检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Encryption Functions Table 1 Encryption functions MySQL GaussDB Difference AES_DECRYPT() Supported, with differences GaussDB does not support ECB mode, which is an insecure encryption mode, but uses CBC mode by default. When characters are specified to be encoded in SQL_ASCII for
Encryption Functions Table 1 Encryption functions MySQL GaussDB Difference AES_DECRYPT() Supported. - AES_ENCRYPT() Supported. - Parent topic: System Functions
Security and Encryption Database Account Security Resetting the Administrator Password to Restore root Access Changing a Security Group Performing a Server-Side Encryption Configuring an SSL Connection Configuring the TDE Function Configuring a Password Expiration Policy Unbinding
Security and Encryption Database Account Security Resetting the Administrator Password to Restore Root Access Configuring an SSL Connection Configuring a Password Expiration Policy Unbinding an EIP Using DBSS (Recommended)
Security and Encryption Database Account Security Resetting the Administrator Password to Restore root Access Changing a Security Group Performing a Server-Side Encryption Using DBSS (Recommended)
Security and Encryption Database Account Security Resetting the Administrator Password Changing a Security Group Performing a Server-Side Encryption Configuring the TDE Function Using DBSS (Recommended)
Decrypting Data Function Description:This API is used to decrypt data. Constraints To decrypt data that was encrypted using an asymmetric key, specify the key ID and encryption algorithm. If the specified key and encryption algorithm do not match those used for data encryption, the
Decrypting a DEK Function Description: This API is used to decrypt a DEK by using a specified CMK. URI POST /v1.0/{project_id}/kms/decrypt-datakey Table 1 Path Parameters Parameter Mandatory Type Description project_id Yes String Project ID Request Parameters Table 2 Request header
Security and Encryption Configuring Database Security Resetting the Administrator Password Changing the Security Group of a DB Instance Configuring SSL for a DB Instance Enabling TDE for a DB Instance
Transparent Data Encryption GaussDB(DWS) supports transparent data encryption (TDE) to encrypt and decrypt data files in real time, protecting user data privacy. Feature Description Transparent Data Encryption (TDE) encrypts GaussDB(DWS) data files. Generally, data security can be
Configuring Bucket Encryption Functions OBS uses the PUT method to create or update the default server-side encryption for a bucket. After you configure encryption for a bucket, objects uploaded to this bucket will be encrypted with the bucket encryption settings you specified. Currently
Server-Side Encryption Overview You can configure server-side encryption for objects, so that they will be encrypted or decrypted when you upload them to or download them from a bucket. The encryption and decryption happen on the server side. The encryption methods provided include
Encryption Data Request This topic is used to publish the request for obtaining encryption data. Topic $hw/{project_id}/encryptdatas/{encryptdata_name}/properties/{properties_name}/decrypt Parameter Type Description project_id String Project ID. For details on how to obtain a project
Encryption Data Acquisition This topic is used to subscribe to encryption data. Topic $hw/{project_id}/encryptdatas/{encryptdata_name}/properties/{properties_name}/plaintext Parameter Type Description project_id String Project ID. For details on how to obtain a project ID, see Obtaining
Encryption Data Request This topic is used to publish the request for obtaining encryption data. Topic $hw/{project_id}/encryptdatas/{encryptdata_name}/properties/{properties_name}/decrypt Parameter Type Description project_id String Project ID. For details on how to obtain a project
Encryption Data Acquisition This topic is used to subscribe to encryption data. Topic $hw/{project_id}/encryptdatas/{encryptdata_name}/properties/{properties_name}/plaintext Parameter Type Description project_id String Project ID. For details on how to obtain a project ID, see Obtaining
File System Encryption You can encrypt data on the newly created SFS Turbo file systems if needed. Keys used by encrypted file systems are provided by the Key Management Service (KMS), which is secure and convenient. You do not need to establish and maintain the key management infrastructure
Rotating Encryption Keys If you have enabled the Encrypt DataStore function in Advanced Settings during cluster creation, you can rotate the encryption keys for the cluster after the cluster is created successfully. When a normal cluster is converted to an encrypted cluster, you can
Configuring SSL Encryption SSL is enabled by default when you create an RDS for PostgreSQL DB instance and cannot be disabled after the instance is created. SSL encryption ensures that all communications between a client and server are encrypted, preventing data leakage and tampering
Server-Side Encryption Overview If you have any questions during development, post them on the Issues page of GitHub. For details about parameters and usage of each API, see the API Reference. OBS provides server-side encryption for objects, so that they will be encrypted or decrypted