Open cardosec

Case 15ACEC · Cloud · L2 Practitioner

Envelope Encryption with KMS

Practise as: Explain it · Interview

Interview questionWhat is envelope encryption and why do cloud KMS services use it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Data is encrypted with a data key; the data key is encrypted by a master key that never leaves the KMS/HSM
  2. Scales: bulk crypto happens locally, only small data keys go to KMS, avoiding size and rate limits
  3. Access control moves to the key policy: no kms:Decrypt permission means no plaintext even with the ciphertext
  4. Rotating the master key does not require re-encrypting bulk data; at most the small data keys are rewrapped
  5. Customer-managed keys add control (own key policy, rotation, disable/delete) at the cost of availability risk

If the interviewer pushes back

  • If someone can read an encrypted S3 object, what else must they have to see plaintext?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.