ReEncrypt
In this article:
ReEncrypt#
Description#
Decrypts encrypted data and re-encrypts it with a KMS key. You can use this method to change the KMS key used to encrypt the data. You can also use it to re-encrypt data with the same KMS key after its rotation or to change the encryption context.
Request Parameters#
Required parameters#
CiphertextBlob — The encrypted data.
Type: Base64-encoded binary data
Required: Yes
Length constraints: From 1 to 6144 bytes
DestinationKeyId — The ID of the KMS key to use to re-encrypt the data. You can specify an alias name with the
alias/prefix as the identifier.Type: String
Required: Yes
Optional parameters#
DestinationEncryptionContext — The encryption context used as additional authenticated data (AAD) during re-encryption.
Type: Map of strings
Required: No
Constraints: The total length of all strings in UTF-8 encoding must not exceed 6144 bytes
SourceEncryptionContext — The encryption context used as additional authenticated data (AAD) during decryption.
Type: Map of strings
Required: No
Constraints: The total length of all strings in UTF-8 encoding must not exceed 6144 bytes
Response Elements#
CiphertextBlob — The re-encrypted data.
Type: Base64-encoded binary data
Length constraints: From 1 to 6144 bytes
Examples#
Sample Request#
POST / HTTP/1.1
Host: kms.<region>.<domain>
Content-Length: <PayloadSizeBytes>
Content-Type: application/x-amz-json-1.1
Authorization: AWS4-HMAC-SHA256 Credential=<Credential>, SignedHeaders=<Headers>, Signature=<Signature>
X-Amz-Date: <Date>
X-Amz-Target: TrentService.ReEncrypt
{
"DestinationKeyId": "1234abcd-12ab-34cd-56ef-1234567890ab",
"CiphertextBlob": "AAAAAM4+iMkZakUYoOjQVwv/+Rble77a9sKsVR2b6Ip5dCTccveHBXG2NShREn9ez3WXAEJYOHwKspxa0GfmLieIiz9sUXPXnfUMTUrLWKtrft+x0dZvcvWU0YY8"
}
Sample Response#
HTTP/1.1 200 OK
Content-Type: application/x-amz-json-1.1
{
"CiphertextBlob": "AAAAAFFmdNZoPkKUiRQHXmxYY1W0I5PNd0IPkbzrMp2YVH+bu42WBzOCzKTSXr+Pozq2rcSgIEfq+5FbSAHogSr5Df7/Ww6QFkj0T9O5G04KoNfvkJ1yGByoLVOF"
}