Skip to main content

Overview

DuoKey
DuoKey for Snowflake — Tri-Secret Secure Overview
19 September 2026
encrypted dataSnowflakeTri-Secret Securewrap / unwrapkey controlDuoKey Cockpityour key (BYOK)vault APIVault / HSMkey never exportedRevoke the key → instant lockout
Snowflake keeps the data; DuoKey keeps the key. You stay in control — revoke the key and the data goes dark, everywhere.
Applies to:
Snowflake Business CriticalAWS KMS External Key StoreDuoKey XKS ProxyDuoKey MPC KMS

What is Tri-Secret Secure?​

Snowflake Tri-Secret Secure (TSS) is an advanced encryption framework available on Business Critical (and higher) editions. It combines three independent secrets into a composite master key that protects all data at rest within a Snowflake account.

Secret 1 — Snowflake Key

Snowflake-managed root key, auto-rotated every 30 days and HSM-protected

Secret 2 — Customer CMK

Your key in AWS KMS backed by DuoKey XKS Proxy and MPC Vault

Secret 3 — Authentication

User identity via MFA, SSO, Okta, or Azure AD with role-based access

Composite Master Key

All three secrets combined — Snowflake cannot decrypt without your CMK

Why DuoKey for Snowflake?​

Standard Tri-Secret Secure relies on a customer-managed key (CMK) in AWS KMS. With DuoKey XKS MPC, the CMK is backed by an External Key Store — meaning the actual key material never exists inside AWS. Instead, it is generated and operated through DuoKey's Multi-Party Computation vault with threshold cryptography.

CapabilityStandard AWS KMS CMKDuoKey XKS MPC CMK
Key material locationInside AWS KMS HSMsDuoKey MPC Vault (external)
AWS access to keyAWS can technically accessAWS has zero access
Key generationAWS HSMDistributed MPC (no single point)
Revocation speedIAM policy changeInstant — disable in DuoKey Cockpit
Insider threat protectionLimitedThreshold crypto (2-of-3, 3-of-5)
ComplianceSOC 2, HIPAASovereign; supports SOC 2 / HIPAA / GDPR programs
Audit trailCloudTrail onlyCloudTrail + DuoKey Audit Log

Tri-Secret Secure Architecture​

Tri-Secret Secure with DuoKey

Three-layer encryption: Snowflake key + Customer-managed key via DuoKey XKS + Authentication

WHWarehouses
DBDatabases
STStages
DSData Shares
SRStreams
Composite Master Key Required
▼

Snowflake Key

Secret 1
Root Key
Snowflake-managed HSM
Auto-rotated 30 daysHSM-Protected
+

Customer Key (CMK)

Secret 2
DuoKey XKS + MPC
Your key, your control
XKS External Key StoreInstant Revocation
+

Authentication

Secret 3
User Identity
MFA + SSO / Okta / Azure AD
Multi-Factor AuthRBAC
Combined into Composite Master Key
▼
Composite Master Key
Snowflake + CMK combined
Root
Account Master Keys
Per-account encryption
L1
Table Master Keys
Per-table encryption
L2
File Keys
Per-file encryption (AES-256)
L3

Each level wraps the level below — the composite master key never encrypts raw data directly

▼

Tri-Secret Secure Encrypted Data

Snowflake cannot decrypt without your CMK — revoke access instantly from DuoKey

Snowflake Key+ DuoKey CMK+ Auth= Protected

How the Customer Key Flows​

When Snowflake needs to generate or unwrap the composite master key, it calls AWS KMS, which routes the request through DuoKey XKS Proxy to the MPC Vault. The key material never leaves DuoKey.

Customer-Managed Key Chain

How Snowflake accesses your CMK through AWS KMS and DuoKey XKS Proxy

SNOWFLAKE
Snowflake Encryption Service
Requests CMK unwrap for composite master key generation
AWS KMS API Call
▼
AWS KMS — EXTERNAL KEY STORE
AWS KMS
XKS-backed CMK
DuoKey XKS Proxy
SigV4 authenticated
TLS 1.2+
Routed to DuoKey MPC Vault
▼
DUOKEY SOVEREIGN KMS
DuoKey Cockpit
Policy routing
MPC Vault
Threshold crypto
HSM-Protected
Audit Log
Full traceability
Key material never leaves DuoKey
▼

Sovereign Key Control

Neither Snowflake nor AWS can access your data alone — disable the CMK to instantly cut all access

Encryption Key Hierarchy​

Snowflake uses a four-level key hierarchy. The composite master key sits at the top and never encrypts raw data directly:

1

Composite Master Key

Generated by combining Snowflake's root key with your CMK (via DuoKey XKS). This is the top-level key.

2

Account Master Keys

Derived per Snowflake account. Wrapped (encrypted) by the composite master key.

3

Table Master Keys

Derived per table or micro-partition group. Wrapped by the account master key.

4

File Keys (AES-256-GCM)

Each micro-partition file has its own AES-256 key. This is the key that actually encrypts your data at rest.

Note

Rekeying is automatic — when Snowflake rotates the composite master key, it re-wraps all account master keys. No data needs to be re-encrypted.

Key Features​

Sovereign Key Control

Key material stays in DuoKey MPC — never enters AWS or Snowflake

Instant Kill Switch

Disable the CMK in DuoKey Cockpit to immediately cut Snowflake access

Threshold Cryptography

MPC key shares distributed — no single party can access the full key

Full Audit Trail

Every key operation logged in both AWS CloudTrail and DuoKey audit

Automatic Key Rotation

Snowflake auto-rotates every 30 days — DuoKey CMK rotation on your schedule

Data Sovereignty

Demonstrate that encryption keys remain under your exclusive control

Use Cases​

Regulated Industries

Finance, healthcare, and government organizations meeting GDPR, HIPAA, PCI DSS, or Schrems II requirements for Snowflake workloads

Zero-Trust Data Platforms

Ensure Snowflake cannot decrypt your data without explicit cryptographic authorization from your external key manager

Crypto-Shred Capability

Instantly render all Snowflake data unreadable by revoking the CMK — no need to delete terabytes of data

Data Sovereignty

Prove to auditors and regulators that encryption keys never leave your sovereign jurisdiction

Real-World Case: The 2024 Snowflake Data Breach​

Warning

In mid-2024, 165+ organizations were compromised through their Snowflake accounts, resulting in one of the largest data breaches in history. This incident demonstrates exactly why Tri-Secret Secure with DuoKey is critical.

What Happened​

A financially motivated threat actor (tracked as UNC5537 by Mandiant) used stolen credentials obtained via infostealer malware to access Snowflake customer instances. The compromised accounts did not have MFA enabled, allowing attackers to log in with just a username and password.

VictimRecords StolenImpact
AT&T110+ million call/text metadata recordsNearly all US customers affected — AT&T paid $370,000 ransom
Ticketmaster / Live Nation560 million customer records (1.3 TB)Names, addresses, emails, partial credit card data listed for $500,000
Santander Bank30 million recordsCustomer details and staff information offered for $2 million
+ 162 other companiesUnknown totalAdvance Auto Parts, Neiman Marcus, LendingTree, Bausch Health, and more

How DuoKey TSS Would Have Prevented This​

Even if attackers had compromised credentials and logged into Snowflake, Tri-Secret Secure with DuoKey XKS would have rendered the stolen data useless:

1.

Data Encrypted at Rest with Composite Key

All data in Snowflake is encrypted with a composite master key that requires your CMK. Logging into Snowflake does not give access to the raw encryption key — the attacker only sees encrypted data that Snowflake must decrypt on-the-fly using the composite key chain.

2.

Instant Kill Switch on Breach Detection

The moment suspicious activity is detected, you disconnect the XKS Proxy from the DuoKey Cockpit or AWS KMS Console. Snowflake immediately loses the ability to decrypt any data — the attacker sees nothing.

3.

Bulk Exfiltration Impossible

UNC5537 used Snowflake utilities to bulk-export data. With TSS, every decryption operation hits the CMK. Anomalous spikes in key operations would trigger DuoKey audit alerts before large-scale exfiltration could complete.

4.

Crypto-Shredding as Last Resort

Even if some data was exfiltrated in an encrypted state, revoking the CMK means the exported data can never be decrypted — not by the attacker, not by Snowflake, not by AWS.

Important

The 2024 Snowflake breach was entirely caused by stolen credentials without MFA. While MFA is essential, Tri-Secret Secure with DuoKey adds a cryptographic layer of defense that protects data even when authentication is fully compromised. It is the last line of defense between an attacker and your data.

Tip

For a live demonstration of the Kill Switch in action, see the Getting Started — Kill Switch Demo.

Prerequisites​

Prerequisites

  • Snowflake Business Critical edition (or higher)
  • Snowflake account on AWS (Azure and GCP use different CMK flows)
  • AWS KMS access with External Key Store capability
  • DuoKey Cockpit access and XKS Proxy license
  • DuoKey MPC Vault deployed and operational
  • ACCOUNTADMIN role in Snowflake for CMK registration

Performance Considerations​

MetricValue
CMK operationsOnly during key wrapping/unwrapping — not for every query
Re-keying impactAutomatic, transparent to users, no downtime
72-hour waiting periodMandatory before first activation (Snowflake safety feature)
XKS Proxy latency< 50ms recommended (same as standard AWS XKS)
Important

Tri-Secret Secure adds a dependency on your external key manager. If DuoKey XKS Proxy or AWS KMS is unreachable, Snowflake cannot generate new composite master keys. Ensure high-availability deployment for production workloads.

Next Steps​

© 2026 DuoKey SA - Confidentialdocs.duokey.com | [email protected]