That sense of accomplishment accompanies an added sense of relief, regardless of how long it took to achieve. But…what does this have to do with Bring Your Own Key (BYOK)? Read on.
Along similar lines, Clumio’s Backup as a Service Cloud promised to support the BYOK feature more than 2 years ago! This feature allowed customers to encrypt their backup data using their own encryption key using the Amazon Web Service (AWS) native Key Management Service (KMS) feature.
AWS KMS consente ai clienti di creare e gestire facilmente le chiavi crittografiche e di controllarne l’utilizzo in un’ampia gamma di servizi AWS e nelle proprie applicazioni.
When Clumio added the BYOK feature, it supported VMWare, Microsoft 365 (M365) and AWS EC2/EBS data sources as these were the data sources Clumio supported at that time. However, between then and now, Clumio added additional critical data sources like S3, RDS and DynamoDB.
Now with the most recent release, Clumio has brought BYOK capabilities to all of our critical data sources, and in doing so has achieved the resolution we started long ago. And it doesn’t stop here, as we will continue to invest efforts to bring BYOK to future data sources also.
Perché i clienti danno importanza al BYOK:
Doesn’t Clumio encrypt all backups already, and if yes, why is BYOK needed? It’s true that Clumio does encrypt all the backup data in its cloud with a customer-dedicated key, and that key is also rotated every 30 days. However, in some cases, certain customers have additional stringent security requirements:
Come funziona la crittografia:
Le chiavi dei bucket AWS S3 hanno ridotto il costo della crittografia lato server di oltre il 99% and don’t need to lookup the key for every single transaction. Since Clumio backs up data with millions of transactions, having to look up the key for every single transaction was a no-go. With AWS’S S3 bucket keys feature, Clumio can use the customers BYOK key as the Amazon S3 Bucket Key and encrypts all the data landing in the S3 bucket using the customers BYOK key.
Come attivare la funzione BYOK:
Go to Settings and Security Features – Encryption Key. When you go to the page, Clumio provides details about the feature, along with its requirements and limitations. Customers can proceed by deploying the AWS CloudFormation StackSets inside any one of their AWS accounts where they want to use the BYOK key.
StackSets è necessario perché Clumio dovrà creare una chiave multiregione (globale) e utilizzarla per crittografare i backup in tutte le regioni in cui sono presenti le fonti di dati. Una volta completata con successo la distribuzione, i clienti possono verificare la connessione nell’interfaccia utente di Clumio accedendo alla pagina in qualsiasi momento.

Il segno di spunta verde nella parte superiore della pagina indica che tutto funziona come previsto. Se, per qualsiasi motivo, la chiave non fosse accessibile, il segno di spunta si trasforma in una X rossa e ti permette di verificare nuovamente l’accesso per vedere se il problema è stato risolto e se tutto funziona di nuovo.

How to verify and audit Clumio’s Access
Uno dei vantaggi della funzionalità BYOK è che i clienti possono verificare e controllare in qualsiasi momento quando Clumio ha effettuato l’accesso alla loro chiave. I clienti possono consultare i log di CloudTrail e visualizzare tutti i dettagli relativi a ogni accesso effettuato da Clumio alla loro chiave, compreso il motivo dell’accesso. I clienti possono accedere alla sezione “CloudTrail Logs” del proprio account AWS in cui è stato distribuito lo StackSet di AWS CloudFormation.
Per quanto riguarda le chiavi dei bucket S3, poiché queste vengono memorizzate nella cache dai bucket S3 di AWS, l’accesso potrebbe non essere garantito per ogni singola transazione. Tuttavia, per i backup EC2/EBS, VMware e M365, l’accesso alle chiavi avviene per ogni singola transazione.

Cosa succede quando non è più possibile accedere alla chiave:

Remember this: BYOK gives you the power of encrypting all backup data, but on the flip side, if the key is lost, then you’re in big trouble! Luckily, keys in AWS aren’t like physical keys and even if someone deletes them, i clienti avrebbero comunque 30 giorni di tempo per recuperarle. Se, per qualsiasi motivo, le chiavi non venissero recuperate, i dati di backup diventerebbero inutilizzabili. Questa funzionalità è pensata come meccanismo di sicurezza, ma va utilizzata con estrema cautela.