aws / aws/aws-dynamodb-encryption-python

AwsKmsCryptographicMaterialsProvider Design/Behavior Improvements

未关闭
#176 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
95
派生
57
PR 合并指标
30 天内没有已合并 PR

描述

### Problem:

The correct behavior of the DirectKMSMaterialProvider is to use the configured CMK on encrypt, and to let KMS determine the correct CMK to use on Decrypt (this is a common KMS pattern, as KMS ciphertext stores the CMK used as metadata).

However, this behavior for DirectKMSMaterialProvider is potentially confusing, as customers may expect that the CMK configured on the CMP is also "used" to decrypt, and may be surprised if decryption succeeds even though the configured CMK was not the CMK used to encrypt the data.

### Solution:

Since the original DirectKMSMaterialProvider was designed, KMS has introduced a `keyId` param on Decrypt that ensures the call fails if a different key was used to encrypt the ciphertext.

We should consider either updating or replacing the DirectKMSMaterialProvider to allow enforcing a particular key on decrypt, similar to the Strict vs. Discovery modes expressed by the AWS Encryption SDK's Keyrings and Master Key Providers.

Our new design should:
- maintain API parity between the DDBEC for Python and Java.
- be as simple as possible to reason about.
- minimize possible "modes" for behavior, and ensure that any "mode" needs to be explicitly chosen by customers on config.
- ensure that any default configuration/behavior chooses the safest/most conservative option for customers.

贡献指南

打开贡献指南

调研方向

该 issue 未指定文件或测试。先检查 DirectKMSMaterialProvider 和 KMS Decrypt 的 keyId 行为,然后定义一种显式选择的解密密钥模式,以保持 Python/Java API 的一致性并使用最安全的默认值。

由索引模型根据 Issue 内容生成。

评估

技术栈
aws, python
领域
security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。