What Is the Maximum Length of a Data Key Generated by KMS?
Envelope encryption is used for encrypting or decrypting large volumes of data. The upstream system creates a data key pair, generating both a plaintext key (plain_text) and a ciphertext key (cipher_text). The plaintext key encrypts your plaintext data into ciphertext data. Both the ciphertext data and the ciphertext key are then stored in the database. During cross-system transmission, the ciphertext data and ciphertext key are passed to the downstream system, which uses the ciphertext key to request the plaintext key from KMS to decrypt the data.
The maximum length of a KMS-generated plaintext symmetric data key is 1,024 bytes, while a ciphertext symmetric data key can be up to 2,296 bytes. To accommodate future business growth, you are advised to allocate more than 2,296 bytes of storage space for ciphertext keys (for example, 3,072 or 4,096 bytes).
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot