简体   繁体   English

自带密钥 (BYOK) 和客户管理密钥 (CMK) 加密之间的区别?

[英]Difference between Bring-Your-Own-Key (BYOK) and Customer-Managed-Key (CMK) encryption?

On the documentation page of Azure I regularly read the abbreviation BYOK encryption (eg here ) and CMK encryption (eg here ).在 Azure 的文档页面上,我经常阅读缩写BYOK加密(例如此处)和CMK加密(例如此处)。

Can these two terms be used synonymously or is there a difference?这两个术语可以同义使用还是有区别?

They are often used interchangeably.它们经常互换使用。 BYOK usually means the vendor holds the key, but you create it and upload it. BYOK 通常意味着供应商持有密钥,但您创建并上传它。 CMK can mean that but also sometimes reflects the case where you hold your key in your own KMS instead, so it tends to encompass more patterns than BYOK does in practice. CMK 可能意味着,但有时也反映了您将密钥保存在自己的 KMS 中的情况,因此它往往包含比 BYOK 在实践中更多的模式。 Neither of these have formal definitions that you can rely on though.但是,它们都没有您可以依赖的正式定义。

Both are the same.两者都是一样的。 In the azure postgres link you can see that both CMK and BYOK are mentioned in the same paragraph.在 azure postgres 链接中,您可以看到 CMK 和 BYOK 都在同一段落中提到。

As a customer, You bring your own encryption key and you are responsible for managing it.作为客户,您携带自己的加密密钥并负责管理它。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM