Safety & Security · Software component
Key Management Service
Software componentSafety & SecuritySafety, Security & Governancearc:KeyManagementService
A service that generates, stores and releases encryption keys for at-rest data so keys never persist on the devices that hold the encrypted data.
Responsibility. Controls access to encryption keys protecting stored models and data.
Also known as: KMS
Relationships
is invoked by dependency
controls access to control
is guarded by control
Design guidance
- MUST store keys separately from the encrypted data so a database compromise does not yield plaintext.
Classification
- Technologies
- NVIDIA key management service
- Quality attributes
- Privacy (NIST AI RMF: privacy-enhanced)
- Risks mitigated
- Model and data exposure from stolen edge hardware
- Frameworks & regulations
- GDPR Art. 32
Sources
- Ch4.6: T. Nguyen, "TensorRT-LLM and NVIDIA Fleet Command," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.6. ISBN: 9798244538229.
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note