A cloud customer is concerned about unauthorized access to sensitive data stored in a public cloud. They want to implement a solution where the encryption keys are never exposed to the cloud provider, even during key usage for encryption and decryption operations. Which key management approach would best satisfy this stringent requirement?
- ACustomer-Provided Keys (CPK) where the customer uploads keys to the cloud provider's KMS
- BCustomer-Controlled Keys (CCK) using an external Hardware Security Module (HSM)
- CCustomer-Managed Keys (CMK) within the cloud provider's Key Management Service (KMS)
- DBring Your Own Key (BYOK) where the customer imports keys into the cloud provider's KMS
Show answer & explanationAnswer & explanation
Correct answer: B. Customer-Controlled Keys (CCK) using an external Hardware Security Module (HSM)
Customer-Controlled Keys (CCK) using an external HSM ensures that the encryption keys are generated, stored, and used entirely outside the cloud provider's control, meaning they are never exposed to the provider. The cloud provider's services can request encryption/decryption operations from the external HSM, but the key itself never leaves the customer's secure environment.
Why the other options are wrong
- A. CPK involves uploading key material to the cloud provider, exposing it at some point to the provider's infrastructure.
- C. CMK within a cloud KMS means the key material is generated and managed by the cloud provider, even if the customer controls its policy.
- D. BYOK involves importing key material into the cloud provider's KMS, meaning the key material resides within the provider's control, even if generated elsewhere.
Customer-Controlled Keys (CCK)
Customer-Controlled Keys (CCK) refers to a key management model where the customer generates, stores, and manages their encryption keys entirely outside the cloud provider's infrastructure, typically using an on-premises or third-party external Hardware Security Module (HSM).
- Keys are never exposed to the cloud provider.
- Customer retains full control over key lifecycle.
- Often involves an external HSM for key generation and storage.
- Cloud services request key operations from the external HSM.
Memory trick: CCK: Customer's Complete Key Control.