UPDATED 14:27 EDT / AUGUST 11 2016

NEWS

AWS now lets companies use on-premise crypto gear to protect their workloads

Though the CIA has deemed Amazon Inc.’s cloud safe enough to run sensitive governmental workloads, some companies still struggle to meet their compliance requirements using the built-in security functionality. To amend the situation, the vendor is rolling out a new encryption feature that makes it possible to harness external cryptographic hardware.

More specifically, the addition enables companies to make use of so-called Hardware Security Modules (HSMs), specialized devices that are designed for the sole purpose of safekeeping encryption keys. They usually come in a temper-proof chassis without any ports and pack extensive alerting functionality capable of detecting even the smallest sign of foul play. Moreover, the on-board software can be configured to periodically refresh keys so that hackers only have a limited time window to cause havoc in the unlikely event they find a vulnerability.

Such equipment is used mainly in the public sector and highly regulated industries like banking where encryption keys are legally required to be kept behind the firewall. Adding support for HSMs should help Amazon court organizations in these segments more effectively amid the growing competition from Microsoft Corp, which has allowed cloud users to use their own cryptographic gear since last year. The software giant is enhancing security throughout its entire infrastructure- and software-as-service lineup in a bid to stand out from rivals.

Redmond most recently unveiled a cloud-supported security engine for Windows that uses machine learning technology to find malicious behavior. Its algorithms then diagnose the threat and inform IT staff whether it’s merely an isolated breach or part of a broader issue. As the stakes continue to rise in the public cloud, Amazon and Microsoft can be expected to add yet more security functionality for their respective platforms.

Image via Pixelcreatures

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.