hexcast.
SECURITY

AWS Nitro Enclaves KMS Integration Faces Attack Risks

AWS Nitro Enclaves and KMS integration faces passive and active attack risks. KMS supports attestation-based access for five operations—GenerateDataKey, GenerateDataKeyPair, Decrypt, DeriveSharedSecret, GenerateRandom—not Encrypt. Attacks target enclave-KMS communication and storage. Mitigations: hardcode CMK ARNs, check keyId from responses, specify key IDs in Decrypt, use encryption context, validate key types.

BLOG.TRAILOFBITS.COM · AUG 5