Home > Storage > ObjectScale and ECS > Product Documentation > Dell ECS: Data at Rest Encryption > Key management
ECS D@RE supports the following two ways for managing keys in the federation:
In both ways, a hierarchy of encryption keys is used, where the parent key in the hierarchy is used to protect its child keys. Keys within the hierarchy can be either Data Encryption keys (DEKs) or Key Encryption Keys (KEKs). DEKs are used to encrypt objects while KEKs are used to protect DEKs or other KEKs. ECS D@RE key management supports key rotation for both native and external key management. See ECS 3.8 Security Configuration and Hardening Guide for more information.