Specifically we want to be able to store the ARN of the key used to generate a data key so that KMS key usage can be audited.