tencent cloud

문서Key Management Service

Overview

다운로드
포커스 모드
폰트 크기
마지막 업데이트 시간: 2026-07-30 16:52:53
AI 번역
Envelope Encryption is a high-performance encryption and decryption solution designed for massive data. For encrypting large files or performance-sensitive data, you can use the GenerateDataKey API to generate a data encryption key (DEK). Only the DEK needs to be transmitted to the KMS server (where it is encrypted or decrypted using a CMK). All business data is processed using efficient local symmetric encryption, which has minimal impact on the user experience. In practical business scenarios that demand high data encryption performance and involve large volumes of data, you can generate a DEK to encrypt and decrypt data locally. This approach meets the performance requirements for business encryption while also leveraging KMS to ensure the randomness and security of the data key.

KMS Encryption Scheme Comparison

Comparison Item
Sensitive Information Encryption
Envelope Encryption
Related Keys
CMK
CMK,DEK
Performance
Symmetric Encryption, Remote Invocation
A small amount of remote symmetric encryption, a massive amount of local symmetric encryption
Main Scenarios
Keys, certificates, and small data are suitable for scenarios with low invocation frequency.
Massive and large-scale data is suitable for scenarios with high performance requirements.

Diagram

In this scenario, the CMK generated by KMS serves as a critical resource. You can use the CMK to generate and obtain the plaintext and ciphertext of the DEK. Based on your actual business scenario, you first encrypt local data in memory using the DEK plaintext. Then, you persist the DEK ciphertext and the encrypted data to disk. Next, in a business decryption scenario, you need to decrypt the DEK ciphertext via KMS. Finally, you decrypt the data in memory using the decrypted DEK plaintext.


Feature Characteristics

High efficiency: All business data is processed using efficient local symmetric encryption, which has minimal impact on the user experience. Regarding the overhead of creating, encrypting, and decrypting DEKs, except in extreme cases where you need to adopt a "one-time-one-key" approach, you can reuse the plaintext and ciphertext of a single DEK for a period of time in most scenarios. Therefore, this overhead is typically very small.
Security and ease of use: The security of envelope encryption is ensured by KMS key security. Business data is protected by the DEK, while Tencent Cloud KMS protects the DEK and provides better availability. Your master key is primarily used to generate DEKs, and only entities with key access permissions can perform operations.

Must-Knows

You must ensure the secure storage of SecretId and SecretKey:
Authentication for Tencent Cloud APIs primarily relies on SecretID and SecretKey, which serve as the user's unique credentials. Business systems require these credentials to call Tencent Cloud APIs.
You must manage the access control for SecretID and SecretKey:
We recommend using a sub-account and authorizing APIs based on business needs to manage risks.
You must pay attention to how business systems handle plaintext keys:
In envelope encryption scenarios, symmetric encryption is used. Therefore, plaintext keys must not be persisted to disk and must be used within the memory of the business process.
You must pay attention to how the backend system handles data keys:
In envelope encryption scenarios, symmetric encryption is used. You can reuse the same data key or use different data keys for different users or at different times based on business needs to encrypt data, thereby avoiding DEK duplication.

도움말 및 지원

문제 해결에 도움이 되었나요?

피드백