tencent cloud

Creating a Data Key

Download
Focus Mode
Font Size
Last updated: 2026-07-24 11:55:51
AI-Translated

Scenarios

You can create a data encryption key (DEK) in the Tencent Cloud KMS (Compliant) console. After creation, you can enable, disable, rotate, or manage permissions for the DEK. This document describes how to create a DEK through the console.

Operation Steps

1. Log in to the KMS (Compliant) console. In the left sidebar, click Key Management > Data Key.
2. On the data key management page, click Create Data Key. In the configuration box that pops up, enter the following information:
Parameter
Description
Key Name
(Required) It represents the UUID of the key within the region.
The key name can only contain letters, digits, and the characters _ and -, and cannot start with "KMS-".
Key length
Supports 256-bit and 128-bit.
Description information.
(Optional) It is used to describe the current key information.
Root Key
(Required) A data encryption key is a secondary key generated based on a root key. You can select an existing root key or create a new one.
3. After clicking OK, you will return to the key list. The newly created key will appear at the top of the list.


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback