A global pharmaceutical company is building a new data lake on AWS using Amazon S3. The data lake will store clinical trial data, which is highly regulated and requires encryption at rest using keys that are regularly rotated. The company's security policy states that the encryption keys must be unique for every object to minimize the blast radius if a single key is compromised. Which S3 encryption option, combined with a key management strategy, fulfills these requirements most effectively?
- AClient-Side Encryption with a single master key stored in AWS Secrets Manager, used to encrypt all objects before upload.
- BServer-Side Encryption with Amazon S3-managed keys (SSE-S3) with automatic key rotation enabled.
- CServer-Side Encryption with AWS KMS-managed keys (SSE-KMS) with a unique data key for each object, enveloped by a CMK with automatic rotation.
- DServer-Side Encryption with AWS KMS-managed keys (SSE-KMS) using a single CMK and automatic key rotation.
Show answer & explanationAnswer & explanation
Correct answer: C. Server-Side Encryption with AWS KMS-managed keys (SSE-KMS) with a unique data key for each object, enveloped by a CMK with automatic rotation.
SSE-KMS inherently uses envelope encryption, where a unique data key encrypts each object, and that data key is then encrypted by a customer master key (CMK) in KMS. This ensures that every object has a unique encryption key, minimizing the blast radius. Automatic CMK rotation within KMS further enhances security without requiring manual intervention, meeting the requirement for unique keys per object and regular rotation.
Why the other options are wrong
- A. Client-Side Encryption with a single master key for all objects defeats the purpose of having unique keys per object to minimize blast radius. Secrets Manager is for storing secrets, not primarily for performing cryptographic operations or managing unique object keys.
- B. SSE-S3 uses a single master key per bucket (or service) and does not provide unique keys per object, nor does it give the customer control over key rotation beyond what AWS provides internally.
- D. While SSE-KMS uses a CMK, if only a single CMK is used without leveraging envelope encryption's data key uniqueness, it doesn't guarantee a unique *encryption key* for *each object* in the way the question implies for blast radius reduction. The strength of SSE-KMS for this requirement comes from its use of unique data keys per object.
KMS Envelope Encryption (Data Keys)
AWS KMS uses envelope encryption, where a unique data key (DEK) is generated for each data object and used to encrypt the object. The DEK itself is then encrypted by a Customer Master Key (CMK) in KMS. This strategy limits the impact of a compromised DEK to a single object.
- Unique data key for every object.
- Data key encrypted by a CMK.
- CMK rotation does not re-encrypt data, only the data key.
- Minimizes blast radius of key compromise.
Memory trick: KMS 'envelopes' each object with its own 'unique key' for security.