BlogsPineconeCustomer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC)

Customer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC)

Customer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC)

1
posts
2024

Pinecone has introduced Customer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC) with API key roles. CMEK enhances data security and tenant isolation by allowing customers to manage their own encryption keys, providing greater control and supporting compliance requirements. The system utilizes hierarchical encryption with Key Encryption Keys (KEKs) and Data Encryption Keys (DEKs) to maintain performance and security. RBAC with API key roles provides more granular control over access to Pinecone's control and data planes, complementing existing user roles for organizations and projects.

2024

Strengthening security and increasing control with CMEK and API key roles

12/2/2024

This post details the implementation of Customer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC) with API key roles. For CMEK, it explains the architecture involving an encryption service that brokers access to customer-managed KMS keys, hierarchical encryption using KEKs and DEKs, and the key revocation process. For RBAC, it introduces six new roles, three for the control plane and three for the data plane, to enable more granular access control.