aws / aws/aws-dynamodb-encryption-python

AwsKmsCryptographicMaterialsProvider Design/Behavior Improvements

Open
#176 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
95
Forks
57
PR merge metrics
No merged PRs in 30d

Description

### Problem:

The correct behavior of the DirectKMSMaterialProvider is to use the configured CMK on encrypt, and to let KMS determine the correct CMK to use on Decrypt (this is a common KMS pattern, as KMS ciphertext stores the CMK used as metadata).

However, this behavior for DirectKMSMaterialProvider is potentially confusing, as customers may expect that the CMK configured on the CMP is also "used" to decrypt, and may be surprised if decryption succeeds even though the configured CMK was not the CMK used to encrypt the data.

### Solution:

Since the original DirectKMSMaterialProvider was designed, KMS has introduced a `keyId` param on Decrypt that ensures the call fails if a different key was used to encrypt the ciphertext.

We should consider either updating or replacing the DirectKMSMaterialProvider to allow enforcing a particular key on decrypt, similar to the Strict vs. Discovery modes expressed by the AWS Encryption SDK's Keyrings and Master Key Providers.

Our new design should:
- maintain API parity between the DDBEC for Python and Java.
- be as simple as possible to reason about.
- minimize possible "modes" for behavior, and ensure that any "mode" needs to be explicitly chosen by customers on config.
- ensure that any default configuration/behavior chooses the safest/most conservative option for customers.

Contributor guide

Open the contributing guide

Research direction

The issue does not name files or tests. Start by reviewing DirectKMSMaterialProvider and the KMS Decrypt keyId behavior, then define an explicitly selected decrypt-key mode that preserves Python/Java API parity and uses the safest default.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.