package google.cloud.kms.v1

Mouse Melon logoGet desktop application:
View/edit binary Protocol Buffers messages

service KeyManagementService

service.proto:46

Google Cloud Key Management Service Manages cryptographic keys and operations using those keys. Implements a REST model with the following objects: * [KeyRing][google.cloud.kms.v1.KeyRing] * [CryptoKey][google.cloud.kms.v1.CryptoKey] * [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion] If you are using manual gRPC libraries, see [Using gRPC with Cloud KMS](https://cloud.google.com/kms/docs/grpc).

message CryptoKey

resources.proto:48

A [CryptoKey][google.cloud.kms.v1.CryptoKey] represents a logical key that can be used for cryptographic operations. A [CryptoKey][google.cloud.kms.v1.CryptoKey] is made up of one or more [versions][google.cloud.kms.v1.CryptoKeyVersion], which represent the actual key material used in cryptographic operations.

Used as response type in: KeyManagementService.CreateCryptoKey, KeyManagementService.GetCryptoKey, KeyManagementService.UpdateCryptoKey, KeyManagementService.UpdateCryptoKeyPrimaryVersion

Used as field type in: CreateCryptoKeyRequest, ListCryptoKeysResponse, UpdateCryptoKeyRequest

enum CryptoKey.CryptoKeyPurpose

resources.proto:52

[CryptoKeyPurpose][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose] describes the cryptographic capabilities of a [CryptoKey][google.cloud.kms.v1.CryptoKey]. A given key can only be used for the operations allowed by its purpose.

Used in: CryptoKey

message CryptoKeyVersion

resources.proto:180

A [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion] represents an individual cryptographic key, and the associated key material. An [ENABLED][google.cloud.kms.v1.CryptoKeyVersion.CryptoKeyVersionState.ENABLED] version can be used for cryptographic operations. For security reasons, the raw cryptographic key material represented by a [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion] can never be viewed or exported. It can only be used to encrypt, decrypt, or sign data when an authorized user or application invokes Cloud KMS.

Used as response type in: KeyManagementService.CreateCryptoKeyVersion, KeyManagementService.DestroyCryptoKeyVersion, KeyManagementService.GetCryptoKeyVersion, KeyManagementService.RestoreCryptoKeyVersion, KeyManagementService.UpdateCryptoKeyVersion

Used as field type in: CreateCryptoKeyVersionRequest, CryptoKey, ListCryptoKeyVersionsResponse, UpdateCryptoKeyVersionRequest

enum CryptoKeyVersion.CryptoKeyVersionAlgorithm

resources.proto:212

The algorithm of the [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion], indicating what parameters must be used for each cryptographic operation. The [GOOGLE_SYMMETRIC_ENCRYPTION][google.cloud.kms.v1.CryptoKeyVersion.CryptoKeyVersionAlgorithm.GOOGLE_SYMMETRIC_ENCRYPTION] algorithm is usable with [CryptoKey.purpose][google.cloud.kms.v1.CryptoKey.purpose] [ENCRYPT_DECRYPT][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose.ENCRYPT_DECRYPT]. Algorithms beginning with "RSA_SIGN_" are usable with [CryptoKey.purpose][google.cloud.kms.v1.CryptoKey.purpose] [ASYMMETRIC_SIGN][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose.ASYMMETRIC_SIGN]. The fields in the name after "RSA_SIGN_" correspond to the following parameters: padding algorithm, modulus bit length, and digest algorithm. For PSS, the salt length used is equal to the length of digest algorithm. For example, [RSA_SIGN_PSS_2048_SHA256][google.cloud.kms.v1.CryptoKeyVersion.CryptoKeyVersionAlgorithm.RSA_SIGN_PSS_2048_SHA256] will use PSS with a salt length of 256 bits or 32 bytes. Algorithms beginning with "RSA_DECRYPT_" are usable with [CryptoKey.purpose][google.cloud.kms.v1.CryptoKey.purpose] [ASYMMETRIC_DECRYPT][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose.ASYMMETRIC_DECRYPT]. The fields in the name after "RSA_DECRYPT_" correspond to the following parameters: padding algorithm, modulus bit length, and digest algorithm. Algorithms beginning with "EC_SIGN_" are usable with [CryptoKey.purpose][google.cloud.kms.v1.CryptoKey.purpose] [ASYMMETRIC_SIGN][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose.ASYMMETRIC_SIGN]. The fields in the name after "EC_SIGN_" correspond to the following parameters: elliptic curve, digest algorithm.

Used in: CryptoKeyVersion, CryptoKeyVersionTemplate, PublicKey

enum CryptoKeyVersion.CryptoKeyVersionState

resources.proto:254

The state of a [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion], indicating if it can be used.

Used in: CryptoKeyVersion

enum CryptoKeyVersion.CryptoKeyVersionView

resources.proto:285

A view for [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion]s. Controls the level of detail returned for [CryptoKeyVersions][google.cloud.kms.v1.CryptoKeyVersion] in [KeyManagementService.ListCryptoKeyVersions][google.cloud.kms.v1.KeyManagementService.ListCryptoKeyVersions] and [KeyManagementService.ListCryptoKeys][google.cloud.kms.v1.KeyManagementService.ListCryptoKeys].

Used in: ListCryptoKeyVersionsRequest, ListCryptoKeysRequest

message CryptoKeyVersionTemplate

resources.proto:137

A [CryptoKeyVersionTemplate][google.cloud.kms.v1.CryptoKeyVersionTemplate] specifies the properties to use when creating a new [CryptoKeyVersion][google.cloud.kms.v1.CryptoKeyVersion], either manually with [CreateCryptoKeyVersion][google.cloud.kms.v1.KeyManagementService.CreateCryptoKeyVersion] or automatically as a result of auto-rotation.

Used in: CryptoKey

message Digest

service.proto:534

A [Digest][google.cloud.kms.v1.Digest] holds a cryptographic message digest.

Used in: AsymmetricSignRequest

message KeyOperationAttestation

resources.proto:152

Contains an HSM-generated attestation about a key operation.

Used in: CryptoKeyVersion

enum KeyOperationAttestation.AttestationFormat

resources.proto:154

Attestion formats provided by the HSM.

Used in: KeyOperationAttestation

message KeyRing

resources.proto:34

A [KeyRing][google.cloud.kms.v1.KeyRing] is a toplevel logical grouping of [CryptoKeys][google.cloud.kms.v1.CryptoKey].

Used as response type in: KeyManagementService.CreateKeyRing, KeyManagementService.GetKeyRing

Used as field type in: CreateKeyRingRequest, ListKeyRingsResponse

message LocationMetadata

service.proto:549

Cloud KMS metadata for the given [google.cloud.location.Location][google.cloud.location.Location].

enum ProtectionLevel

resources.proto:350

[ProtectionLevel][google.cloud.kms.v1.ProtectionLevel] specifies how cryptographic operations are performed.

Used in: CryptoKeyVersion, CryptoKeyVersionTemplate