BlogsElasticBring Your Own Key (BYOK) for Encryption at Rest

Bring Your Own Key (BYOK) for Encryption at Rest

Bring Your Own Key (BYOK) for Encryption at Rest

4
posts
2024

Elastic Cloud now supports Bring Your Own Key (BYOK) for encryption at rest with AWS KMS and Azure Key Vault, allowing users to leverage their own keys to encrypt data and snapshots stored within Elastic Cloud deployments. This enhances data security and control, with features for key rotation and revocation.

2024

Encryption at rest in Elastic Cloud: Bring your own key with Google Cloud

9/25/2024

This post details the technical steps and considerations for integrating Elastic Cloud with Google Cloud KMS for Bring Your Own Key (BYOK) encryption at rest. It covers the architecture of the integration, prerequisites including Google Cloud IAM permissions and Elastic Enterprise license, the process of creating and configuring a Google Cloud KMS key, granting specific roles (Cloud KMS CryptoKey Encrypter/Decrypter, Cloud KMS Viewer) to Elastic service accounts, and completing the Elastic Cloud deployment creation with the Google Cloud Key resource name. It also outlines verification steps and discusses key rotation and revocation management within Google Cloud KMS and its impact on Elastic Cloud.

Implement encryption at rest with Azure Key Vault and Elastic Cloud

8/20/2024

This post details the technical implementation of BYOK for encryption at rest specifically for Elastic Cloud deployments on Microsoft Azure, using Azure Key Vault. It outlines the architecture, prerequisites (Enterprise subscription, RSA key creation in Azure Key Vault, IAM policies), the step-by-step process of creating an Azure Key Vault key and configuring it with an Elastic Cloud deployment, and verification methods. It also touches upon key rotation and revocation within the Azure Key Vault context.

Encryption at rest in Elastic Cloud: Bring your own key with AWS KMS

8/1/2024

This post details the technical implementation of BYOK for encryption at rest in Elastic Cloud using AWS KMS. It covers the architecture of the integration, prerequisites including KMS key creation (symmetric/multi-region, KMS/External/XKS origins) and Enterprise subscription level, the step-by-step process of creating an AWS KMS key and configuring its policy to grant Elastic access, and the integration of this key into an Elastic Cloud deployment. It also outlines verification steps and discusses key rotation and revocation mechanisms.

Elastic Platform 8.14: ES|QL GA, encryption at rest & vector search optimizations

6/5/2024

This post announces the general availability of encryption at rest using customer-managed keys from AWS KMS for Elastic Cloud deployments. It details the ability to leverage AWS KMS keys for encrypting deployment data and snapshots, including features for key rotation and revocation, expanding on the existing BYOK support for Azure Key Vault.