Skip to main content

Overview

encrypted dataAWS KMSExternal Key Store (XKS)wrap / unwrapkey controlDuoKey Cockpityour external keyvault APIVault / HSMkey never exportedRevoke the key → instant lockout
AWS KMS keeps the data; DuoKey keeps the key. You stay in control — revoke the key and the data goes dark, everywhere.
Applies to:
AWS KMSExternal Key StoreHashiCorp VaultDuoKey MPC

What is AWS External Key Store?​

AWS External Key Store (XKS) is an advanced feature of AWS KMS that allows you to protect your AWS resources using cryptographic keys stored in an external key management system outside of AWS. This feature is designed for regulated workloads that require encryption keys to remain under your exclusive control.

External Key Store

Custom key store backed by your external key manager

XKS Proxy

Mediates communication between AWS KMS and your key manager

External Key Manager

Your HSM or software key manager generating 256-bit AES keys

Double Encryption

Data encrypted by both AWS KMS and your external key

What is DuoKey XKS Proxy?​

DuoKey XKS Proxy is a built-in feature of DuoKey Cockpit that implements the AWS XKS Proxy specification, letting AWS KMS use a key already stored in a DuoKey Cockpit vault. There is nothing to install separately — you deploy an XKS endpoint from the same Cockpit interface you use to manage your other apps and keys, and each endpoint is bound to the single vault and key you select during deployment.

FeatureDescription
Multiple Vault TypesBack an endpoint with HashiCorp Vault, AWS KMS, or DuoKey MPC
Vault-Backed KeysEach endpoint uses a single vault and key selected at deployment time — no runtime routing
High AvailabilityBuilt-in redundancy and failover capabilities
Centralized ManagementSingle interface to manage keys and endpoints
Compliance ReadyMeets strict regulatory requirements for key sovereignty
Threshold CryptographyOptional DuoKey MPC for distributed key operations
Performance OptimizedLow-latency operations
Comprehensive Audit LoggingDetailed logs of all key operations

How AWS XKS Works​

Architecture Overview​

DuoKey XKS Proxy Architecture

External Key Store with multi-backend routing and sovereign key management

S3S3
EBEBS
RDRDS
λLambda
SMSecrets Mgr
Encrypt / Decrypt Request
▼

AWS KMS

External Key Store
Layer 1 — AWS Key
AWS-managed encryption
SigV4 AuthenticationDouble Encryption
XKS

DuoKey XKS Proxy

External Key Manager
Layer 2 — Your Key
Customer-controlled, HSM-backed
Intelligent RoutingInstant Revocation
DuoKey Cockpit routes to backend
▼
HashiCorp Vault
Transit Engine
CyberArk
PAM Integration
DuoKey MPC
Threshold Crypto
AWS KMS
Cross-Account
Securosys
Primus HSM
Thales Luna
Network HSM

DuoKey Cockpit provides policy-based routing — each key can use a different backend based on compliance and security requirements

Double-Encrypted Response
▼

Double-Encrypted Data in AWS

Neither AWS nor DuoKey can decrypt alone — revoke access instantly by disabling the external key

AWS Key (L1)+ Your Key (L2)= Protected

Encryption Workflow​

Encryption Workflow

Step-by-step double encryption through DuoKey XKS Proxy

1
AWS Service
Encrypt Request
S3, EBS, or RDS sends encrypt request to AWS KMS using XKS-backed key
2
AWS KMS
Layer 1 Encryption
Generates data key and encrypts with AWS-managed key material
3
AWS KMS
Proxy Request
Sends ciphertext + external key ID + SigV4 signature to XKS Proxy
4
DuoKey Cockpit
Intelligent Routing
Routes request to the correct backend based on key policy
5
External KMS
Layer 2 Encryption
Your key manager encrypts using your external key (AES-256)
6
XKS Proxy
Double-Encrypted Response
Returns ciphertext through secure channel (TLS 1.2+) to AWS KMS
7
AWS Service
Store Encrypted Data
AWS service stores the double-encrypted data with encrypted data key
1

Encryption Request

An AWS service needs to encrypt data and sends a request to AWS KMS using a KMS key in your external key store

2

Double Encryption Preparation

AWS KMS generates a data key and performs the first layer of encryption using AWS-managed key material specific to your KMS key

3

Proxy Request

AWS KMS sends an encrypt request to your DuoKey XKS Proxy, including the AWS-encrypted ciphertext, external key ID, and SigV4 authentication signature

4

Vault Lookup

DuoKey Cockpit forwards the request to the vault backing this endpoint's key (HashiCorp Vault, AWS KMS, or DuoKey MPC, as configured when the endpoint was deployed)

5

External Encryption

The selected key manager encrypts the data using your external key, completing the double encryption process

6

Response

The double-encrypted ciphertext is returned through the proxy to AWS KMS, then to the requesting AWS service

7

Storage

The AWS service stores the encrypted data along with the encrypted data key

Double Encryption Process​

Double Encryption Process

Two independent encryption layers — both required for decryption

Plaintext Data
From AWS service (S3, EBS, RDS...)
▼
LAYER 1 — AWS KMS
AWS-Managed Encryption
AWS KMS encrypts using key material specific to your KMS key
Ciphertext sent to XKS Proxy
▼
LAYER 2 — YOUR EXTERNAL KEY
Customer-Controlled Encryption
Your external key manager encrypts using AES-256 key under your exclusive control
▼

Double-Encrypted Ciphertext

Meets or exceeds standard AWS KMS encryption strength

Neither party decrypts alone Instant crypto-shred Transit-protected

Dual Protection

Neither AWS KMS nor you can decrypt the ciphertext alone

Transit Security

Data is protected in transit from AWS to your proxy

Strength Guarantee

Ciphertext meets or exceeds standard AWS KMS encryption strength

Instant Shredding

Crypto-shred capability by revoking external key access

Key Features​

Complete Key Sovereignty

Keys never leave your external key manager. AWS cannot access them.

Multiple Vault Types

Back an endpoint with HashiCorp Vault, AWS KMS, or DuoKey MPC

Vault-Backed Keys

Each endpoint uses a single vault and key you select during deployment

Instant Revocation

Immediately revoke AWS access by disabling external keys

Enhanced Security

mTLS support, SigV4 auth, and independent authorization

High Performance

Optimized for low-latency operations well within AWS KMS's 250ms proxy timeout

Supported AWS Services​

  • Amazon EC2: EBS volume encryption
  • AWS Lambda: Environment variable encryption
  • Amazon ECS: Task definition encryption

Proxy Connectivity Options​

OptionDescriptionBest For
Public EndpointAWS KMS sends requests over internet to your endpointDevelopment, testing, mature internet security
VPC Endpoint ServiceTraffic stays on AWS network via VPC endpointProduction, regulated workloads, strict compliance

Use Cases​

Regulated Industries

Healthcare, finance, and government organizations meeting GDPR, HIPAA, PCI DSS, or FedRAMP requirements

Data Sovereignty

Demonstrate cryptographic keys remain under exclusive control in specific geographic locations

Zero-Trust Architecture

AWS authenticates for every key operation with instant revocation capability

Multi-Cloud Key Management

Centralized key management across AWS, Azure, GCP through single external key manager

Architecture Scenarios​

AWS KMS → Internet → DuoKey Cockpit (XKS Proxy) → HashiCorp Vault

Ideal for organizations already using HashiCorp Vault for secrets management who want to extend their vault infrastructure to protect AWS resources.

Prerequisites​

Prerequisites

  • AWS account with appropriate permissions
  • AWS KMS access in your target region
  • DuoKey Cockpit access and XKS Proxy license
  • External key manager already configured as a vault in DuoKey Cockpit (e.g. HashiCorp Vault or DuoKey MPC)
  • TLS 1.2+ support with HTTP/1.1 or later
  • Public IP or VPC endpoint infrastructure
  • Round-trip time (RTT) of 35ms or less recommended

Performance Considerations​

ConfigurationAverage Latency
Standard KMS Key~10ms
XKS with Optimal Network~50-100ms
XKS with High Network RTT100-200ms+
Note

Latency includes AWS KMS processing (~10ms), network round-trip, proxy processing (~5-10ms), and external key manager operation (~10-50ms).

Quotas and Limits​

Warning
  • Maximum 10 custom key stores per account per region
  • Lower request quotas for XKS keys compared to standard KMS keys
  • Not supported in China (Beijing) and China (Ningxia) regions

Unsupported Features​

  • Asymmetric KMS keys
  • HMAC KMS keys
  • KMS keys with imported key material
  • Automatic key rotation
  • Multi-region keys

Security Best Practices​

Security Checklist

Backup StrategyMaintain secure backups of all external keys
Key RotationImplement regular key rotation schedules
Access ControlUse least-privilege access for all operations
TLS ConfigurationUse TLS 1.2+ with strong cipher suites
Audit LoggingEnable detailed logging on all components
Network SegmentationIsolate proxy in dedicated network segment

Next Steps​