Overview
DuoKey AWS XKS Proxy
Use AWS KMS with encryption keys stored in external key managers you control
What is AWS External Key Store?
AWS External Key Store (XKS) is an advanced feature of AWS KMS that allows you to protect your AWS resources using cryptographic keys stored in an external key management system outside of AWS. This feature is designed for regulated workloads that require encryption keys to remain under your exclusive control.
External Key Store
Custom key store backed by your external key manager
XKS Proxy
Mediates communication between AWS KMS and your key manager
External Key Manager
Your HSM or software key manager generating 256-bit AES keys
Double Encryption
Data encrypted by both AWS KMS and your external key
What is DuoKey XKS Proxy?
DuoKey XKS Proxy is a built-in feature of DuoKey Cockpit that implements the AWS XKS Proxy specification, letting AWS KMS use a key already stored in a DuoKey Cockpit vault. There is nothing to install separately — you deploy an XKS endpoint from the same Cockpit interface you use to manage your other apps and keys, and each endpoint is bound to the single vault and key you select during deployment.
| Feature | Description |
|---|---|
| Multiple Vault Types | Back an endpoint with HashiCorp Vault, AWS KMS, or DuoKey MPC |
| Vault-Backed Keys | Each endpoint uses a single vault and key selected at deployment time — no runtime routing |
| High Availability | Built-in redundancy and failover capabilities |
| Centralized Management | Single interface to manage keys and endpoints |
| Compliance Ready | Meets strict regulatory requirements for key sovereignty |
| Threshold Cryptography | Optional DuoKey MPC for distributed key operations |
| Performance Optimized | Low-latency operations |
| Comprehensive Audit Logging | Detailed logs of all key operations |
How AWS XKS Works
Architecture Overview
DuoKey XKS Proxy Architecture
External Key Store with multi-backend routing and sovereign key management
AWS KMS
External Key StoreDuoKey XKS Proxy
External Key ManagerDuoKey Cockpit provides policy-based routing — each key can use a different backend based on compliance and security requirements
Double-Encrypted Data in AWS
Neither AWS nor DuoKey can decrypt alone — revoke access instantly by disabling the external key
Encryption Workflow
Encryption Workflow
Step-by-step double encryption through DuoKey XKS Proxy
Encryption Request
An AWS service needs to encrypt data and sends a request to AWS KMS using a KMS key in your external key store
Double Encryption Preparation
AWS KMS generates a data key and performs the first layer of encryption using AWS-managed key material specific to your KMS key
Proxy Request
AWS KMS sends an encrypt request to your DuoKey XKS Proxy, including the AWS-encrypted ciphertext, external key ID, and SigV4 authentication signature
Vault Lookup
DuoKey Cockpit forwards the request to the vault backing this endpoint's key (HashiCorp Vault, AWS KMS, or DuoKey MPC, as configured when the endpoint was deployed)
External Encryption
The selected key manager encrypts the data using your external key, completing the double encryption process
Response
The double-encrypted ciphertext is returned through the proxy to AWS KMS, then to the requesting AWS service
Storage
The AWS service stores the encrypted data along with the encrypted data key
Double Encryption Process
Double Encryption Process
Two independent encryption layers — both required for decryption
Double-Encrypted Ciphertext
Meets or exceeds standard AWS KMS encryption strength
Dual Protection
Neither AWS KMS nor you can decrypt the ciphertext alone
Transit Security
Data is protected in transit from AWS to your proxy
Strength Guarantee
Ciphertext meets or exceeds standard AWS KMS encryption strength
Instant Shredding
Crypto-shred capability by revoking external key access
Key Features
Complete Key Sovereignty
Keys never leave your external key manager. AWS cannot access them.
Multiple Vault Types
Back an endpoint with HashiCorp Vault, AWS KMS, or DuoKey MPC
Vault-Backed Keys
Each endpoint uses a single vault and key you select during deployment
Instant Revocation
Immediately revoke AWS access by disabling external keys
Enhanced Security
mTLS support, SigV4 auth, and independent authorization
High Performance
Optimized for low-latency operations well within AWS KMS's 250ms proxy timeout
Supported AWS Services
- Amazon EC2: EBS volume encryption
- AWS Lambda: Environment variable encryption
- Amazon ECS: Task definition encryption
Proxy Connectivity Options
| Option | Description | Best For |
|---|---|---|
| Public Endpoint | AWS KMS sends requests over internet to your endpoint | Development, testing, mature internet security |
| VPC Endpoint Service | Traffic stays on AWS network via VPC endpoint | Production, regulated workloads, strict compliance |
Use Cases
Regulated Industries
Healthcare, finance, and government organizations meeting GDPR, HIPAA, PCI DSS, or FedRAMP requirements
Data Sovereignty
Demonstrate cryptographic keys remain under exclusive control in specific geographic locations
Zero-Trust Architecture
AWS authenticates for every key operation with instant revocation capability
Multi-Cloud Key Management
Centralized key management across AWS, Azure, GCP through single external key manager
Architecture Scenarios
AWS KMS → Internet → DuoKey Cockpit (XKS Proxy) → HashiCorp Vault
Ideal for organizations already using HashiCorp Vault for secrets management who want to extend their vault infrastructure to protect AWS resources.
Prerequisites
Prerequisites
- AWS account with appropriate permissions
- AWS KMS access in your target region
- DuoKey Cockpit access and XKS Proxy license
- External key manager already configured as a vault in DuoKey Cockpit (e.g. HashiCorp Vault or DuoKey MPC)
- TLS 1.2+ support with HTTP/1.1 or later
- Public IP or VPC endpoint infrastructure
- Round-trip time (RTT) of 35ms or less recommended
Performance Considerations
| Configuration | Average Latency |
|---|---|
| Standard KMS Key | ~10ms |
| XKS with Optimal Network | ~50-100ms |
| XKS with High Network RTT | 100-200ms+ |
Latency includes AWS KMS processing (~10ms), network round-trip, proxy processing (~5-10ms), and external key manager operation (~10-50ms).
Quotas and Limits
- Maximum 10 custom key stores per account per region
- Lower request quotas for XKS keys compared to standard KMS keys
- Not supported in China (Beijing) and China (Ningxia) regions
Unsupported Features
- Asymmetric KMS keys
- HMAC KMS keys
- KMS keys with imported key material
- Automatic key rotation
- Multi-region keys