Skip to main navigation Skip to search Skip to main content

A machine-checked proof of security for AWS key management service

  • José Bacelar Almeida
  • , Matthew Campagna
  • , Vitor Pereira
  • , Manuel Barbosa
  • , Ernie Cohen
  • , Bernardo Portela
  • , Serdar Tasiran
  • , Gilles Barthe
  • , Benjamin Gregoire
  • , Pierre Yves Strub
  • Universidade de Minho
  • Amazon Machine Learning Solutions Lab
  • University of Porto
  • IMDEA Software Institute
  • INRIA

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We present a machine-checked proof of security for the domain management protocol of Amazon Web Services' KMS (Key Management Service) a critical security service used throughout AWS and by AWS customers. Domain management is at the core of AWS KMS; it governs the top-level keys that anchor the security of encryption services at AWS. We show that the protocol securely implements an ideal distributed encryption mechanism under standard cryptographic assumptions. The proof is machine-checked in the EasyCrypt proof assistant and is the largest EasyCrypt development to date.

Original languageEnglish
Title of host publicationCCS 2019 - Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages63-78
Number of pages16
ISBN (Electronic)9781450367479
DOIs
Publication statusPublished - 6 Nov 2019
Event26th ACM SIGSAC Conference on Computer and Communications Security, CCS 2019 - London, United Kingdom
Duration: 11 Nov 201915 Nov 2019

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference26th ACM SIGSAC Conference on Computer and Communications Security, CCS 2019
Country/TerritoryUnited Kingdom
CityLondon
Period11/11/1915/11/19

Keywords

  • Key Management
  • Machine-Checked Proof
  • Provable-Security

Fingerprint

Dive into the research topics of 'A machine-checked proof of security for AWS key management service'. Together they form a unique fingerprint.

Cite this