AsymmetricDecrypt
Decrypts data using an asymmetric key.
Operation description
Precautions
-
For details about the access policies that must be granted to a RAM user or RAM role to invoke this operation, see Access control.
-
This operation can be invoked through a shared gateway or a dedicated gateway. For more information, see Alibaba Cloud SDK.
Shared gateway: Access KMS using a public endpoint or a VPC endpoint. This method requires you to enable public network access. For more information, see Access keys in a KMS instance over the Internet.
Dedicated gateway: Access KMS using a KMS private endpoint (
<YOUR_KMS_INSTANCE_ID>.cryptoservice.kms.aliyuncs.com).
QPS limits
Calls through a shared gateway: The QPS limit for a single user is 200 calls per second. If this limit is exceeded, API calls are throttled, which may affect your business. Call this operation at a reasonable rate.
Calls through a dedicated gateway: The QPS limit for a single user is determined by the performance specifications of your KMS instance. For more information, see Performance data.
Details
Only asymmetric keys with Usage set to ENCRYPT/DECRYPT are supported. The following table lists the supported encryption algorithms:
| KeySpec | Algorithm | Description | Ciphertext length (bytes) |
| RSA_2048 | RSAES_OAEP_SHA_256 | RSAES-OAEP using SHA-256 and MGF1 with SHA-256 | 256 |
| RSA_2048 | RSAES_OAEP_SHA_1 | RSAES-OAEP using SHA1 and MGF1 with SHA1 | 256 |
| RSA_3072 | RSAES_OAEP_SHA_256 | RSAES-OAEP using SHA-256 and MGF1 with SHA-256 | 384 |
| RSA_3072 | RSAES_OAEP_SHA_1 | RSAES-OAEP using SHA1 and MGF1 with SHA1 | 384 |
| EC_SM2 | SM2PKE | SM2 elliptic curve public key encryption algorithm | Up to 6144 |
This topic provides an example of using an asymmetric key with key ID key-hzz630494463ejqjx**** and key version ID 2ab1a983-7072-4bbc-a582-584b5bd8**** to decrypt the ciphertext BQKP+1zK6+ZEMxTP5qaVzcsgXtWplYBKm0NXdSnB5FzliFxE1bSiu4dnEIlca2JpeH7yz1/S6fed630H+hIH6DoM25fTLNcKj+mFB0Xnh9m2+HN59Mn4qyTfcUeadnfCXSWcGBouhXFwcdd2rJ3n337bzTf4jm659gZu3L0i6PLuxM9p7mqdwO0cKJPfGVfhnfMz+f4alMg79WB/NNyE2lyX7/qxvV49ObNrrJbKSFiz8Djocaf0IESNLMbfYI5bXjWkJlX92DQbKhibtQW8ZOJ//ZC6t0AWcUoKL6QDm/dg5koQalcleRinpB+QadFm894sLbVZ9+N4GVsv1W****== using the decryption algorithm RSAES_OAEP_SHA_1.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
kms:AsymmetricDecrypt |
get |
*Key
|
|
None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| CiphertextBlob |
string |
Yes |
The ciphertext to decrypt, encoded in Base64. Note
You can call the AsymmetricEncrypt operation to generate the ciphertext. |
BQKP+1zK6+ZEMxTP5qaVzcsgXtWplYBKm0NXdSnB5FzliFxE1bSiu4dnEIlca2JpeH7yz1/S6fed630H+hIH6DoM25fTLNcKj+mFB0Xnh9m2+HN59Mn4qyTfcUeadnfCXSWcGBouhXFwcdd2rJ3n337bzTf4jm659gZu3L0i6PLuxM9p7mqdwO0cKJPfGVfhnfMz+f4alMg79WB/NNyE2lyX7/qxvV49ObNrrJbKSFiz8Djocaf0IESNLMbfYI5bXjWkJlX92DQbKhibtQW8ZOJ//ZC6t0AWcUoKL6QDm/dg5koQalcleRinpB+QadFm894sLbVZ9+N4GVsv1W****== |
| KeyId |
string |
Yes |
The ID of the key. You can also specify a key alias or a key Amazon Resource Name (ARN). For more information about aliases, see Manage key aliases. Note
To access a key that belongs to another Alibaba Cloud account, you must specify the key ARN. The key ARN format is |
key-hzz630494463ejqjx**** |
| KeyVersionId |
string |
Yes |
The key version ID. The globally unique identifier of the key version. |
2ab1a983-7072-4bbc-a582-584b5bd8**** |
| Algorithm |
string |
Yes |
The decryption algorithm. |
RSAES_OAEP_SHA_1 |
| DryRun |
string |
No |
Specifies whether to enable DryRun mode. Valid values:
DryRun mode is used to test API calls, verify that you have the required permissions on the relevant resources, and check whether the request parameters are configured correctly. When DryRun mode is enabled, KMS always returns a failure with a reason. The failure reasons include the following:
|
false |
| Recipient |
string |
No |
{ "AttestationDocument":"base64-encoded-attestion-document", "KeyEncryptionAlgorithm":"RSAES_OAEP_SHA_256" } |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| KeyVersionId |
string |
The version number of the master key used to encrypt the plaintext data. |
2ab1a983-7072-4bbc-a582-584b5bd8**** |
| KeyId |
string |
The key ID. If the KeyId parameter in the request specifies a key alias or key ARN, the key ID is also returned in the response. |
key-hzz630494463ejqjx**** |
| RequestId |
string |
The request ID. This is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot and locate issues. |
475f1620-b9d3-4d35-b5c6-3fbdd941423d |
| Plaintext |
string |
The decrypted plaintext, encoded in Base64. |
SGVsbG8gd29ybGQ= |
| CiphertextForRecipient |
string |
***Ciphertext*** |
Examples
Success response
JSON format
{
"KeyVersionId": "2ab1a983-7072-4bbc-a582-584b5bd8****",
"KeyId": "key-hzz630494463ejqjx****",
"RequestId": "475f1620-b9d3-4d35-b5c6-3fbdd941423d",
"Plaintext": "SGVsbG8gd29ybGQ=",
"CiphertextForRecipient": "***Ciphertext***"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | Rejected.UnsupportedOperation | Unsupported operation. | The operation is not supported. |
| 404 | Forbidden.AliasNotFound | The specified Alias is not found. | The error message returned because the specified alias does not exist. |
| 404 | Forbidden.KeyNotFound | The specified Key is not found. | The error message returned because the specified CMK does not exist. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.