Master's thesis idea around encryption key management
Hi
I finished my university some years ago but I need to finally write my master thesis. I need to present idea what should I write about so I need to ask here because I don't have supervisor available now.
Now I have idea to write about: cryptoperiods, key rotations and that a rotated KMS key has an infinite cryptoperiod, while CIS/Prowler/AWS Config all report it as compliant because they only check a boolean flag that key is rotated.
My thesis would build a tool that infers actual cryptoperiods from CloudTrail and S3 Inventory instead of config, flags ciphertext still stranded on retired key versions, and generates a re-encryption plan to close the recipient-usage period.
Does this hold up, or am I missing something obvious? And is it master's thesis level or not? Maybe someone has other idea around this key management and cloud topic.