< ciso
brief />
Tag Banner

All news with #aws kms tag

38 articles

Timestream for InfluxDB adds customer managed KMS

πŸ” Amazon Timestream for InfluxDB now supports AWS KMS customer managed keys to encrypt data at rest for InfluxDB 2 databases, InfluxDB 2 Read Replicas, and InfluxDB 3 clusters. Customers choose a symmetric AWS KMS key during resource creation; the key must reside in the same AWS account and Region and cannot be changed later. The capability is available via the AWS Console, AWS CLI, and the Timestream for InfluxDB API across all supported Regions, with standard AWS KMS charges applying.
read more β†’

Timestream for InfluxDB adds backup and restore

πŸ”’ Amazon Timestream for InfluxDB now supports customer-driven backups and restores for InfluxDB 2 and 3 engines. You can trigger one-time on-demand backups, schedule up to four recurring backup configurations per resource with custom frequency and retention, and restore either to a new resource or overwrite an existing one via the Console, CLI, or API. The first backup is full and subsequent backups are incremental, and KMS-managed keys are preserved for encrypted resources.
read more β†’

Caching KMS Data Keys to Prevent Cache Stampedes

πŸ” This post examines how NICE Actimize reduced AWS KMS costs by 77% for a multi-tenant, event-driven platform by rethinking data key caching. It outlines the cache stampede problem that arises when envelope encryption operates at high concurrency and describes two solutions: the AWS-recommended hierarchical keyring with DynamoDB branch keys and a custom CachedKmsClient using Caffeine caches. The article covers design, trade-offs, and security considerations for both patterns.
read more β†’

AWS Glue Data Catalog adds S3 Tables export

πŸ”” Today AWS Glue Data Catalog preview adds two features: exporting catalog metadata to S3 Tables and enabling semantic search for catalogs encrypted with customer managed AWS KMS keys. Exported metadata β€” including glossary terms, custom attachments, and descriptions β€” is written to the managed aws-catalog S3 table bucket in Apache Iceberg format, enabling SQL queries, auditing, and time travel in engines like Amazon Athena and third-party tools. These capabilities are available in US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Ireland); S3 Tables usage follows S3 pricing.
read more β†’

Choosing AWS KMS or AWS CloudHSM for Key Management

πŸ” This post compares AWS KMS and AWS CloudHSM, explaining their differences, deployment models, pricing, region coverage, and typical use cases. It emphasizes that AWS KMS is the recommended, fully managed option for most workloads while CloudHSM is appropriate for legacy applications or strict dedicated-HSM requirements. The article outlines shared security assurances, compliance coverage, supported algorithms, and operational trade-offs to guide selection.
read more β†’

Lambda durable functions add customer managed KMS support

πŸ”’ AWS Lambda durable functions now support encrypting durable execution data with an AWS KMS customer managed key. Durable functions let you run long-lived workflows with automatic state management; execution state is encrypted at rest by default with an AWS‑owned key. With this update you can select and manage your own KMS key for execution data, enabling separate control of rotation and access for execution history and state. The feature is available in all Regions where durable functions exist; standard AWS KMS charges apply.
read more β†’

CloudWatch Synthetics adds customer managed KMS keys

πŸ” Amazon CloudWatch Synthetics now supports using customer managed AWS KMS keys to encrypt canary environment variables, allowing teams to control encryption for sensitive data such as API keys and tokens. Previously, only an AWS owned key was used; now you can specify a symmetric KMS key for at-rest encryption or perform client-side encryption and decrypt at runtime. This capability meets requirements for key management, auditability, and rotation and is available in all commercial AWS Regions, with multi-location canaries able to use per-replica Region keys.
read more β†’

Amazon S3 delivers server access logs to CloudWatch

πŸ“£ Amazon S3 now supports delivering server access logs to Amazon CloudWatch Logs, enabling instant querying, alarms, cross-account and cross-Region aggregation, and AWS KMS encryption for access log data. You can also mirror logs to Amazon S3 Tables in Apache Iceberg format at no additional storage cost. These delivery options complement existing free delivery to S3 buckets and provide more flexibility for monitoring and analysis.
read more β†’

Amazon Cognito adds customer managed KMS keys

πŸ” Amazon Cognito now supports customer managed keys in AWS Key Management Service (KMS) to encrypt user pool data at rest. While AWS-owned keys remain the default, customer managed keys let organizations control key lifecycle and access policies to meet governance requirements. You can set a key when creating a new user pool or update an existing one, and audit key usage via AWS CloudTrail. Available in Essentials and Plus tiers with standard AWS KMS charges.
read more β†’

AWS KMS GetKeyLastUsage improves key audits

πŸ” AWS KMS introduced the GetKeyLastUsage API to report the date, time, operation type, CloudTrail event ID, and KMS request ID for the most recent cryptographic operation on a key. The feature works for customer-managed and AWS-managed keys across specs and origins and is visible in the AWS Management Console and AWS CLI. Tracking of last usage began on April 23, 2026 for most Regions, so historical gaps before tracking began should be considered. Use DisableKey, monitoring, and the kms:TrailingDaysWithoutKeyUsage condition to prevent accidental deletions.
read more β†’

Amazon Quick Research adds customer-managed KMS keys

πŸ”’ Amazon Quick Research now supports encryption using customer-managed keys (CMKs) via AWS Key Management Service, enabling organizations to control encryption, auditing, and key lifecycle. Customers can use multiple CMKs with one default key per AWS account per region and must create CMKs in the same account and region as Quick resources. Only symmetric KMS keys are supported, and CloudTrail integration provides comprehensive audit trails and the ability to revoke compromised keys within 15 minutes. The feature is generally available in all AWS Regions where Amazon Quick is offered.
read more β†’

Amazon Quick Research adds customer-managed KMS keys

πŸ” Amazon Quick Research now supports customer-managed keys (CMKs) via AWS Key Management Service (KMS), enabling organizations to manage encryption keys for their Quick data. Customer-managed keys provide enhanced control, CloudTrail-based auditing, and the ability to revoke compromised keys within 15 minutes. Only symmetric KMS keys created in the same account and region are supported, with one default CMK per account per region and support for multiple CMKs across datasets.
read more β†’

SageMaker HyperPod Adds Data Capture for Inference

🧾 Amazon SageMaker HyperPod now supports data capture for inference workloads, allowing organizations to record request and response payloads for monitoring, compliance, debugging, and offline analysis. You can capture traffic at the SageMaker endpoint, load balancer, or model pod and combine layers for richer observability. Captured data is delivered asynchronously to Amazon S3 with configurable sampling and encryption using customer-managed AWS KMS keys and is designed to never block inference. Enable data capture via the HyperPod Inference Operator or SageMaker JumpStart.
read more β†’

AWS Transform Adds Customer-Owned S3 Artifact Storage

πŸ—‚οΈ AWS Transform now supports customer-owned Amazon S3 buckets, letting customers control where transformation artifacts are stored and how they are secured. You can configure your own S3 bucket, optionally encrypt artifacts with your AWS KMS key, and manage access policies in your account. Migration teams can upload files directly and centralize artifacts across accounts to support regulated industries and data sovereignty requirements. This capability is available in all Regions where AWS Transform is offered.
read more β†’

AWS Payment Cryptography Achieves PCI PIN and P2PE

πŸ”’ AWS announced the completion of PCI PIN and PCI P2PE assessments for AWS Payment Cryptography, expanding validations to include Key Management (KMCP) and Key Loading (KLCP) alongside the existing Decryption Management (DMCP). The coverage is extended to South America (SΓ£o Paulo) and Asia Pacific (Sydney) Regions. These attestations allow customers to use PCI PTS HSM-certified, AWS-managed HSMs with compliant key management to simplify regulated deployments.
read more β†’

AWS Payment Cryptography: Cross-Account Key Sharing

πŸ” AWS announced support for cross-account key sharing in AWS Payment Cryptography using resource-based policies (RBP). Organizations can now maintain a single authoritative copy of cryptographic keys and grant per-resource access to other AWS accountsβ€”internal or externalβ€”without import/export workflows. This reduces duplication, simplifies key lineage and access control, and helps teams scale cryptography operations in cloud-hosted payment applications. The feature is available in all Regions where the service runs; consult the user guide to get started.
read more β†’

AWS KMS Adds Last-Usage Visibility for Keys Across Regions

πŸ”’ AWS Key Management Service (KMS) now surfaces the timestamp, operation type, and AWS CloudTrail event ID for the last cryptographic operation performed with each KMS key, viewable in the console or via API. This eliminates manual log queries and helps administrators and compliance teams quickly identify unused keys, verify active usage, and trace key activity. A new condition key, kms:TrailingDaysWithoutKeyUsage, enables policy-based protection against accidental deletion of recently used keys, and the capability is available in all AWS Regions including GovCloud and China.
read more β†’

Amazon Quick Automate Adds Export/Import Migration

πŸ” Quick Automate now supports secure export and import of automation versions across automation groups, AWS accounts, and Regions. The feature packages workflows, runtime configuration, and step metadata into an encrypted link protected by AWS KMS; export links remain valid for 12 hours and are reusable, eliminating repeated exports. It speeds promotion between environments and enables point-in-time snapshots for recovery. Note that connectors, credentials, and human-in-the-loop queues are excluded and must be reconfigured.
read more β†’

Cloning AWS CloudHSM Clusters Across Regions Securely

πŸ›‘οΈ This AWS Security Blog post demonstrates how to clone an AWS CloudHSM cluster across Regions using the copy-backup-to-region workflow and Client SDK 5 (recommended version 5.17 or later). It walks through creating and initializing a source cluster, generating a backup, copying that backup to a destination Region, and launching a new cluster from the copied backup, including certificate transfer and security group adjustments. The guide emphasizes that non-exportable keys can only be synchronized to cloned clusters, that users and passwords must be maintained manually after the initial backup, and that Client SDK 3 reached end-of-support on January 1, 2025, so migration to SDK 5 is required.
read more β†’

How AWS KMS and Encryption SDK Avoid AES-GCM Limits

πŸ”’ This post explains how AWS KMS and the AWS Encryption SDK mitigate AES-GCM invocation and data bounds by deriving a fresh symmetric key per encryption using nonce-based KDFs. By producing unique K_d values (via HMAC-SHA256 in KMS and HKDF-SHA512 in the SDK) and using per-invocation IV and frame controls, they prevent (K, IV) reuse and limit exhaustion. Default settingsβ€”128- or 256-bit nonces, 96-bit IVs, and 4 KB framesβ€”keep total data and invocation counts well within conservative security margins, reducing the need for manual key rotation and operational tracking.
read more β†’