Study Guides/AWS Cybersecurity Notes/Amazon KMS

From Cramsession
Jump to navigationJump to search
✍️ Verified Author: MflavellClick to view professional profile & credentials

Overview

  • Data encryption is the most critical aspect.
  • Must know KMS and the API calls used in the service


Two types of encryption:

  • Symmetric - Same key
This is fast for large ammounts of data.
  • Asymmetric - Uses a pair of keys
Private key - Kept secret (Decripts data)
Public key - Distributed (Encrypts data)


Exaples of symmetric are AES and DES


AWS KMS

Customer Master Keys

  • Contain key material for encryption and decryption.
  • CMKs are managed in KMS
  • Think of CMK as a keychain
  • KMS provides a way to store and manage keys - this is the AWS lockbox for your keys
  • KMS protects the CMKs
  • Uses industry standard practices to safeguard CMK


About CMKs:


  • They manage encryption keys for sensative data.
  • Control encryption and decryption of data
  • Securely stored by KMS
  • Fine grained access control
  • Work inside and ourside of AWS
  • use envelope encryption.
A data key is generated and used for encrypting data.
That key is encrypted with the CMK.
  • Auditable in AWS Cloud Trail and AWS Cloud Watch


  • Two different types of CMK exist:
  • Customer managed.
  • AWS managed.


AWS Managed CMKs

  • Owned and used by AWS services
  • Independent from the customer account.
You cannot track their useage or audit them!
  • Can be used by services inside an account.
  • They are maintained in MKS and provide a quick way to implement encryption.
  • They are rotated at least once per year.
  • No control over when these keys roll.
  • These keys are region specific.


Examples of AWS Managed CMKs

  • AWS managed CMK for S3 - Used in data buckets.
  • AWS KMS Default CMK - used for default encryption in EBS, RDS and Redshift.



Customer Managed Keys

  • Provides the customer total control over the key.


The key Policy can be defined:

  • Rotation schedules.
  • Permissions.


  • These keys are not tied to any feature or service.


  • It is the customer responsibility to protect customer managed keys.

Selecting a key type

  • Policy will dictate the key type.


  • AWS managed keys may be ok if complete control is not needed.
  • AWS managed keys have no charge.


  • If policy states keys must be rotated on demand (after an incident) customer managed is best.