Shield Platform Encryption 외부 키 관리(EKM)를 사용할 경우 데이터 암호화 키(DEK)를 관리하기 위해 고객의 외부 키 관리 서비스(KMS)에 의존합니다. 해당 DEK는 데이터 암호화 및 암호 해독에 모두 중요합니다. 사용하지 않을 경우 DEK는 Shield Platform Encryption 키 캐시에 "래핑됨"(암호화됨) 상태로 저장됩니다. 암호화 또는 암호 해독 작업의 경우 Shield Platform Encryption 래핑된 DEK를 고객의 외부 키 서비스로 전송한 다음, 래핑을 해제하고 안전하게 반환합니다. 이 프로세스는 Data 360 사용자에도 일관되게 유지됩니다.
필수 Edition
Lightning Experience 및 Salesforce Classic에서 모두 사용할 수 있습니다(일부 조직에서 사용할 수 없음).
지원 제품: Enterprise, Performance, Unlimited및 Developer Edition Salesforce Shield 또는 Shield Platform Encryption 및 외부 키 관리 서비스를 구매해야 합니다. Data 360 고객은 Consumer용 플랫폼 암호화 라이센스도 있어야 합니다.
필요한 사용자 권한
테넌트 암호 및 고객이 제공한 키 자료 생성, 폐기, 내보내기, 가져오기, 업로드 및 구성:
암호화 키 관리
EKM을 설정하는 프로세스는 고객이 KMS에서 루트 키를 만드는 과정에서 시작됩니다. 그런 다음, Salesforce 지역 KMS에 루트 키를 사용하여 DEK를 생성 및 래핑하고 루트 키를 사용하여 DEK를 래핑 해제하도록 고객 키 서비스에 요청하는 특정 권한을 부여하는 정책이 생성됩니다. 이 정책을 사용하면 Salesforce 설정에서 EKM DEK를 만들 수 있습니다. 이후 Shield Platform Encryption 고객 KMS에 DEK를 생성해달라고 요청합니다. 그러면 고객 KMS가 해당 DEK를 래핑하고 안전하게 Shield Platform Encryption 전송합니다. 이 래핑된 DEK는 존재하고 TenantSecret 데이터베이스에 저장되는 유일한 복사본입니다.
암호화 작업에 EKM DEK가 필요한 경우 Shield Platform Encryption 암호화된 키 캐시를 확인합니다. 래핑되지 않은 DEK가 없는 경우 Shield Platform Encryption 키 서비스를 요청하여 래핑을 해제한 다음, 안전하게 다시 보냅니다. 그런 다음, 즉시 사용할 수 있도록 암호화된 키 캐시에 래핑되지 않은 키가 추가됩니다. 후속 작업의 경우 래핑되지 않은 DEK가 이미 캐시에 있는 경우 암호화 및 암호 해독에 직접 사용됩니다. Shield KMS에는 조직별 AES 256비트 캐시 암호화 키로 가져온 키 자료를 암호화하는 고급 캐시 컨트롤이 포함되어 있어 보안 저장소를 보장합니다. 이 캐시 암호화 키는 HSM 보호 키로 보호되며 주요 수명 주기 이벤트 동안 순환됩니다.
노트 평균적으로 캐시는 72시간마다 플러시됩니다. 일부 내부 작업은 24시간마다 캐시를 플러시합니다.
이 기사를 통해 문제를 해결했습니까?
개선을 위한 의견을 보내주세요.
로드 중
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.