View a markdown version of this page

Supported cryptographic algorithms - AWS Key Management Service

Supported cryptographic algorithms

AWS KMS supports the following cryptographic algorithms for KMS keys. The algorithms you can use depend on the key spec and key usage of the KMS key. For detailed descriptions of each key spec and the algorithms it supports, see Key spec reference.

For guidance on which algorithms to use and when, see Cryptography algorithms and AWS services.

Symmetric key algorithms

AWS KMS supports the following algorithms for symmetric KMS keys.

Supported algorithms for symmetric KMS keys
Algorithm Key usage Key spec
AES-256-GCM Encrypt and decrypt SYMMETRIC_DEFAULT
SM4-128 (China Regions only) Encrypt and decrypt SYMMETRIC_DEFAULT
HMAC_SHA_224 Generate and verify MAC HMAC_224
HMAC_SHA_256 Generate and verify MAC HMAC_256
HMAC_SHA_384 Generate and verify MAC HMAC_384
HMAC_SHA_512 Generate and verify MAC HMAC_512

Asymmetric key algorithms

Each asymmetric KMS key has a single key usage that determines which of these algorithms you can use.

Supported algorithms for asymmetric KMS keys
Algorithm Key usage Key spec
RSAES_OAEP_SHA_1, RSAES_OAEP_SHA_256 Encrypt and decrypt RSA_2048, RSA_3072, RSA_4096
RSASSA_PSS_SHA_256, RSASSA_PSS_SHA_384, RSASSA_PSS_SHA_512, RSASSA_PKCS1_V1_5_SHA_256, RSASSA_PKCS1_V1_5_SHA_384, RSASSA_PKCS1_V1_5_SHA_512 Sign and verify RSA_2048, RSA_3072, RSA_4096
ECDSA_SHA_256 Sign and verify ECC_NIST_P256 (secp256r1)
ECDSA_SHA_384 Sign and verify ECC_NIST_P384 (secp384r1)
ECDSA_SHA_512 Sign and verify ECC_NIST_P521 (secp521r1)
ECDSA_SHA_256 Sign and verify ECC_SECG_P256K1 (secp256k1)
ED25519_SHA_512, ED25519_PH_SHA_512 Sign and verify ECC_NIST_EDWARDS25519 (ed25519)
ML_DSA_SHAKE_256 Sign and verify ML_DSA_44, ML_DSA_65, ML_DSA_87
ECDH Key agreement ECC_NIST_P256, ECC_NIST_P384, ECC_NIST_P521
SM2PKE (encryption), SM2DSA (signing), ECDH (key agreement) Encrypt and decrypt, sign and verify, or key agreement SM2 (China Regions only)