Supported cryptographic algorithms
AWS KMS supports the following cryptographic algorithms for KMS keys. The algorithms you can use depend on the key spec and key usage of the KMS key. For detailed descriptions of each key spec and the algorithms it supports, see Key spec reference.
For guidance on which algorithms to use and when, see Cryptography algorithms and AWS services.
Symmetric key algorithms
AWS KMS supports the following algorithms for symmetric KMS keys.
| Algorithm | Key usage | Key spec |
|---|---|---|
| AES-256-GCM | Encrypt and decrypt | SYMMETRIC_DEFAULT |
| SM4-128 (China Regions only) | Encrypt and decrypt | SYMMETRIC_DEFAULT |
| HMAC_SHA_224 | Generate and verify MAC | HMAC_224 |
| HMAC_SHA_256 | Generate and verify MAC | HMAC_256 |
| HMAC_SHA_384 | Generate and verify MAC | HMAC_384 |
| HMAC_SHA_512 | Generate and verify MAC | HMAC_512 |
Asymmetric key algorithms
Each asymmetric KMS key has a single key usage that determines which of these algorithms you can use.
| Algorithm | Key usage | Key spec |
|---|---|---|
| RSAES_OAEP_SHA_1, RSAES_OAEP_SHA_256 | Encrypt and decrypt | RSA_2048, RSA_3072, RSA_4096 |
| RSASSA_PSS_SHA_256, RSASSA_PSS_SHA_384, RSASSA_PSS_SHA_512, RSASSA_PKCS1_V1_5_SHA_256, RSASSA_PKCS1_V1_5_SHA_384, RSASSA_PKCS1_V1_5_SHA_512 | Sign and verify | RSA_2048, RSA_3072, RSA_4096 |
| ECDSA_SHA_256 | Sign and verify | ECC_NIST_P256 (secp256r1) |
| ECDSA_SHA_384 | Sign and verify | ECC_NIST_P384 (secp384r1) |
| ECDSA_SHA_512 | Sign and verify | ECC_NIST_P521 (secp521r1) |
| ECDSA_SHA_256 | Sign and verify | ECC_SECG_P256K1 (secp256k1) |
| ED25519_SHA_512, ED25519_PH_SHA_512 | Sign and verify | ECC_NIST_EDWARDS25519 (ed25519) |
| ML_DSA_SHAKE_256 | Sign and verify | ML_DSA_44, ML_DSA_65, ML_DSA_87 |
| ECDH | Key agreement | ECC_NIST_P256, ECC_NIST_P384, ECC_NIST_P521 |
| SM2PKE (encryption), SM2DSA (signing), ECDH (key agreement) | Encrypt and decrypt, sign and verify, or key agreement | SM2 (China Regions only) |