跳到主要内容
知仓学习社ZHICANG

implementing-envelope-encryption-with-aws-kms

Implements envelope encryption with AWS KMS, encrypting data locally with a data encryption key (DEK) and protecting that DEK with a KMS-managed key…

读凭据读文件写文件严重 7 · 高危 0mukul975/Anthropic-Cybersecurity-Skills

它会碰到什么

扫了多少8 个文本文件,39 KB
它会碰到什么读凭据读文件写文件
命中总数10 处
命中统计严重 7 · 高 0 · 中 3 · 低 0
逐条看命中(7 条严重或高危)
  • 严重 references/standards.md:6cred-paths
    - **URL**: https://docs.aws.amazon.com/kms/latest/developerguide/
  • 严重 references/standards.md:7cred-paths
    - **Envelope Encryption**: https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html#enveloping
  • 严重 references/standards.md:10cred-paths
    - **GenerateDataKey**: https://docs.aws.amazon.com/kms/latest/APIReference/API_GenerateDataKey.html
  • 严重 references/standards.md:11cred-paths
    - **Decrypt**: https://docs.aws.amazon.com/kms/latest/APIReference/API_Decrypt.html
  • 严重 references/standards.md:12cred-paths
    - **ReEncrypt**: https://docs.aws.amazon.com/kms/latest/APIReference/API_ReEncrypt.html
  • 严重 references/standards.md:15cred-paths
    - **URL**: https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/
  • 严重 scripts/process.py:19cred-paths
    or ~/.aws/credentials

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Implementing Envelope Encryption with AWS KMS

Overview

Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting large volumes of data locally while keeping the master key secure in a hardware security module (HSM) managed by AWS. This skill covers implementing envelope encryption using AWS KMS GenerateDataKey API.

When to Use

  • When deploying or configuring implementing envelope encryption with aws kms capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with cryptography concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Understand the envelope encryption pattern and its advantages
  • Generate data encryption keys using AWS KMS GenerateDataKey
  • Encrypt/decrypt data locally using DEKs
  • Store encrypted DEK alongside ciphertext
  • Implement key caching to reduce KMS API calls
  • Handle key rotation with automatic re-encryption
  • Implement multi-region encryption for disaster recovery

Key Concepts

Envelope Encryption Flow

  1. Call kms:GenerateDataKey to get plaintext DEK + encrypted DEK
  2. Use plaintext DEK to encrypt data locally (AES-256-GCM)
  3. Store encrypted DEK alongside ciphertext
  4. Discard plaintext DEK from memory
  5. For decryption: call kms:Decrypt on encrypted DEK, then decrypt data

Advantages Over Direct KMS Encryption

| Aspect | Direct KMS | Envelope Encryption |

|--------|-----------|-------------------|

| Max data size | 4 KB | Unlimited |

| Latency | Network round-trip per operation | Local encryption |

| Cost | $0.03/10,000 requests | Fewer KMS requests |

| Offline | Not possible | Yes (with cached DEKs) |

KMS Key Types

  • AWS Managed: AWS creates and manages (aws/s3, aws/ebs)
  • Customer Managed: You create and manage policies
  • Custom Key Store: Backed by CloudHSM cluster

Security Considerations

  • Never store plaintext DEK; only keep encrypted DEK
  • Use key policies to restrict who can call GenerateDataKey and Decrypt
  • Enable AWS CloudTrail logging for all KMS API calls
  • Implement key rotation (automatic annual rotation for CMKs)
  • Use encryption context for authenticated encryption metadata
  • Handle KMS throttling with exponential backoff

Validation Criteria

  • [ ] GenerateDataKey returns plaintext and encrypted DEK
  • [ ] Data encrypts correctly with plaintext DEK using AES-256-GCM
  • [ ] Encrypted DEK can be decrypted via KMS Decrypt API
  • [ ] Decrypted DEK recovers the original data
  • [ ] Plaintext DEK is wiped from memory after use
  • [ ] Encryption context is validated during decryption
  • [ ] Key rotation re-encrypts DEKs with new master key

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。