DATANEWS

Ring’s TAKE Makes Temporary Cloud Key Access the New Default for Home Security Video

Amazon / Ring · 2026-08-26

Ring says its new TAKE system will rotate video keys, restrict temporary cloud access through secure infrastructure and delete Ring’s key copy after 24 hours while preserving cloud features.

Why it matters: Ring’s new default raises expectations for customer-controlled keys and purpose-limited AI processing across the camera and video-analytics market.

Ring is introducing a new default video-encryption architecture designed to preserve cloud-based camera features while reducing how long the company can independently decrypt customer recordings.

The system, called Throw Away the Key Encryption, or TAKE, is scheduled to begin a phased rollout in September 2026 and is intended to become the default for supported Ring customers worldwide after the rollout is complete. Ring’s existing end-to-end encryption option will remain available on a per-camera basis.

Under TAKE, each camera adds another encryption layer using keys that rotate regularly. Ring’s technical paper says its cloud member manages key access inside AWS Nitro Enclaves and that content-encryption keys rotate every five minutes. During the first 24 hours, approved cloud services may retrieve a key only while performing features enabled on the customer’s account, such as smart alerts, video search or video descriptions. Ring says those keys stay in protected memory, are not written to disk and are cleared after processing.

Once a key passes the rolling 24-hour window, Ring says it advances the relevant key-derivation state and permanently loses its retained copy. If a customer later requests a feature that requires an older recording, an enrolled Ring app can temporarily provide key material scoped to the required time range. The service is then expected to discard that key after the processing session.

TAKE is therefore stronger than conventional encryption in transit and at rest, but it is not the same as end-to-end encryption. With TAKE, Ring can temporarily decrypt video inside defined service boundaries. In Ring’s E2EE mode, the cloud member is removed from the camera’s encryption group and Ring says it cannot decrypt video at any point. That stronger restriction also disables cloud-dependent features and Shared Users.

The architecture is based on Messaging Layer Security, the IETF group-encryption standard defined in RFC 9420. Ring uses separate cryptographic groups for customer accounts and individual cameras so devices and Shared Users can be added or removed while group keys advance to new epochs. The design also supports multiple recovery methods, including authorized-device approval, recovery passphrases and platform backup services.

The limitations matter as much as the improvement. TAKE protects video stored by Ring for subscription customers, but Ring’s paper says recordings deliberately shared through external links, third parties or community tools fall under those recipients’ security systems. The initial 24-hour processing window also means TAKE should not be described as zero-access encryption.

Even with those boundaries, the announcement raises the competitive standard for connected-camera providers. Buyers will increasingly expect video platforms to separate storage from lasting decryption authority, rotate keys frequently, limit cloud processing by feature and time, and offer a clear path to a stricter mode when customers are willing to give up cloud intelligence.

Source and attribution →