ݺߣ

ݺߣShare a Scribd company logo
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
? ? ?
AWS Korea / Solutions Architect
AWS KMS? ???? ???
AWS ??? ???? ??
??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??
AWS ??? ??
? ?? ? ??? ???
? ?? ? ??? ???
KMS ?? ????
? Infrastructure ??
? IAM ??
? ?? ?? ??
? ??? ?? ??
? ?? ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ??? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??????? ???
???? ??:
? ?? ??? ??
? ?? ????? ??? ??
? ???? ?????? ? ???? ???? ??
? ???? ???? ?? ???? ?? ? ???? ???? ??
IT ?? ??
? ??
?? ??
????? ??? ?? ???
?? ? ??
??? ??
??? ???
?? ??? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ???? ???? ?? ??? ??
??? ??
? ??? ??
? ???? ?? ?? C ??? ??
??? ??, TLS, IPsec
? ??/?? ?? - AWS Snowball
? ??? ??
? ??? ?? ??? ????
? ?? ??? C ??? ??, ??,
????, ?? ???, ?? ???
? ??? ??
? ??? ?? ??? ???? - CCTV
??? ??
? ??? ??
? ???? ???? C VPC, Security
Groups, NACL ?
? ?? ??? C TLS, IPsec
? ??? ??
? ??? ???? ?? ??? ?? ??
? ??? ??? C ?? ???? ??
??? ??, ??, ????, ?? ???,
?? ??? ???
? ??? ??
? ???? ?? ??? ???? C FIPS
140-2 ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ? ??? ???
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??? ??? ? ???? ?? TLS??
??? ?? ??? ???? ????? ??:
Amazon EC2? ???? ?? ????????
Elastic Load Balancing (CLB/ALB) ???
Amazon CloudFront ???
Amazon API Gateway ???
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS Certificate Manager (ACM)
? ??? AWS ????? ?? TLS??? ??:
? Elastic Load Balancing (CLB/ALB)
? Amazon CloudFront
? Amazon API Gateway
? AWS Elastic Beanstalk
??? ??/??/??/?? ??? AWS? ???
? ? ??? ???? ?? ?? ?? ??
? ??? ??? ? ??? ?? ??
? ??? ??? ?? ??
DNS ?? ? ??? ??? ?? ??? ??(DV)
Transparency Log ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ACM Private Certificate Authority
?? SSL/TLS ??? ????(CA)? ????? ??
? ?? ??? ???, API G/W, SSL VPN, IoT ?? ?
???? ??? ????
? RSA 2048 / RSA 4096 / ECDSA P256 / ECDSA P384
??? ???? PKI ??? AWS? ???
? ??CA ???? ???? ??
? ???? ??? ??(FIPS 140-2 Level 3? ???? HSM)
? ??? ?? ??(CRL)?? ??
?? ??
? N. Virginia, Ohio, Oregon, Singapore, Sydney, Tokyo, Canada, Frankfurt, Ireland
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
TLS? ? ???? ?? C S2N
? ?? ?? ??? ?? ??? ?? AWS? ??? TLS ?????
? SSL v3 / TLS 1.0 / TLS 1.1 / TLS 1.2
? ?? ???? ?? TLS ??? ??(extension) ??? ??; ~6,000 ??
??? ??
? ??? AWS?????? ?????, ?? ??? ??
https://github.com/awslabs/s2n
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Virtual Private Networking
AWS ??? VPN
??? VPC? ?? ??? ???? IPsec ?? VPN?? ??.
AWS VPN CloudHub
??? VPC? ???? ??? ???? IPsec ???? ???? ?? VPN ??.
??? ?? ????? ?? VPN
EC2??? VPN S/W? ???? ??? ???? ??.
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ? ??? ???
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??? ??? ??? ??
??
???
???? /
?????
????
???
?????
??? ??
????
??? ?
??? ?
(???)
??? ???? ?
(???)
? ?? ??
? ????
?
?? ???(Envelop Encryption)
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS?? ??? ???? ???? 2?? ??
????? ? ???(Client-Side Encryption)
? ???? ???? ?? ??? ??
? ??? ?? ??? ?? ???? ?? ?????, AWS KMS/CloudHSM??
?? ??
? ???: AWS Encryption SDK, S3 Encryption Client, EMRFS Client, DynamoDB
Encryption Client
?? ? ???(Server-Side Encryption)
? AWS? ??? ???? ?? ?? ?? ?? ??? ??? ?? ??
? ? 34 ? ??? ?? : Amazon S3, Amazon EBS, Amazon RDS, Amazon Redshift,
Amazon WorkSpaces, Amazon Kinesis Streams, AWS CloudTrail
? ?? ?? ?? ?? AWS KMS? ??? ? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
????? ? ???(Client-Side Encryption)
A W S E n c r y p t i o n S D K , S 3 / E M R F S / D y n a m o D B c l i e n t s , c u s t o m e r - s u p p l i e d
?? IDC?
??
??????
EC2?? ??
??? ???
??? ?? ?????
??? ??? ??? EC2?? ??
??????
AWS??? ?? ???? ???
AWS
KMS
AWS
CloudHSM
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS Encryption SDK
??? ????, ???? ?? 2?? ??? ??:
? ??? ? ???/??/??????
? ??? ??? ???? ??? ? ???(key provider)
SDK? ??? ???? ???????? ??
? ?? ???? ???? ?? ???? ???
? ???? ?? KMS Limit? ???? ?? ??? ? ?? ??? ???? KMS?? ???
??
?? Java, Python, CLI ?? ??
http://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/introduction.html
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ? ???(Server-Side Encryption)
2?? ? ??? ?? ???(envelope
encryption)
? ???? ?????? ???? ??? ?
? KMS ??? ?? ?? ??? ?? ???
??
? ??? ?? ?? ?? ??
? ??? ??? ???? ?? ?? ??
? ??? ??? ???? ?? ?? ??
??? ?? ?? ????? ???
? ? ?? ??? ?? ?? ??? ?????
??
CMK(?? ??? ?)
????1
S3 ?? EBS ??
Amazon
Redshift
????
????2 ????3 ????4
??
??????
KMS
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS KMS? ? ???? ??
KMS? ??
KMS ??? ??? ?
? ?? ?? ?? HSA(Hardened Security Appliances)?
CMK? ????? ?? ??? ??? ??? ?? ??.
? ?? ??? ??? ?? ?? CMK? ? ???.
????
Keys on HSAs in a Region
??? ?(CMK)
? 256-bit ????, HSA? ????? ??? ???? Import?.
? ???? ?? KMS??? ???? Copy? ????, ???
? ??? ?, ?? CMK? ??? HSA ??? ??? ???.
????
??? ?(CMK)
??? ?
? 256-bit ????, ??? ?/???? ???
? AWS???/?? ???????? ???? ??? ?? ???
?? ???? ???.
??? ?
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CMK(??? ?) ??
AWS ??? CMK ?? ??? CMK
?? AWS??? ???? KMS? ???
AWS??? ? 1?
AWS??? ???? KMS? ??? AWS??? ?
???
?? AWS? ?? ??? ?? ????? ???
?? ? 3? ?? ???? ?? 1?? ???? ?? ?? ?? ???? ?? ??
?? ?? ?? ?? ??
?? ?? ?? AWS ???? ??? CMK / IAM ??? ?? ?? ??
Key ?? AWS? ?? ??? ??
??? ?? IAM ???? ?? IAM ???? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ????? KMS? ???? ??
EC2/EBS ??
? EBS ?? ?? ??? ?? ????, CMK? ???? ? ?? ?????? ??
? ??? EBS???? EC2? ?? ?? ??, ?? EBS??? ?????? ???? ??
??? ?? ??????? ??? ??? ?? ??  ??, I/O, ???? ???
? ?? ???: EBS, RDS, Redshift, WorkSpaces, Amazon Lightsail
S3 ??
? S3? 3?? ?? ? ??? ? SSE-KMS ??
? ?? ?? ??? ?? ????, CMK? ???? ?, ?? ?????? ??
? ??? ?? ???? S3 ???? ??? ??? ??? ???? ?? ??? ?? ?? ?
?? ???.
? ????? Get??? ?? S3? KMS??? ???? ??? ?? CMK? ???? ???
????, ???? ??? ?? ??? ?? ??? ??? ? ?, ?? ? ???.
? ?? ???: S3, EMR, CloudTrail, Amazon Athena, Amazon Kinesis, Amazon SQS,
Amazon CloudWatch
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??? ?? CMK(??? ?) ????? ??
??? ?? CMK ?? ??? ?? ????? ? ??(CMK Policy)??
??
? ?? ??:
? <??? ????>? <??? ???? Role>?? ?/??? ??
? ?????? A??? ???? ?????, ?????? B??? ? ????
???? ? ??.
? ??? ?? ?? ?? Role? ?? ?????.
? <??? ????>?? ?/??? ??? ??? ? ???, ??
????(??/??/????/?? ?)? ??.
AWS Identity and Access Management? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CloudTrail?? CMK(??? ?) ????
"EventName":"DecryptResult", ??? API
"EventTiime":"2014-08-18T18:13:07Z", .??? ??
"RequestParameters":
"{"keyId":"2b42x363-1911-4e3a-8321-6b67329025ex}, ??? ?? ?? ??
EncryptionContext":"volumeid-12345", ?? ??? AWS ???
"SourceIPAddress":" 203.0.113.113", ???? IP??
"UserIdentity":
{"arn":"arn:aws:iam:: 111122223333:user/User123} ???? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ????? ???
Amazon EBS
Amazon RDS
Amazon Redshift
Amazon S3
Amazon Glacier
?? ? ???
AWS
CloudTrail
IAM
??
?? ??
??? ?? ??????
?? ? ???
KMS? ??
?? ???
???
???? ?
?? ???
???
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
KMS ?? ????
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS Cloud Adoption Framework
5 ?? ?? ?? ??
??? ??
??? ? ?? ??
?? ??
??? ??
?? ??
??? ? ?? ? ??? ??
??? ? ?? ??? ??
????? ?? ?? ?? ?? ?? ??
??? ?? ?? ?? ?? ???
? ?? ???? ?? ???? ?? ? ??
???? ??? ???
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Infrastructure ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
KMS? ??? ?? ??
KMS HSA? ??? ??? ?:
? AWS ???? ?? ???? ?? ???.
? ??? ????? ????/??? ?? ??.
HSA? reboot??? ? ???? ??:
? ??? ?? ? ???? ?? ??? ??.
? ????? ????/?? ?? ??:
? ??? AWS???? ??? ??? ???.
? ??? ???? ??? ????? ??? ???? ??? ???.
3rd Party??
? SOC 1 C Control 4.5: KMS?? ??? ??? ??? CMK? ???? ????
??? ? ??? ????? ????.
Keys on HSAs in a Region
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS KMS? ??? ??
? ??? ????(cryptographic material)? ??? ??????
???.
? ?? KMS API??? ?? TLS PFS(Perfect Forward Secrecy) ??.
? KMS ???? ?? CMK? ??? ? ?? ?? ??/??? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CMK(??? ?) ?? ? ??
? ??, ??? ??, ?? ?? ?? ?? ??? ?? ???? ??.
? ?? ???? ????? ??? ??? ?? ?????? ?? ??? ?? ??
? ?? ? ??(Retention) ?? ??
? ? ?????? ? ID, ARN, ??, ??/?? ?? ??? ???
? Old?? ?? ?? ???? ???? ??? ???? ?? ???.
Security Account
111111111111
Analytics Account
333333333333
Application Account
222222222222
Bank App CMK Analytics CMK
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
IAM ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CMK(??? ?) ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CMK(??? ?) ??? ????
? ??? ?? ?? - CMK ??? ??
? 3?? ??
? CMK ??? ?? C ?? ?? ???? ??? ??? ??? ??? ??.
? CMK ??? IAM ??? ?? ??(??) C ?? ? ???? ??? ??.
? CMK ??? Grants??(??) C ?? ???? ?? AWS ???? ? ??? ??.
? ?? CMK ??? ?? ?? ??? ??? ??? ?!
? ? - ? ??/?? ??? ? ?? ??? ???? ?? ??
? IAM ???? ? ??? KMS action? ??(No kms:*)
? ?? ?? ?? ??? ?? White-listing ?? ?? ?? ??
? ??? ??? ? ??? Deny ??, NotPrincipal + Effect:Deny
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CMK ??: Key??? vs. Key???
{
"Sid": "Allow access for Key Administrators",
"Effect": "Allow",
"Principal": {"AWS": [
"arn:aws:iam::111111111111:user/KMSAdminUser",
"arn:aws:iam::111122223333:role/KMSAdminRole
]},
"Action": [
"kms:Create*", "kms:Describe*",
"kms:Enable*", "kms:List*",
"kms:Put*", "kms:Update*",
"kms:Revoke*", "kms:Disable*,
"kms:Get*", "kms:Delete*",
"kms:TagResource", "kms:UntagResource",
"kms:ScheduleKeyDeletion", "kms:CancelKeyDeletion
],
"Resource": "*
}
{
"Sid": "Allow use of the key",
"Effect": "Allow",
"Principal": {"AWS": [
"arn:aws:iam::111122223333:user/KMSUser",
"arn:aws:iam::111122223333:role/KMSRole",
"arn:aws:iam::444455556666:root" ]},
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:ReEncrypt*",
"kms:GenerateDataKey*",
"kms:DescribeKey
],
"Resource": "*"
}
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
???? ? ? ?? CMK ??
{
"Sid": "Enable IAM User Permissions",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::222222222222:root
},
"Action": "kms:*",
"Resource": "*"
}
{
"Sid": "Enable IAM User Permissions",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::222222222222:root
"AWS": "arn:aws:iam::222222222222:role/CMKAdmin
.....
},
"Action": "kms:*",
"Resource": "*"
}
Option 1.
Option 2.
:: ??? ?????
????? ??? IAM
user/role ?? ?? ???
??(?? ??)
:: ? ?? ??????
CMK ??? ?????
Principal? ????
???? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Grants ??
? Grants: AWS ??? ?? ?? ???? CMK??? ???? ?? ?? ??
??? ?????? ???? ??
? ??!! Grant Limit
? CMK(*) ? Grant Limit :: 2,500?
:: ??? CMK? ???? ???? ???? 2,500? ??? ??
(EBS?? ?)
? CMK(*) ? ?? ?? ??(Principals)? ?? Grants Limit :: 500?
:: ??? CMK? ???? ?? EC2 ????? ???? EBS???
500? ?? ??
(* ??? ?? upload ? CMK? ??, AWS ??? CMK? ?? ??)
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
ViaService
kms:ViaService: ? ?? Condition? ??. ?? ?????? ?????? ??
{
"Sid": "Allow use of CMK via RDS",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::222222222222:role/MortgageApp,
},
"Action" : [ "kms:ListGrants", "kms:CreateGrant",
"kms:Decrypt", "kms:GenerateDataKey*", "kms:ReEncrypt*", "kms:DescribeKey", "kms:Encrypt" ],
"Resource" : "*",
"Condition" : {
"StringEquals" : {
"kms:ViaService" : "rds.us-west-1.amazonaws.com"
}
}
},
? : R D S ? ? ? ? C M K ? ? ? ? ? ?
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
MFA ??
? :: ?? KMS API ??? ?? 5? ?? MFA??? ???? ??
{
"Sid": "MFACriticalKMSEvents",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::111122223333:user/ExampleUser"
},
"Action": [
"kms:DeleteAlias, "kms:DeleteImportedKeyMaterial", "kms:PutKeyPolicy", "kms:ScheduleKeyDeletion"
],
"Resource": "*",
"Condition":{
"NumericLessThan :{
"aws: MultiFactorAuthAge":"300
}
}
}
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ?????? CloudTrail ?? ??
?? ????
111111111111
?? ????
333333333333
?????? ????
222222222222
AWS
CloudTrail
AWS
CloudTrail AWS
CloudTrail
????
??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
???? AWS Config Rules
???? ?? ??
? cloudTrail-enabled
? encrypted-volumes
? rds-storage-encrypted
? s3-bucket-public-read-prohibited
? s3-bucket-public-write-
prohibited
? s3-bucket-ssl-requests-only
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
CMK Tagging
? CMK?? ????/??/???? ?? ??? ??
? ??? ??? ?? ??? CMK??
? CloudTrail?? ?? ??? ?? CMK? ???? ?????? ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?????
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Application Design(??)
?? ????
333333333333
?????? ????
222222222222
Amazon S3
Amazon S3
???? RDS ???
Amazon
RDS
AWS
Encryption SDK
??? ???
??? ???
AWS Encryption SDK
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Encryption Context
AWS KMS? ??? ???? ?????? ?? ????(Key-value pair)
? ???? ???? ?? ?? ??  ??? ? ???? ?? ?? ??/???
??(??? ??? ???? ??)
? ?? ??? ?? ??? ??? ?? ?? ??
? Encryption Context? CloudTrail?? ???? ???  ?? ?? ??? ???? ??
? CMK??? Condition?? ??
{
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::111122223333:role/RoleForExampleApp" },
"Action": [ "kms:Encrypt", "kms:Decrypt" ],
"Resource": "*",
"Condition": {
"StringEquals": {
"kms:EncryptionContext:AppName": "ExampleApp",
"kms:EncryptionContext:Version": "1.0.24"
}
}
}
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? KMS API??? ?? ??
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? API? ?? Alerting
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS KMS ?? ????
AWS KMS
Cryptographic Details
https://d0.awsstatic.com/whitepa
pers/KMS-Cryptographic-
Details.pdf
AWS KMS Best
Practices Whitepaper
https://d0.awsstatic.com/whitepa
pers/aws-kms-best-practices.pdf
AWS KMS Compliance
Reports
https://aws.amazon.com/artifact/
? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS Summit ??? ?? QR???
?? ?? ?? ? ?? ??? ???
??? ????.
?? Summit? ?? ???? ???
?? ?? ????.
#AWSSummit ????? ?? ???? ???? ??
??? ?????.
?? ?? ? ?? ???? AWS Korea ?? ?? ???
??? ?????.
???? ???? ?????!
?????.

More Related Content

What's hot (20)

AWS EMR Cost optimization
AWS EMR Cost optimizationAWS EMR Cost optimization
AWS EMR Cost optimization
SANG WON PARK
?
³Υ٥ȥץ饯ƥ
³Υ٥ȥץ饯ƥ³Υ٥ȥץ饯ƥ
³Υ٥ȥץ饯ƥ
Akihiro Kuwano
?
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...
Amazon Web Services
?
AWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMailAWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMail
Amazon Web Services Japan
?
AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...
AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...
AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...
Amazon Web Services Korea
?
20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito
Amazon Web Services Japan
?
?? 3: IT ???? ?? Cloud ?? ??
?? 3: IT ???? ?? Cloud ?? ???? 3: IT ???? ?? Cloud ?? ??
?? 3: IT ???? ?? Cloud ?? ??
Amazon Web Services Korea
?
????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016
????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016
????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016
Amazon Web Services Korea
?
??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????)
??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????) ??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????)
??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????)
Amazon Web Services Korea
?
AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...
AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...
AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...
Amazon Web Services Korea
?
AWS? ??? ?? ? ??? ??? (???)- ???? ?? 2015
AWS? ??? ?? ? ??? ??? (???)- ???? ?? 2015 AWS? ??? ?? ? ??? ??? (???)- ???? ?? 2015
AWS? ??? ?? ? ??? ??? (???)- ???? ?? 2015
Amazon Web Services Korea
?
Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...
Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...
Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...
Amazon Web Services Korea
?
12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`
12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`
12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`
Amazon Web Services Japan
?
AWS Black Belt Tech` Amazon EBS
AWS Black Belt Tech`  Amazon EBSAWS Black Belt Tech`  Amazon EBS
AWS Black Belt Tech` Amazon EBS
Amazon Web Services Japan
?
20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA
20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA
20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA
Amazon Web Services Japan
?
AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016
AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016
AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016
Amazon Web Services Korea
?
Amazon OpenSearch Deep dive - ????, ????? ??? ????
Amazon OpenSearch Deep dive - ????, ????? ??? ????Amazon OpenSearch Deep dive - ????, ????? ??? ????
Amazon OpenSearch Deep dive - ????, ????? ??? ????
Amazon Web Services Korea
?
???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017
???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017
???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017
Amazon Web Services Korea
?
[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ
[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ
[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ
Amazon Web Services Japan
?
AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020
AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020 AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020
AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020
AWSKRUG - AWS???????
?
AWS EMR Cost optimization
AWS EMR Cost optimizationAWS EMR Cost optimization
AWS EMR Cost optimization
SANG WON PARK
?
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...
Amazon Web Services
?
AWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMailAWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Tech` Amazon WorkDocs / Amazon WorkMail
Amazon Web Services Japan
?
AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...
AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...
AWS Fault Injection Simulator? ?? ?? ??? ????? - ??? AWS ?? ???????? / ?? SW?...
Amazon Web Services Korea
?
20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito
Amazon Web Services Japan
?
????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016
????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016
????? ??? AWS?? ????? ??:: Splunk ??? :: AWS Summit Seoul 2016
Amazon Web Services Korea
?
??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????)
??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????) ??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????)
??????? ?? ???? ???? ?? ?? ?? - ??? (AWS ????????)
Amazon Web Services Korea
?
AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...
AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...
AWS Fargate? Amazon ECS? ??? CI/CD ???? - ???, AWS ???? ???? :: AWS Game Mast...
Amazon Web Services Korea
?
Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...
Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...
Datadog? ??? Elastic Kubernetes Service(EKS)??? ??????? ?? ??? - ??? ??? ??? ...
Amazon Web Services Korea
?
12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`
12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`
12/5 °桿AWS Black Belt Online Seminar AWS re:Invent 2018 åץǩ`
Amazon Web Services Japan
?
20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA
20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA
20200219 AWS Black Belt Online Seminar ץߥAWSgLӾA
Amazon Web Services Japan
?
AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016
AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016
AWS Lambda 100% ???? :: ??? ???? ???? :: Gaming on AWS 2016
Amazon Web Services Korea
?
Amazon OpenSearch Deep dive - ????, ????? ??? ????
Amazon OpenSearch Deep dive - ????, ????? ??? ????Amazon OpenSearch Deep dive - ????, ????? ??? ????
Amazon OpenSearch Deep dive - ????, ????? ??? ????
Amazon Web Services Korea
?
???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017
???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017
???????? ?? AWS ???? ?? ? ?? ?? - AWS Summit Seoul 2017
Amazon Web Services Korea
?
[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ
[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ
[AWS EXpert Online for JAWS-UG 18] ҊƤ衢Step Functions αݤäƤĤ
Amazon Web Services Japan
?
AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020
AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020 AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020
AWS SAM?? ???? ???? ???? - ???(????????) :: AWS Community Day 2020
AWSKRUG - AWS???????
?

Similar to AWS KMS? ???? ??? AWS ??? ???? ?? ??::???::AWS Summit Seoul 2018 (20)

AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...
AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...
AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...
Amazon Web Services Korea
?
202003 AWS ISV/DNB KMS_WAF_webinar
202003 AWS ISV/DNB KMS_WAF_webinar202003 AWS ISV/DNB KMS_WAF_webinar
202003 AWS ISV/DNB KMS_WAF_webinar
Yijeong Cho
?
[AWS & ??????, ????????????? ?? ???] AWS ???? ??
[AWS & ??????, ????????????? ?? ???] AWS ???? ??[AWS & ??????, ????????????? ?? ???] AWS ???? ??
[AWS & ??????, ????????????? ?? ???] AWS ???? ??
BESPIN GLOBAL
?
AWS?? ???? ???? ???? - ??? ???? ????, AWS
AWS?? ???? ???? ???? - ??? ???? ????, AWSAWS?? ???? ???? ???? - ??? ???? ????, AWS
AWS?? ???? ???? ???? - ??? ???? ????, AWS
Amazon Web Services Korea
?
?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018
?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018
?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018
Amazon Web Services Korea
?
???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...
???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...
???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...
Amazon Web Services Korea
?
???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018
???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018
???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018
Amazon Web Services Korea
?
???? ?????? Data Lake ?? - ??? ???? ????, AWS
???? ?????? Data Lake ?? - ??? ???? ????, AWS???? ?????? Data Lake ?? - ??? ???? ????, AWS
???? ?????? Data Lake ?? - ??? ???? ????, AWS
Amazon Web Services Korea
?
???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018
???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018 ???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018
???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018
Amazon Web Services Korea
?
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018 ???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
Amazon Web Services Korea
?
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
Amazon Web Services Korea
?
??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...
??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...
??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...
Amazon Web Services Korea
?
?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018
?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018
?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018
Amazon Web Services Korea
?
AWS risk_detection_webinar
AWS risk_detection_webinarAWS risk_detection_webinar
AWS risk_detection_webinar
Yijeong Cho
?
AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???
AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???
AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???
Amazon Web Services Korea
?
???? ???? ?? AWS? ??? ???? ?? l ??? ???? ????
???? ???? ?? AWS? ??? ???? ?? l ??? ???? ???????? ???? ?? AWS? ??? ???? ?? l ??? ???? ????
???? ???? ?? AWS? ??? ???? ?? l ??? ???? ????
Amazon Web Services Korea
?
IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...
IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...
IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...
Amazon Web Services Korea
?
AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??
AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??
AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??
Amazon Web Services Korea
?
AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))
AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))
AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))
Amazon Web Services Korea
?
??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)
??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)
??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)
Amazon Web Services Korea
?
AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...
AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...
AWS KMS ?? ???? ????? ??? ??? ? ??? ??? ?? ??? ?? - ???, AWS ???? ???? :: AWS...
Amazon Web Services Korea
?
202003 AWS ISV/DNB KMS_WAF_webinar
202003 AWS ISV/DNB KMS_WAF_webinar202003 AWS ISV/DNB KMS_WAF_webinar
202003 AWS ISV/DNB KMS_WAF_webinar
Yijeong Cho
?
[AWS & ??????, ????????????? ?? ???] AWS ???? ??
[AWS & ??????, ????????????? ?? ???] AWS ???? ??[AWS & ??????, ????????????? ?? ???] AWS ???? ??
[AWS & ??????, ????????????? ?? ???] AWS ???? ??
BESPIN GLOBAL
?
?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018
?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018
?? ???? ?? AWS ???? ???? ????::???::AWS Summit Seoul 2018
Amazon Web Services Korea
?
???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...
???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...
???? ??? ?? ??? ?? AWS ??? C ??? AWS ???? ???? ????, ??? AWS ???? ???? ???:: ...
Amazon Web Services Korea
?
???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018
???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018
???? ???? ? AWS ??? ?? (???, ???) :: AWS DevDay 2018
Amazon Web Services Korea
?
???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018
???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018 ???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018
???? ??? ????? ???? ?? AWS IAM ?? ??::???:: AWS Summit Seoul 2018
Amazon Web Services Korea
?
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018 ???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
Amazon Web Services Korea
?
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
???? ?? ??? ?? ??? ?? ?? ???? ?? ??::???::AWS Summit Seoul 2018
Amazon Web Services Korea
?
??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...
??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...
??? ??? ?? ???? ?? ? ?? ?? ??? - ??? ???? ????? ???, AWS :: AWS Summit Seoul ...
Amazon Web Services Korea
?
?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018
?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018
?? 1 - AWS ???? ?? (??? ???? ????, AWS) :: AWSome Day ??? ???? 2018
Amazon Web Services Korea
?
AWS risk_detection_webinar
AWS risk_detection_webinarAWS risk_detection_webinar
AWS risk_detection_webinar
Yijeong Cho
?
AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???
AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???
AWS Summit Seoul 2023 | ?? ?? ? ????? ???? ??? IAM ?? ???
Amazon Web Services Korea
?
IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...
IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...
IAM ??? ? ??? AWS ??? ????. ??? ? ?? ??! - ??? ???? ????, AWS :: AWS Summit S...
Amazon Web Services Korea
?
AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??
AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??
AWS Builders - Industry Edition: DevSecOps on AWS - ??? IAM ??
Amazon Web Services Korea
?
AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))
AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))
AWS CLOUD 2017 - ?? ???? AWS ???? ?? (??? ???? ????))
Amazon Web Services Korea
?
??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)
??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)
??? ???? ???? ??? ??? ?? Data Lake ?? ? ?? ?? - ??? (AWS ???? ????)
Amazon Web Services Korea
?

More from Amazon Web Services Korea (20)

[D3T1S01] Gen AI? ?? Amazon Aurora ?? ?? ??
[D3T1S01] Gen AI? ?? Amazon Aurora  ?? ?? ??[D3T1S01] Gen AI? ?? Amazon Aurora  ?? ?? ??
[D3T1S01] Gen AI? ?? Amazon Aurora ?? ?? ??
Amazon Web Services Korea
?
[D3T1S06] Neptune Analytics with Vector Similarity Search
[D3T1S06] Neptune Analytics with Vector Similarity Search[D3T1S06] Neptune Analytics with Vector Similarity Search
[D3T1S06] Neptune Analytics with Vector Similarity Search
Amazon Web Services Korea
?
[D3T1S03] Amazon DynamoDB design puzzlers
[D3T1S03] Amazon DynamoDB design puzzlers[D3T1S03] Amazon DynamoDB design puzzlers
[D3T1S03] Amazon DynamoDB design puzzlers
Amazon Web Services Korea
?
[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...
[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...
[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...
Amazon Web Services Korea
?
[D3T1S07] AWS S3 - ???? ???? ?????? ????
[D3T1S07] AWS S3 - ???? ???? ?????? ????[D3T1S07] AWS S3 - ???? ???? ?????? ????
[D3T1S07] AWS S3 - ???? ???? ?????? ????
Amazon Web Services Korea
?
[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????
[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????
[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????
Amazon Web Services Korea
?
[D3T1S02] Aurora Limitless Database Introduction
[D3T1S02] Aurora Limitless Database Introduction[D3T1S02] Aurora Limitless Database Introduction
[D3T1S02] Aurora Limitless Database Introduction
Amazon Web Services Korea
?
[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??
[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??
[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??
Amazon Web Services Korea
?
[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??
[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??
[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??
Amazon Web Services Korea
?
AWS Modern Infra with Storage Roadshow 2023 - Day 2
AWS Modern Infra with Storage Roadshow 2023 - Day 2AWS Modern Infra with Storage Roadshow 2023 - Day 2
AWS Modern Infra with Storage Roadshow 2023 - Day 2
Amazon Web Services Korea
?
AWS Modern Infra with Storage Roadshow 2023 - Day 1
AWS Modern Infra with Storage Roadshow 2023 - Day 1AWS Modern Infra with Storage Roadshow 2023 - Day 1
AWS Modern Infra with Storage Roadshow 2023 - Day 1
Amazon Web Services Korea
?
??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...
??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...
??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...
Amazon Web Services Korea
?
Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...
Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...
Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...
Amazon Web Services Korea
?
Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...
Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...
Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...
Amazon Web Services Korea
?
Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...
Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...
Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...
Amazon Web Services Korea
?
[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...
[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...
[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...
Amazon Web Services Korea
?
Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...
Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...
Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...
Amazon Web Services Korea
?
Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...
Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...
Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...
Amazon Web Services Korea
?
Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...
Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...
Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...
Amazon Web Services Korea
?
Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...
Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...
Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...
Amazon Web Services Korea
?
[D3T1S06] Neptune Analytics with Vector Similarity Search
[D3T1S06] Neptune Analytics with Vector Similarity Search[D3T1S06] Neptune Analytics with Vector Similarity Search
[D3T1S06] Neptune Analytics with Vector Similarity Search
Amazon Web Services Korea
?
[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...
[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...
[D3T1S04] Aurora PostgreSQL performance monitoring and troubleshooting by use...
Amazon Web Services Korea
?
[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????
[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????
[D3T1S05] Aurora ?? ?? ????? ???? ??? ?? ??? ?? ????
Amazon Web Services Korea
?
[D3T1S02] Aurora Limitless Database Introduction
[D3T1S02] Aurora Limitless Database Introduction[D3T1S02] Aurora Limitless Database Introduction
[D3T1S02] Aurora Limitless Database Introduction
Amazon Web Services Korea
?
[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??
[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??
[D3T2S01] Amazon Aurora MySQL ??? ?? ????? ? Amazon B/G Deployments ??
Amazon Web Services Korea
?
[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??
[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??
[D3T2S03] Data&AI Roadshow 2024 - Amazon DocumentDB ??
Amazon Web Services Korea
?
AWS Modern Infra with Storage Roadshow 2023 - Day 2
AWS Modern Infra with Storage Roadshow 2023 - Day 2AWS Modern Infra with Storage Roadshow 2023 - Day 2
AWS Modern Infra with Storage Roadshow 2023 - Day 2
Amazon Web Services Korea
?
AWS Modern Infra with Storage Roadshow 2023 - Day 1
AWS Modern Infra with Storage Roadshow 2023 - Day 1AWS Modern Infra with Storage Roadshow 2023 - Day 1
AWS Modern Infra with Storage Roadshow 2023 - Day 1
Amazon Web Services Korea
?
??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...
??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...
??? ???? Database Migration Service : ?????? ? ??? ??, ??, ??, ??? ?? - ???: ...
Amazon Web Services Korea
?
Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...
Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...
Amazon DocumentDB - Architecture ? Best Practice (Level 200) - ???: ???, Sr. ...
Amazon Web Services Korea
?
Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...
Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...
Amazon Elasticache - Fully managed, Redis & Memcached Compatible Service (Lev...
Amazon Web Services Korea
?
Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...
Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...
Internal Architecture of Amazon Aurora (Level 400) - ???: ???, APAC RDS Speci...
Amazon Web Services Korea
?
[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...
[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...
[Keynote] ???? AWS ?????? ???? - ???: ???, Korea Database SA Manager, WWSO, A...
Amazon Web Services Korea
?
Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...
Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...
Demystify Streaming on AWS - ???: ???, Sr Analytics Specialist, WWSO, AWS :::...
Amazon Web Services Korea
?
Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...
Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...
Amazon EMR - Enhancements on Cost/Performance, Serverless - ???: ???, Sr Anal...
Amazon Web Services Korea
?
Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...
Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...
Amazon OpenSearch - Use Cases, Security/Observability, Serverless and Enhance...
Amazon Web Services Korea
?
Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...
Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...
Enabling Agility with Data Governance - ???: ???, Analytics Specialist, WWSO,...
Amazon Web Services Korea
?

AWS KMS? ???? ??? AWS ??? ???? ?? ??::???::AWS Summit Seoul 2018

  • 1. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ? ? ? AWS Korea / Solutions Architect AWS KMS? ???? ??? AWS ??? ???? ?? ??
  • 2. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? AWS ??? ?? ? ?? ? ??? ??? ? ?? ? ??? ??? KMS ?? ???? ? Infrastructure ?? ? IAM ?? ? ?? ?? ?? ? ??? ?? ?? ? ?? ?? ??
  • 3. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS ??? ??
  • 4. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ??????? ??? ???? ??: ? ?? ??? ?? ? ?? ????? ??? ?? ? ???? ?????? ? ???? ???? ?? ? ???? ???? ?? ???? ?? ? ???? ???? ?? IT ?? ?? ? ?? ?? ?? ????? ??? ?? ??? ?? ? ?? ??? ?? ??? ??? ?? ??? ??
  • 5. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS ???? ???? ?? ??? ?? ??? ?? ? ??? ?? ? ???? ?? ?? C ??? ?? ??? ??, TLS, IPsec ? ??/?? ?? - AWS Snowball ? ??? ?? ? ??? ?? ??? ???? ? ?? ??? C ??? ??, ??, ????, ?? ???, ?? ??? ? ??? ?? ? ??? ?? ??? ???? - CCTV ??? ?? ? ??? ?? ? ???? ???? C VPC, Security Groups, NACL ? ? ?? ??? C TLS, IPsec ? ??? ?? ? ??? ???? ?? ??? ?? ?? ? ??? ??? C ?? ???? ?? ??? ??, ??, ????, ?? ???, ?? ??? ??? ? ??? ?? ? ???? ?? ??? ???? C FIPS 140-2 ?? ??
  • 6. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ? ??? ???
  • 7. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ??? ??? ? ???? ?? TLS?? ??? ?? ??? ???? ????? ??: Amazon EC2? ???? ?? ???????? Elastic Load Balancing (CLB/ALB) ??? Amazon CloudFront ??? Amazon API Gateway ???
  • 8. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS Certificate Manager (ACM) ? ??? AWS ????? ?? TLS??? ??: ? Elastic Load Balancing (CLB/ALB) ? Amazon CloudFront ? Amazon API Gateway ? AWS Elastic Beanstalk ??? ??/??/??/?? ??? AWS? ??? ? ? ??? ???? ?? ?? ?? ?? ? ??? ??? ? ??? ?? ?? ? ??? ??? ?? ?? DNS ?? ? ??? ??? ?? ??? ??(DV) Transparency Log ?? ??
  • 9. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS ACM Private Certificate Authority ?? SSL/TLS ??? ????(CA)? ????? ?? ? ?? ??? ???, API G/W, SSL VPN, IoT ?? ? ???? ??? ???? ? RSA 2048 / RSA 4096 / ECDSA P256 / ECDSA P384 ??? ???? PKI ??? AWS? ??? ? ??CA ???? ???? ?? ? ???? ??? ??(FIPS 140-2 Level 3? ???? HSM) ? ??? ?? ??(CRL)?? ?? ?? ?? ? N. Virginia, Ohio, Oregon, Singapore, Sydney, Tokyo, Canada, Frankfurt, Ireland
  • 10. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. TLS? ? ???? ?? C S2N ? ?? ?? ??? ?? ??? ?? AWS? ??? TLS ????? ? SSL v3 / TLS 1.0 / TLS 1.1 / TLS 1.2 ? ?? ???? ?? TLS ??? ??(extension) ??? ??; ~6,000 ?? ??? ?? ? ??? AWS?????? ?????, ?? ??? ?? https://github.com/awslabs/s2n
  • 11. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Virtual Private Networking AWS ??? VPN ??? VPC? ?? ??? ???? IPsec ?? VPN?? ??. AWS VPN CloudHub ??? VPC? ???? ??? ???? IPsec ???? ???? ?? VPN ??. ??? ?? ????? ?? VPN EC2??? VPN S/W? ???? ??? ???? ??.
  • 12. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ? ??? ???
  • 13. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ??? ??? ??? ?? ?? ??? ???? / ????? ???? ??? ????? ??? ?? ???? ??? ? ??? ? (???) ??? ???? ? (???) ? ?? ?? ? ???? ? ?? ???(Envelop Encryption)
  • 14. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS?? ??? ???? ???? 2?? ?? ????? ? ???(Client-Side Encryption) ? ???? ???? ?? ??? ?? ? ??? ?? ??? ?? ???? ?? ?????, AWS KMS/CloudHSM?? ?? ?? ? ???: AWS Encryption SDK, S3 Encryption Client, EMRFS Client, DynamoDB Encryption Client ?? ? ???(Server-Side Encryption) ? AWS? ??? ???? ?? ?? ?? ?? ??? ??? ?? ?? ? ? 34 ? ??? ?? : Amazon S3, Amazon EBS, Amazon RDS, Amazon Redshift, Amazon WorkSpaces, Amazon Kinesis Streams, AWS CloudTrail ? ?? ?? ?? ?? AWS KMS? ??? ? ??
  • 15. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ????? ? ???(Client-Side Encryption) A W S E n c r y p t i o n S D K , S 3 / E M R F S / D y n a m o D B c l i e n t s , c u s t o m e r - s u p p l i e d ?? IDC? ?? ?????? EC2?? ?? ??? ??? ??? ?? ????? ??? ??? ??? EC2?? ?? ?????? AWS??? ?? ???? ??? AWS KMS AWS CloudHSM
  • 16. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS Encryption SDK ??? ????, ???? ?? 2?? ??? ??: ? ??? ? ???/??/?????? ? ??? ??? ???? ??? ? ???(key provider) SDK? ??? ???? ???????? ?? ? ?? ???? ???? ?? ???? ??? ? ???? ?? KMS Limit? ???? ?? ??? ? ?? ??? ???? KMS?? ??? ?? ?? Java, Python, CLI ?? ?? http://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/introduction.html
  • 17. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ? ???(Server-Side Encryption) 2?? ? ??? ?? ???(envelope encryption) ? ???? ?????? ???? ??? ? ? KMS ??? ?? ?? ??? ?? ??? ?? ? ??? ?? ?? ?? ?? ? ??? ??? ???? ?? ?? ?? ? ??? ??? ???? ?? ?? ?? ??? ?? ?? ????? ??? ? ? ?? ??? ?? ?? ??? ????? ?? CMK(?? ??? ?) ????1 S3 ?? EBS ?? Amazon Redshift ???? ????2 ????3 ????4 ?? ?????? KMS
  • 18. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS KMS? ? ???? ?? KMS? ?? KMS ??? ??? ? ? ?? ?? ?? HSA(Hardened Security Appliances)? CMK? ????? ?? ??? ??? ??? ?? ??. ? ?? ??? ??? ?? ?? CMK? ? ???. ???? Keys on HSAs in a Region ??? ?(CMK) ? 256-bit ????, HSA? ????? ??? ???? Import?. ? ???? ?? KMS??? ???? Copy? ????, ??? ? ??? ?, ?? CMK? ??? HSA ??? ??? ???. ???? ??? ?(CMK) ??? ? ? 256-bit ????, ??? ?/???? ??? ? AWS???/?? ???????? ???? ??? ?? ??? ?? ???? ???. ??? ?
  • 19. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CMK(??? ?) ?? AWS ??? CMK ?? ??? CMK ?? AWS??? ???? KMS? ??? AWS??? ? 1? AWS??? ???? KMS? ??? AWS??? ? ??? ?? AWS? ?? ??? ?? ????? ??? ?? ? 3? ?? ???? ?? 1?? ???? ?? ?? ?? ???? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? AWS ???? ??? CMK / IAM ??? ?? ?? ?? Key ?? AWS? ?? ??? ?? ??? ?? IAM ???? ?? IAM ???? ??
  • 20. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS ????? KMS? ???? ?? EC2/EBS ?? ? EBS ?? ?? ??? ?? ????, CMK? ???? ? ?? ?????? ?? ? ??? EBS???? EC2? ?? ?? ??, ?? EBS??? ?????? ???? ?? ??? ?? ??????? ??? ??? ?? ?? ??, I/O, ???? ??? ? ?? ???: EBS, RDS, Redshift, WorkSpaces, Amazon Lightsail S3 ?? ? S3? 3?? ?? ? ??? ? SSE-KMS ?? ? ?? ?? ??? ?? ????, CMK? ???? ?, ?? ?????? ?? ? ??? ?? ???? S3 ???? ??? ??? ??? ???? ?? ??? ?? ?? ? ?? ???. ? ????? Get??? ?? S3? KMS??? ???? ??? ?? CMK? ???? ??? ????, ???? ??? ?? ??? ?? ??? ??? ? ?, ?? ? ???. ? ?? ???: S3, EMR, CloudTrail, Amazon Athena, Amazon Kinesis, Amazon SQS, Amazon CloudWatch
  • 21. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ??? ?? CMK(??? ?) ????? ?? ??? ?? CMK ?? ??? ?? ????? ? ??(CMK Policy)?? ?? ? ?? ??: ? <??? ????>? <??? ???? Role>?? ?/??? ?? ? ?????? A??? ???? ?????, ?????? B??? ? ???? ???? ? ??. ? ??? ?? ?? ?? Role? ?? ?????. ? <??? ????>?? ?/??? ??? ??? ? ???, ?? ????(??/??/????/?? ?)? ??. AWS Identity and Access Management? ??
  • 22. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CloudTrail?? CMK(??? ?) ???? "EventName":"DecryptResult", ??? API "EventTiime":"2014-08-18T18:13:07Z", .??? ?? "RequestParameters": "{"keyId":"2b42x363-1911-4e3a-8321-6b67329025ex}, ??? ?? ?? ?? EncryptionContext":"volumeid-12345", ?? ??? AWS ??? "SourceIPAddress":" 203.0.113.113", ???? IP?? "UserIdentity": {"arn":"arn:aws:iam:: 111122223333:user/User123} ???? ??
  • 23. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ????? ??? Amazon EBS Amazon RDS Amazon Redshift Amazon S3 Amazon Glacier ?? ? ??? AWS CloudTrail IAM ?? ?? ?? ??? ?? ?????? ?? ? ??? KMS? ?? ?? ??? ??? ???? ? ?? ??? ???
  • 24. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. KMS ?? ????
  • 25. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS Cloud Adoption Framework 5 ?? ?? ?? ?? ??? ?? ??? ? ?? ?? ?? ?? ??? ?? ?? ?? ??? ? ?? ? ??? ?? ??? ? ?? ??? ?? ????? ?? ?? ?? ?? ?? ?? ??? ?? ?? ?? ?? ??? ? ?? ???? ?? ???? ?? ? ?? ???? ??? ???
  • 26. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Infrastructure ??
  • 27. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. KMS? ??? ?? ?? KMS HSA? ??? ??? ?: ? AWS ???? ?? ???? ?? ???. ? ??? ????? ????/??? ?? ??. HSA? reboot??? ? ???? ??: ? ??? ?? ? ???? ?? ??? ??. ? ????? ????/?? ?? ??: ? ??? AWS???? ??? ??? ???. ? ??? ???? ??? ????? ??? ???? ??? ???. 3rd Party?? ? SOC 1 C Control 4.5: KMS?? ??? ??? ??? CMK? ???? ???? ??? ? ??? ????? ????. Keys on HSAs in a Region
  • 28. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS KMS? ??? ?? ? ??? ????(cryptographic material)? ??? ?????? ???. ? ?? KMS API??? ?? TLS PFS(Perfect Forward Secrecy) ??. ? KMS ???? ?? CMK? ??? ? ?? ?? ??/??? ??
  • 29. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CMK(??? ?) ?? ? ?? ? ??, ??? ??, ?? ?? ?? ?? ??? ?? ???? ??. ? ?? ???? ????? ??? ??? ?? ?????? ?? ??? ?? ?? ? ?? ? ??(Retention) ?? ?? ? ? ?????? ? ID, ARN, ??, ??/?? ?? ??? ??? ? Old?? ?? ?? ???? ???? ??? ???? ?? ???. Security Account 111111111111 Analytics Account 333333333333 Application Account 222222222222 Bank App CMK Analytics CMK
  • 30. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. IAM ??
  • 31. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CMK(??? ?) ?? ??
  • 32. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CMK(??? ?) ??? ???? ? ??? ?? ?? - CMK ??? ?? ? 3?? ?? ? CMK ??? ?? C ?? ?? ???? ??? ??? ??? ??? ??. ? CMK ??? IAM ??? ?? ??(??) C ?? ? ???? ??? ??. ? CMK ??? Grants??(??) C ?? ???? ?? AWS ???? ? ??? ??. ? ?? CMK ??? ?? ?? ??? ??? ??? ?! ? ? - ? ??/?? ??? ? ?? ??? ???? ?? ?? ? IAM ???? ? ??? KMS action? ??(No kms:*) ? ?? ?? ?? ??? ?? White-listing ?? ?? ?? ?? ? ??? ??? ? ??? Deny ??, NotPrincipal + Effect:Deny
  • 33. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CMK ??: Key??? vs. Key??? { "Sid": "Allow access for Key Administrators", "Effect": "Allow", "Principal": {"AWS": [ "arn:aws:iam::111111111111:user/KMSAdminUser", "arn:aws:iam::111122223333:role/KMSAdminRole ]}, "Action": [ "kms:Create*", "kms:Describe*", "kms:Enable*", "kms:List*", "kms:Put*", "kms:Update*", "kms:Revoke*", "kms:Disable*, "kms:Get*", "kms:Delete*", "kms:TagResource", "kms:UntagResource", "kms:ScheduleKeyDeletion", "kms:CancelKeyDeletion ], "Resource": "* } { "Sid": "Allow use of the key", "Effect": "Allow", "Principal": {"AWS": [ "arn:aws:iam::111122223333:user/KMSUser", "arn:aws:iam::111122223333:role/KMSRole", "arn:aws:iam::444455556666:root" ]}, "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey ], "Resource": "*" }
  • 34. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ???? ? ? ?? CMK ?? { "Sid": "Enable IAM User Permissions", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::222222222222:root }, "Action": "kms:*", "Resource": "*" } { "Sid": "Enable IAM User Permissions", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::222222222222:root "AWS": "arn:aws:iam::222222222222:role/CMKAdmin ..... }, "Action": "kms:*", "Resource": "*" } Option 1. Option 2. :: ??? ????? ????? ??? IAM user/role ?? ?? ??? ??(?? ??) :: ? ?? ?????? CMK ??? ????? Principal? ???? ???? ??
  • 35. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Grants ?? ? Grants: AWS ??? ?? ?? ???? CMK??? ???? ?? ?? ?? ??? ?????? ???? ?? ? ??!! Grant Limit ? CMK(*) ? Grant Limit :: 2,500? :: ??? CMK? ???? ???? ???? 2,500? ??? ?? (EBS?? ?) ? CMK(*) ? ?? ?? ??(Principals)? ?? Grants Limit :: 500? :: ??? CMK? ???? ?? EC2 ????? ???? EBS??? 500? ?? ?? (* ??? ?? upload ? CMK? ??, AWS ??? CMK? ?? ??)
  • 36. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ViaService kms:ViaService: ? ?? Condition? ??. ?? ?????? ?????? ?? { "Sid": "Allow use of CMK via RDS", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::222222222222:role/MortgageApp, }, "Action" : [ "kms:ListGrants", "kms:CreateGrant", "kms:Decrypt", "kms:GenerateDataKey*", "kms:ReEncrypt*", "kms:DescribeKey", "kms:Encrypt" ], "Resource" : "*", "Condition" : { "StringEquals" : { "kms:ViaService" : "rds.us-west-1.amazonaws.com" } } }, ? : R D S ? ? ? ? C M K ? ? ? ? ? ?
  • 37. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. MFA ?? ? :: ?? KMS API ??? ?? 5? ?? MFA??? ???? ?? { "Sid": "MFACriticalKMSEvents", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::111122223333:user/ExampleUser" }, "Action": [ "kms:DeleteAlias, "kms:DeleteImportedKeyMaterial", "kms:PutKeyPolicy", "kms:ScheduleKeyDeletion" ], "Resource": "*", "Condition":{ "NumericLessThan :{ "aws: MultiFactorAuthAge":"300 } } }
  • 38. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ?? ??
  • 39. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ?????? CloudTrail ?? ?? ?? ???? 111111111111 ?? ???? 333333333333 ?????? ???? 222222222222 AWS CloudTrail AWS CloudTrail AWS CloudTrail ???? ??
  • 40. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ???? AWS Config Rules ???? ?? ?? ? cloudTrail-enabled ? encrypted-volumes ? rds-storage-encrypted ? s3-bucket-public-read-prohibited ? s3-bucket-public-write- prohibited ? s3-bucket-ssl-requests-only
  • 41. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. CMK Tagging ? CMK?? ????/??/???? ?? ??? ?? ? ??? ??? ?? ??? CMK?? ? CloudTrail?? ?? ??? ?? CMK? ???? ?????? ?? ??
  • 42. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?????
  • 43. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Application Design(??) ?? ???? 333333333333 ?????? ???? 222222222222 Amazon S3 Amazon S3 ???? RDS ??? Amazon RDS AWS Encryption SDK ??? ??? ??? ??? AWS Encryption SDK
  • 44. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Encryption Context AWS KMS? ??? ???? ?????? ?? ????(Key-value pair) ? ???? ???? ?? ?? ?? ??? ? ???? ?? ?? ??/??? ??(??? ??? ???? ??) ? ?? ??? ?? ??? ??? ?? ?? ?? ? Encryption Context? CloudTrail?? ???? ??? ?? ?? ??? ???? ?? ? CMK??? Condition?? ?? { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::111122223333:role/RoleForExampleApp" }, "Action": [ "kms:Encrypt", "kms:Decrypt" ], "Resource": "*", "Condition": { "StringEquals": { "kms:EncryptionContext:AppName": "ExampleApp", "kms:EncryptionContext:Version": "1.0.24" } } }
  • 45. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? ?? ??
  • 46. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? KMS API??? ?? ??
  • 47. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. ?? API? ?? Alerting
  • 48. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS KMS ?? ???? AWS KMS Cryptographic Details https://d0.awsstatic.com/whitepa pers/KMS-Cryptographic- Details.pdf AWS KMS Best Practices Whitepaper https://d0.awsstatic.com/whitepa pers/aws-kms-best-practices.pdf AWS KMS Compliance Reports https://aws.amazon.com/artifact/
  • 49. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. AWS Summit ??? ?? QR??? ?? ?? ?? ? ?? ??? ??? ??? ????. ?? Summit? ?? ???? ??? ?? ?? ????. #AWSSummit ????? ?? ???? ???? ?? ??? ?????. ?? ?? ? ?? ???? AWS Korea ?? ?? ??? ??? ?????. ???? ???? ?????!