KMS Key
A KMS Key is an encryption key managed by AWS Key Management Service, used to encrypt data across S3, EBS, RDS, DynamoDB, and other services without your application ever handling raw key material directly. Every encrypt and decrypt operation is logged automatically in CloudTrail. Only Customer Managed Keys (CMKs) can be shared across AWS accounts — AWS-owned and AWS-managed keys cannot.
CRED encrypts customer PII in S3 using SSE-KMS with a Customer Managed Key so every access to sensitive records generates a CloudTrail entry auditors can review.
Three Key Types
- AWS Owned — free, AWS controls it fully, no visibility, cannot be shared
- AWS Managed — free, AWS rotates it, view-only, cannot be shared
- Customer Managed (CMK) — ~$1/month, full control, shareable across accounts
A Scaling Gotcha
SSE-KMS calls KMS on every S3 upload and download. At high throughput (millions of requests/hour) this can exceed the default KMS request quota and cause throttling that looks like an S3 problem but isn't.
RememberIf you need to share an encrypted EBS snapshot or S3 object with another AWS account, it must be encrypted with a Customer Managed Key — AWS Managed Keys block cross-account sharing entirely.
Frequently Asked Questions
How does a KMS Key protect data without your application ever seeing the raw key?
KMS uses an envelope encryption model: your application calls KMS to generate a data key, which KMS returns both in plaintext (used once, in memory, to encrypt the actual data) and in an encrypted form (stored alongside the data). To decrypt later, the application sends the encrypted data key back to KMS, which returns the plaintext version — the master key itself never leaves KMS's hardware security modules, and every operation is logged in CloudTrail automatically.
What's the difference in practice between AWS-managed keys and Customer Managed Keys, and why does it matter?
AWS-managed keys (the ones auto-created with names like aws/s3) can't be shared across accounts, rotated on your schedule, or given a custom key policy — they're the zero-effort default. Customer Managed Keys (CMKs) cost a small monthly fee per key but let you control the key policy, enable cross-account sharing, and set custom rotation. A common mistake is defaulting to AWS-managed keys for everything and then hitting a wall when a cross-account access pattern (e.g., a shared S3 bucket) requires a CMK.