The database encryption key encrypts the database where
the device encryption key is stored. It is initialized at the installation
of the first instance of the Key Management Server (for On-Premise
deployment of SecureCloud). Once you specify a passphrase or accept
a generated passphrase for the database encryption key, key back
up is possible.
The passphrase is needed to import the backed up data encryption
key. You would need to import the data encryption key backup in
order to restore a corrupt database encryption key. You would also
need to import the data encryption key backup to give any additional
Management Servers access to the device encryption key database.