GenerateDataKey#

Description#

Generates a random encryption key for use outside KMS. The method returns a plaintext copy of the key and a copy of the key encrypted with a KMS key.

Request Parameters#

Required parameters#

  • KeyId — The ID of the KMS key or an alias name with the alias/ prefix.

    • Type: String

    • Required: Yes

Optional parameters#

  • EncryptionContext — The encryption context used as additional authenticated data (AAD).

    • Type: Map of strings

    • Required: No

    • Constraints: The total length of all strings in UTF-8 encoding must not exceed 6144 bytes

  • KeySpec — The key type. Use AES_128 to generate a 128-bit key, or AES_256 to generate a 256-bit key.

    • Type: String

    • Required: Yes, if NumberOfBytes is not specified

    • Valid values: AES_128 | AES_256

  • NumberOfBytes — The key length in bytes.

    • Type: String

    • Required: Yes, if KeySpec is not specified

    • Range: From 1 to 1024

Response Elements#

  • CiphertextBlob — A copy of the key encrypted with a KMS key.

    • Type: Base64-encoded binary data

    • Length constraints: From 1 to 6144 bytes

  • Plaintext — A plaintext copy of the key.

    • Type: Base64-encoded binary data

    • Length constraints: From 1 to 4096 bytes

Examples#

Sample Request#

POST / HTTP/1.1
Host: kms.<region>.<domain>
Content-Length: <PayloadSizeBytes>
Content-Type: application/x-amz-json-1.1
Authorization: AWS4-HMAC-SHA256 Credential=<Credential>, SignedHeaders=<Headers>, Signature=<Signature>
X-Amz-Date: <Date>
X-Amz-Target: TrentService.GenerateDataKey

{
    "KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab",
    "KeySpec": "AES_256"
}

Sample Response#

HTTP/1.1 200 OK
Content-Type: application/x-amz-json-1.1

{
    "CiphertextBlob": "AAAAAM4+iMkZakUYoOjQVwv/+RaNerguTbNtiK78FmF8u+P9u6gNwryNN5JSqsv3meTKbhXnO6vi7OW028t4wbFW7Qbr5FvWRLPtlTSrLqcpZO1R8gB+7JPYMdW+/ndH2BiCMoYwOmjVOiXN/CclpQ==",
    "Plaintext": "0PBAnZfnI00Q+GGesjC0AXg6orjmHUMirVhh0ahYyqY="
}