SSE-KMS requires that AWS manage the data key but you manage the customer master key (CMK) in AWS KMS.
Amazon S3 supports only symmetric CMKs. You cannot use an asymmetric CMK to encrypt your data in Amazon S3.
Amazon S3 and AWS KMS perform the following actions when you request that your data be decrypted.