This page tracks significant changes to Key Management Service (KMS), including new features, optimizations, and bug fixes.
Important
KMS 1.0 entered End of Full Support (EoFS) on March 30, 2025, and will reach End of Service (EOS) on September 30, 2025 (both at 00:00:00 GMT+8). Migrate your KMS 1.0 resources to KMS 3.0 instances before the EOS date to avoid service disruption. See Migrate KMS 1.0 resources to KMS 3.0 instances.
2026
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| dkms-3.9.0 | New feature | Instance Gateway OpenAPI now authenticates GenerateDataKey and Decrypt calls from Trusted Computing Environments (TCE), so workloads running in TCE can access KMS with policy-based access control. | 2026-01-13 | All regions | Policy condition keys |
| dkms-3.9.0 | Optimization | Instance SDK now supports asymmetric key rotation, aligning SDK capabilities with OpenAPI. | 2026-01-13 | All regions | None |
| dkms-3.8.0 | New feature | Hardware instances now support manual backup, giving you control over when backups are created in addition to automatic backups. | 2026-01-06 | All regions | Backup management |
2025
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| dkms-3.7.0 | New feature | International hardware instances now support asymmetric Bring Your Own Key (BYOK) import. International single-version keys can also be migrated to hardware instances. | 2025-12-09 | International regions | Migration steps |
| dkms-3.6.2 | Optimization | Resource policy authentication now supports Strict Mode, allowing you to enforce stricter access control when evaluating policy conditions. | 2025-10-28 | All regions | Policy condition keys |
| dkms-3.6.1 | Optimization | Resolved a backup failure that occurred in single-owner instance scenarios. | 2025-10-09 | All regions | None |
| dkms-3.6.0 | New feature | Instance sharing now supports Independent Ownership mode, enabling the instance owner to retain control over shared resources. Software instances now also support multi-version BYOK key import. | 2025-09-12 | All regions | Share KMS instances across multiple accounts |
| dkms-3.5.0 | New feature | Multi-version symmetric keys in Chinese mainland regions can now be migrated to hardware instances. | 2025-08-13 | US regions | Migration steps |
| dkms-3.4.0 | New feature | New instances in US regions exclusively use TLSv1.2, enforcing a minimum TLS version for data in transit. | 2025-08-06 | All regions | N/A |
| dkms-3.3.0 | New feature | Hardware instances in China now support key rotation, bringing this capability in line with software instances. | 2025-08-12 | All regions | Migration steps |
| dkms-3.3.0 | Optimization | Resolved session handling issues for international hardware instances. | — | — | None |
| dkms-3.2.2 | New feature | Software key management instances now support creating asymmetric keys with the RSA-4096 specification. | 2025-06-18 | All regions | Understanding KMS keys |
| dkms-3.2.0 | Optimization | Secret retrieval performance is improved by caching secrets in ciphertext in Redis, reducing latency for high-frequency secret reads. | 2025-02-19 | All regions | None |
| dkms-3.1.0 | Optimization | KMS instances now dynamically detect Hardware Security Module (HSM) cluster changes after scale-out, keeping data synchronized without manual intervention. | 2025-01-07 | All regions | Purchase and enable a KMS instance |
2020
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| — | New feature | An API operation to activate KMS is now supported. New APIs: OpenKmsService and DescribeAccountKmsStatus. | 2020-10-20 | All regions | OpenKmsService · DescribeAccountKmsStatus |
| — | New feature | KMS now supports cross-system exchange, re-encryption, and cross-region import and export of data keys. New APIs: GenerateDataKeyWithoutPlaintext, GenerateAndExportDataKey, ExportDataKey, and ReEncrypt. KMS is now available in China (Guangzhou). | 2020-07-07 | All regions | GenerateDataKeyWithoutPlaintext · GenerateAndExportDataKey · ExportDataKey · ReEncrypt |
| — | New feature | Secrets Manager is released. KMS is now available in China (Ulanqab) and China (Heyuan). | 2020-02-24 | All regions | Overview of Secrets Manager · Overview of generic secrets · Manage generic secrets · Rotate a generic secret |
2019
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| — | New feature | KMS now supports asymmetric keys for encryption, decryption, and digital signature operations. New APIs: AsymmetricEncrypt, AsymmetricDecrypt, AsymmetricSign, AsymmetricVerify, and GetPublicKey. | 2019-12-13 | All regions | Overview of asymmetric keys · Asymmetric data encryption and decryption · Asymmetric digital signatures |
| — | New feature | Hardware key management instances can now use an HSM cluster to store keys, meeting the regulatory requirements of State Cryptography Administration (SCA). | 2019-11-18 | China (Beijing) and China (Shanghai) | KMS hardware key management instances support HSMs |
| — | New feature | Each customer master key (CMK) now supports multiple versions and automatic rotation. New APIs: UpdateKeyDescription and GenerateDataKeyWithoutPlaintext. | 2019-09-24 | All regions | Automatic rotation of keys |
| — | New feature | Hardware key management instances can now use an HSM cluster to store keys. | 2019-07-31 | Singapore and China (Hong Kong) | KMS hardware key management instances support HSMs |
| — | New feature | Key tags and tag-based authentication are now supported. | 2019-05-01 | All regions | TagResource · Use RAM to implement access control on resources |
2018
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| — | New feature | ActionTrail integration is now supported for auditing KMS operations. | 2018-07-24 | All regions | Use ActionTrail to query the operations of Key Management Service |
| — | New feature | BYOK support added via new API operations for importing key material. CMK aliases are now supported. KMS is now available in Indonesia (Jakarta), US (Virginia), and US (Silicon Valley). | 2018-08-30 | All regions | Import key material |
2017
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| — | New feature | KMS is now available in China (Qingdao), China (Hohhot), and Malaysia (Kuala Lumpur). | 2017-11-15 | China (Qingdao), China (Hohhot), and Malaysia (Kuala Lumpur) | None |
| — | New feature | New API: DescribeRegions. KMS SDK updated to V2.4.0. | 2017-06-05 | All regions | DescribeRegions |
| — | New feature | KMS is now available for commercial use (launched April 25, 2017). KMS is now available in China (Zhangjiakou). | 2017-05-10 | All regions | None |
| — | Optimization | Performance optimization. | 2017-03-01 | All regions | None |
| — | New feature | KMS is now available in China (Hong Kong). | 2017-01-22 | China (Hong Kong) | None |
2016
| Version | Change type | Description | Date | Region | References |
|---|---|---|---|---|---|
| — | New feature | KMS is now available in Japan (Tokyo), Germany (Frankfurt), and UAE (Dubai). | 2016-11-29 | Japan (Tokyo), Germany (Frankfurt), and UAE (Dubai) | None |
| — | New feature | New APIs for key deletion scheduling: ScheduleKeyDeletion and CancelKeyDeletion. | 2016-09-20 | All regions | ScheduleKeyDeletion · CancelKeyDeletion |
| — | New feature | The EncryptionContext parameter is now supported in the Encrypt and Decrypt API operations. | 2016-08-10 | All regions | Description of EncryptionContext |
| — | New feature | CMKs can now be enabled or disabled. | 2016-06-22 | All regions | Create a CMK |
| — | New feature | KMS is now available in China (Beijing), China (Shanghai), and China (Shenzhen). | 2016-05-19 | China (Beijing), China (Shanghai), and China (Shenzhen) | None |
| — | New feature | KMS is released. | 2016-04-06 | All regions | What is Key Management Service |
该文章对您有帮助吗?