How to Create and Use an AWS KMS Key for Encryption in AWS

Table of Contents

Introduction

Security is a critical part of managing workloads in AWS. AWS Key Management Service (AWS KMS) makes it easier to create and manage cryptographic keys that can be used to protect data across AWS services.

AWS KMS Key Creation at a Glance

Create an AWS KMS Key through the AWS KMS console by selecting the key type, configuring administrators and key users, reviewing the key policy, and creating the key. The KMS key can then be used to protect data across supported AWS services.

What is AWS KMS?

AWS Key Management Service (KMS) is a managed service that allows you to create and control cryptographic keys used to protect data. AWS services can use KMS keys to encrypt data at rest, while KMS handles the underlying cryptographic operations and access control.

KMS keys can be used with services such as:

  • Amazon EC2 / EBS
  • Amazon S3
  • Amazon RDS
  • Amazon EFS

Prerequisites

Before creating the KMS key, make sure you have:

  1. An AWS account
  2. Access to the required AWS region
  3. IAM permissions to create and manage KMS keys

Create a KMS Key Using AWS Console

Log in to the AWS Management Console and open:

AWS KMS → Customer managed keys

Click: Create key

Select Key Type

Under Key type, select: Symmetric

Under Key usage, select: Encrypt and decrypt

Then click: Next

Add Key Details

Provide a meaningful alias. For example: alias/prod-data-encryption

Click: Next

Configure Key Administrators

AWS KMS allows you to specify which IAM users or roles can administer the key. Typical administrative permissions include:

  • Enable key
  • Disable key
  • Schedule key deletion
  • Change key policy
  • Configure rotation
  • Manage aliases

Configure Key Users

Next, select the IAM users or roles that should be allowed to use the key. The exact permissions required depend on how the key will be used. For an application that needs encryption and decryption, permissions may include:

kms:Encrypt

kms:Decrypt

kms:GenerateDataKey

kms:DescribeKey

For AWS services, the required permissions can vary depending on the service.

Review the Key Policy

AWS KMS uses a key policy to control access to a KMS key. A simplified example looks like:

{

  “Version”: “2012-10-17”,

  “Statement”: [

    {

      “Sid”: “Enable IAM User Permissions”,

      “Effect”: “Allow”,

      “Principal”: {

        “AWS”: “arn:aws:iam::123456789012:root”

      },

      “Action”: “kms:*”,

      “Resource”: “*”

    }

  ]

}

The root principal in a KMS key policy does not mean that the AWS account root user is the only person who can use the key. It establishes account-level control that can allow IAM policies to grant access. However, KMS policies should be designed carefully according to the principle of least privilege.

Click: Finish

The KMS key is now created.

Find the KMS Key ID

After creating the key, open:

AWS KMS → Customer managed keys

You should see something similar to:

Alias

alias/prod-data-encryption

Key ID

12345678-abcd-1234-abcd-123456789012

Key ARN

arn:aws:kms:ap-south-1:123456789012:key/12345678-abcd-1234-abcd-123456789012

The Key ID or Key ARN can be used when configuring AWS services.

Test the KMS Key

Before attaching the key to production resources, you can verify that it is enabled. Run: 

aws kms describe-key –key-id alias/prod-data-encryption

Look for: “KeyState”: “Enabled”

You can also test encryption directly. Generate a data key:

aws kms generate-data-key –key-id alias/prod-data-encryption –key-spec AES_256

AWS will return an encrypted data key and plaintext data key. Do not store or expose the plaintext data key unnecessarily.

Conclusion

AWS KMS provides a centralized way to manage encryption keys and control access to encrypted data.

A typical implementation involves:

Create KMS Key

       ↓

Create Alias

       ↓

Configure Key Administrators

       ↓

Configure Key Users

       ↓

Configure Key Policy

       ↓

Enable Rotation

       ↓

Attach KMS Key to AWS Resource

       ↓

Test Encryption

       ↓

Monitor Usage with CloudTrail

The important point is that creating a KMS key is only the first step. The key must also be correctly integrated with the AWS service and the IAM/KMS policies must allow the required operations.

Need Help With AWS KMS Configuration?

AWS KMS requires careful configuration of encryption keys, permissions, and key policies. If you need help setting up or managing AWS encryption and security, Skynats can assist with AWS infrastructure management and support.

Explore AWS Cloud Management Services

Picture of Jishnu V

Jishnu V

Jishnu is a Level 2 System Engineer at Skynats Technologies, specializing in Linux server administration, cloud infrastructure, and advanced technical support.

Liked!! Share the post.

Get Support right now!

Start server management with our 24x7 monitoring and active support team

Subscribe and get your first issue fixed for Free!

Looking for server support and 24x7 monitoring?

Have doubts? Connect with us now.