Study Guides/AWS Cybersecurity Notes/Amazon KMS

From Cramsession
Jump to navigationJump to search
✍️ Verified Author: MflavellClick to view professional profile & credentials

Overview

  • Data encryption is the most critical aspect.
  • Must know KMS and the API calls used in the service


Two types of encryption:

  • Symmetric - Same key
This is fast for large ammounts of data.
  • Asymmetric - Uses a pair of keys
Private key - Kept secret (Decripts data)
Public key - Distributed (Encrypts data)


Exaples of symmetric are AES and DES


AWS KMS

Customer Master Keys

  • Contain key material for encryption and decryption.
  • CMKs are managed in KMS
  • Think of CMK as a keychain
  • KMS provides a way to store and manage keys - this is the AWS lockbox for your keys
  • KMS protects the CMKs
  • Uses industry standard practices to safeguard CMK


About CMKs:


  • They manage encryption keys for sensative data.
  • Control encryption and decryption of data
  • Securely stored by KMS
  • Fine grained access control
  • Work inside and ourside of AWS
  • use envelope encryption.
A data key is generated and used for encrypting data.
That key is encrypted with the CMK.
  • Auditable in AWS Cloud Trail and AWS Cloud Watch


  • Two different types of CMK exist:
  • Customer managed.
  • AWS managed.


AWS Managed CMKs

  • Owned and used by AWS services
  • Independent from the customer account.
You cannot track their useage or audit them!
  • Can be used by services inside an account.
  • They are maintained in MKS and provide a quick way to implement encryption.
  • They are rotated at least once per year.
  • No control over when these keys roll.
  • These keys are region specific.


Examples of AWS Managed CMKs

  • AWS managed CMK for S3 - Used in data buckets.
  • AWS KMS Default CMK - used for default encryption in EBS, RDS and Redshift.



Customer Managed Keys

Provides the customer total control over the key.

Customer has complete control over the lifecycle of a key.
This provides greater flexibility and customization.


The key Policy can be defined:

  • Rotation schedules.
  • Permissions based on requirements.


These keys are not tied to any feature or service.

  • They can be used inside or outside of AWS.
  • Much more contol over key use and permissions.


It is the customer responsibility to protect customer managed keys.

KMS provides the rools and security measures - but security is on the customer.


Selecting a key type

  • Policy will dictate the key type.
  • AWS managed keys may be ok if complete control is not needed.
  • AWS managed keys have no charge.
  • If policy states keys must be rotated on demand (after an incident) customer managed is best.


Data Encryption Keys

These are generated by KMS for encrypting data.

They are used WITH customer-managed keys to protect infomation.

They are short lived - only used for specific encryption operations.

DEKs proide an extra layer of security:

DEK - Encrypts the data
CMK - Encrypts the DEK


About DEKs:

  • Managed and generated in KMS
  • Used with CMK's
  • They are randomly generated.
  • Use envelope encryption Encrypted > DEC > CMK > Decrypted
  • DEKs are fast and efficient.
  • Can be used with vrious AWS services
  • KMS manages the DEC lifecycle.
  • Important part: DECs are symmetrical keys!


Key Material

Key material is used to encryptd and decrypt.

  • Customers cannot manage the key material in any way!
  • The key material is inside the CMK.
  • The CMK material is used to create the DMK
  • AWS Manged CMK - automatically creates the material inside the CMK.
  • For cusomter manaaged CMK - you create the CMK and import your own key material.


Importing key material

This may be needed if you have keys in use outside of AWS and need to bring them in.

This also could be for regulatary needs.

To do this:

Import (external) key material under advanced options