Configuring Disk Encryption
Introduction
The RDS console provides server-side encryption with DEW-managed keys. (DEW is short for Data Encryption Workshop.)
DEW uses a hardware security module (HSM) to protect keys, enabling you to easily create and control encryption keys. For security reasons, keys are not displayed in plaintext outside of HSMs. With DEW, all operations on keys are controlled and logged, and usage records of all keys can be provided to meet regulatory compliance requirements.
If server-side encryption is enabled, disk data will be encrypted and stored on the server when you create a DB instance or expand disk capacity. When downloading encrypted objects, the encrypted data will be decrypted on the server and displayed to you in plaintext.
This section describes how to enable or modify disk encryption after an instance is purchased.
Prerequisites
For server-side encryption, you need to first create a key using DEW or use the default key that DEW comes with. When creating a DB instance, enable disk encryption and select an existing key or create a new one as the tenant key. The key is used for server-side encryption.
- You will need the KMS administrator permission for the region where the RDS instance is deployed. This permission can be granted using Identity and Access Management (IAM).
- If you want to use a user-defined key to encrypt objects to be uploaded, create a key using DEW. Currently, RDS supports only symmetric keys.
Constraints
- Enabling disk encryption will cause a brief interruption, so enable it during off-peak hours.
- Data can be encrypted only when the instance is in the Available state. Once disk encryption is enabled, it cannot be disabled later.
- If backup encryption has been enabled for your instance, disable backup encryption first.
- Cluster instances do not support disk encryption.
- Disk encryption does not encrypt backup data stored in Object Storage Service (OBS) buckets. You need to configure backup encryption. For details, see Configuring Backup Encryption.
- After disk encryption is enabled, newly added storage is encrypted using the key you selected when enabling disk encryption.
- After disk encryption settings are modified, newly added storage is encrypted using the new key.
- You can configure disk encryption only for existing instances that use any of the following storage types: cloud SSD, ultra-high I/O, and extreme SSD.
- The AES_256 and SM4 algorithms are supported.
- If a shared KMS key is used, the corresponding CTS events are createdatakey and decrydatakey. Only the key owner can receive the events.
- Keep the key secure. Once the key is disabled, deleted, or frozen, your instance will be inaccessible and its data may not be restored.
If disk encryption is enabled but backup data encryption is not enabled, you can restore the data to a new instance from backups.
If both disk encryption and backup data encryption are enabled, data cannot be restored.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot