There is a Key Management Service (KMS) under Alibaba Eco system which providing comprehensive on-cloud data encryption solution that includes KMS and Cloud Hardware Security Module. This solution helps solve concerns such as data security, key security, key management, and secret management.
I would like to share KMS options, roadmap of KMS, cost model, as well as BYOK (Bring Your Own Key)!
KMS Options:
Alibaba Clooud offers Service-Managed Key, Shared KMS, KMS 2.0 & 3.0 so far
For Shared KMS, it is customer managed key (Master key per Account) which
• Shared HSM
• FIPS Comply
• Manual Key Rotation
• Integrated with Alibaba Cloud Service - ECS, RDS, OSS, NAS etc.
KMS 2.0 highlight:
There is a roadmap for KMS upgrade back to a year ago
• Shared KMS retired at the end of 2023 already
• More Flexibility with KMS 3.0
• Upgrade from Shared KMS to KMS 3.0 involves resource re-deployment
KMS 3.0 cost model:
• Default Key Management: 1 free tier CMK (BYOK) per UID. This key is shared across VPC for cloud resource protection ( not app level api encryption)
• Software Key Management: 1 x USD 500 instance + USD 125 for additional VPC/UID
• This cost model is applicable to the public
• Email confirmation by Alibaba Cloud
GUI reference on KMS 3.0
You may also interest
Disclaimer: The views expressed herein are for reference only and don't necessarily represent the official views of Alibaba Cloud.
Microsoft Entra Single Sign-On (SSO) Integration with Alibaba Cloud
Alibaba Clouder - May 29, 2019
Rupal_Click2Cloud - September 8, 2023
Alibaba Cloud Community - November 12, 2024
Rupal_Click2Cloud - December 14, 2023
Yagr - July 8, 2020
Alibaba Cloud Community - March 16, 2022
Industry-standard hardware security modules (HSMs) deployed on Alibaba Cloud.
Learn MoreOrganize and manage your resources in a hierarchical manner by using resource directories, folders, accounts, and resource groups.
Learn MoreCreate, delete and manage encryption keys with Alibaba Cloud Key Management Service
Learn MoreA Web browser-based admin tool that allows you to use command line tools to manage Alibaba Cloud resources.
Learn MoreMore Posts by Kidd Ip