

本指南記載於 2025 年 3 月 13 日發行的新 AWS Wickr 管理主控台。如需 AWS Wickr 管理主控台傳統版本的文件，請參閱[傳統管理指南](https://docs.aws.amazon.com/wickr/latest/adminguide-classic/what-is-wickr.html)。

本文為英文版的機器翻譯版本，如內容有任何歧義或不一致之處，概以英文版為準。

# 資料保留服務的自訂 KMS 金鑰設定
<a name="custom-kms-key"></a>

若要將您自己的 KMS 金鑰與資料保留服務搭配使用，請在啟動產品之前，使用下列組態建立金鑰：

保留金鑰  
+ 金鑰類型：對稱 (`SYMMETRIC_DEFAULT`)
+ 金鑰用量：加密和解密
+ 金鑰輪換：建議啟用

密碼復原金鑰  
+ 金鑰類型：非對稱 (`ECC_NIST_P384`)
+ 金鑰用量：金鑰協議
+ 金鑰輪換：不支援非對稱金鑰

## 自訂 KMS 金鑰政策設定
<a name="custom-kms-key-policy-setup"></a>

1. 使用上述所需的組態建立 KMS 金鑰。

1. 從 KMS 主控台複製每個金鑰的**金鑰 ID**。

1. 在 Service Catalog 中啟動資料保留產品，在 `KmsKeyId`和 `PasswordRecoveryKeyId` 欄位中輸入金鑰 IDs。

1. 堆疊完成後，導覽至**輸出**索引標籤。

1. 複製 `DRSCustomerCrossAccountRoleArn`和 的值`DecryptionLambdaRoleArn`。

1. 開啟 KMS 主控台，然後選取您的自訂保留金鑰。

1. 在 **Key policy (金鑰政策)** 區段中，選擇 **Switch to policy view (切換至政策檢視)**。

1. 選擇**編輯**。

1. 將下列陳述式新增至金鑰政策的`"Statement"`陣列，將預留位置 ARNs 取代為步驟 5 的值。

1. 選擇**儲存變更**。

1. 使用下列密碼復原陳述式，對密碼復原金鑰重複步驟 6–10。

### 保留金鑰 — 要新增的陳述式
<a name="custom-kms-key-retention-statements"></a>

```
{
  "Sid": "EnclaveGenerateDataKey",
  "Effect": "Allow",
  "Principal": {
    "AWS": "{DRSCustomerCrossAccountRoleArn}"
  },
  "Action": "kms:GenerateDataKey",
  "Resource": "*",
  "Condition": {
    "StringLike": {
      "kms:RecipientAttestation:PCR0": "*",
      "kms:RecipientAttestation:PCR1": "*",
      "kms:RecipientAttestation:PCR2": "*"
    },
    "ForAnyValue:StringEquals": {
      "kms:EncryptionContextKeys": [
        "aws:wickr:network:id",
        "aws:wickr:app:id"
      ]
    }
  }
},
{
  "Sid": "EnclaveDescribeKey",
  "Effect": "Allow",
  "Principal": {
    "AWS": "{DRSCustomerCrossAccountRoleArn}"
  },
  "Action": "kms:DescribeKey",
  "Resource": "*"
},
{
  "Sid": "EnclaveDecryptWithAttestation",
  "Effect": "Allow",
  "Principal": {
    "AWS": "{DRSCustomerCrossAccountRoleArn}"
  },
  "Action": "kms:Decrypt",
  "Resource": "*",
  "Condition": {
    "StringLike": {
      "kms:RecipientAttestation:PCR0": "*",
      "kms:RecipientAttestation:PCR1": "*",
      "kms:RecipientAttestation:PCR2": "*"
    },
    "ForAnyValue:StringEquals": {
      "kms:EncryptionContextKeys": "aws:wickr:app:id"
    }
  }
},
{
  "Sid": "DecryptLambdaDecrypt",
  "Effect": "Allow",
  "Principal": {
    "AWS": "{DecryptionLambdaRoleArn}"
  },
  "Action": "kms:Decrypt",
  "Resource": "*",
  "Condition": {
    "ForAnyValue:StringEquals": {
      "kms:EncryptionContextKeys": "aws:wickr:network:id"
    }
  }
}
```

您可以在設定**使用客戶受管 KMS 金鑰的許可**一節[靜態加密](encryption-rest.md)下找到每個陳述式的目的。

### 密碼復原金鑰 — 要新增的陳述式
<a name="custom-kms-key-password-recovery-statements"></a>

```
{
  "Sid": "EnclaveDeriveSharedSecret",
  "Effect": "Allow",
  "Principal": {
    "AWS": "{DRSCustomerCrossAccountRoleArn}"
  },
  "Action": "kms:DeriveSharedSecret",
  "Resource": "*",
  "Condition": {
    "StringLike": {
      "kms:RecipientAttestation:PCR0": "*",
      "kms:RecipientAttestation:PCR1": "*",
      "kms:RecipientAttestation:PCR2": "*"
    }
  }
},
{
  "Sid": "CustomerGetPublicKey",
  "Effect": "Allow",
  "Principal": {
    "AWS": "{DRSCustomerCrossAccountRoleArn}"
  },
  "Action": [
    "kms:DescribeKey",
    "kms:GetPublicKey"
  ],
  "Resource": "*"
}
```

每個陳述式的目的：

**EnclaveDeriveSharedSecret**
+ kms:DeriveSharedSecret — Nitro Enclave 調用，以使用密碼復原金鑰的私有金鑰執行 ECDH 金鑰協議。這衍生了一個共用秘密，用於在遷移工作流程期間解密您的密碼。只有在 enclave 提供有效的 Nitro Enclave 證明文件 (PCR0/1/2 條件） 時，才允許，確保金鑰協議不會發生在 enclave 之外。

**CustomerGetPublicKey**
+ kms:GetPublicKey — 允許擷取密碼復原金鑰的 ECC P-384 公有金鑰。這是由在客戶機器上執行的密碼集合指令碼用來執行密碼的本機 ECDH 加密。
+ kms:DescribeKey — 允許擷取金鑰中繼資料 （金鑰規格、用量、狀態） 以進行驗證。

### 範例 — 保留金鑰
<a name="custom-kms-key-example"></a>

之前：

```
{
  "Version": "2012-10-17", 		 	 	 
  "Statement": [
    {
      "Sid": "YourExistingStatements",
      "Effect": "...",
      "...": "..."
    }
  ]
}
```

之後：

```
{
  "Version": "2012-10-17", 		 	 	 
  "Statement": [
    {
      "Sid": "YourExistingStatements",
      "Effect": "...",
      "...": "..."
     },
    {
      "Sid": "EnclaveGenerateDataKey",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::{account-id}:role/DRSCustomerCrossAccountRole-{network-id}-{region}"
      },
      "Action": "kms:GenerateDataKey",
      "Resource": "*",
      "Condition": {
        "StringLike": {
          "kms:RecipientAttestation:PCR0": "*",
          "kms:RecipientAttestation:PCR1": "*",
          "kms:RecipientAttestation:PCR2": "*"
        },
        "ForAnyValue:StringEquals": {
          "kms:EncryptionContextKeys": [
            "aws:wickr:network:id",
            "aws:wickr:app:id"
          ]
        }
      }
    },
    {
      "Sid": "EnclaveDescribeKey",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::{account-id}:role/DRSCustomerCrossAccountRole-{network-id}-{region}"
      },
      "Action": "kms:DescribeKey",
      "Resource": "*"
    },
    {
      "Sid": "EnclaveDecryptWithAttestation",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::{account-id}:role/DRSCustomerCrossAccountRole-{network-id}-{region}"
      },
      "Action": "kms:Decrypt",
      "Resource": "*",
      "Condition": {
        "StringLike": {
          "kms:RecipientAttestation:PCR0": "*",
          "kms:RecipientAttestation:PCR1": "*",
          "kms:RecipientAttestation:PCR2": "*"
        },
        "ForAnyValue:StringEquals": {
          "kms:EncryptionContextKeys": "aws:wickr:app:id"
        }
      }
    },
    {
      "Sid": "DecryptLambdaDecrypt",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::{account-id}:role/{DecryptionLambdaRoleName}"
      },
      "Action": "kms:Decrypt",
      "Resource": "*",
      "Condition": {
        "ForAnyValue:StringEquals": {
          "kms:EncryptionContextKeys": "aws:wickr:network:id"
        }
      }
    }
  ]
}
```