Overview
DuoKey for Snowflake
Tri-Secret Secure encryption with customer-managed keys powered by DuoKey AWS XKS MPC
What is Tri-Secret Secure?
Snowflake Tri-Secret Secure (TSS) is an advanced encryption framework available on Business Critical (and higher) editions. It combines three independent secrets into a composite master key that protects all data at rest within a Snowflake account.
Secret 1 — Snowflake Key
Snowflake-managed root key, auto-rotated every 30 days and HSM-protected
Secret 2 — Customer CMK
Your key in AWS KMS backed by DuoKey XKS Proxy and MPC Vault
Secret 3 — Authentication
User identity via MFA, SSO, Okta, or Azure AD with role-based access
Composite Master Key
All three secrets combined — Snowflake cannot decrypt without your CMK
Why DuoKey for Snowflake?
Standard Tri-Secret Secure relies on a customer-managed key (CMK) in AWS KMS. With DuoKey XKS MPC, the CMK is backed by an External Key Store — meaning the actual key material never exists inside AWS. Instead, it is generated and operated through DuoKey's Multi-Party Computation vault with threshold cryptography.
| Capability | Standard AWS KMS CMK | DuoKey XKS MPC CMK |
|---|---|---|
| Key material location | Inside AWS KMS HSMs | DuoKey MPC Vault (external) |
| AWS access to key | AWS can technically access | AWS has zero access |
| Key generation | AWS HSM | Distributed MPC (no single point) |
| Revocation speed | IAM policy change | Instant — disable in DuoKey Cockpit |
| Insider threat protection | Limited | Threshold crypto (2-of-3, 3-of-5) |
| Compliance | SOC 2, HIPAA | Sovereign; supports SOC 2 / HIPAA / GDPR programs |
| Audit trail | CloudTrail only | CloudTrail + DuoKey Audit Log |
Tri-Secret Secure Architecture
Tri-Secret Secure with DuoKey
Three-layer encryption: Snowflake key + Customer-managed key via DuoKey XKS + Authentication
Snowflake Key
Secret 1Customer Key (CMK)
Secret 2Authentication
Secret 3Each level wraps the level below — the composite master key never encrypts raw data directly
Tri-Secret Secure Encrypted Data
Snowflake cannot decrypt without your CMK — revoke access instantly from DuoKey
How the Customer Key Flows
When Snowflake needs to generate or unwrap the composite master key, it calls AWS KMS, which routes the request through DuoKey XKS Proxy to the MPC Vault. The key material never leaves DuoKey.
Customer-Managed Key Chain
How Snowflake accesses your CMK through AWS KMS and DuoKey XKS Proxy
Sovereign Key Control
Neither Snowflake nor AWS can access your data alone — disable the CMK to instantly cut all access
Encryption Key Hierarchy
Snowflake uses a four-level key hierarchy. The composite master key sits at the top and never encrypts raw data directly:
Composite Master Key
Generated by combining Snowflake's root key with your CMK (via DuoKey XKS). This is the top-level key.
Account Master Keys
Derived per Snowflake account. Wrapped (encrypted) by the composite master key.
Table Master Keys
Derived per table or micro-partition group. Wrapped by the account master key.
File Keys (AES-256-GCM)
Each micro-partition file has its own AES-256 key. This is the key that actually encrypts your data at rest.
Rekeying is automatic — when Snowflake rotates the composite master key, it re-wraps all account master keys. No data needs to be re-encrypted.
Key Features
Sovereign Key Control
Key material stays in DuoKey MPC — never enters AWS or Snowflake
Instant Kill Switch
Disable the CMK in DuoKey Cockpit to immediately cut Snowflake access
Threshold Cryptography
MPC key shares distributed — no single party can access the full key
Full Audit Trail
Every key operation logged in both AWS CloudTrail and DuoKey audit
Automatic Key Rotation
Snowflake auto-rotates every 30 days — DuoKey CMK rotation on your schedule
Data Sovereignty
Demonstrate that encryption keys remain under your exclusive control
Use Cases
Regulated Industries
Finance, healthcare, and government organizations meeting GDPR, HIPAA, PCI DSS, or Schrems II requirements for Snowflake workloads
Zero-Trust Data Platforms
Ensure Snowflake cannot decrypt your data without explicit cryptographic authorization from your external key manager
Crypto-Shred Capability
Instantly render all Snowflake data unreadable by revoking the CMK — no need to delete terabytes of data
Data Sovereignty
Prove to auditors and regulators that encryption keys never leave your sovereign jurisdiction
Real-World Case: The 2024 Snowflake Data Breach
In mid-2024, 165+ organizations were compromised through their Snowflake accounts, resulting in one of the largest data breaches in history. This incident demonstrates exactly why Tri-Secret Secure with DuoKey is critical.
What Happened
A financially motivated threat actor (tracked as UNC5537 by Mandiant) used stolen credentials obtained via infostealer malware to access Snowflake customer instances. The compromised accounts did not have MFA enabled, allowing attackers to log in with just a username and password.
| Victim | Records Stolen | Impact |
|---|---|---|
| AT&T | 110+ million call/text metadata records | Nearly all US customers affected — AT&T paid $370,000 ransom |
| Ticketmaster / Live Nation | 560 million customer records (1.3 TB) | Names, addresses, emails, partial credit card data listed for $500,000 |
| Santander Bank | 30 million records | Customer details and staff information offered for $2 million |
| + 162 other companies | Unknown total | Advance Auto Parts, Neiman Marcus, LendingTree, Bausch Health, and more |
How DuoKey TSS Would Have Prevented This
Even if attackers had compromised credentials and logged into Snowflake, Tri-Secret Secure with DuoKey XKS would have rendered the stolen data useless:
Data Encrypted at Rest with Composite Key
All data in Snowflake is encrypted with a composite master key that requires your CMK. Logging into Snowflake does not give access to the raw encryption key — the attacker only sees encrypted data that Snowflake must decrypt on-the-fly using the composite key chain.
Instant Kill Switch on Breach Detection
The moment suspicious activity is detected, you disconnect the XKS Proxy from the DuoKey Cockpit or AWS KMS Console. Snowflake immediately loses the ability to decrypt any data — the attacker sees nothing.
Bulk Exfiltration Impossible
UNC5537 used Snowflake utilities to bulk-export data. With TSS, every decryption operation hits the CMK. Anomalous spikes in key operations would trigger DuoKey audit alerts before large-scale exfiltration could complete.
Crypto-Shredding as Last Resort
Even if some data was exfiltrated in an encrypted state, revoking the CMK means the exported data can never be decrypted — not by the attacker, not by Snowflake, not by AWS.
The 2024 Snowflake breach was entirely caused by stolen credentials without MFA. While MFA is essential, Tri-Secret Secure with DuoKey adds a cryptographic layer of defense that protects data even when authentication is fully compromised. It is the last line of defense between an attacker and your data.
For a live demonstration of the Kill Switch in action, see the Getting Started — Kill Switch Demo.
Prerequisites
Prerequisites
- Snowflake Business Critical edition (or higher)
- Snowflake account on AWS (Azure and GCP use different CMK flows)
- AWS KMS access with External Key Store capability
- DuoKey Cockpit access and XKS Proxy license
- DuoKey MPC Vault deployed and operational
- ACCOUNTADMIN role in Snowflake for CMK registration
Performance Considerations
| Metric | Value |
|---|---|
| CMK operations | Only during key wrapping/unwrapping — not for every query |
| Re-keying impact | Automatic, transparent to users, no downtime |
| 72-hour waiting period | Mandatory before first activation (Snowflake safety feature) |
| XKS Proxy latency | < 50ms recommended (same as standard AWS XKS) |
Tri-Secret Secure adds a dependency on your external key manager. If DuoKey XKS Proxy or AWS KMS is unreachable, Snowflake cannot generate new composite master keys. Ensure high-availability deployment for production workloads.