External Key Store (XKS) for AWS
AWS Key Management Service (KMS)
Challenge
In today's digital landscape, organizations face increasing challenges in maintaining data sovereignty and complying with stringent regulatory requirements. The need for robust security measures and control over encryption keys has become paramount, especially in multi-cloud environments.
Solution
AWS External Key Store (XKS) addresses these concerns by allowing organizations to manage and secure their encryption keys externally. Integrating AWS External Key Store with our Primus HSM, available both on-premises and in the cloud, offers unparalleled security for your most sensitive workloads.
AWS XKS allows you to protect your resources across the 100+ AWS services, using cryptographic keys stored outside of AWS, giving you complete control over your encryption keys. This advanced feature is perfect for businesses with regulated workloads that demand the highest level of security and compliance. By combining AWS's innovative cloud solutions with the robust security of Primus HSM, on-premises or in the cloud, you can ensure your critical data is safeguarded, meeting the most stringent regulatory requirements. Experience peace of mind with a seamless, secure integration tailored to your needs.
Alternatively, Securosys also supports the AWS Bring Your Own Key (BYOK) processes for keys generated inside a Securosys Primus HSM or via the Securosys CloudHSM service.
How does it work?
The Securosys XKS Proxy serves as an intermediary between AWS KMS External Key Store (XKS) and Securosys Primus HSMs, whether on-premises or in the cloud. Deployed as a Docker image within your AWS infrastructure, the XKS Proxy adds an additional security layer by facilitating bidirectional communication between AWS KMS and your HSMs without accessing cryptographic data. It handles all request forwarding, ensuring secure communication for a range of performance requirements
Key Benefits
Seamless Deployment
Easy to deploy using the user-friendly Securosys XKS Proxy docker image, providing full control over encryption workloads.
Available Worldwide
Securosys Primus HSM, on premises or in the cloud is available anywhere int he world. There are CloudHSM regional clusters in Switzerland, Germany, Singapore, and the USA as well a global cluster. The geo-redundant configuration ensures uninterrupted service.
Scalability
Our Primus HSM technology is modular and meet from low to highest performance (transaction loads) requirements.