Introduction
This document provides information on how to enable server-side encryption when objects are uploaded. Server-side encryption keys are classified into three types:
COS-managed encryption keys
KMS-managed encryption keys
Customer-provided encryption keys
Related Examples
Feature Name | Description | Example code |
Server-Side Encryption | Provides the feature of enabling server-side encryption when objects are uploaded. |
Preliminary Preparation
Before you start, you must first create a TransferManager instance. Before creating a TransferManager instance, you need to create a CosXmlService instance. For detailed code, see Create CosXmlService.
// Initialize TransferConfig with the default configuration. For customization, see the SDK API documentation.// By default, files larger than or equal to 2 MB are automatically uploaded in parts, with a part size of 1 MB. You can modify the part threshold using the following code.TransferConfig transferConfig = new TransferConfig.Builder() // Set the minimum object size for enabling multipart upload. The default is 2 MB. .setDivisionForUpload(2097152) // Set the part size for multipart upload. The default is 1 MB. .setSliceSizeForUpload(1048576) // Set whether to force simple upload and disable multipart upload. .setForceSimpleUpload(false) .build();// Initialize TransferManagerTransferManager transferManager = new TransferManager(cosXmlService,transferConfig);
Use Case
Protecting Data with Server-Side Encryption Using COS-Managed Keys (SSE-COS)
Tencent Cloud COS hosts and manages the master keys and data. COS automatically encrypts your data when it is written to the data center and decrypts it when you access the data. Currently, it supports using the COS master key to encrypt data with AES-256.
PutObjectRequest putObjectRequest = new PutObjectRequest(bucket, cosPath, srcPath);// Enable server-side encryption with COS-managed encryption keys (SSE-COS) to protect data.putObjectRequest.setCOSServerSideEncryption();// Upload documents.COSXMLUploadTask cosxmlUploadTask = transferManager.upload(putObjectRequest, uploadId);
Protecting Data with Server-Side Encryption Using KMS-Managed Keys (SSE-KMS)
SSE-KMS encryption is server-side encryption that uses KMS-managed keys. KMS is a security management service launched by Tencent Cloud. It uses third-party certified Hardware security modules (HSMs) to generate and protect keys. KMS helps users easily create and manage keys, meeting their key management needs across multiple applications and businesses, as well as fulfilling regulatory and compliance requirements. For information on how to activate the KMS service, see: Server-Side Encryption Overview.
// Server-side encryption keysString customKey = "Customer Master Key (CMK)";String encryptContext = "Encryption Context";PutObjectRequest putObjectRequest = new PutObjectRequest(bucket, cosPath, srcPath);// Enable server-side encryption with customer-provided customer master keys (SSE-KMS) to protect data.try {putObjectRequest.setCOSServerSideEncryptionWithKMS(customKey, encryptContext);} catch (CosXmlClientException e) {e.printStackTrace();}// Upload documents.COSXMLUploadTask cosxmlUploadTask = transferManager.upload(putObjectRequest, uploadId);
Protecting Data with Server-Side Encryption Using Customer-Provided Keys (SSE-C)
The encryption key is provided by the user. When the user uploads an object, COS will use the user-provided encryption key to encrypt the user's data with AES-256.
Note:
The service running with this encryption requires HTTPS requests.
The user must provide a 32-byte string as the encryption key. The string must consist of a combination of numbers, letters, and characters, and must not contain Chinese characters.
If a key is configured for encryption when a file is uploaded, you must include the same key in the request when using GET (download) or HEAD (query) operations on the source object to receive a normal response.
// Server-side encryption keysString customKey = "Server-side encryption key";PutObjectRequest putObjectRequest = new PutObjectRequest(bucket, cosPath, srcPath);// Enable server-side encryption with customer-provided encryption keys (SSE-C) to protect data.try {putObjectRequest.setCOSServerSideEncryptionWithCustomerKey(customKey);} catch (CosXmlClientException e) {e.printStackTrace();}// Upload documents.COSXMLUploadTask cosxmlUploadTask = transferManager.upload(putObjectRequest, uploadId);