Boundary transfer

Prev Next

Available in Classic and VPC

Boundary transfer

Global key transfer converts the key used in the Global Region to a key in a specific Region. Once the transfer is complete, new encryption operations will use the transferred Region key, and the Global Region key will no longer be retained.

Caution

Since key transfer is irreversible, a thorough review is required before proceeding.

Transfer can only be done on disabled keys. To prevent conflicts, if a key with the same name already exists in the transfer target Region, transfer is not allowed.

Note

For more information about key isolation and boundaries, see Key Management Service concepts > Key isolation.

Caution

If the transfer is successful, the key in the Global Region is immediately deleted and cannot be restored or transferred to a different Region.

kms-migrate-01-251114

  1. In the NAVER Cloud Platform console, navigate to i_menu > Services > Security > Key Management Service > Key.
  2. Select the region you want to transfer to, and then click [Transfer isolation key].
    kms-migrate-03-251114
  3. When the Transfer isolation key window pops up, click [Transfer]. If the key to be transferred has a usage history, exercise caution during the transfer.
    kms-migrate-02-251114
  4. If the transfer is successful, you can view the key information in the isolation Region.
    kms-migrate-04-251114
  5. If the transfer ends abnormally, you can check it using the [Transfer isolation key] button in the Global Region.
    kms-migrate-05-251114