The page has been translated by Gen AI.

How-to guides

Users can create the service by entering the required information for the Key Management Service through the Samsung Cloud Platform Console and selecting detailed options.

Reference

Key Management Service provides the following two key services.

  • Customer-managed key: To securely protect important application data, users can generate and manage encryption keys themselves.
  • Platform-managed key: Since CSP(Cloud Service Provider) creates and manages it directly, users cannot change or delete the key’s properties.

Create a customer-managed key

You can create and use a customer-managed key in the Samsung Cloud Platform Console.

To create a customer-managed key, follow these steps.

  1. All Services > Security > Key Management ServiceClick the menu. 1. Go to the Service Home page of Key Management Service.

  2. On the Service Home page, click the Create Customer Managed Key button. 2. Go to the Customer Managed Key Creation page.

  3. On the Customer Managed Key Creation page, enter the information required to create the service and provide additional details.

    • Enter or select the required information in the Service Information Input area.
      Category
      required status
      Detailed description
      Key nameRequiredEnter key name
      Public authentication algorithmSelectionUse When selected, you can generate encryption keys that comply with public encryption standards
      • The public authentication algorithm option is available only in the KR SOUTH region
      • The public authentication algorithm provides the ARIA algorithm, which has passed security verification through Korea’s cryptographic module validation program
      PurposeRequiredSelect the key purpose and encryption method
      • If you do not select the use of public authentication algorithms, choose among encryption/decryption (AES-256), encryption/decryption and signing/verification (RSA-2048), signing/verification (ECDSA), and generation/verification (HMAC)
      Auto rotationSelectionSelect whether to enable automatic key rotation
      • If Use is selected, the internal algorithm of the generated key is converted to a different value and applied at each configured rotation interval
      • The rotation interval can be set to a value between 1 and 730 days. If the rotation interval is not specified, it defaults to 90 days
      Public access controlRequiredEnter the IP range to allow access
      • After entering the IP range to use, click the Add button
      • You must enter at least one, and up to a maximum of 10 can be entered
      • /24 - /32 ranges can be used, but may be vulnerable to security risks
      • Click Delete All in the IP list to remove all registered entries
      Private access controlSelectionSelect the resource to allow access
      • Use select, then click the Add button to select the resource to use
      • Click Delete in the resource list to remove the registered item
      • If private access control is not set, you cannot access any private resources
      ExplanationSelectionEnter additional information for the key
      Table. Customer Managed Key Service Information Input Items
    • In the Additional Information Input area, enter or select the required information.
      Category
      required status
      Detailed description
      tagSelectionAdd Tag
      • Up to 50 per resource can be added
      • Add Tag After clicking the Add Tag button, enter or select Key, Value values
      Table. Customer-managed key additional information input fields
  4. Summary Check the detailed information and estimated charges generated in the panel, and click the Create button.

    • Once creation is complete, check the created resource on the Customer Managed Key List page.
Reference
When selecting a public authentication algorithm, you can create up to 100 customer-managed keys.

Check detailed information of customer-managed key

You can view and edit the full resource list and detailed information of customer-managed keys. Customer Managed Key Details page consists of Details, Tags, Activity Log tabs.

Reference

If the status of the customer-managed key service is Creating, the service is being created, so you cannot navigate to the detail page.

  • If it remains in the Creating state after a certain amount of time, delete the key and recreate it.

To view detailed information about the Key Management Service, follow these steps.

  1. Click the All Services > Security > Key Management Service menu. 1. Go to the Service Home page of Key Management Service.
  2. On the Service Home page, click the Customer Managed Key menu. 2. Navigate to the Customer Managed Key List page.
  3. On the Customer Managed Key List page, click the resource to view its details. 3. Go to the Customer Managed Key Details page.
    • Customer Managed Key Details The top of the page displays status information and descriptions of additional features.
      CategoryDetailed description
      statusDisplays the status of a customer-managed key
      • Active: available/activated
      • Stop: stopped/disabled
      • To be terminated: scheduled for deletion
      • Creating: creating/creation error (immediate retry possible)
      Key rotationButton to manually rotate the generated key
      Key DeactivationButton to deactivate the generated key
      Service cancellationButton to terminate the service
      • When the status is To be terminated, display the Cancel termination button
      Table. Customer-managed key status information and additional features

Detailed Information

Customer Managed Key List page allows you to view detailed information of the selected resource and edit the information if necessary.

Category
Detailed description
serviceService Name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Name
Resource ID서비스에서의 고유 자원 ID
생성자서비스를 생성한 사용자
생성 일시서비스를 생성한 일시
키명생성된 키의 이름
공공 인증 알고리즘공공 인증 알고리즘 사용 여부
용도암/복호화 및 서명/검증 같은 키의 용도 및 암호화 방식
현재 버전생성된 키의 현재 버전
  • 키 회전 시 버전이 1씩 증가
자동 회전키의 자동 회전 사용 여부
  • 수정 아이콘을 클릭하면 수정 가능
다음 회전일회전 주기에 따른 키의 다음 회전일 표시
  • 해당 날짜에 자동으로 키 회전 실행
회전 주기자동 회전 사용 시 회전 주기 기간
URL퍼블릭/프라이빗 접속 URL 주소
  • 복사 아이콘을 클릭하면 주소 복사 가능
퍼블릭 접근 제어퍼블릭 접근 허용 IP 주소
  • 수정 아이콘을 클릭하면 수정 가능
프라이빗 접근 제어프라이빗 접근 허용 리소스
  • 수정 아이콘을 클릭하면 수정 가능
설명키에 대한 추가 설명 표시
  • 수정 아이콘을 클릭하면 수정 가능
Table. Customer-managed key detailed information tab items

Tag

On the Customer Managed Key List page, you can view the tag information of the selected resource and add, modify, or delete it.

구분상세 설명
태그 목록태그 목록
  • 태그의 Key, Value 정보 확인 가능
  • 태그는 자원 당 최대 50개까지 추가 가능
  • 태그 입력 시 기존에 생성된 Key와 Value 목록을 검색하여 선택
Table. Customer-managed key tag tab items

Job History

On the Customer Managed Key List page, you can view the operation history of the selected resource.

구분상세 설명
작업 내역작업 수행 내용
  • 암호화, 복호화, 서명, 검증, 데이터 키 생성, rewrap API 로그 항목 표시
작업 일시작업 수행 일시
자원 유형자원 유형
자원명자원 이름
작업 결과작업 수행 결과(성공/실패)
작업자 정보작업을 수행한 사용자 정보
Table. Customer Managed Key Operation History Tab Detailed Information Items

Managing Customer-Managed Keys

You can create a new version of a registered key or change its usage status.

Configure customer-managed key rotation

Key rotation is a feature that transforms the internal algorithm of a generated key into a different value.

Reference
  • When rotating the key, only the master key value changes, and the ciphertext and plaintext values of previously generated data keys remain unchanged.
  • Even if key rotation is performed, the master key retains the previous version’s data, so decryption using the master key is unaffected, and the value of the data key in use also remains unchanged.
    • However, when wrapping with a changed master key (decrypting and then re‑encrypting), calling the rewrapData API will trigger the key rotation function.
  • When rotating a customer-managed key, the key’s version is changed internally. * By using a newly generated version key, you can decrypt data encrypted with the previous version’s key, preserving compatibility.
    • Versions changed by key rotation are compatible up to the 100th version, regardless of the encryption algorithm.

To create a new version of a customer-managed key (key rotation), follow these steps.

  1. Click the All Services > Security > Key Management Service menu. 1. Go to the Service Home page of Key Management Service.
  2. On the Service Home page, click the Customer Managed Key menu. 2. Navigate to the Customer Managed Key List page.
  3. On the Customer Managed Key List page, click the resource to view detailed information. 3. Navigate to the Customer Managed Key Details page.
  4. On the Customer Managed Key Details page, click the Key Rotation button. 4. Key Rotation Navigate to the notification window.
  5. In the Key rotation notification dialog, click the Confirm button.

Configure Customer-Managed Key Activation

You can configure the usage of the selected key.

Reference
If you set the key to a disabled state, users who rely on that key will no longer be able to use it.

To set the activation/deactivation status of a customer-managed key you created, follow these steps.

  1. Click the All Services > Security > Key Management Service menu. 1. Go to the Service Home page of Key Management Service.
  2. On the Service Home page, click the Customer Managed Key menu. 2. Navigate to the Customer Managed Key List page.
  3. On the Customer Managed Key List page, click the resource to view its details. 3. Navigate to the Customer Managed Key Details page.
  4. On the Customer Managed Key Details page, click the Enable/Disable Key button. 4. Key activation/Key deactivation Navigate to the notification dialog.
  5. In the Key activation/key deactivation notification dialog, click the OK button.

Encryption case using Key Management Service keys

An example procedure for encrypting and storing a user application’s critical data by obtaining a data key from KMS is as follows.

  1. When the application starts, it obtains a data key using the KMS master key information, and then uses the plaintext data key on the client side to perform secure data encryption and store it.
  2. The data key is stored in the database in an encrypted form using the master key.
  3. When performing secure data decryption, the data key stored in the database is retrieved and a decryption request is made using the KMS master key information.

The encryption/decryption process using the Key Management Service key is explained with the following diagram.

Encryption

Encryption Process Example
Figure. KMS encryption process example

Decryption

Decryption Procedure Example
Figure. KMS Decryption Procedure Example

Terminate Customer Managed Key

You can revoke customer-managed keys that are not in use.

Caution
If you revoke the key, you will no longer be able to use any requests or features of the customer-managed key, and it will be permanently deleted either immediately upon revocation or 72 hours later through a scheduled revocation.

To cancel a customer-managed key, follow these steps.

  1. Click the All Services > Security > Key Management Service menu. 1. Go to the Service Home page of Key Management Service.
  2. On the Service Home page, click the Customer Managed Key menu. 2. Go to the Customer Managed Key List page.
  3. On the Customer Managed Key List page, click the resource to view its details. 3. Go to the Customer Managed Key Details page.
  4. On the Customer Managed Key Details page, click the Terminate Service button. 4. Navigate to the Service Cancellation alert window.
  5. Service cancellation alert dialog, select Immediate cancellation / Scheduled cancellation and verify the contents, then click the Confirm button.
  6. When termination is complete, check on the Customer Managed Key List page whether the resource has been terminated.
    • When the key deletion is complete, a notification is sent to both the user who created the key and the user who deleted it.
Reference
  • Even if you click the Service Termination button in the More Options menu at the far right of the generated customer-managed key list, you can terminate the selected key.
  • To undo the cancellation of a reserved service, click the Cancel Cancellation button on the customer-managed key list page or the detail page.
    • Cancel Service Termination in the popup window, if you click Confirm, the selected key will not be deleted and will be restored in a disabled state.
    • To reuse the key, click the Customer Managed Key Details page’s Activate Key button.
Overview
Encryption Example Using Key Management Service Keys