Glossary

    AWS CloudHSM

    Data Protection

    AWS CloudHSM provides dedicated Hardware Security Module (HSM) instances in the AWS Cloud. You have exclusive, single-tenant access to the HSM hardware.

    Key Differences from KMS

    • Single-tenant: dedicated HSM appliance (vs KMS multi-tenant)
    • FIPS 140-2 Level 3: physical tamper evidence and tamper response (vs KMS Level 2)
    • Full Key Control: you manage the HSM, AWS cannot access your keys
    • Industry Standards: supports PKCS#11, JCE, CNG/KSP, and OpenSSL interfaces

    Use Cases

    • Regulatory requirements mandating FIPS 140-2 Level 3 (PCI DSS, HIPAA, FedRAMP)
    • Custom key store for AWS KMS (HSM-backed KMS keys)
    • TLS/SSL offloading for web servers
    • Certificate authority (CA) private key protection
    • Code signing and document signing

    Architecture

    • Deploy HSMs in a cluster across multiple AZs for high availability
    • Keys are automatically replicated within the cluster
    • HSMs run inside your VPC - accessible only through ENIs

    Related AWS Services

    Related Content

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.