Using AWS Security for Developers
Rahul Singh
Technical Product Manager


Server-side

Server-side
Client-side


Same algorithm, four key owners
SSE-S3: AWS key, nothing to manageSSE-KMS: your key, CloudTrail, and a key policy attached to the key saying who it will answer
Same algorithm, four key owners
SSE-S3: AWS key, nothing to manageSSE-KMS: your key, CloudTrail, and a key policy attached to the key saying who it will answerDSSE-KMS: two independent layersSSE-C: your key each request, yours to lose

DSSE-KMS99% fewer KMS requestsAt rest is already on

At rest is already on
AWS Database Encryption SDK

Offered, not enforced

Offered, not enforced
Make it a requirement
aws:SecureTransport is false
Public name
Name only your network resolves

Who holds it

Who holds it
If it's yours


Using AWS Security for Developers