AWS KMS, Key Vault and Cloud KMS compared
Most companies should use provider-managed keys and stop there. Customer-managed keys are worth their cost when a contract asks for key control, a regulator names it, or you need to prove who could decrypt data.
There are four levels of key control in the cloud. Provider-managed keys are free and invisible. Customer-managed keys in the provider's KMS let you set the key policy and see every use. Bring your own key lets you generate the key material yourself. Dedicated or external HSMs keep keys in hardware you control or even outside the provider. Each step up adds cost and operational risk: lose access to a key you manage and the data is gone.
| Level | AWS | Azure | Google Cloud |
|---|---|---|---|
| Provider-managed | AWS owned or AWS managed keys | Microsoft-managed keys | Google default encryption |
| Customer-managed in the provider KMS | KMS customer managed keys | Key Vault keys (CMK) | Cloud KMS keys (CMEK) |
| Bring your own key material | KMS imported key material | Key Vault BYOK | Cloud KMS imported keys |
| Dedicated HSM | CloudHSM, KMS custom key store | Managed HSM, Dedicated HSM | Cloud HSM |
| Keys held outside the provider | External key store (XKS) | Managed HSM with your key release policy | Cloud External Key Manager |
When are customer-managed keys worth it?
- A contract names them. Financial services and some public sector buyers ask for customer-managed keys by name.
- You need a decrypt log. Every use of a customer-managed key is logged in CloudTrail, Azure Monitor or Cloud Audit Logs, which proves who read encrypted data.
- Crypto-shredding. Deleting a per-tenant key makes that tenant's data unrecoverable, which some deletion commitments rely on.
- Foreign access concerns. External key management means the provider cannot decrypt without your key service, which answers the hardest residency question a buyer asks.
If none of those apply, provider-managed keys meet SOC 2, ISO 27001 and PIPEDA's safeguarding principle. The key management decider walks through the choice.
What you take on with customer-managed keys
- Key policy
- Who can use and administer each key. A wrong key policy can lock out your own services.
- Rotation
- Automatic annual rotation on AWS and configurable rotation on Azure and Google Cloud. Turn it on and record it.
- Deletion protection
- AWS enforces a 7 to 30 day waiting period; Key Vault soft delete and purge protection; Cloud KMS scheduled destruction. Keep these on.
- Separation of duties
- Key administrators should not also be the people who read the data. Auditors look for this.
- Cost
- A monthly charge per key and per request. Small for a handful of keys, material for per-tenant keys at scale.
Key management evidence
Auditors ask for the key inventory, key policies, rotation settings, deletion protection status and a sample of key usage logs. For ISO 27001, control 8.24 (use of cryptography) expects a written cryptography policy covering algorithms, key lengths, key lifecycle and responsibilities. It can be two pages.
What is the difference between CMK and BYOK?
A customer-managed key is created and stored in the provider's key service, under your policy. Bring your own key means you generate the key material outside the provider and import it. BYOK gives you an offline copy of the key material and more work to manage it.
Does Azure Key Vault keep keys in Canada?
A Key Vault is created in a region, and keys in a Canada Central or Canada East vault are stored there. Managed HSM is regional too. Check Microsoft's documentation for geo-replication behaviour of the tier you use.
Can the cloud provider read data encrypted with my key?
With keys in the provider's KMS, the provider's systems perform encryption and decryption on your behalf under your key policy. Contractual commitments and logging govern that. Only external key management keeps the key entirely outside the provider's control.
Need a key management design?
Firms in the network design key hierarchies and write the cryptography policy.
Get matched