Server-side encryption available for AWS S3 storage

 

Summary

One of the legitimizing aspects of cloud computing is to self-manage the encryption keys, such as Amazon’s new SSE. But, how does one go about doing this? IT pro Rick Vanover shares a few tips.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

In many areas of IT, we have to learn to managing key. This could be simple stuff such as usernames and passwords, but also more complicated topics such as encryption keys. While I'm not an encryption key expert per se, I do know enough about them to get a number of things done. But more importantly, I know that they need to be fully protected.

With the recent news of Amazon launching Server Side Encryption (SSE) for data-at-rest encryption, this is another reminder to me of the critical nature of key management. The Amazon solution allows 256-bit AES encryption to be performed locally on data before it is uploaded into the S3 storage cloud. Further, there is an option within the encryption client provided by the AmazonS3EncryptionClient class to leverage APIs to do the encryption locally with self-managed keys before transferring to S3. Given the popularity of public cloud computing and the inevitable increase in its use, it's critical to refine some best practices on key management for cloud applications.

We can borrow a few tricks from the things we've always done on key management, such as ensuring encryption keys are used for backups that go offsite.

  • Limit the number of encryption keys in use (but protect them very well) and spread out the encryption. For example, if you lose one key somehow, don't make that bring down your whole encryption algorithm.
  • Store the keys on a mechanism with robust auditing, including reads on a file system as well as any other access. That way, any activity (even a read) is logged for any forensic requirement.
  • Issue an escrow copy of newly rotated encryption keys to an internal security team or external software escrow agency. Limited information on what the keys are for may need to be provided, but the takeaway is that a backup or check-and-balance of the protection of the keys is made.

In the case of Amazon SSE, cloud solution administrators will be able to manage keys for data going in and out of cloud applications for S3 data transfers. Currently for Amazon's Elastic Block Store storage resources (EBS), SSE is not supported. I personally don't think SSE would be capable on EBS, but a new encryption mechanism may be available or used within AMIs to provide at-rest encryption of data traveling to, through, and from the Amazon clouds.

Rick Vanover (MCITP, MCSA, VCP, vExpert) is an IT Infrastructure Manager for a financial services organization in Columbus, Ohio. Rick has years of IT experience and focuses on virtualization, Windows-based server administration, and system hardware.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

RT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Integration, focused investments to propel Windows Phone http://t.co/6JkDa9sB

RT @AsianFashionLaw: Malaysia offers some manufacturing benefits over China http://t.co/bMquIFiX

Acquisitions in the Big Data market increasingly important to enterprises… http://t.co/Br4BkXyZ

Experience trumps content in apps monetization http://t.co/iaCY5ebX

Malaysia offers some manufacturing benefits over China http://t.co/bMquIFiX

RT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Thats it.Im digging up an old bus plan i wrote around acquisition of #bigdata talent. http://t.co/gpkha5A1 Any investors want2 read/discuss?

Integration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 mins ag... http://t.co/aaa0Cb73

Homegrown smartphone OSes gaining favor in China http://t.co/lOBVp1T6

Homegrown smartphone OSes gaining favor in China: 59 Jakarta 10350, Indonesia Locally-made mobile operating syst... http://t.co/gHypbdIY

Integration, focused investments to propel Windows Phone - ZDNet Asia http://t.co/7sZi6Dhb

RT @zdnetasia: Homegrown smartphone OSes gaining favor in China. http://t.co/lL8KbccW

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia: Big data acquisition... http://t.co/r6taCmG1 #ITNews #BigData

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate