tencent cloud

ドキュメントKey Management Service

Glossary

Download
フォーカスモード
フォントサイズ
最終更新日: 2026-07-30 17:04:47
AI翻訳

Auxiliary Verification Data

Auxiliary verification data (Encryption Context) is a piece of data in JSON format. If this data is passed when calling the encryption API, equivalent JSON data must be provided during decryption, otherwise decryption fails. You can improve business security by periodically updating the Encryption Context without disabling the customer master key (CMK), and quickly prevent unauthorized access.

KMS

See KMS.

KMS

Key Management Service (KMS) is a security management service that enables you to easily create and manage keys, protects the confidentiality, integrity, and availability of keys, meets key management requirements for multiple applications and business scenarios, and complies with regulatory and compliance requirements.

Data Encryption Key

A data Encryption key (DEK) is a key used to encrypt business data. It is protected by a customer master key (CMK), can be customized, and can also be created through the KMS API.

Envelope Encryption

Envelope encryption is a high-performance encryption and decryption scheme for massive amounts of data. It uses DEKs to encrypt and decrypt workload data through the high-performance symmetric encryption method and ensures the secure use of the DEKs through KMS. It can ensure data security while providing high data read-write performance.

Customer Master Key

A Customer Master Key (CMK) is a master key managed by Tencent Cloud for you. The CMK is protected by a third-party certified Hardware Security Module (HSM) and is used to encrypt and decrypt sensitive data such as passwords, certificates, and data keys used by your workloads. You can create and manage CMKs through the console and API. Customer Master Keys include customer-managed keys and cloud product keys.

Cloud Services Managed CMK

A cloud product key is a customer master key automatically created for you when Tencent Cloud products/services (such as COS, TDSQL) call KMS. You can query and enable key rotation for cloud product keys, but you cannot disable or schedule deletion for them.

ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック