Case 817453 · Cryptography · L3 Applied
Key Management with KMS and HSMs
Practise as: Deep dive · Explain it
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Envelope encryption: data keys (DEKs) encrypt data; a KMS-held key-encryption key (KEK) wraps the DEKs.
- HSMs (FIPS 140-3 validated) keep keys non-exportable and perform crypto inside the boundary.
- Rotation is cheap with envelope encryption: rewrap DEKs without re-encrypting bulk data.
- Separate duties with IAM key policies; log every key use (e.g. CloudTrail) and alert on anomalous decrypts.
- Crypto-shredding: destroying a key renders all data under it unreadable, useful for retention and erasure.
If the interviewer pushes back
- How would you design per-tenant keys (BYOK/HYOK) for a SaaS product, and what breaks if a tenant revokes access?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.