Open cardosec

Case 817453 · Cryptography · L3 Applied

Key Management with KMS and HSMs

Practise as: Deep dive · Explain it
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Envelope encryption: data keys (DEKs) encrypt data; a KMS-held key-encryption key (KEK) wraps the DEKs.
  2. HSMs (FIPS 140-3 validated) keep keys non-exportable and perform crypto inside the boundary.
  3. Rotation is cheap with envelope encryption: rewrap DEKs without re-encrypting bulk data.
  4. Separate duties with IAM key policies; log every key use (e.g. CloudTrail) and alert on anomalous decrypts.
  5. Crypto-shredding: destroying a key renders all data under it unreadable, useful for retention and erasure.

If the interviewer pushes back

  • How would you design per-tenant keys (BYOK/HYOK) for a SaaS product, and what breaks if a tenant revokes access?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.