You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Nitro Enclave中解密KMS的CiphertextForRecipient应使用哪个私钥?

解答:Nitro Enclave解密KMS返回的CiphertextForRecipient的私钥选择
  • 结论:你需要使用attestation文档中可选公钥对应的私钥来解密CiphertextForRecipient。
  • 原因说明:
    1. 用于签名attestation文档的公钥对应的私钥属于AWS Nitro Enclave的硬件根密钥体系,完全由AWS控制,你的enclave内部无法获取到这个私钥,因此不可能用它来解密。
    2. 那个可选公钥是你在enclave初始化阶段自行生成的密钥对中的公钥,对应的私钥仅存储在你的enclave内部(不会泄露到外部)。KMS在处理Decrypt请求时,会从你提交的attestation文档中提取这个可选公钥,用它加密明文得到CiphertextForRecipient,所以只有你enclave内的对应私钥才能解密。

补充操作逻辑:
当你调用KMS Decrypt API时,需将enclave生成的attestation文档作为参数传入。KMS验证attestation的合法性后,用其中的可选公钥加密解密后的明文,返回CiphertextForRecipient。你在enclave内用对应的私钥解密该字段,即可得到原始明文。

内容的提问来源于stack exchange,提问作者thant zin tun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 10:24:54