That sense of accomplishment accompanies an added sense of relief, regardless of how long it took to achieve. But…what does this have to do with Bring Your Own Key (BYOK)? Read on.
Along similar lines, Clumio’s Backup as a Service Cloud promised to support the BYOK feature more than 2 years ago! This feature allowed customers to encrypt their backup data using their own encryption key using the Amazon Web Service (AWS) native Key Management Service (KMS) feature.
AWS KMS facilita a los clientes la creación y gestión de claves criptográficas, así como el control de su uso en una amplia gama de servicios de AWS y en sus aplicaciones.
When Clumio added the BYOK feature, it supported VMWare, Microsoft 365 (M365) and AWS EC2/EBS data sources as these were the data sources Clumio supported at that time. However, between then and now, Clumio added additional critical data sources like S3, RDS and DynamoDB.
Now with the most recent release, Clumio has brought BYOK capabilities to all of our critical data sources, and in doing so has achieved the resolution we started long ago. And it doesn’t stop here, as we will continue to invest efforts to bring BYOK to future data sources also.
¿Por qué les importa a los clientes el BYOK?:
Doesn’t Clumio encrypt all backups already, and if yes, why is BYOK needed? It’s true that Clumio does encrypt all the backup data in its cloud with a customer-dedicated key, and that key is also rotated every 30 days. However, in some cases, certain customers have additional stringent security requirements:
Cómo funciona el cifrado:
Las claves de los buckets de AWS S3 han reducido el coste del cifrado del lado del servidor en más del 99 % and don’t need to lookup the key for every single transaction. Since Clumio backs up data with millions of transactions, having to look up the key for every single transaction was a no-go. With AWS’S S3 bucket keys feature, Clumio can use the customers BYOK key as the Amazon S3 Bucket Key and encrypts all the data landing in the S3 bucket using the customers BYOK key.
Cómo activar la función BYOK:
Go to Settings and Security Features – Encryption Key. When you go to the page, Clumio provides details about the feature, along with its requirements and limitations. Customers can proceed by deploying the AWS CloudFormation StackSets inside any one of their AWS accounts where they want to use the BYOK key.
La razón por la que se necesita StackSets es que Clumio tendrá que crear una clave multirregional (global) y utilizarla para cifrar las copias de seguridad en todas las regiones en las que se encuentren las fuentes de datos. Una vez implementado correctamente, los clientes pueden comprobar la conexión en la interfaz de usuario de Clumio accediendo a la página en cualquier momento.

La marca verde de la parte superior de la página indica que todo funciona según lo previsto. Si, por cualquier motivo, no se puede acceder a la clave, la marca cambia a una «X» roja y te permite volver a comprobar el acceso para ver si el problema se ha resuelto y todo vuelve a funcionar correctamente.

How to verify and audit Clumio’s Access
Una de las ventajas de la función BYOK es que los clientes pueden comprobar y auditar en cualquier momento cuándo Clumio ha accedido a su clave. Los clientes pueden consultar los registros de CloudTrail y ver todos los detalles de cada vez que Clumio accede a su clave, incluido el motivo del acceso. Los clientes pueden acceder a la sección «Registros de CloudTrail» de su cuenta de AWS, donde se ha implementado el StackSet de AWS CloudFormation.
En el caso de las claves de los buckets de S3, dado que estas se almacenan en caché por el propio servicio de AWS S3, es posible que no se acceda a ellas en todas y cada una de las transacciones. Sin embargo, en las copias de seguridad de EC2/EBS, VMware y M365 sí se accede a las claves en todas y cada una de las transacciones.

¿Qué ocurre cuando ya no se puede acceder a la clave?:

Remember this: BYOK gives you the power of encrypting all backup data, but on the flip side, if the key is lost, then you’re in big trouble! Luckily, keys in AWS aren’t like physical keys and even if someone deletes them, los clientes siguen disponiendo de 30 días para recuperarlas. Si, por cualquier motivo, no se recuperan las claves, los datos de copia de seguridad quedarían inservibles. Está pensada para funcionar como un mecanismo de seguridad ante fallos, pero hay que tener mucho cuidado al utilizar esta función.