AWS Key Management Service launches External Key Store
Amazon Web Services Key Management Service launched a new tool, the External Key Store, enabling customers to protect data with encryption keys under their own control. Customers can “encrypt or decrypt data with cryptographic keys, independent authorization, and audit in an external key management system outside of AWS.” XKS is based on “a new, external root of trust.” Root keys are stored hardware security modules operated by the user.