Software-Hardware Synergy for Secure Acceleration | GBase 8a and Hygon HCT Hardware Encryption Deep Integration: Core Parameter Configuration and Scenario-Based Selection Guide

Published on 2026-05-22

Driven by the acceleration of China’s homegrown technology initiatives and stringent data security and compliance requirements, the security capabilities and performance of domestic databases have become key criteria for core industries such as finance, government, and energy. As a benchmark for homegrown MPP analytical databases, GBase 8a has long been dedicated to ecosystem adaptation with Chinese hardware and software. It recently completed deep integration with Hygon HCT hardware encryption technology, achieving a leap in encryption performance through kernel-level adaptation and flexible parameter configuration. It also provides a clear encryption algorithm selection path for various business scenarios, truly delivering both security compliance and high-efficiency analytics.

GBase 8a × Hygon HCT: Kernel-Level Adaptation Unlocks the Core Value of Hardware Encryption

Traditional database encryption often relies on software algorithms, where encryption and decryption operations consume main CPU resources throughout the process. In high-load scenarios such as massive data loading and complex multi-dimensional queries, this can easily cause dramatic performance degradation and task stalling, creating an inherent conflict between “security compliance” and “business efficiency.”

GBase 8a has completed low-level adaptation at the database kernel level, linking the database encryption logic with Hygon HCT hardware encryption instructions, achieving two major breakthroughs:

01 Intelligent Identification, Seamless Switching

At startup, GBase 8a automatically detects the hardware environment. Upon identifying a Hygon CPU, it enables HCT hardware encryption mode; in non-Hygon environments, it automatically falls back to stable software encryption mode, ensuring cross-platform compatibility without additional modification.

02 Compute Offloading, Performance Boost

All encryption, decryption, and verification operations are offloaded to Hygon’s dedicated hardware co-processor, freeing the main CPU to focus on core business logic such as data storage, parallel computing, and result aggregation, completely eliminating the computing resource contention caused by software encryption.

Core Encryption Parameters Explained: Precise Configuration to Meet Different Encryption Needs

After adapting to Hygon HCT hardware encryption, GBase 8a provides two core configuration parameters to flexibly control the encryption mode and algorithm type. The parameters are simple to configure and take effect conveniently, suitable for scenarios with varying compliance levels and performance requirements. Their specific meanings and configuration rules are as follows:

01 gbase_encrypt_new_mode: Encryption Algorithm Specification Parameter

· Parameter role: Defines the encryption algorithm type used by the database, catering to both general encryption and China’s national cryptographic compliance. This is a foundational setting for data encryption.

· Parameter values and meanings
o =0: Encryption disabled. No data encryption is enabled. Suitable for non-sensitive, public data storage scenarios, offering optimal performance.
o =1: Enable AES-128 algorithm. An international standard symmetric encryption algorithm with high computational efficiency and strong compatibility, suitable for scenarios not requiring China’s national cryptographic compliance.
o =2: Enable SM4 national cryptographic algorithm. An independently developed symmetric encryption algorithm by China, compliant with the Cryptography Law and Data Security Law. Suitable for core sensitive data scenarios in finance and government.
o =3: Enable AES-256 algorithm. An international standard symmetric encryption algorithm, suitable for scenarios not requiring mandatory national cryptographic compliance.

02 gbase_hct_enabled: Hygon HCT Hardware Encryption Switch Parameter

· Parameter role: Controls whether Hygon HCT hardware encryption acceleration is enabled, toggling between “software encryption” and “hardware encryption” modes, directly determining encryption performance.

· Parameter values and meanings
o =0: Software encryption mode. Encryption operations are performed by the CPU via software algorithms. Suitable for non-Hygon platform environments.
o =1: Hygon platform hardware encryption mode. Encryption operations are executed by the encryption module, freeing up main CPU resources. Performance improves by 114% to 212% compared to software encryption. Suitable for encryption scenarios on Hygon platforms. If the system detects HCT hardware encryption is not supported, it automatically falls back to software encryption.

03 Parameter Configuration Instructions

These two parameters must be used together. For example, “_gbase_encrypt_new_mode=2 + _gbase_hct_enabled=1” enables the SM4 national cryptographic algorithm plus Hygon HCT hardware acceleration, providing dual guarantees of “compliance + high performance” for core sensitive data. The configuration takes effect after restarting the GBase 8a cluster, with no additional changes to application code required.

Scenario-Based Encryption Algorithm Selection: Matching Needs to Balance Compliance and Performance

After integrating with Hygon HCT hardware encryption, GBase 8a supports AES-128, AES-256, and SM4—major encryption algorithms. Different algorithms prioritize compliance levels, computational efficiency, and applicable scenarios. Based on data sensitivity, compliance requirements, and workload characteristics, we recommend the following selection schemes:

01 SM4 National Cryptographic Algorithm

Recommended scenario: Core sensitive data + mandatory compliance

Applicable scenarios:
· Finance: storage of customer transaction data, credit records, capital flow, and other core sensitive data;
· Government: resident identity information, government approval data, confidential business data, etc.;
· Energy and state-owned enterprises: core production data, operational reports, classified statistical data;
· Scenarios requiring China’s Classified Protection Level 3 or national cryptographic certification.

Selection advantages:
SM4 is China’s independently controllable national cryptographic algorithm, fully complying with national data security regulations. It offers the strongest compliance and outstanding stability under high-load conditions, balancing compliance and performance.

02 AES-128 Algorithm

Recommended scenario: Non-sensitive data + high concurrency & low latency

Applicable scenarios:
· Non-core business data: public enterprise reports, non-sensitive operation logs, test environment data;
· High-concurrency write scenarios: real-time data collection, IoT data ingestion, high-throughput data synchronization;
· Cross-ecosystem compatibility scenarios: businesses requiring integration with international standard systems or third-party non-Chinese platforms.

Selection advantages:
AES-128 features simple computation logic and broad compatibility.

03 AES-256 Algorithm

Recommended scenario: Highly sensitive data + international security compliance + extreme data security

Applicable scenarios:
· High-grade sensitive data: core confidential business data, user privacy core data, advanced technology data, classified scientific research data;
· International compliance business: confidential business scenarios requiring compliance with overseas data security regulations and international industry security standards, interfacing with overseas systems;
· High-risk protection scenarios: data with high breach risk, long-term encrypted retention, archiving and storage requiring the highest encryption strength;
· Core businesses of government, enterprises, and confidential units that do not mandate national cryptographic algorithms but demand ultra-high security protection levels.

Selection advantages:
AES-256 is an internationally recognized ultra-high-strength symmetric encryption algorithm with a longer key length, suitable for scenarios that demand the utmost data confidentiality without mandatory national cryptographic requirements.

04 Disable Encryption

Recommended scenario: Public data + extreme performance priority

Applicable scenarios:
· Public shared data, non-sensitive archived data, offline analysis test data;
· Offline computation and batch data processing scenarios where extreme performance is the priority.

Selection advantages:
With no encryption computational overhead, GBase 8a can unleash its full parallel computing power, delivering optimal performance for data loading, querying, and writing, perfectly matching the efficient processing needs of non-sensitive data.

Conclusion: Integrated Hardware-Software Adaptation Builds a New Benchmark for Domestic Database Security and Performance

The deep integration of GBase 8a with Hygon HCT hardware encryption is not simply a feature overlay. It realizes synergistic hardware-software collaboration between “homegrown database + homegrown chip” at the kernel level. Through clear parameter configuration and scenario-based algorithm selection, it overcomes the pain points of traditional encryption: difficult compliance, poor performance, and complex adaptation.

At the parameter level, the two core configurations are simple to understand, flexible, and controllable, accommodating different hardware environments and encryption needs. At the scenario level, the SM4 national cryptographic algorithm solidifies the compliance baseline for sensitive data, while the AES-128 algorithm suits high-concurrency, high-efficiency scenarios, achieving “encryption on-demand with precise acceleration.”

Looking ahead, GBase 8a will continue to deepen ecosystem adaptation with domestic hardware and software, collaborating with computing partners like Hygon to refine security encryption solutions that better meet core industry needs. It will provide finance, government, and energy sectors with a “secure, compliant, high-performance, and independently controllable” homegrown data foundation, safeguarding the high-quality development of China’s indigenous IT industry.