Alibaba Cloud services that integrate with KMS for data encryption.
If your Alibaba Cloud service supports KMS encryption and the default service key or master key meets your needs, you do not need a separate KMS instance.
Workload data encryption
Service | Description | Related documentation |
Elastic Compute Service (ECS) | ECS cloud disk encryption uses a service key by default, or a CMK you specify. Each cloud disk is associated with a CMK and data key for envelope encryption. Data transferred between an ECS instance and its cloud disk is automatically encrypted and decrypted on the host, with negligible performance impact. After you create an encrypted cloud disk and attach it to an ECS instance, the following data is encrypted:
| |
Container Service for Kubernetes (ACK) | ACK supports KMS-based server-side encryption for two types of workload data:
| |
Container Registry (ACR) | ACR supports automatic namespace-level image signing to prevent man-in-the-middle attacks and unauthorized image use. Pushed images are signed based on matching rules, ensuring integrity from distribution to deployment. | |
Elastic Container Instance (ECI) | Each ECI Pod has a 30 GiB temporary storage space (expandable) for container images and runtime data. Enable encryption for this space to protect sensitive data. |
Persistent storage data encryption
Service | Description | Related documentation |
Object Storage Service (OSS) |
| |
File Storage NAS | NAS encryption uses a service key by default. Each volume is assigned a unique CMK and data key for envelope encryption. | |
Tablestore | Tablestore encryption uses a service key by default, or a key you select. Each table is assigned a unique CMK and data key for envelope encryption. | None |
Cloud Storage Gateway (CSG) | Encrypts data based on OSS encryption. | |
Microservices Engine (MSE) | MSE integrates with KMS to encrypt sensitive configuration data (data sources, tokens, usernames, and passwords), reducing the risk of plaintext leaks. | |
Cloud Backup | Cloud Backup supports server-side encryption of backup data using KMS keys. You can use KMS service keys or customer-managed keys (CMKs) to encrypt backup data from ECS instances, NAS file systems, OSS buckets, and other data sources, reducing the risk of data leaks. |
Database encryption
Service | Description | Related documentation |
ApsaraDB RDS | RDS provides the following two data encryption methods:
|
|
ApsaraDB for MongoDB | Provides TDE. The encryption method is similar to RDS. | |
PolarDB |
| |
OceanBase | ||
Tair (Redis OSS-compatible) | ||
Tair | ||
AnalyticDB | Encrypts the entire data disk at the block storage level, ensuring that leaked backups cannot be decrypted. |
|
ApsaraDB for ClickHouse |
Log data encryption
Service | Description | Related documentation |
ActionTrail | Encrypt operational events delivered to OSS when you create a single-account or multi-account trail. | |
Simple Log Service (SLS) | SLS uses KMS to encrypt data at rest. |
Big data and AI
Service | Description | Related documentation |
MaxCompute | MaxCompute supports data encryption by using a service key or a CMK. | |
Platform for AI | Cloud services at each stage of the PAI data flow (compute engines, container services, data storage) support server-side encryption. | None |
E-MapReduce | Data disk encryption protects both data in transit and data at rest, helping meet security and compliance requirements. |
Additional use cases
Service | Description | Related documentation |
CDN | Supports OSS server-side encryption when using an OSS bucket as origin. | |
ApsaraVideo Media Processing (MPS) | MPS supports two methods for protecting video content with KMS: proprietary encryption and standard HLS encryption. | None |
ApsaraVideo VOD | VOD supports two methods for protecting video content with KMS: Alibaba Cloud video encryption and standard HLS encryption. | |
Hologres | Hologres uses KMS to encrypt data at rest, helping meet regulatory and security compliance requirements. | |
ApsaraVideo Live | Encrypts video data so that downloaded videos remain encrypted and cannot be redistributed. Prevents leaks and unauthorized hotlinking for copyrighted content such as online education, finance, industry training, and exclusive drama series. | |
Wuying Workspace Enterprise Edition | Enable disk encryption for system and data disks when creating a cloud computer. |