> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Encryption and Decryption Using KMS

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/encryption-and-decryption-using-kms" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Lab Details

This lab walks you through the steps to encrypt and decrypt and re-encrypt the data.
Duration: **1 Hour**
AWS Region: **US East (N. Virginia)**

#### Introduction

#### What is KMS ?

AWS Key Management Service (KMS) is a pivotal component of Amazon Web Services' security infrastructure, providing a managed service designed to simplify the creation and management of encryption keys. Encryption is a crucial aspect of data security, especially when it comes to protecting data at rest. AWS KMS seamlessly integrates with various AWS services, such as EBS, S3, Redshift, Elastic Transcoder, and Amazon relational databases, facilitating easy encryption of data using keys managed by the service.

**Case Study:**

In scenarios where safeguarding data is paramount, AWS KMS offers a fully managed key management infrastructure. The selection of reliable key sources becomes critical during processes like encrypting data at rest and performing server-side encryption. AWS KMS addresses this by storing customer master keys, which can directly perform encryption or generate unique symmetric data keys. These data keys, whether 128 or 256 bits, are encrypted using the customer master key.

#### Key Functions of AWS KMS:

* **Storage of Customer Master Keys:** KMS stores customer master keys, enabling direct encryption or generation of data keys.
* **Hardware Security Modules:** All encryption and key generation are performed within hardware security modules, ensuring high security standards validated against FIPS 140-2.
* **Multi-Tenant API:** KMS acts as a multi-tenant API in front of HSMs, with customers interacting through the KMS API, while AWS maintains exclusive access to the hardware.
* **Logging and Compliance:** KMS logs key usage to CloudTrail, aiding in compliance requirements and facilitating audits to track key usage.
* **Cryptographic Material Protection:** The cryptographic material constituting the customer master key remains within the HSM, enhancing the overall security of KMS.
* **Integration with AWS Services:** KMS seamlessly integrates with various AWS services that perform server-side encryption, allowing them to retrieve data keys from KMS.
* **Certifications:** AWS KMS is certified against stringent controls including SOC1, SOC2, SOC3, and PCI DDS level 1, ensuring a high level of security compliance.

AWS KMS serves as a robust and versatile solution for managing encryption keys, providing a secure foundation for protecting sensitive data within the AWS ecosystem.

### Architecture Diagram

### Lab Tasks

1. Sign in to AWS Management Console
2. Create a group for KMS users and attach a policy to the group.
3. Create 2 users for managing the KMS.
4. Creating a KMS Key
5. Launch an EC2 instance.
6. SSH into EC2 Instance
7. Perform KMS Encryption and Decryption.

### Launching Lab Environment

1. To launch the lab environment, Click on the **Start Lab** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Lab is started, you will be provided with **IAM user name, Password, Access Key, and Secret Access Key.**

> **Note** : You can only start one lab at any given time

## Lab guide

### Lab Steps

#### Task 1: Sign in to AWS Management Console

1. Click on the **Open Console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

   * Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
   * Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.
3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

#### Task 2: Create a User group for KMS users and attach a Policy to the Group

1. Make sure to choose **N.Virginia** region in the AWS Management console dashboard, which is present in the top right corner.

2. Navigate to the **Services** menu at the top, click on **IAM** in the **Security, Idenitity, & Compliance** section.

3. In the IAM section, click on **IAM** **User groups**.

4. Click on **Create group**

* Enter the following **user group name**  :

  ```
  KMSGroup
  ```
* **Attach permissions policies:** For the Policy name type **KMS** and select **ROSAKMSProviderPolicy**

  <img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/001.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=98995042d74812898693e020af4f2a15" alt="" width="2284" height="448" data-path="images/labs/encryption-and-decryption-using-kms/001.png" />

5. Now, Click on **Create Group** button.
6. We have successfully created a new group for our KMS lab.

##### Task 3: Create two users for managing the KMS

In this task, We are going to add two users to the group we created.

1. Click on **Users** on the left side of the IAM dashboard.
2. Click on the **Create User** button.
3. Enter the following **user name** **:**

KeyManager

4. Check **Provide user access to the AWS Management Console** checkbox.

5. Click on the **Custom password.**

6. Give the following **password:**

whizlabs\@123

7. Uncheck **the Users must create a new password at the next sign-in**. Click on **Next.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/002.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=3a4ba440bb0ac8f49d758848ab67eac4" alt="" width="1494" height="727" data-path="images/labs/encryption-and-decryption-using-kms/002.png" />

8. For permission, select **Add User to group** .

9. Select the **KMSGroup** that we created, and click on the **Next** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/003.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=010b0e0793bd8dfdb2728b107c955b3a" alt="" width="1502" height="639" data-path="images/labs/encryption-and-decryption-using-kms/003.png" />

10. In the review section, if all the settings are as per the requirement.

11. Click on **Create User.**

12. We have successfully created our **KeyManager.** Click on **Return to users list** button and click again on **Continue** button to return back to Users tab.

* Now similarly we're going to create a new user and this will be the person who does the decryption.

1. Click on **Users** on the left side of the IAM dashboard.
2. Click on the **Create User** button.
3. Enter the following **user name** **:**

KeyEncryption

4. Check **Provide user access to the AWS Management Console** checkbox.

5. Click on the **Custom password**

6. Give the following **password:**

123\@whizlabs

7. Uncheck **the Users must create a new password at the next sign-in**. Click on **Next.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/004.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=242b5d5d01434367b2a7e1e42900d4af" alt="" width="1500" height="731" data-path="images/labs/encryption-and-decryption-using-kms/004.png" />

8. For permission, select **Add User to group** .

9. Select the **KMSGroup** that we created, and click on the **Next** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/005.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=b33e5b185209d7cc273d7cf1e2368bb5" alt="" width="1502" height="639" data-path="images/labs/encryption-and-decryption-using-kms/005.png" />

10. In the review section, if all the settings are as per the requirement

11. Click on **Create User.** Click on **Return to users list** button and click again on **Continue** button to return back to Users tab.

Now, to get Access Key and Secret Access Key

1. Click on **Users** on the left side of the IAM dashboard.
2. Click on **KeyEncryption** user and go to the **Security credentials** tab.
3. Scroll down and click on **Create access key** button.
4. Select Use case as **Command Line Interface (CLI)**, check the confirmation box and click on **Next** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/006.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=19fc37845bdcec1dffa15d0fd550a707" alt="" width="1258" height="791" data-path="images/labs/encryption-and-decryption-using-kms/006.png" />
5. Leave **Description tag value** as blank in **Set description tag** step.
6. Click on **Create access key** button.
7. Click on **Download .csv file** button to download the secret access key of the user as it will be required to connect with our EC2 instance for encryption.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/007.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=c84e33ea78ee9d6607abf4a3fe4374f0" alt="" width="1246" height="505" data-path="images/labs/encryption-and-decryption-using-kms/007.png" />

   ?

##### Task 4 : Creating a KMS Key

1. Navigate to the **Services** menu at the top, click on **AWS Key Management Service (KMS)** in the **Security, Identity, & Compliance** section
2. Click on the **Create a key** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/008.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=01277a6c2ff134f6ce1b37bcd9b714b9" alt="" width="1059" height="365" data-path="images/labs/encryption-and-decryption-using-kms/008.png" />
3. Select Key type as **Symmetric** and Key usage as **Encrypt and decrypt,** click on **next** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/009.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=6fc3a46ac57b76eec8900e170dc1a53b" alt="" width="1602" height="938" data-path="images/labs/encryption-and-decryption-using-kms/009.png" />

4. Enter Alias as :

Admin

5. Leave the other field as it is, and click on the **Next** button.

6. In **Define key administrative permissions** select **KeyManager** and click on **Next** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/010.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=2bde9915d05cee4bb0413935480964e7" alt="" width="1664" height="728" data-path="images/labs/encryption-and-decryption-using-kms/010.png" />

7. In **Define key usage permissions** select **KeyEncryption** and click on **Next** button.

8. Once you click on Next you’ll be moved to the review section. Review the key policy that we have created and if everything is fine, just click on **Finish** button.

9. We have successfully created the KMS key. **Copy** the **Key ID** in Notepad for future use.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/011.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=86263fb44b7be7b612e27aff3c1fec53" alt="" width="1600" height="257" data-path="images/labs/encryption-and-decryption-using-kms/011.png" />

10. Now that we have created the KMS and User policies, move to the **service** section and choose **EC2** under the Compute section.

**Note :** Don't forget to save the created KMS key id into any text editor for further use.

#### Task 5 : Launching an EC2 Instance

1. Make sure you are in **N.Virginia** Region.
2. Navigate to the **Services** menu at the top, click on **EC2** in the **Compute** section.
3. Click on **Launch Instance**
4. Enter Name as following: **MyEC2Server**
5. For AMI Select **Amazon Linux 2023** in the quickstart menu.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/012.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=9b0281821a0d87ce34cd477b64543c6f" alt="" width="927" height="459" data-path="images/labs/encryption-and-decryption-using-kms/012.png" />

6. For **Instance Type**: Select **t2.micro.**
7. For **Key pair(login)**: Select **Create a new key pair** Button

   * Key pair name: **WhizKey**
   * Key pair type: **RSA**
   * Private key file format: **.pem**
8. Keep all the settings as default and click on the **Launch instance** button.
9. Click on **View all instances** button.
10. Your instance is now launching, wait for the complete initialization of the instance till the Status check changes to **2/2 checks passed**

    <img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/013.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=325346ee5bf718965f357e1039768b41" alt="" width="1612" height="159" data-path="images/labs/encryption-and-decryption-using-kms/013.png" />

#### Task 6: SSH into the EC2 Instance

* Please follow the steps in [**SSH into EC2 Instance**](https://play.whizlabs.com/site/task_support/ssh-into-ec-instance)**.**

#### Task 7 : Perform KMS Encryption and Decryption

1. Once you click on connect you get a terminal which is our EC2-user login on EC2-instance. Here we will perform KMS Encryption and Decryption.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/014.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=f05a6328544d6608d50a812125f55718" alt="" width="613" height="199" data-path="images/labs/encryption-and-decryption-using-kms/014.png" />
2. First we need to **create a file** with the name **secret.txt** , Execute the command.

echo “Welcome to Whizlab” > secret.txt

3. Now that we have created a file secret.txt we need to **execute** the following **configuration** command.

aws configure

4. Enter the **AWS Access key ID** and **AWS Secret Access Key** from the user **KeyEncryption** **file** that you **downloaded in task 3.**

5. Enter default region as **us-east-1**

6. Leave the default output as blank and press **Enter**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/015.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=c1475210319f6d06814f83c3bed05ed5" alt="" width="638" height="116" data-path="images/labs/encryption-and-decryption-using-kms/015.png" />

7. Once AWS configure is complete, we need to execute the command for encryption.

8. Run the following command to **encrypt text** file but first replace **\<replace-key-id>** with the **Key ID copied** earlier.

aws kms encrypt --key-id \<replace-key-id> --plaintext fileb://secret.txt --output text --query CiphertextBlob | base64 --decode > encryptedsecret.txt

**Note:** The following command encrypts data from the **"secret.txt"** file using AWS Key Management Service (KMS). It specifies the encryption key **(--key-id)**, reads plaintext from the file in binary mode **(--plaintext)**, and retrieves the base64-encoded ciphertext **(--output text --query CiphertextBlob)**. The subsequent Unix shell command decodes the ciphertext and saves the binary data in **"encryptedsecret.txt"**. This process ensures secure encryption using AWS KMS.

10. We have successfully encrypted our text file. To view the statement, execute

cat encryptedsecret.txt

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/016.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=01100f087672f3480791578e05b5fe22" alt="" width="910" height="88" data-path="images/labs/encryption-and-decryption-using-kms/016.png" />

11. We are going to decrypt the encrypted file to view the data.

aws kms decrypt --ciphertext-blob fileb://encryptedsecret.txt --output text --query Plaintext | base64 --decode > decryptedsecret.txt

**Note:** The following command decrypts data from the **"encryptedsecret.txt"** file using AWS Key Management Service (KMS). It takes the base64-encoded ciphertext from the file **(--ciphertext-blob fileb://encryptedsecret.txt)**, and the **--output text --query Plaintext** flags specify that the output should be in plain text, querying and retrieving the plaintext. The Unix shell command then decodes the **base64-encoded** plaintext and saves the resulting binary data in **"decryptedsecret.txt".** This process ensures secure decryption of previously encrypted data using AWS KMS.

12. We have successfully decrypted our text file . To view the statement execute.

cat decryptedsecret.txt

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/017.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=5772560590f508c3bac60e20454d260c" alt="" width="494" height="61" data-path="images/labs/encryption-and-decryption-using-kms/017.png" />

13. Run the following command to **re-encrypt text** file but first replace **\<replace-key-id>** with the **Key ID copied** earlier.

aws kms encrypt --key-id \<replace-key-id> --plaintext fileb://decryptedsecret.txt --output text --query CiphertextBlob > newencryptedsecret.txt

14. You can check the created files by using command :

ls -lrt

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/018.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=03b0e12a87fc688a64df606e9722fb63" alt="" width="652" height="130" data-path="images/labs/encryption-and-decryption-using-kms/018.png" />

15. We have successfully encrypted our text file . To view the statement execute

cat newencryptedsecret.txt

<img src="https://mintcdn.com/ip-cloud-architect-pathway/4J_NjyMeVcLG0gf_/images/labs/encryption-and-decryption-using-kms/019.png?fit=max&auto=format&n=4J_NjyMeVcLG0gf_&q=85&s=af2be5a0b712ced7b480477404784348" alt="" width="862" height="87" data-path="images/labs/encryption-and-decryption-using-kms/019.png" />

16. We have successfully executed the **re-encrypt** statement.

**Note:** The following command is an AWS CLI command used to **enable key rotation** for a specified AWS Key Management Service (KMS) key. The **--key-id \<replace-key-id>** flag identifies the key to which rotation is applied. Enabling key rotation is a security best practice, ensuring that cryptographic keys used for encryption are regularly rotated to enhance overall security. This command, when executed, activates the automatic rotation of the specified KMS key, helping to mitigate potential risks associated with long-term key usage.

> ### Do You Know?
>
> KMS enforces access control policies to ensure that only authorized individuals or systems can use or manage cryptographic keys. This helps prevent unauthorized access to sensitive information.

1. Once the lab steps are completed, please click on the **Validation** button on the left side panel.

### Completion and Conclusion

1. You have successfully created a group for KMS users and attached a policy to the group.
2. You have successfully created 2 users for managing the KMS.
3. You have successfully created a KMS Key.
4. You have successfully launched an EC2 Instance and connected to SSH using the browser.
5. You have successfully configured KMS.
6. You have become familiar with Encryption, decryption, re-encryption.

### End Lab

1. Sign out of AWS Account.
2. You have successfully completed the lab.
3. Once you have completed the steps, click on **End Lab** from your IP Lab Portal and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create Private S3 bucket** — Check whether a private S3 bucket is created or not
* **Create an Amazon SNS Topic** — Check If SNS Topic created or not
* **AWS config rule** — check whether AWS config rule is created or not

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.