kmsKeyId  
  An identifier for the symmetric KMS key to use when creating the encrypted AMI. This parameter is only required if you want to use a non-default KMS key; if this parameter is not specified, the default KMS key for EBS is used. If a KmsKeyId is specified, the Encrypted flag must also be set.
The KMS key identifier may be provided in any of the following formats:
- Key ID 
- Key alias 
- ARN using key ID. The ID ARN contains the - arn:aws:kmsnamespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the- keynamespace, and then the key ID. For example, arn:aws:kms:us-east-1:012345678910:key/abcd1234-a123-456a-a12b-a123b4cd56ef.
- ARN using key alias. The alias ARN contains the - arn:aws:kmsnamespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the- aliasnamespace, and then the key alias. For example, arn:aws:kms:us-east-1:012345678910:alias/ExampleAlias.
Amazon Web Services parses KmsKeyId asynchronously, meaning that the action you call may appear to complete even though you provided an invalid identifier. This action will eventually report failure.
The specified KMS key must exist in the Region that the AMI is being copied to.
Amazon EBS does not support asymmetric KMS keys.