Cloud HSM

From Cramsession
Jump to navigationJump to search
✍️ Verified Author: MflavellClick to view professional profile & credentials

Overview

  • This is a managed services for data encryption.
  • HSM = Hardware Security Module [1]
  • Validated to FIPS 140-2 Level 3
  • Generate encryption keys


A cloud HSM is a custom keystore.

  • Allows the storage of keys outside the KMS in side the CloudHSM cluster.
  • Useful if the key material cannot be stored in a shared environment.


Cloud HSM is deployed as a cluster:

  • The default size is 6 per account per region.
  • Cloud HSM manages key synchronizations for you.


Cloud HSM features

  • High availability.
  • Load balancing.
  • Replication.
  • Scaling.
  • Managed by AWS.
  • Integrates with AWS services.