Key Management Service (KMS) offers three tiers: free default keys, paid software key management instances, and paid hardware key management instances. Default keys come in two forms — service keys and customer master keys (CMKs).
indicates that the item is supported. indicates that the item is not supported.
Category | Item | Default key | Software key management instance | Hardware key management instance | References | |
Service key | CMK | |||||
Billing method | Free | Free | Subscription, Pay as you go | Subscription, Pay as you go To use this instance, you must purchase two hardware security modules (HSMs). For more information, see Billing. | ||
Scenario | Server-side encryption in Alibaba Cloud services | |||||
Data encryption in self-managed applications | ||||||
Secret lifecycle management | ||||||
Compliance with Federal Information Processing Standard (FIPS) 140-3 Level 3 validation requirements | ||||||
Quota | Computing performance (symmetric encryption and decryption) | 1,000 QPS. The specification cannot be upgraded. | 1,000 QPS. The specification cannot be upgraded. | Shared gateway access: 1,000 QPS. Upgrade is not supported. Dedicated gateway access: 1,000, 2,000, or 4,000 QPS available at purchase. Upgrades are supported. | Shared gateway access: 1,000 QPS. Upgrade is not supported. Dedicated gateway access: 2,000, 4,000, 6,000, or 8,000 QPS available at purchase. Upgrades are supported. | |
Number of keys | Within an Alibaba Cloud account, each Alibaba Cloud service can create one service key in each region. | Within an Alibaba Cloud account, you can create one CMK in each region. | 1,000 to 100,000 | 1,000 to 100,000 | None | |
Number of secrets | Secrets are not supported. | Secrets are not supported. | 0 to 100,000 | 0 to 100,000 | None | |
Network type of the endpoint | Public network, VPC | Public network, VPC | Public network, VPC | Public network, VPC | ||
Multi-account resource sharing | ||||||
Backup management | ||||||
Security audit | ||||||
Key management | Key specifications | Aliyun_AES_256 | Aliyun_AES_256 |
|
| |
Import of external key material (BYOK mode) | ||||||
Key rotation | You must purchase a value-added plan. | You must purchase a value-added plan. | Only symmetric keys are supported. Asymmetric keys are not supported. | |||
Scheduled key deletion | ||||||
Key deletion protection | ||||||
Key alias | ||||||
Key tag | ||||||
Cryptographic operation | Data encryption and decryption | |||||
Signature generation and verification | ||||||
Secret management | Secret creation | |||||
Secret deletion | ||||||
Secret rotation | ||||||
Secret tag | ||||||
Secret value retrieval | ||||||