SYSTEM Cited by 4 sources
AWS KMS¶
AWS Key Management Service (KMS) is AWS's managed key-management service. It hosts customer keys (HSM-backed), exposes Wrap/Unwrap / Encrypt/Decrypt / Sign APIs under IAM, logs every operation to CloudTrail, and is the AWS endpoint of the Customer-Managed Key pattern for most AWS-hosted services.
Residency-aware recovery¶
Cryptographic-boundary recovery uses KMS as the controlled transition between an encrypted cross-Region copy and recoverable plaintext. A customer key policy can deny decryption in the recovery Region until an authorized recovery decision changes it. The source recommends limiting policy mutation to named principals/condition keys and optionally separating MFA approval from operational credentials; for client-side-encrypted S3 backups, multi-Region KMS keys can preserve the same key material across Regions. (Source: sources/2026-08-13-aws-recovery-strategies-to-meet-data-residency-requirements)
Seen in¶
- sources/2026-04-20-databricks-take-control-customer-managed-keys-for-lakebase-postgres — one of the three KMSes Databricks' Lakebase CMK feature integrates with; keys identified by ARN; Databricks assumes a customer- granted IAM role to Wrap/Unwrap KEKs under an concepts/envelope-encryption hierarchy; every operation lands in the customer's CloudTrail.
Related¶
- concepts/envelope-encryption
- concepts/byok-bring-your-own-key
- cryptographic-shredding
- systems/azure-key-vault, systems/google-cloud-kms — the other two cloud-native KMSes Lakebase CMK supports.
Seen in¶
- sources/2026-09-18-aws-readyons-four-walls-of-tenant-isolation-on-amazon-eks — Per-tenant KMS key as a data-isolation wall. ReadyOn gives each tenant a distinct KMS key so every tenant's data-at-rest in its dedicated Aurora cluster is encrypted under a separate key — even if raw storage were accessed, one tenant's key cannot decrypt another's (envelope encryption as cross-tenant cryptographic separation). Framed as strictly easier to reason about than per-tenant row-level security in a shared database.
- sources/2026-09-30-aws-how-mhk-built-a-hipaa-eligible-agentic-ai-solution-on-amazon-bedrock — KMS doing double duty: per-client encryption keys AND capability-token signing. In MHK's SmartProminence AI Orchestrator, every health-plan client has its own KMS key; S3 documents are double-encrypted (S3 SSE + client-specific KMS) and the database adds row-level encryption on top of RDS storage-level encryption — a misrouted job can't be decrypted by the receiving agent because it lacks that client's key (tenant isolation enforced cryptographically). KMS also signs/validates the per-dispatch capability tokens that scope what each controller/agent can touch, so even a compromised agent can't reach other steps, workflows, or clients. (Source: sources/2026-09-30-aws-how-mhk-built-a-hipaa-eligible-agentic-ai-solution-on-amazon-bedrock)
Related¶
- concepts/envelope-encryption
- concepts/byok-bring-your-own-key
- concepts/tenant-isolation — per-client KMS keys as a cryptographic isolation wall.
- systems/smartprominence-ai-orchestrator — per-client keys + capability-token signing.