Class: Google::Apis::DlpV2::GooglePrivacyDlpV2CryptoKey
- Inherits:
-
Object
- Object
- Google::Apis::DlpV2::GooglePrivacyDlpV2CryptoKey
- Includes:
- Core::Hashable, Core::JsonObjectSupport
- Defined in:
- lib/google/apis/dlp_v2/classes.rb,
lib/google/apis/dlp_v2/representations.rb,
lib/google/apis/dlp_v2/representations.rb
Overview
This is a data encryption key (DEK) (as opposed to a key encryption key (KEK) stored by Cloud Key Management Service (Cloud KMS). When using Cloud KMS to wrap or unwrap a DEK, be sure to set an appropriate IAM policy on the KEK to ensure an attacker cannot unwrap the DEK.
Instance Attribute Summary collapse
-
#kms_wrapped ⇒ Google::Apis::DlpV2::GooglePrivacyDlpV2KmsWrappedCryptoKey
Include to use an existing data crypto key wrapped by KMS.
-
#transient ⇒ Google::Apis::DlpV2::GooglePrivacyDlpV2TransientCryptoKey
Use this to have a random data crypto key generated.
-
#unwrapped ⇒ Google::Apis::DlpV2::GooglePrivacyDlpV2UnwrappedCryptoKey
Using raw keys is prone to security risks due to accidentally leaking the key.
Instance Method Summary collapse
-
#initialize(**args) ⇒ GooglePrivacyDlpV2CryptoKey
constructor
A new instance of GooglePrivacyDlpV2CryptoKey.
-
#update!(**args) ⇒ Object
Update properties of this object.
Constructor Details
#initialize(**args) ⇒ GooglePrivacyDlpV2CryptoKey
Returns a new instance of GooglePrivacyDlpV2CryptoKey.
1980 1981 1982 |
# File 'lib/google/apis/dlp_v2/classes.rb', line 1980 def initialize(**args) update!(**args) end |
Instance Attribute Details
#kms_wrapped ⇒ Google::Apis::DlpV2::GooglePrivacyDlpV2KmsWrappedCryptoKey
Include to use an existing data crypto key wrapped by KMS. The wrapped key
must be a 128-, 192-, or 256-bit key. Authorization requires the following IAM
permissions when sending a request to perform a crypto transformation using a
KMS-wrapped crypto key: dlp.kms.encrypt For more information, see Creating a
wrapped key. Note: When you use Cloud KMS for cryptographic operations,
charges apply.
Corresponds to the JSON property kmsWrapped
1966 1967 1968 |
# File 'lib/google/apis/dlp_v2/classes.rb', line 1966 def kms_wrapped @kms_wrapped end |
#transient ⇒ Google::Apis::DlpV2::GooglePrivacyDlpV2TransientCryptoKey
Use this to have a random data crypto key generated. It will be discarded
after the request finishes.
Corresponds to the JSON property transient
1972 1973 1974 |
# File 'lib/google/apis/dlp_v2/classes.rb', line 1972 def transient @transient end |
#unwrapped ⇒ Google::Apis::DlpV2::GooglePrivacyDlpV2UnwrappedCryptoKey
Using raw keys is prone to security risks due to accidentally leaking the key.
Choose another type of key if possible.
Corresponds to the JSON property unwrapped
1978 1979 1980 |
# File 'lib/google/apis/dlp_v2/classes.rb', line 1978 def unwrapped @unwrapped end |
Instance Method Details
#update!(**args) ⇒ Object
Update properties of this object
1985 1986 1987 1988 1989 |
# File 'lib/google/apis/dlp_v2/classes.rb', line 1985 def update!(**args) @kms_wrapped = args[:kms_wrapped] if args.key?(:kms_wrapped) @transient = args[:transient] if args.key?(:transient) @unwrapped = args[:unwrapped] if args.key?(:unwrapped) end |