Data encryption

更新时间:
复制 MD 格式

Cloud Backup provides encryption at rest and encryption in transit to protect your cloud data against potential security risks. Encryption in transit is implemented based on the SSL or TLS protocol.

Encryption at rest

Cloud Backup encrypts backup data at the source using AES-256 before the data is transferred to the cloud. By default, Cloud Backup uses self-managed keys to encrypt data. You can also use keys that you create in Key Management Service (KMS).

KMS is a secure and easy-to-use key management service provided by Alibaba Cloud. KMS lets you ensure the privacy, integrity, and availability of your keys at a low cost. You can use the keys in a secure and convenient manner. You can also develop encryption and decryption solutions as needed. You can view and manage the keys in the KMS console. For more information, see Overview of the key service.

Encryption in transit based on SSL or TLS

Cloud Backup supports access over HTTP and HTTPS. HTTPS is a secure version of HTTP that uses SSL or TLS to encrypt data. SSL or TLS is a Layer 4 protocol that helps ensure data privacy and data integrity between two applications.