Envelope Encryption is a high-performance encryption and decryption solution designed for massive data. For encrypting large files or performance-sensitive data, you can use the GenerateDataKey API to generate a data encryption key (DEK). Only the DEK needs to be transmitted to the KMS server (where it is encrypted or decrypted using a CMK). All business data is processed using efficient local symmetric encryption, which has minimal impact on the user experience.
In practical business scenarios that demand high data encryption performance and involve large volumes of data, you can generate a DEK to encrypt and decrypt data locally. This approach meets the performance requirements for business encryption while also leveraging KMS to ensure the randomness and security of the data key.
KMS Encryption Scheme Comparison
|
| | |
| Symmetric Encryption, Remote Invocation | A small amount of remote symmetric encryption, a massive amount of local symmetric encryption |
| Keys, certificates, and small data are suitable for scenarios with low invocation frequency. | Massive and large-scale data is suitable for scenarios with high performance requirements. |
Diagram
In this scenario, the CMK generated by KMS serves as a critical resource. You can use the CMK to generate and obtain the plaintext and ciphertext of the DEK. Based on your actual business scenario, you first encrypt local data in memory using the DEK plaintext. Then, you persist the DEK ciphertext and the encrypted data to disk. Next, in a business decryption scenario, you need to decrypt the DEK ciphertext via KMS. Finally, you decrypt the data in memory using the decrypted DEK plaintext.
Feature Characteristics
High efficiency: All business data is processed using efficient local symmetric encryption, which has minimal impact on the user experience. Regarding the overhead of creating, encrypting, and decrypting DEKs, except in extreme cases where you need to adopt a "one-time-one-key" approach, you can reuse the plaintext and ciphertext of a single DEK for a period of time in most scenarios. Therefore, this overhead is typically very small.
Security and ease of use: The security of envelope encryption is ensured by KMS key security. Business data is protected by the DEK, while Tencent Cloud KMS protects the DEK and provides better availability. Your master key is primarily used to generate DEKs, and only entities with key access permissions can perform operations.
Must-Knows
You must ensure the secure storage of SecretId and SecretKey:
Authentication for Tencent Cloud APIs primarily relies on SecretID and SecretKey, which serve as the user's unique credentials. Business systems require these credentials to call Tencent Cloud APIs.
You must manage the access control for SecretID and SecretKey:
We recommend using a sub-account and authorizing APIs based on business needs to manage risks.
You must pay attention to how business systems handle plaintext keys:
In envelope encryption scenarios, symmetric encryption is used. Therefore, plaintext keys must not be persisted to disk and must be used within the memory of the business process.
You must pay attention to how the backend system handles data keys:
In envelope encryption scenarios, symmetric encryption is used. You can reuse the same data key or use different data keys for different users or at different times based on business needs to encrypt data, thereby avoiding DEK duplication.