Skip to content
Clumio

Enhancing Clumio’s Bring Your Own Key (BYOK) Feature

Don’t you love the beginning of the year when you come up with a resolution that gives a surge of motivation to achieve? But as new priorities emerge, your determined sprint inevitably becomes a leisurely walk. So long as you periodically remind yourself why you made the resolution in the first place, even slow progress will eventually get you to your goal.


That sense of accomplishment accompanies an added sense of relief, regardless of how long it took to achieve. But…what does this have to do with Bring Your Own Key (BYOK)? Read on.

Along similar lines, Clumio’s Backup as a Service Cloud promised to support the BYOK feature more than 2 years ago! This feature allowed customers to encrypt their backup data using their own encryption key using the Amazon Web Service (AWS) native Key Management Service (KMS) feature.

Mit AWS KMS können Kunden auf einfache Weise kryptografische Schlüssel erstellen und verwalten sowie deren Verwendung in einer Vielzahl von AWS-Diensten und in ihren Anwendungen steuern.

When Clumio added the BYOK feature, it supported VMWare, Microsoft 365 (M365) and AWS EC2/EBS data sources as these were the data sources Clumio supported at that time. However, between then and now, Clumio added additional critical data sources like S3, RDS and DynamoDB.

Now with the most recent release, Clumio has brought BYOK capabilities to all of our critical data sources, and in doing so has achieved the resolution we started long ago. And it doesn’t stop here, as we will continue to invest efforts to bring BYOK to future data sources also.

Warum ist BYOK für Kunden wichtig:

Doesn’t Clumio encrypt all backups already, and if yes, why is BYOK needed? It’s true that Clumio does encrypt all the backup data in its cloud with a customer-dedicated key, and that key is also rotated every 30 days. However, in some cases, certain customers have additional stringent security requirements:

So funktioniert die Verschlüsselung:

AWS-S3-Bucket-Schlüssel haben die Kosten für die serverseitige Verschlüsselung um mehr als 99 % gesenkt and don’t need to lookup the key for every single transaction. Since Clumio backs up data with millions of transactions, having to look up the key for every single transaction was a no-go. With AWS’S S3 bucket keys feature, Clumio can use the customers BYOK key as the Amazon S3 Bucket Key and encrypts all the data landing in the S3 bucket using the customers BYOK key.

So aktivieren Sie die BYOK-Features:

Go to Settings and Security Features – Encryption Key. When you go to the page, Clumio provides details about the feature, along with its requirements and limitations. Customers can proceed by deploying the AWS CloudFormation StackSets inside any one of their AWS accounts where they want to use the BYOK key.

StackSets wird benötigt, da Clumio einen regionenübergreifenden (globalen) Schlüssel erstellen und diesen zur Verschlüsselung von Backups in allen Regionen verwenden muss, in denen sich die Datenquellen befinden. Nach erfolgreicher Bereitstellung können Kunden die Verbindung jederzeit in der Clumio-Benutzeroberfläche überprüfen, indem sie die entsprechende Seite aufrufen.

Das grüne Häkchen oben auf der Seite zeigt an, dass alles wie erwartet funktioniert. Sollte der Schlüssel aus irgendeinem Grund nicht zugänglich sein, verwandelt es sich in ein rotes X und Sie können den Zugriff erneut überprüfen, um festzustellen, ob das Problem behoben wurde und alles wieder funktioniert.

Screenshot of Clumio Encryption Key - Check Access

How to verify and audit Clumio’s Access

Einer der Vorteile der BYOK-Funktion besteht darin, dass Kunden jederzeit überprüfen und nachverfolgen können, wann Clumio auf ihren Schlüssel zugegriffen hat. Kunden können in den CloudTrail-Protokollen alle Details zu jedem Zugriff von Clumio auf ihren Schlüssel einsehen, einschließlich des Grundes für den Zugriff. Kunden können den Abschnitt „CloudTrail-Protokolle“ in ihrem AWS-Konto aufrufen, in dem das AWS CloudFormation StackSet bereitgestellt wurde.

Da die S3-Bucket-Schlüssel von den AWS S3-Bucket-Schlüsseln zwischengespeichert werden, ist der Zugriff darauf möglicherweise nicht bei jeder einzelnen Transaktion gegeben. Bei EC2/EBS-, VMware- und M365-Backups wird jedoch bei jeder einzelnen Transaktion auf die Schlüssel zugegriffen.

Screenshot of the CloudTrail logs

Was passiert, wenn der Schlüssel nicht mehr verfügbar ist:


Remember this: BYOK gives you the power of encrypting all backup data, but on the flip side, if the key is lost, then you’re in big trouble! Luckily, keys in AWS aren’t like physical keys and even if someone deletes them, haben Kunden noch 30 Tage Zeit, sie wiederherzustellen. Sollten die Schlüssel aus welchem Grund auch immer nicht wiederhergestellt werden, wären die Sicherungsdaten unbrauchbar. Diese Funktion ist als Ausfallsicherheitsmechanismus gedacht, sollte jedoch mit großer Sorgfalt eingesetzt werden.

More related posts


Thumbnail_Blog-Tabletop-Exercise-2026

SaaS Matters – Enterprise Support Made Possible by Clumio

Read more about SaaS Matters – Enterprise Support Made Possible by Clumio
Thumbnail_Blog-QTFY-Advisory-2026

The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.

Read more about The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.
Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio