Alibaba Cloud SDK

Updated at:

Alibaba Cloud SDK supports both management operations (creating instances and keys) and business operations (encryption, decryption, and secret retrieval) for KMS. Management operations use the shared gateway only; business operations support both shared and dedicated gateways.

Access overview

Management operations are accessible only through the shared gateway. Business operations are accessible through both the shared and dedicated gateways.

image

Shared vs. dedicated gateway

The following table compares the shared and dedicated gateways for KMS business operations.

Item

Shared gateway

Dedicated gateway

Network

Public network or VPC network.

KMS private network.

Performance

API requests are subject to per-second quotas.

Example: encryption and decryption QPS is fixed at 1,000.

No per-request quota. Requests are processed in best-effort mode using all available computing and storage resources. You select the QPS capacity when purchasing a KMS instance.

Supported APIs

All cryptographic operations and secret retrieval APIs.

All cryptographic operations and secret retrieval APIs, except ReEncrypt.

Network access control

Supports VPC ID (condition key: acs:SourceVpc) and VPC IP addresses (condition key: acs:VpcSourceIp) for network access control.

Does not support VPC ID (condition key: acs:SourceVpc) or source IP addresses within a VPC (condition key: acs:VpcSourceIp) for network access control. Contact your account manager if you require this capability.

Authorization

With STS authentication, authorization applies only to GetSecretValue, not Decrypt. Other authentication methods authorize both operations.

Both GetSecretValue and Decrypt are authorized during secret retrieval.

Log auditing

ActionTrail

Simple Log Service (SLS)

SDK configurations

Endpoint

During client initialization, configure the shared gateway endpoint in one of the following formats:

  • Public network domain names: kms.<REGION_ID>.aliyuncs.com.

  • VPC domain names: kms-vpc.<REGION_ID>.aliyuncs.com.

During client initialization, configure the dedicated gateway endpoint in the format: <KMS_INSTANCE_ID>.cryptoservice.kms.aliyuncs.com.

CA certificate

Not required.

  • Alibaba Cloud SDK V2.0: Requires setting a CA certificate.

  • Alibaba Cloud SDK V1.0: Does not support certificates. Instead, the HTTPSInsecure runtime parameter must be set to true: client.SetHTTPSInsecure(true).

Supported APIs

Management operations use the shared gateway only. Business operations support both shared and dedicated gateways.

Management operations

Service management

API

Title

Description

DescribeAccountKmsStatus DescribeAccountKmsStatus Queries the status of Key Management Service (KMS) within your Alibaba Cloud account.
OpenKmsService OpenKmsService Activates Key Management Service (KMS) for your Alibaba Cloud account.

Instances management

API

Title

Description

DescribeAccountKmsStatus

DescribeAccountKmsStatus

Queries the status of Key Management Service (KMS) within your Alibaba Cloud account.

OpenKmsService

OpenKmsService

Activates Key Management Service (KMS) for your Alibaba Cloud account.

Key management

API

Title

Description

CreateKey

CreateKey

Creates a customer master key (CMK) for envelope encryption, digital signatures, or other cryptographic operations.

ListKeys

ListKeys

Queries the IDs and ARNs of all CMKs in the current region.

DescribeKey

DescribeKey

Queries the metadata of a CMK, such as the key state, usage, and rotation configuration.

UpdateKeyDescription

UpdateKeyDescription

Updates the description of a CMK.

EnableKey

EnableKey

Enables a key to encrypt and decrypt data.

DisableKey

DisableKey

Disables a key.

CreateAlias

CreateAlias

Creates an alias for a key.

ListAliases

ListAliases

Queries all aliases in the current region for the current account.

ListAliasesByKeyId

ListAliasesByKeyId

Queries all aliases that are bound to a key.

DeleteAlias

DeleteAlias

Deletes an alias.

UpdateAlias

UpdateAlias

Binds an existing alias to a different customer master key (CMK) ID.

GetParametersForImport

GetParametersForImport

Queries the parameters that are used to import key material for a customer master key (CMK).

ImportKeyMaterial

ImportKeyMaterial

Imports externally generated key material into a CMK whose origin is EXTERNAL.

DeleteKeyMaterial

DeleteKeyMaterial

Deletes the imported key material from a CMK. After deletion, the CMK enters the PendingImport state until you re-import key material.

ScheduleKeyDeletion

ScheduleKeyDeletion

Deletes a specified customer master key (CMK).

CancelKeyDeletion

CancelKeyDeletion

Cancels the deletion task of a CMK.

SetDeletionProtection

SetDeletionProtection

Enables or disables deletion protection for a customer master key (CMK).

UpdateRotationPolicy

UpdateRotationPolicy

Updates the automatic rotation policy of a CMK.

DescribeKeyVersion

DescribeKeyVersion

Queries the metadata of a specific CMK version.

CreateKeyVersion

CreateKeyVersion

Creates a version for a customer master key (CMK).

ListKeyVersions

ListKeyVersions

Queries all versions of a specified CMK.

SetKeyPolicy

SetKeyPolicy

Sets the key policy for a CMK in a KMS instance.

GetKeyPolicy

GetKeyPolicy

Queries the key policy of a CMK in a KMS instance.

Secrets management

API

Title

Description

ListSecrets

ListSecrets

Queries all secrets in the current region.

DeleteSecret

DeleteSecret

Deletes a secret.

CreateSecret

CreateSecret

Creates a secret and stores its initial version.

UpdateSecret

UpdateSecret

Updates the metadata of a secret.

UpdateSecretVersionStage

UpdateSecretVersionStage

Moves a version stage label to a different version of a secret.

UpdateSecretRotationPolicy

UpdateSecretRotationPolicy

Updates the rotation policy of a secret.

DescribeSecret

DescribeSecret

Queries the metadata of a secret.

ListSecretVersionIds

ListSecretVersionIds

Queries all version IDs and stage labels of a specified secret.

GetRandomPassword

GetRandomPassword

Generates a random password string.

PutSecretValue

PutSecretValue

Stores a new version of a secret value for a generic secret.

RestoreSecret

RestoreSecret

Restores a deleted secret.

RotateSecret

RotateSecret

Immediately rotates a secret.

SetSecretPolicy

SetSecretPolicy

Sets the access policy for a secret in a KMS instance.

GetSecretPolicy

GetSecretPolicy

Queries the access policy of a specified secret in a KMS instance.

Tag management

API

Title

Description

UntagResources UntagResources Removes tags from keys or secrets.
TagResources TagResources Adds tags to one or more keys or secrets.
ListTagResources ListTagResources Lists the tags that are bound to a key or a secret.
GetKmsInstanceQuotaInfos GetKmsInstanceQuotaInfos Queries the quota usage and limits for a KMS instance.
ListResourceTags ListResourceTags Queries the tags of a customer master key (CMK).
TagResource TagResource Adds tags to a CMK, secret, or certificate.
UntagResource UntagResource Removes tags from a CMK, secret, or certificate.

Applications management

API

Title

Description

CreateNetworkRule CreateNetworkRule Creates a network access rule to configure the private IP addresses or private CIDR blocks that are allowed to access a Key Management Service (KMS) instance.
ListNetworkRules ListNetworkRules Queries all network access rules in the current region.
DescribeNetworkRule DescribeNetworkRule Retrieves the details of a network access rule.
UpdateNetworkRule UpdateNetworkRule Updates a network access rule.
DeleteNetworkRule DeleteNetworkRule Deletes a network access rule.
CreatePolicy CreatePolicy Creates a permission policy to configure the keys and secrets that are allowed to access.
ListPolicies ListPolicies Queries all permission policies in the current region.
DescribePolicy DescribePolicy Retrieves the details of a permission policy.
UpdatePolicy UpdatePolicy Updates a permission policy.
DeletePolicy DeletePolicy Deletes a permission policy.
CreateApplicationAccessPoint CreateApplicationAccessPoint Creates an application access point (AAP)
ListApplicationAccessPoints ListApplicationAccessPoints Queries all application access points (AAPs) in the current region.
DescribeApplicationAccessPoint DescribeApplicationAccessPoint Retrieves the details of an application access point (AAP).
UpdateApplicationAccessPoint UpdateApplicationAccessPoint Updates the information about an application access point (AAP).
DeleteApplicationAccessPoint DeleteApplicationAccessPoint Deletes an application access point (AAP).
CreateClientKey CreateClientKey Creates a client key.
ListClientKeys ListClientKeys Queries all client keys within an AAP.
GetClientKey GetClientKey Retrieves information about a client key.
DeleteClientKey DeleteClientKey Deletes a client key.

Business operations-Cryptographic operations

Important

To perform cryptographic operations through the shared gateway, you must first enable public access.

API

Description

Shared gateway

Dedicated gateway

GenerateDataKey

Generates a random data key for envelope encryption. The data key is returned in both plaintext and ciphertext forms.

Supported

Supported

GenerateAndExportDataKey

Generates a random data key, encrypts it by using a CMK and a public key that you specify, and returns both ciphertexts.

Supported

Supported

Encrypt

Encrypts plaintext by using a symmetric CMK.

Supported

Supported

Decrypt

Decrypts ciphertext that was encrypted by using a CMK.

Supported

Supported

ReEncrypt

Re-encrypts ciphertext under a different CMK without exposing the plaintext.

Supported

Supported

ExportDataKey

Exports a data key encrypted by a CMK. The data key is re-encrypted by a public key that you specify for secure transmission.

Supported

Supported

GenerateDataKeyWithoutPlaintext

Generates a random data key in only ciphertext form, without the plaintext copy.

Supported

Unsupported

AsymmetricSign

Generates a digital signature by using an asymmetric CMK.

Supported

Supported

AsymmetricVerify

Verifies a digital signature by using the public key of an asymmetric CMK.

Supported

Supported

AsymmetricEncrypt

Encrypts data by using the public key of an asymmetric CMK.

Supported

Supported

AsymmetricDecrypt

Decrypts data by using the private key of an asymmetric CMK.

Supported

Supported

GetPublicKey

Retrieves the public key of an asymmetric key. You can use the public key to encrypt data or verify a signature on your device.

Supported

Supported

Business operations-Retrieving secret values

API

Description

Shared gateway

Dedicated gateway

GetSecretValue

Retrieves a secret value.

Supported

Supported

Supported programming languages

The following table lists SDK download links and documentation for each supported language.

Supported programming language

V2.0 SDK

V1.0 SDK (not recommended)

Java

Python

C++

PHP

.NET (C#)

Go

TypeScript

None

Swift

None