home | tags


key rotation

tags: #crypto #database #expert

During a recent discussion, I was surprised to find that what I thought I knew about database key rotation was not all correct!

background: KEK and DEK

Any bulk data is normally encrypted using a symmetric key which is usually called a Data Encryption Key (DEK). This in turn is protected using another key called a Key Encryption Key (KEK).

Key rotation is a process whereby, in a scheduled manner, you remove an old key and replace it with a new key. Naturally, for a DEK this means you have to decrypt and re-encrypt all the data – something that is generally pretty darn hard to do for most enterprise data sizes (heck I’d have trouble doing that even on all the laptops I’m responsible for at home!)

So my impression was that it was either this untenable/impractical process, or just rotate the KEK and be done.

various DBs take the shortcut!

Spurred by some discussion at work, I went digging. At first everything I found corroborated the more relaxed “rotate the KEK only” school of thought. The threat model here seems to be:

Some example links for the “relaxed” mode:

PCI-DSS takes the high road!

There was literally only one site I found which said something different. PCI-DSS Key Rotation requirements basically say you have to rotate the DEK, not just rotate the KEK and “call it a day” :)

The reasons given are:

The process it outlines is quite complex, but it is much more scalable than “decrypt and re-encrypt all your data”:

Of course, it’s kinda hard to imagine how this would work in practice – it certainly won’t work with what databases call “Transparent Data Encryption” – which can (I think) use only one key. Think of your hard disk encryption – you can’t say “all files created after today will now use a different key”.

Thus, it is almost certainly something that the database has to explicitly support, perhaps using “row level security” or something similar. And the bookkeeping associated with mixing records with different keys is likely to be horrendous, and almost certainly error-prone and requiring rigorous testing.

But for some people, it may be cheaper than the alternative!

my take

I find myself not completely agreeing with the reasons that PCI-DSS outlines. Perhaps for really large sites it makes a difference, but I think cryptanalytic methods are easier said than done, and I really think protecting the DEK is not that hard (on a proper system).

The best I will say is that, sure if you can rotate the DEK, by all means go ahead, but you and your threat model have to decide if it’s worth it or not.