This guide describes how to integrate AWS Bring Your Own Key (BYOK) with Utimaco Enterprise Secure Key Manager (ESKM).
The AWS BYOK integration with ESKM allows you to use encryption keys that are created and managed in ESKM to protect data in Amazon Web Services (AWS). Using this integration, keys are generated in ESKM and securely imported into AWS Key Management Service (AWS KMS).
This approach helps organizations maintain control over their encryption keys while using AWS services for data encryption and decryption. The integration supports centralized key management and helps meet security and compliance requirements.
Target Audience
This guide is intended for Utimaco ESKM and AWS-BYOK administrators.
Purpose of the Integration
The AWS‑BYOK and Enterprise Secure Key Manager (ESKM) integration allows customers to use AWS services while keeping full control of their encryption keys. With this integration, encryption keys are created, stored, and managed in ESKM, ensuring enhanced security and compliance while enabling secure data encryption in AWS.
Abbreviations
|
Abbreviation |
Meaning |
|---|---|
|
HSM |
Hardware Security Module |
|
AWS |
Amazon Web Services |
|
ARN |
Amazon Resource Name |
|
BYOK |
Bring Your Own Key |
|
KMS |
Key Management Service |
|
ESKM |
Enterprise Secure Key Manager |
|
IAM |
Identity and Access Management |
|
API |
Application Programming Interface |
Abbreviations
Document Conventions
The following conventions are used in this guide:
|
Convention |
Use |
Example |
|---|---|---|
|
Bold |
Items of the Graphical User Interface (GUI), e.g., menu options |
Press OK |
|
|
Code that is given for explanation or as an example, file paths |
|
|
Italic |
References and important terms |
See Sample Chapter in the CryptoServer - Sample Manual |
Document conventions
We use special icons to highlight the most important notes and information.
Here you will find important safety information that should be followed.
Here you will find additional notes or supplementary information.
This message indicates the expected result after the successful execution of an instruction.