
Ring has announced a new video encryption system called Throw Away the Key Encryption (TAKE) that will eventually become the default for all customers worldwide.
The system limits how long Ring retains the encryption keys needed to process recordings while preserving cloud-based features that are unavailable with full end-to-end encryption.
Amazon announced TAKE alongside a technical whitepaper detailing the architecture. The rollout will begin in phases in September, and customers will be notified when they can enroll. Once deployment is complete, TAKE will replace Ring's current default encryption, while the company's existing end-to-end encryption (E2EE) mode will remain optional.
Ring, an Amazon-owned maker of video doorbells and home security cameras, stores customer recordings in its cloud and provides features including Smart Alerts, Video Search, video descriptions, playback, and sharing. Currently, Ring videos are encrypted in transit and at rest, but Ring's cloud services can access video when needed to provide supported features.
TAKE changes that model by giving each camera frequently rotating encryption keys and limiting how long Ring keeps its own copy. Video content keys rotate every five minutes, and Ring permanently deletes its copies after 24 hours.
During that window, Ring's Cloud Member Management Service manages keys inside AWS Nitro Enclaves, isolated computing environments designed to prevent operators or other systems from directly accessing protected root key material. Keys are released only to services authorized for features enabled on the customer's account, and temporary keys used during processing are kept in memory rather than written to disk.
After 24 hours, Ring says the relevant key material is cryptographically ratcheted forward and the previous secrets discarded. The key-management database has no backups, making expired keys infeasible to reconstruct, according to the whitepaper.

Ring
Customers' enrolled phones, tablets, browsers, and supported cameras retain the information necessary to access recordings. If an older recording requires cloud processing, for example, for playback optimization or a newly enabled search feature, the Ring app can temporarily send the required key to the relevant service. Ring says this transfer is push-only, meaning its cloud cannot independently request an expired key from a customer's device.
TAKE is built on the Messaging Layer Security (MLS) protocol and uses AES-128-GCM for video-frame encryption. Newer Ring cameras perform encryption on the device before footage leaves the camera, while older models that cannot support this process encrypt footage immediately after it reaches Ring's infrastructure.
The main privacy trade-off is that TAKE is not end-to-end encryption. Ring can still decrypt video temporarily when cloud features require it. Customers wanting to prevent Ring from decrypting footage at any point can continue using E2EE, but doing so disables features including Video Search, Smart Video Descriptions, cloud-based Smart Alerts, and Shared Users.







Leave a Reply