Key Management System (KMS) FOR AWS XKS
AWS KMS has a feature called AWS External Key Store (XKS) that allows secure communication with external encryption keys. This means that you hold your own key (HYOK).
Using this solution, it’s possible to encrypt data with private external keys for many AWS services including Amazon EBS, AWS Lambda, Amazon S3, Amazon DynamoDB, and over 100 other services. It is possible to do this without requiring any modifications to the current configuration parameters or code used for these services.
Obtain digital sovereignty and meet compliance requirements
- Using CipherTrust manager and Cloud Key Manager (CCKM).
- Hold keys outside of AWS to align with the shared responsibility model.
- Choose between industry-leading CipherTrust Manager or Thales HSM as a key source.
- Manage Native, BYOK, HYOK keys across clouds from a single console, maximizing choice.
- Demonstrate compliance with privacy regulations such as GDPR, Shrems II, PCI-DSS, CCPA.
- Improve operational sovereignty to protect against internal and external threats.
- Centralize control of keys outside of cloud providers to reduce the threat surface.
- Simplify key management to increase efficiency and reduce costs.
- Speed up migration to the cloud for faster time to value.
Learn more
How is with sensitive data in Amazon (AWS)? Is it even possible?
The eSam legal expert group has stated that using American cloud services for sensitive data is not feasible without strong encryption
Unlock the Possibilities: A HYOK Solution for SaaS Companies
Hold Your Own Keyrefers to the ability for customers to point to their private key in order to protect their data within a SaaS service.
BYOK – ”Bring Your Own Key”
BYOK stands for ”Bring Your Own Key” and is a security concept that allows organizations to retain control over the cryptographic keys