tencent cloud

DokumentasiKey Management Service

Overview

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-07-30 17:00:44
Diterjemahkan oleh AI
A Customer Master Key (CMK) is a basic element of the KMS service. The CMK contains key ID, key metadata (alias, description, status, etc.), and key material used to encrypt and decrypt data.
By default, the underlying encryptor of KMS creates secure key material for a CMK when the CMK is created in KMS. If you want to use your own key material, i.e., implementing a Bring Your Own Key (BYOK) solution, you can use KMS to generate a CMK with the key material left empty, and then import your own key material into the CMK to form an external CMK. The external CMK can be distributed and managed by KMS.


Feature Characteristics

Implementing a Bring Your Own Key (BYOK) solution on Tencent Cloud allows you to use your own key material for encrypting and decrypting sensitive data within the Tencent Cloud architecture.
Fully control and manage the key services you use on Tencent Cloud, including importing or deleting key material on demand.
You can back up a copy of the key material in your local key management infrastructure as an additional disaster recovery measure for Tencent Cloud KMS.
Supporting the encryption and decryption operations on the cloud using your own key material to meet the compliance requirements of related industries.

Must-Knows

Ensure the security of the imported key material:
When using the key importing feature, you need to ensure that the random material generation source is secure and reliable. Currently, the national cryptography edition of KMS only supports importing 128-bit symmetric keys, while the FIPS-compliant edition only supports importing 256-bit symmetric keys.
Ensure the availability of the imported key material:
KMS provides high availability of its own services and the capability for restoring from backups, but the availability of users' key material is users' responsibility. It is strongly recommended that you keep the original backup of the key material in a safe and reliable way, so that if the key material is deleted accidentally or expired, the backup can be imported into KMS timely.
Note the standardization of the key import operation:
Once the key material is imported into an external CMK, the two will be associated permanently, i.e., other key materials cannot be imported into this CMK. If this CMK is used for data encryption, the encrypted data can only be decrypted with the CMK used for encryption (i.e., the CMK metadata and key material should match those of the imported key); otherwise, decryption would fail. Please be cautious when deleting key materials and CMKs.
Note the status of key import: A key in the "Pending Import" status is an enabled key, and this enabled key requires payment for use.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan