aws / aws/aws-encryption-sdk-java
duplicate requests on CMM cache miss
- Vorherrschende Sprache
- Java
- Sterne
- 240
- Forks
- 125
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### Problem:
While profiling an application we noticed duplicate request for encryption keys and decryption keys, typically after an DEK has just expired
### Solution:
The cause of this was on a miss used by expiration of an encryption DEK or a decryption DEK. In our case both were related to TTL
for a simple example - imaging 10 threads encrypting data, using the same keys. The key expires, and 10 threads, make 10 request to the MasterKey for 10 new encryption DEKs, which causes a little more latency, and cost (if the underlying KMS charges)
I think that the library can easily de-duplicate these requests (maybe as an option). We have done this in our application
Happy to contribute/colaborate on this but will need some steer from the maintainers
### Out of scope:
Is there anything the solution will intentionally NOT address?
[//]: # (NOTE: If you believe this might be a security issue, please email aws-security@amazon.com instead of creating a GitHub issue. For more details, see the AWS Vulnerability Reporting Guide: https://aws.amazon.com/security/vulnerability-reporting/ )
Beitragsleitfaden
Rechercherichtung
Beginne damit, den CMM-Cache-Miss-Pfad rund um den Ablauf von DEK bei Verschlüsselung und Entschlüsselung nachzuverfolgen, einschließlich der Frage, wie Anfragen den MasterKey erreichen. Reproduziere den gemeldeten Fall mit nebenläufigen Threads und abgelaufenen TTLs; als erledigt sollte gelten, dass äquivalente nebenläufige Misses dedupliziert werden, ohne das Verhalten beim Abrufen von Schlüsseln zu ändern, und dass es Leitlinien der Maintainer zum Design der API oder Option gibt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- java
- Bereich
- cryptography, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 35/100