AWS All-in-One Security Guide: Design, Build, Monitor, and Manage a Fortified Application Ecosystem on AWS by Adrin Mukherjee

AWS All-in-One Security Guide: Design, Build, Monitor, and Manage a Fortified Application Ecosystem on AWS by Adrin Mukherjee

Author:Adrin Mukherjee [Mukherjee, Adrin]
Language: eng
Format: epub
Publisher: BPB Publications
Published: 2022-01-15T00:00:00+00:00


Client-side encryption

Client-side encryption can serve as the security of objects in transit. With this strategy, we (or customers) can encrypt the data/objects before sending the same to Amazon S3. The decryption of the objects also takes place after these have been downloaded from Amazon S3. There are essentially two options for enabling the client-side encryption, which are as follows:

Use a CMK stored in AWS KMS In this case, while uploading an object to S3, we can make a request to AWS KMS for a symmetric data key by passing the key-id of an existing CMK. In response, we will get a plaintext version of the data key which is used to encrypt the data/object and an encrypted version of the same data key which can be uploaded to Amazon S3 as object metadata.

During decryption, we can first download the encrypted object from Amazon S3, along with the object metadata that contains the encrypted version of the symmetric data key. Then, we can send a request to AWS KMS to decrypt the encrypted version of the data key by passing the cipher blob (from object metadata) and the CMK key-id. In response, AWS KMS will send the plaintext version of the data key, which should be used to decrypt the encrypted data/object.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Popular ebooks
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(56085)
What's Done in Darkness by Kayla Perrin(26619)
The Fifty Shades Trilogy & Grey by E L James(19100)
Shot Through the Heart: DI Grace Fisher 2 by Isabelle Grey(19083)
Shot Through the Heart by Mercy Celeste(18955)
Wolf & Parchment: New Theory Spice & Wolf, Vol. 10 by Isuna Hasekura and Jyuu Ayakura(17139)
Python GUI Applications using PyQt5 : The hands-on guide to build apps with Python by Verdugo Leire(17026)
Peren F. Statistics for Business and Economics...Essential Formulas 3ed 2025 by Unknown(16900)
Wolf & Parchment: New Theory Spice & Wolf, Vol. 03 by Isuna Hasekura and Jyuu Ayakura & Jyuu Ayakura(16840)
Wolf & Parchment: New Theory Spice & Wolf, Vol. 01 by Isuna Hasekura and Jyuu Ayakura & Jyuu Ayakura(16470)
The Subtle Art of Not Giving a F*ck by Mark Manson(14384)
The 3rd Cycle of the Betrayed Series Collection: Extremely Controversial Historical Thrillers (Betrayed Series Boxed set) by McCray Carolyn(14158)
Stepbrother Stories 2 - 21 Taboo Story Collection (Brother Sister Stepbrother Stepsister Taboo Pseudo Incest Family Virgin Creampie Pregnant Forced Pregnancy Breeding) by Roxi Harding(13678)
Scorched Earth by Nick Kyme(12788)
Drei Generationen auf dem Jakobsweg by Stein Pia(10984)
Suna by Ziefle Pia(10903)
The Ultimate Python Exercise Book: 700 Practical Exercises for Beginners with Quiz Questions by Copy(10573)
D:\Jan\FTP\HOL\Work\Alien Breed - Tower Assault CD32 Alien Breed II - The Horror Continues Manual 1.jpg by PDFCreator(10550)
De Souza H. Master the Age of Artificial Intelligences. The Basic Guide...2024 by Unknown(10522)
Scythe by Neal Shusterman(10370)