בדף הזה מוסבר איך להגדיר מפתח הצפנה ב-Cloud Speech-to-Text כדי להצפין משאבים של Speech-to-Text.
ב-Speech-to-Text אפשר לספק מפתחות הצפנה של Cloud Key Management Service ולהצפין נתונים באמצעות המפתח שסופק. למידע נוסף על הצפנה, ראו מבוא להצפנה.
לפני שמתחילים
- נכנסים לחשבון Google Cloud . אנחנו ממליצים למשתמשים חדשים ב- Google Cloud ליצור חשבון כדי שיוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Speech-to-Text APIs, if any are not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Make sure that you have the following role or roles on the project: Cloud Speech Administrator
Check for the roles
-
In the Google Cloud console, go to the IAM page.
Go to IAM - Select the project.
-
In the Principal column, find all rows that identify you or a group that you're included in. To learn which groups you're included in, contact your administrator.
- For all rows that specify or include you, check the Role column to see whether the list of roles includes the required roles.
Grant the roles
-
In the Google Cloud console, go to the IAM page.
Go to IAM - Select the project.
- Click Grant access.
-
In the New principals field, enter your user identifier. This is typically the email address for a Google Account.
- Click Select a role, then search for the role.
- To grant additional roles, click Add another role and add each additional role.
- Click Save.
-
-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Speech-to-Text APIs, if any are not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Make sure that you have the following role or roles on the project: Cloud Speech Administrator
Check for the roles
-
In the Google Cloud console, go to the IAM page.
Go to IAM - Select the project.
-
In the Principal column, find all rows that identify you or a group that you're included in. To learn which groups you're included in, contact your administrator.
- For all rows that specify or include you, check the Role column to see whether the list of roles includes the required roles.
Grant the roles
-
In the Google Cloud console, go to the IAM page.
Go to IAM - Select the project.
- Click Grant access.
-
In the New principals field, enter your user identifier. This is typically the email address for a Google Account.
- Click Select a role, then search for the role.
- To grant additional roles, click Add another role and add each additional role.
- Click Save.
-
-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
אם אתם משתמשים במעטפת מקומית, צריך ליצור פרטי כניסה לאימות מקומי עבור חשבון המשתמש:
gcloud auth application-default login
אם אתם משתמשים ב-Cloud Shell, אתם לא צריכים לעשות את זה.
אם מוחזרת שגיאת אימות ואתם משתמשים בספק זהויות חיצוני (IdP), ודאו ש נכנסתם ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.
בספריות הלקוח אפשר להשתמש ב-Application Default Credentials כדי לעבור בקלות אימות מול Google APIs ולשלוח בקשות לאותם ממשקי API. באמצעות Application Default Credentials, אתם יכולים לבדוק את האפליקציה ברמה המקומית ולפרוס אותה בלי לשנות את הקוד שלה. למידע נוסף, קראו את המאמר אימות לצורך שימוש בספריות לקוח.
צריך גם לוודא שספריית הלקוח מותקנת.
הפעלת גישה למפתחות של Cloud Key Management Service
שירות Cloud Speech-to-Text משתמש בחשבון שירות כדי לגשת למפתחות Cloud KMS שלכם. כברירת מחדל, לחשבון השירות אין גישה למפתחות של Cloud KMS.
כתובת האימייל של חשבון השירות היא:
service-PROJECT_NUMBER@gcp-sa-speech.iam.gserviceaccount.com
כדי להצפין משאבים של Speech-to-Text באמצעות מפתחות Cloud KMS, אתם יכולים לתת לחשבון השירות הזה את התפקיד roles/cloudkms.cryptoKeyEncrypterDecrypter:
gcloud projects add-iam-policy-binding PROJECT_NUMBER \
--member=serviceAccount:service-PROJECT_NUMBER@gcp-sa-speech.iam.gserviceaccount.com \
--role=roles/cloudkms.cryptoKeyEncrypterDecrypterמידע נוסף על מדיניות ניהול הזהויות והרשאות הגישה (IAM) בפרויקט זמין במאמר ניהול הגישה לפרויקטים, לתיקיות ולארגונים.
מידע נוסף על ניהול הגישה ל-Cloud Storage זמין במאמר יצירה וניהול של רשימות של בקרת גישה במסמכי התיעוד של Cloud Storage.
ציון מפתח הצפנה
הנה דוגמה לאספקת מפתח הצפנה ל-Cloud Speech-to-Text באמצעות משאב Config:
Python
כשמציינים מפתח הצפנה במשאב Config של הפרויקט, כל משאב חדש שנוצר במיקום המתאים מוצפן באמצעות המפתח הזה. במאמר מבוא להצפנה מוסבר מה מוצפן ומתי.
במשאבים מוצפנים, השדות kms_key_name ו-kms_key_version_name מאוכלסים בתגובות מה-API של Speech-to-Text.
הסרת ההצפנה
כדי למנוע הצפנה של משאבים עתידיים באמצעות מפתח הצפנה, משתמשים בקוד שלמעלה ומספקים את המחרוזת הריקה ("") כמפתח בבקשה. כך מוודאים שמשאבים חדשים לא מוצפנים. הפקודה הזו לא מבצעת פענוח של משאבים קיימים.
רוטציית מפתחות ומחיקה
במהלך רוטציית מפתחות, משאבים שמוצפנים באמצעות גרסה קודמת של מפתח Cloud KMS נשארים מוצפנים באמצעות אותה גרסה. כל המשאבים שנוצרו אחרי רוטציית המפתחות מוצפנים באמצעות גרסת ברירת המחדל החדשה של המפתח.
כל המשאבים שעודכנו (באמצעות שיטות Update*) אחרי רוטציית המפתח מוצפנים מחדש באמצעות גרסת ברירת המחדל החדשה של המפתח.
אחרי מחיקת המפתח, מערכת Speech-to-Text לא יכולה לפענח את הנתונים שלכם, ליצור משאבים או לגשת למשאבים שהוצפנו באמצעות המפתח שנמחק. באופן דומה, כשמבטלים את ההרשאה של Speech-to-Text למפתח, Speech-to-Text לא יכול לפענח את הנתונים וליצור משאבים או לגשת למשאבים שמוצפנים באמצעות המפתח שההרשאה שלו ל-Speech-to-Text בוטלה.
הצפנה מחדש של נתונים
כדי להצפין מחדש את המשאבים, אפשר לקרוא לשיטת Update* המתאימה לכל משאב אחרי עדכון מפרט המפתח במשאב Config.
הסרת המשאבים
כדי לא לצבור חיובים לחשבון Google Cloud על המשאבים שבהם השתמשתם בדף הזה, פועלים לפי השלבים הבאים.
-
אם תרצו, תוכלו לבטל את פרטי הכניסה שיצרתם ולמחוק את הקובץ המקומי של פרטי הכניסה.
gcloud auth application-default revoke
-
אם רוצים, מבטלים את פרטי הכניסה של ה-CLI של gcloud.
gcloud auth revoke
המסוף
gcloud
כדי למחוק Google Cloud פרויקט:
gcloud projects delete PROJECT_ID
המאמרים הבאים
- מה מוצפן כשמציינים מפתחות הצפנה ב-Speech-to-Text
- איך מתמללים אודיו בסטרימינג
- איך מתמללים קובצי אודיו ארוכים
- איך מתמללים קובצי אודיו קצרים
- כדי לקבל את הביצועים והדיוק הטובים ביותר, וטיפים נוספים, עיינו במסמכי התיעוד בנושא שיטות מומלצות.