top of page

100% cloud data control achieved through double key encryption (Duokey)

Migrating systems to cloud platforms like Microsoft 365, AWS, or Salesforce brings outstanding operational efficiency and infinite scalability. However, behind this convenience lies a complex dilemma regarding control: organizations are handing over their core data to infrastructure providers. To enjoy the benefits of the cloud while maintaining absolute security privileges, the application of Double Key Encryption (DKE) emerges as the ultimate solution for enterprises to master the digital space.

The cloud security paradox: Keys in the hands of others

Most current cloud platforms provide default data encryption features. However, the most dangerous limitation of this method is that the service provider (such as Microsoft or Amazon) still holds the decryption tool, known as the "availability key". Technically, these providers retain the capability to access customer content.

The cloud security paradox: Keys in the hands of others
The cloud security paradox: Keys in the hands of others

If the provider's servers suffer a supply chain attack or if a high-level cloud administrator account is compromised by insider threats, highly sensitive data—from design blueprints and M&A documents to financial records—will be exposed. To eliminate this blind spot, organizations require an independent security architecture where access privileges do not reside with any third party.

Anatomy of the double key encryption (Duokey) mechanism

Unlike conventional methods, Double Key Encryption establishes a strictly isolated cryptographic control structure. When a document is uploaded to the cloud, it is protected by two separate encryption keys:

  • The first key: Held exclusively by the enterprise and stored entirely outside the cloud provider's infrastructure through IPSIP's Duokey service.

  • The second key: Managed by the cloud platform provider (e.g., Microsoft's Azure Rights Management).

This dual-encryption model creates an immutable rule: to decrypt and read the document, the system requires the simultaneous presence of both keys. Microsoft cannot read the data without the enterprise's key, and the enterprise cannot decrypt content without Microsoft's key. Even if hackers completely breach Microsoft's systems, the stolen data remains meaningless ciphertext because they do not possess the core key secured in the organization's vault.

Core technologies powering the Duokey service

To operate the two-layer key mechanism smoothly without disrupting the user experience, IPSIP's Double Key Encryption solution is built upon three state-of-the-art technological pillars:

  • Multi-Party Computation (MPC): Instead of storing the encryption key on a single vulnerable server, MPC technology splits the key into multiple shares distributed across different network nodes. No single entity or compromised system holds the complete root key, completely eliminating the risk of a single point of failure.

  • Zero Trust Access Control: Every key retrieval request for document decryption must pass rigorous identity verification. The system enforces strict authorization through role-based permissions, IP addresses, Azure groups, and geographic locations. Only verified users are granted access privileges, with continuous monitoring of all access attempts.

  • Seamless Cross-Platform Integration: The solution not only provides a protective shield for the Microsoft 365 ecosystem but also extends robust encryption capabilities to AWS (S3, XKS), Salesforce, ServiceNow, and SQL databases. Integration occurs seamlessly without altering established workflows or applications.

Turning legal compliance into an inevitable added value

By establishing a proactive security perimeter through DKE, organizations not only thwart real-world threats but also neatly resolve legal compliance pressures.

Since the official implementation of Decree 356/2025/ND-CP and the Cybersecurity Law 116/2025/QH15, the Vietnamese legal framework has set extremely strict technical boundaries. According to Article 12 of Decree 356/2025/ND-CP, all personal data stored and processed on cloud computing services must be encrypted both at rest and in transit, accompanied by strict access authorization mechanisms.

Instead of struggling with patchwork solutions to cope with regulatory inspections, Duokey's robust client-side encryption automatically meets and exceeds these technical standards. Coupled with the ability to prevent unauthorized access from the cloud provider itself, enterprises possess transparent technical evidence to prove absolute compliance with the most stringent legal frameworks, including GDPR, DORA, and Vietnam's data protection laws.

Completing the defensive ecosystem with IPSIP experts

Deploying an independent encryption architecture requires high precision in network infrastructure. To relieve the burden on internal IT teams, IPSIP Vietnam offers an accompanying service ecosystem to protect the outer perimeter of the encryption key vault.

Through professional IT Support services, engineering teams assist in configuring and synchronizing the Duokey encryption system into the enterprise environment smoothly. Concurrently, IPSIP's 24/7 SOC (Security Operations Center) and NOC (Network Operations Center) systems act as continuous scanning radars, promptly detecting and intercepting any signs of anomalous network access. This ensures the integrity of the encryption key 24 hours a day, 7 days a week.

24/7 SOC
24/7 SOC

Control over digital assets is a vital factor determining the competitive capacity of any organization. Instead of leaving data security to the mercy of cloud computing platforms, applying Double Key Encryption (Duokey) provides a solid layer of assurance. This is not only a perfect technological shield against hackers and insider risks but also the strongest commitment to respecting customer privacy and strictly complying with all mandatory legal regulations.

FAQ (Frequently Asked Questions)

How does Double Key Encryption (DKE) work on Microsoft 365?

DKE protects documents by applying two layers of encryption: one key managed by Microsoft and an independent key hosted exclusively by the enterprise (via IPSIP Duokey). Both keys are required simultaneously to decrypt and access the content.

Why is the cloud provider's default encryption insufficient?

With standard customer-managed keys (BYOK), platform providers like Microsoft still retain an "availability key" and possess the technical capability to access protected content. This creates a vulnerability if their systems are hacked or administrators are compromised. DKE completely eliminates this provider access.

How does IPSIP's Duokey solution assist with legal compliance in Vietnam?

Duokey technology strongly encrypts data outside the cloud environment and establishes Zero Trust authorization. This helps businesses automatically meet the mandatory requirements for cloud data encryption at rest and in transit under Article 12 of Decree 356/2025/ND-CP.

 

  

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page