Updated on 2026-06-09 GMT+08:00

Decrypting Data

Function

This API is used to decrypt data.

Constraints

When decrypting the data encrypted using asymmetric keys, you need to specify the key ID and encryption algorithm. If the specified key ID and encryption algorithm do not match those used for encrypting data, the decryption fails.

Calling Method

For details, see Calling APIs.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependencies

    kms:cmk:decryptData

    Write

    KeyId *

    • kms:KeyOrigin

    • kms:KeySpec

    • kms:KeyUsage

    • kms:MultiRegionKeyType

    • g:EnterpriseProjectId

    • g:ResourceTag/<tag-key>

    • kms:cmk:crypto
    • kms:cmk:decrypt

    -

    -

    • kms:EncryptionAlgorithm

    • kms:RecipientAttestation

    • kms:RequestAlias

    • kms:ResourceAliases

    • kms:EncryptionContext

URI

POST /v1.0/{project_id}/kms/decrypt-data

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

cipher_text

Yes

String

Definition

Ciphertext of the encrypted data

Constraints

  • The value is the cipher_text in the data encryption result.

  • The value must match the regular expression ^[0-9a-zA-Z+/=]{128,5648}$.

Range

N/A

Default Value

N/A

encryption_algorithm

No

String

Definition

Data encryption algorithm. This parameter must be specified if only an asymmetric key is used.

Constraints

N/A

Range

  • SYMMETRIC_DEFAULT

  • RSAES_OAEP_SHA_256

  • SM2_ENCRYPT

Default Value

SYMMETRIC_DEFAULT

key_id

No

String

Definition

Key ID

Constraints

  • The value must be a 36-byte ID.

  • The value must match the regular expression ^[0-9a-z]{8}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{12}$.

Range

N/A

Default Value

N/A

additional_authenticated_data

No

String

Definition

Non-sensitive extra data used for authentication

Constraints

Maximum length: 128 bytes

Range

Any string

Default Value

N/A

sequence

No

String

Definition

A 36-byte serial number of a request message, for example, 919c82d4-8046-4722-9094-35c3c6524cff.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

key_id

String

Definition

Key ID

Range

N/A

plain_text

String

Definition

Data plaintext

Range

N/A

plain_text_base64

String

Definition

Base64 value of the plaintext. In asymmetric encryption scenarios, if the encrypted plaintext contains invisible characters, the value of this parameter is used as the decryption result.

Range

N/A

Example Requests

Decrypt the ciphertext AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx and add 123aad as the associated data. The data encryption algorithm is SYMMETRIC_DEFAULT.

{
  "cipher_text" : "AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx",
  "encryption_algorithm" : "SYMMETRIC_DEFAULT",
  "additional_authenticated_data" : "123aad"
}

Example Responses

Status code: 200

Request succeeded.

{
  "key_id" : "bb6a3d22-dc93-47ac-b5bd-88df7ad35f1e",
  "plain_text" : "hello world",
  "plain_text_base64" : "aGVsbG8gd29ybGQ="
}

SDK Sample Code

The SDK sample code is as follows.

Decrypt the ciphertext AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx and add 123aad as the associated data. The data encryption algorithm is SYMMETRIC_DEFAULT.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.kms.v2.region.KmsRegion;
import com.huaweicloud.sdk.kms.v2.*;
import com.huaweicloud.sdk.kms.v2.model.*;


public class DecryptDataSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");
        String projectId = "{project_id}";

        ICredential auth = new BasicCredentials()
                .withProjectId(projectId)
                .withAk(ak)
                .withSk(sk);

        KmsClient client = KmsClient.newBuilder()
                .withCredential(auth)
                .withRegion(KmsRegion.valueOf("<YOUR REGION>"))
                .build();
        DecryptDataRequest request = new DecryptDataRequest();
        DecryptDataRequestBody body = new DecryptDataRequestBody();
        body.withAdditionalAuthenticatedData("123aad");
        body.withEncryptionAlgorithm(DecryptDataRequestBody.EncryptionAlgorithmEnum.fromValue("SYMMETRIC_DEFAULT"));
        body.withCipherText("AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx");
        request.withBody(body);
        try {
            DecryptDataResponse response = client.decryptData(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Decrypt the ciphertext AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx and add 123aad as the associated data. The data encryption algorithm is SYMMETRIC_DEFAULT.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkkms.v2.region.kms_region import KmsRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkkms.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]
    projectId = "{project_id}"

    credentials = BasicCredentials(ak, sk, projectId)

    client = KmsClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(KmsRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = DecryptDataRequest()
        request.body = DecryptDataRequestBody(
            additional_authenticated_data="123aad",
            encryption_algorithm="SYMMETRIC_DEFAULT",
            cipher_text="AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx"
        )
        response = client.decrypt_data(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Decrypt the ciphertext AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx and add 123aad as the associated data. The data encryption algorithm is SYMMETRIC_DEFAULT.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    kms "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/kms/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/kms/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/kms/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")
    projectId := "{project_id}"

    auth, err := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        WithProjectId(projectId).
        SafeBuild()

    if err != nil {
        fmt.Println(err)
        return
    }

    hcClient, err := kms.KmsClientBuilder().
         WithRegion(region.ValueOf("<YOUR REGION>")).
         WithCredential(auth).
         SafeBuild()


    if err != nil {
        fmt.Println(err)
        return
    }

    client := kms.NewKmsClient(hcClient)

    request := &model.DecryptDataRequest{}
	additionalAuthenticatedDataDecryptDataRequestBody:= "123aad"
	encryptionAlgorithmDecryptDataRequestBody:= model.GetDecryptDataRequestBodyEncryptionAlgorithmEnum().SYMMETRIC_DEFAULT
	request.Body = &model.DecryptDataRequestBody{
		AdditionalAuthenticatedData: &additionalAuthenticatedDataDecryptDataRequestBody,
		EncryptionAlgorithm: &encryptionAlgorithmDecryptDataRequestBody,
		CipherText: "AgDoAG7EsEc2OHpQxz4gDFDH54Cqwaelxxxxxxx",
	}
	response, err := client.DecryptData(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.