sdkms.v1.apis.encryption_and_decryption_api module

Fortanix DSM REST API

This is a set of REST APIs for accessing the Fortanix Data Security Manager. This includes APIs for managing accounts, and for performing cryptographic and key management operations.

OpenAPI spec version: 1.0.0-20200608 Contact: support@fortanix.com Generated by: https://github.com/swagger-api/swagger-codegen.git

Licensed under the Apache License, Version 2.0 (the “License”); you may not use this file except in compliance with the License. You may obtain a copy of the License at

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an “AS IS” BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

class sdkms.v1.apis.encryption_and_decryption_api.EncryptionAndDecryptionApi(api_client=None)[source]

Bases: object

__init__(api_client=None)[source]
batch_decrypt(body, async_call=False, **kwargs)[source]

The data to be decrypted and the key ids to be used are provided in the request body. The decrypted plain text is returned in the response body. The ordering of the body matches the ordering of the request. An individual status code is returned for each batch item. Maximum size of the entire batch request is 512 KB.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (BatchDecryptRequest) – Batch decryption request (required)

Return type:

BatchDecryptResponse

Returns:

If the method is called asynchronously, returns the request thread.

batch_encrypt(body, async_call=False, **kwargs)[source]

The data to be encrypted and the key ids to be used are provided in the request body. The encrypted cipher text is returned in the response body. The ordering of the body matches the ordering of the request. An individual status code is returned for each batch item. Maximum size of the entire batch request is 512 KB.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (BatchEncryptRequest) – Batch Encryption request (required)

Return type:

BatchEncryptResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt(key_id, body, async_call=False, **kwargs)[source]

Decrypt data using a symmetric or asymmetric key. For symmetric ciphers, mode (specifying the block cipher mode) is a required field. <br> For GCM and CCM modes, tag_len is a required field. <br> iv is required for symmetric ciphers and unused for asymmetric ciphers. It must contain the initialization value used when the object was encrypted. <br> Objects of type opaque, EC, or HMAC may not be used for encryption or decryption. <br>

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (DecryptRequest) – Decryption request (required)

Return type:

DecryptResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_ex(body, async_call=False, **kwargs)[source]

Decrypt data using a symmetric or asymmetric key. For symmetric ciphers, mode (specifying the block cipher mode) is a required field. <br> For GCM and CCM modes, tag_len is a required field. <br> iv is required for symmetric ciphers and unused for asymmetric ciphers. It must contain the initialization value used when the object was encrypted. <br> Objects of type opaque, EC, or HMAC may not be used for encryption or decryption. <br>

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (DecryptRequestEx) – Decryption request (required)

Return type:

DecryptResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_final(key_id, body, async_call=False, **kwargs)[source]

Conclude a multi-part decryption operation. See decrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (DecryptFinalRequest) – Finish multi-part decryption (required)

Return type:

DecryptFinalResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_final_ex(body, async_call=False, **kwargs)[source]

Conclude a multi-part decryption operation. See decrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (DecryptFinalRequestEx) – Finish multi-part decryption (required)

Return type:

DecryptFinalResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_init(key_id, body, async_call=False, **kwargs)[source]

This API is used when decrypting more data than the client wishes to submit in a single request. It supports only symmetric ciphers and CBC, CBCNOPAD, CTR, and GCM modes of operation. To perform multi-part decryption, the client makes one request to the init resource, zero or more requests to the update resource, followed by one request to the final resource. The response to init and update requests includes a state field. The state is an opaque data blob that must be supplied unmodified by the client with the subsequent request.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (DecryptInitRequest) – Multi-part decryption initialization request (required)

Return type:

DecryptInitResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_init_ex(body, async_call=False, **kwargs)[source]

This API is used when decrypting more data than the client wishes to submit in a single request. It supports only symmetric ciphers and CBC, CBCNOPAD, CTR, and GCM modes of operation. To perform multi-part decryption, the client makes one request to the init resource, zero or more requests to the update resource, followed by one request to the final resource. The response to init and update requests includes a state field. The state is an opaque data blob that must be supplied unmodified by the client with the subsequent request.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (DecryptInitRequestEx) – Multi-part decryption initialization request (required)

Return type:

DecryptInitResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_update(key_id, body, async_call=False, **kwargs)[source]

Continue a multi-part decryption operation. See decrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (DecryptUpdateRequest) – Multi-part decryption (required)

Return type:

DecryptUpdateResponse

Returns:

If the method is called asynchronously, returns the request thread.

decrypt_update_ex(body, async_call=False, **kwargs)[source]

Continue a multi-part decryption operation. See decrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (DecryptUpdateRequestEx) – Multi-part decryption (required)

Return type:

DecryptUpdateResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt(key_id, body, async_call=False, **kwargs)[source]

Encrypt data using a symmetric or asymmetric key. <br> For symmetric ciphers, mode (specifying the block cipher mode) is a required field. <br> For GCM and CCM modes, tag_len is a required field. <br> iv is optional for symmetric ciphers and unused for asymmetric ciphers. If provided, it will be used as the cipher initialization value. Length of iv must match the initialization value size for the cipher and mode. If not provided, SDKMS will create a random iv of the correct length for the cipher and mode and return this value in the response. <br> Objects of type Opaque, EC, or HMAC may not be used for encryption or decryption. <br>

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (EncryptRequest) – Encryption request (required)

Return type:

EncryptResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_ex(body, async_call=False, **kwargs)[source]

Encrypt data using a symmetric or asymmetric key. <br> For symmetric ciphers, mode (specifying the block cipher mode) is a required field. <br> For GCM and CCM modes, tag_len is a required field. <br> iv is optional for symmetric ciphers and unused for asymmetric ciphers. If provided, it will be used as the cipher initialization value. Length of iv must match the initialization value size for the cipher and mode. If not provided, SDKMS will create a random iv of the correct length for the cipher and mode and return this value in the response. <br> Objects of type Opaque, EC, or HMAC may not be used for encryption or decryption. <br>

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (EncryptRequestEx) – Encryption request (required)

Return type:

EncryptResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_final(key_id, body, async_call=False, **kwargs)[source]

Conclude a multi-part encryption operation. See encrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (EncryptFinalRequest) – Finish multi-part encryption (required)

Return type:

EncryptFinalResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_final_ex(body, async_call=False, **kwargs)[source]

Conclude a multi-part encryption operation. See encrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (EncryptFinalRequestEx) – Finish multi-part encryption (required)

Return type:

EncryptFinalResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_init(key_id, body, async_call=False, **kwargs)[source]

This API is used when encrypting more data than the client wishes to submit in a single request. It supports only symmetric ciphers and CBC, CBCNOPAD, CTR, and GCM modes of operation. To perform multi-part encryption, the client makes one request to the init resource, zero or more requests to the update resource, followed by one request to the final resource. The response to init and update requests includes a state field. The state is an opaque data blob that must be supplied unmodified by the client with the subsequent request.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (EncryptInitRequest) – Multi-part encryption initialization request (required)

Return type:

EncryptInitResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_init_ex(body, async_call=False, **kwargs)[source]

This API is used when encrypting more data than the client wishes to submit in a single request. It supports only symmetric ciphers and CBC, CBCNOPAD, CTR, and GCM modes of operation. To perform multi-part encryption, the client makes one request to the init resource, zero or more requests to the update resource, followed by one request to the final resource. The response to init and update requests includes a state field. The state is an opaque data blob that must be supplied unmodified by the client with the subsequent request.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (EncryptInitRequestEx) – Multi-part encryption initialization request (required)

Return type:

EncryptInitResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_update(key_id, body, async_call=False, **kwargs)[source]

Continue a multi-part encryption operation. See encrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (EncryptUpdateRequest) – Multi-part encryption (required)

Return type:

EncryptUpdateResponse

Returns:

If the method is called asynchronously, returns the request thread.

encrypt_update_ex(body, async_call=False, **kwargs)[source]

Continue a multi-part encryption operation. See encrypt/init for details.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (EncryptUpdateRequestEx) – Multi-part encryption (required)

Return type:

EncryptUpdateResponse

Returns:

If the method is called asynchronously, returns the request thread.

stream_decrypt(body, async_call=False, **kwargs)[source]

Decrypt a stream of data. Like the multi-part API, this API is used when the data to be encrypted is large (>512KiB), or the size of the data is not known ahead of time. It supports symmetric ciphers in the ECB, CBC, CBCNOPAD, CFB, OFB, CTR, and GCM modes of operation. Unlike the multi-part API, a single long-running request is used, where the request and response bodies are streamed simultaneously. <br> Both the request and response are a sequence of frames, each encoded in CBOR. The frames are concatenated into a CBOR sequence, following RFC 8742. The request consists of an “init” frame, zero or more “ad” frames, one or more “cipher” frames, and a “final” frame. A successful response consists of an “init” frame, one or more “plain” frames, and a “final” frame. <br> If an error occurs processing the “init” frame, the error is indicated as an HTTP status code and plain-text body, like all other APIs. If an error occurs later, it is reported as an “error” frame, and no further frames are sent.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (DecryptRequestFrame) – Stream of decrypt request frames (required)

Return type:

DecryptResponseFrame

Returns:

If the method is called asynchronously, returns the request thread.

stream_encrypt(body, async_call=False, **kwargs)[source]

Encrypt a stream of data. Like the multi-part API, this API is used when the data to be encrypted is large (>512KiB), or the size of the data is not known ahead of time. It supports symmetric ciphers in the ECB, CBC, CBCNOPAD, CFB, OFB, CTR, and GCM modes of operation. Unlike the multi-part API, a single long-running request is used, where the request and response bodies are streamed simultaneously. <br> Both the request and response are a sequence of frames, each encoded in CBOR. The frames are concatenated into a CBOR sequence, following RFC 8742. The request consists of an “init” frame, zero or more “ad” frames, one or more “plain” frames, and a “final” frame. A successful response consists of an “init” frame, one or more “cipher” frames, and a “final” frame. <br> If an error occurs processing the “init” frame, the error is indicated as an HTTP status code and plain-text body, like all other APIs. If an error occurs later, it is reported as an “error” frame, and no further frames are sent.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (EncryptRequestFrame) – Stream of encrypt request frames (required)

Return type:

EncryptResponseFrame

Returns:

If the method is called asynchronously, returns the request thread.