Skip to content
LakeBench
ProblemsCommunityPricing
Sign inStart practicing
Back
  1. Home
  2. Interview prep
  3. Encryption at rest and customer-managed keys

Cloud · Cloud Architecture Basics

Encryption at rest and customer-managed keys

Mediumcloud-41
cloud-securitycmekkmsencryptioncompliance

Question

What's the difference between Google/AWS-managed encryption keys and customer-managed keys (CMEK)?

Solution

Cloud platforms automatically encrypt all data at rest by default using provider-managed encryption keys at zero additional cost and without administrative overhead. Customer-Managed Encryption Keys allow organizations to generate and control their own encryption keys inside services like AWS KMS or Google Cloud KMS, enabling custom rotation policies, detailed audit logs, and immediate access revocation. Regulatory standards in healthcare and financial industries frequently require customer-managed keys, which allow instant crypto-shredding by destroying the root key.

Key management models compared

Understanding who controls the cryptographic root key clarifies the boundary between default security and advanced regulatory compliance.

Provider-Managed:  Cloud Provider Generates Key ---> Transparent Default Encryption
Customer-Managed:  Enterprise KMS Key (Rotation/IAM) ---> Bound to Bucket/Warehouse

Engineers evaluate key management across several operational properties:

  • Default encryption operates transparently. AWS S3 encrypts objects using SSE-S3 or AWS-managed KMS keys, while Google Cloud Storage uses Google-managed keys. Users configure nothing, pay no extra fees, and cannot view or revoke the internal keys.
  • Customer-Managed Encryption Keys (CMEK) are created within AWS KMS or GCP Cloud KMS. Your security team defines who can use the key, monitors every cryptographic request in access logs, and controls automated annual rotation.
  • Deleting or disabling a customer-managed key makes all underlying data unreadable immediately. This practice, known as crypto-shredding, provides cryptographic proof of data destruction for sensitive records.
  • Industry compliance standards like HIPAA, PCI-DSS, and European banking frameworks often mandate CMEK to protect against unauthorized data exposure by hosting providers.

Operational impact on pipelines

Implementing customer-managed encryption introduces minor operational considerations:

  • CMEK introduces negligible latency overhead because storage services use envelope encryption, caching local data encryption keys while encrypting only the key itself with KMS.
  • Every read and write operation invokes KMS APIs, incurring small request costs that can accumulate during high-frequency micro-batch ingestion.
  • Misconfiguring IAM permissions on the KMS key blocks pipelines immediately, preventing services like BigQuery or Athena from reading table files even when bucket-level permissions are valid.
PreviousNext