aws / aws/aws-encryption-sdk-java
CMM cache policy on encryption and decryption DEKs
- 主要语言
- Java
- 星标
- 240
- 派生
- 125
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Problem:
While profiling an application I could find latency spikes, relate to decryption
If an application is regularly using a DEK for decryption, it can expire due to its TTL
As I read the code the TTL is set when the key is created. Is seems sensible that the key would expire when not used, but if used frequently why should it expire?
as [ajewellamz](https://github.com/ajewellamz) poned our when I raised this in the wrong project -https://github.com/aws/aws-encryption-sdk/issues/841 https://github.com/aws/aws-encryption-sdk/issues/841#issuecomment-3628451811 it is also experied to ensure correctness, and that the application has access to decrypt
We may have several thousand decryption DEKs in the cache, and regularly in use, and then we see a spike of a many decryption DEKs being regenerated, because they have expired due to TTL, which causes application latency (and some cost)
We have implemented a mechanism to rotate encryption DEKs as we know the limited set of keys in use. Effectively just regenerate the key 10 second before it would expire, but his path doesn't block encryption calls as it doesn't evict from the cache, it just replaces the entry when regenerated - https://github.com/aws/aws-encryption-sdk/issues/840
### Solution:
I think there could be some option to refresh the DEKs before they expire, to keep DEKs that are in use (within some time window), without DEK access causing latency to the calling app
We have some code in our project that does this for the encryption DEKs, which we could export to this library if its useful to others, which I imagine it would be
### Out of scope:
贡献指南
调研方向
首先查看 CMM 缓存策略以及链接的 AWS Encryption SDK issue 840 和 841,以了解现有的 DEK 刷新和过期行为。定义应应用于频繁使用的解密 DEK 的可配置刷新行为,包括其与 TTL 和缓存替换的交互;当策略已完成规范定义,并且其对延迟和正确性的影响已得到涵盖时,即视为完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- aws, java
- 领域
- cryptography, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 30/100