A global pharmaceutical company processes highly sensitive patient data in an AWS environment. Due to stringent regulatory requirements and internal security policies, all data must be encrypted at the application layer before being written to Amazon S3. The company also requires that the encryption keys are managed within an on-premises Hardware Security Module (HSM) and never leave the HSM for cryptographic operations. Which data encryption solution should the company implement?
- AServer-Side Encryption with customer-provided encryption keys (SSE-C).
- BClient-Side Encryption (CSE) with an encryption client that integrates with the on-premises HSM.
- CServer-Side Encryption with AWS KMS (SSE-KMS).
- DClient-Side Encryption (CSE) using an AWS KMS Custom Key Store backed by AWS CloudHSM.
Show answer & explanationAnswer & explanation
Correct answer: B. Client-Side Encryption (CSE) with an encryption client that integrates with the on-premises HSM.
Client-Side Encryption (CSE) allows the application to encrypt data before sending it to S3. Integrating the encryption client with an on-premises HSM ensures that keys are managed and cryptographic operations occur exclusively within the on-premises HSM, meeting the strict requirements.
Why the other options are wrong
- A. SSE-C requires the customer to provide keys, but S3 performs the encryption. The keys are sent to S3, and the HSM itself doesn't perform the cryptographic operations, failing the 'keys never leave HSM' and 'HSM performs operations' requirements.
- C. SSE-KMS uses AWS-managed KMS keys, which are not managed within an on-premises HSM, failing that critical requirement.
- D. An AWS KMS Custom Key Store backed by AWS CloudHSM manages keys within a CloudHSM *in AWS*, not an *on-premises* HSM, violating the 'on-premises HSM' requirement.
Client-Side Encryption with On-Premises HSM
Client-Side Encryption (CSE) integrated with an on-premises Hardware Security Module (HSM) allows an application to encrypt data locally using keys stored and managed exclusively within the on-premises HSM, ensuring keys never leave the HSM for cryptographic operations before data is sent to cloud storage.
- Data is encrypted at the application layer before being sent to AWS services like S3.
- Encryption keys are generated, stored, and used within the customer's on-premises HSM.
- Cryptographic operations are performed by the on-premises HSM, maintaining full key control.
- Ensures the highest level of key control and compliance for sensitive data.
Memory trick: Client-Side Cryptography Controls Keys Completely On-Premises.