- 概述
- 入门指南
- Activities (活动)
- Insights 仪表板
- Document Understanding 流程
- 快速入门教程
- 框架组件
- 模型详细信息
- 概述
- Document Understanding - ML 包
- DocumentClassifier - ML 包
- 具有 OCR 功能的 ML 包
- 1040 - ML 包
- 1040 附表 C - ML 包
- 1040 附表 D - ML 包
- 1040 附表 E - ML 包
- 1040x - ML 包
- 3949a - ML 包
- 4506T - ML 包
- 709 - ML 包
- 941x - ML 包
- 9465 - ML 包
- ACORD125 - ML 包
- ACORD126 - ML 包
- ACORD131 - ML 包
- ACORD140 - ML 包
- ACORD25 - ML 包
- 银行对账单 - ML 包
- 提单 - ML 包
- 公司注册证书 - ML 包
- 原产地证书 - ML 包
- 检查 - ML 包
- 儿童产品证书 - ML 包
- CMS1500 - ML 包
- 欧盟符合性声明 - ML 包
- 财务报表 (Financial statements) - ML 包
- FM1003 - ML 包
- I9 - ML 包
- ID Cards - ML 包
- Invoices - ML 包
- InvoicesAustralia - ML 包
- 中国发票 - ML 包
- 希伯来语发票 - ML 包
- 印度发票 - ML 包
- 日本发票 - ML 包
- 装运发票 - ML 包
- 装箱单 - ML 包
- 工资单 - ML 包
- 护照 - ML 包
- 采购订单 - ML 包
- 收据 - ML 包
- 汇款通知书 - ML 包
- UB04 - ML 包
- 水电费账单 - ML 包
- 车辆所有权证明 - ML 包
- W2 - ML 包
- W9 - ML 包
- 其他开箱即用的 ML 包
- 公共端点
- 流量限制
- OCR 配置
- 管道
- OCR 服务
- 支持的语言
- 深度学习
- 数据与安全性
- 许可和计费逻辑
配置客户托管密钥 (CMK),以保留对 Automation Cloud SaaS 环境中 Document Understanding 数据加密密钥的完全控制。
概述
客户管理的密钥 (CMK) 将安全控制与操作灵活性融合在一起,如果您希望对加密密钥拥有完全的管理权限,则这是一个专用的架构。如果您拥有这些密钥的完全所有权,则 CMK 可以保护软件即服务 (SaaS) 应用程序中包含的数据,而不会影响实用性或便利性。
它是如何工作的?
CMK 是围绕两个主要需求设计的。第一个是提供租户级别的加密。这意味着您可以决定要加密哪些存储的数据,无论是全部还是部分。
第二个是密钥管理主权。主加密密钥以及任何其他解密密钥由您控制。监控密钥访问及其使用方式,甚至随时撤销它们的能力,都在您的控制范围内。
它能解决什么问题?
CMK 架构在客户端数据和租户服务之间构建了安全障碍。通过授予您对密钥访问和使用的控制权,即使遇到服务漏洞,您的数据仍会受到保护。您只需撤销密钥,即可立即让他人无法访问任何关联的数据工件。
CMK 也可以成为遵守合规性驱动的复杂密钥管理策略的解决方案。定期更改密钥是信息安全的关键。您可通过 CMK 管理轮换策略。此服务还允许您密切监控您的密钥,以确保您在发生任何未经批准的使用或尝试时立即了解情况。
使用客户管理的密钥
我们的 CMK 专为保护您的数据安全而量身定制,可让您完全控制用于保护所存储数据的加密密钥。此页面可帮助您在租户中启用 CMK。
该功能有什么要求?
要使用此功能,您需要满足一些先决条件:
- 您必须拥有我们平台的高级帐户。有关更多信息,请查看 《Automation Cloud TM 管理员指南》 中的“关于许可” 页面。
- 您必须指定 Document Understanding TM的 CMK 要求。
- 必须在 Azure Key Vault 中配置和存储密钥。
重要提示:
要启用 CMK,您的租户在 Document Manager 中必须没有数据。否则,您需要从 Document Manager 导出数据。留在 Document Manager 中的任何现有数据将无法使用。
如何启用 CMK?
请按照以下说明在租户中启用 CMK:
- 通过 UiPath™ 支持渠道提交支持工单,其中包含用于 Document Understanding 的客户管理密钥的请求。确保添加要使用 CMK 功能加密的租户的租户 ID。
- 提交请求后,我们的产品支持团队将为您的租户启用 CMK,并根据您的请求为您提供更新。
- Once enabled, Document Understanding uses the customer-managed key configured for your organization. You manage this key, the same key used across all opted-in services, in the Encryption section found under Security Settings in your admin panel. There is no separate, Document Understanding-specific key to configure.
Sequencing with the platform-level key
Requesting CMK for Document Understanding and configuring the platform-level customer-managed key are independent steps. Neither blocks the other, and you can complete them in any order. As noted above, any data already in Document Manager before CMK is enabled must be exported before enablement to be protected by the customer-managed key — CMK is not applied retroactively to that data.
The Encryption section does not show a separate indicator for whether CMK is active for Document Understanding specifically. To verify, check the Audit logs section under Admin. For details on the relevant events, see Verifying customer-managed key status per service.
这有什么影响?
请记住,启用 CMK 后,将产生以下影响:
- 客户数据:您的所有数据都将在硬件层和应用程序层加密。该租户的现有数据仍可访问,但将仅使用 UiPath 密钥进行加密。
- 数据解密:解密过程需要 UiPath 支持,可确保您的数据安全。即使是 UiPath 工程师,包括产品支持工程师,也无权访问这些数据。
- 功能限制:CMK 激活后会使某些 Document Understanding 功能发生变化。Document Manager 中的“生成和监控”功能会禁用全文搜索,并且计量服务不会保存图像。