保护与内部审计要求的定期报表Periodic reports aligned with regulatory and internal audit requirements

终端证书自动续期支持Endpoint Certificate Renewal Support

持续扩展中的设备与平台适配清单A continuously expanding list of supported devices & platforms

HuKey 可将公共 CA(如 DigiCert,基于 ACMEv2)或内部 CA 签发的证书自动部署至以下终端与应用平台,实现从签发到端侧生效的全链路自动化续期。HuKey can automatically deploy certificates — issued by public CAs such as DigiCert via ACMEv2, or by an internal CA — to the endpoints and platforms below, automating renewal end-to-end from issuance to activation.

A10 F5 Imperva Fortigate Palo Alto Nginx Apache IBM HTTP Server WebSphere WebLogic Windows IIS Microsoft Exchange Active Directory Federation Services
// 支持清单持续更新,如需新增终端类型请联系我们// SUPPORT LIST CONTINUOUSLY UPDATED — CONTACT US TO REQUEST A NEW ENDPOINT TYPE
对比Comparison

HuKey 与传统密钥管理方式HuKey vs. traditional secret management

维度Dimension 传统方式Traditional Approach HuKey
密钥存储Key Storage 分散在配置文件与代码中Scattered across config files & code 集中加密存储,统一管控Centralized, encrypted, unified control
证书管理Certificate Management 人工台账,容易遗漏过期Manual spreadsheets, easy to miss expirations 自动签发、预警与轮换Automated issuance, alerts & rotation
权限控制Access Control 粗粒度,难以审计Coarse-grained, hard to audit 精细化 ACL + 完整审计日志Fine-grained ACL + full audit trail
密钥轮换Rotation 依赖人工排期Manual scheduling 自动化、事件驱动Automated, event-driven
合规支撑Compliance 缺乏统一审计链路No unified audit trail 内置合规报表与日志留存Built-in compliance reporting & retention

想看 HuKey 如何接入你的业务?Want to see HuKey working with your stack?

我们的解决方案团队会根据你的场景给出接入建议与部署方案。Our solutions team will map out an integration and deployment plan for your environment.