What would happen if someone intercepted your file while it was being uploaded to the internet? Encryption is the practice of transforming data into an unreadable form to prevent this. AWS manages these encryption keys securely through a service called KMS.
DVA-C02 exam questions in this area focus on which encryption method to use and how to manage keys.
What is AWS KMS (Key Management Service)?
KMS is an AWS service for creating and managing encryption keys. Think of it as a digital vault key storage. It safely stores the keys that lock your data, allowing them to be used only when needed.
KMS Key Types
There are three types depending on who manages the key.
AWS Managed Keys: AWS handles everything automatically. No extra cost. Key rotation is automatic. Used for most default services. Customer Managed Keys (CMK): You directly manage key policies, rotation schedules, and deletion. Used when finer-grained access control is needed. Costs $1/month plus API call fees. AWS Owned Keys: Keys used only internally by AWS. Not visible to customers.
Envelope Encryption
KMS can only directly encrypt data up to 4KB at a time. But real-world data is much larger. Envelope encryption solves this problem.
Think of it as putting a letter in an envelope, then putting that envelope in a safe.
Call the GenerateDataKey API to create a data key (the key that locks your letter). Encrypt your actual data locally using that data key. Encrypt the data key itself using the KMS master key (the safe key). Store the encrypted data together with the encrypted data key.
This approach minimizes the amount of data sent directly to KMS while still allowing large data to be encrypted securely.
S3 Server-Side Encryption (SSE)
This is the method where AWS automatically encrypts files when storing them in S3. There are three options depending on which key is used.
| Option | Key Manager | Feature | |--------|-------------|---------| | SSE-S3 | S3 manages | Default. No setup required. Simplest option. | | SSE-KMS | KMS manages | Who used the key and when can be tracked via CloudTrail. Used when security auditing is required. | | SSE-C | You provide the key | For when you have your own key management infrastructure. You send the key in headers with each request. |
Important note: SSE-KMS calls the KMS API with every S3 request. Under heavy traffic, this can hit KMS throughput limits (throttling). Enabling S3 Bucket Key dramatically reduces the number of KMS calls and mitigates this issue.
Client-Side vs Server-Side Encryption
Server-side encryption: AWS handles encryption and decryption. This is the method used in most cases. SSE-S3 and SSE-KMS fall into this category. Client-side encryption: Your app encrypts the data first, then sends it to AWS. Think of it as putting the lock on before placing it in the safe. Since even AWS cannot see the plaintext data, this is used in environments with strict compliance requirements.
!Client-side versus server-side encryption
In-Transit Encryption
Data also needs encryption while being transmitted over the internet. Using HTTPS/TLS prevents data from being exposed during transmission. Adding the aws:SecureTransport condition to an S3 bucket policy can outright deny requests using HTTP (unencrypted).
Exam Key Points
"Encrypting large data over 4KB" -- Envelope encryption (GenerateDataKey)
"Audit trail of encryption key usage (CloudTrail)" -- SSE-KMS
"Default S3 encryption, no setup required" -- SSE-S3
"S3 encryption with your own key" -- SSE-C
"Mitigating SSE-KMS throttling" -- S3 Bucket Key
"Prevent AWS from seeing plaintext" -- Client-side encryption
"Deny HTTP access" -- aws:SecureTransport condition
Core of envelope encryption: encrypt data with data key, encrypt data key with master key