In today’s digital world, ensuring the security of stored data is a top priority. Popular cloud storage service, Amazon S3, has introduced a new feature to enhance its data protection measures. This feature is known as “Dual-layer server-side encryption with keys stored in AWS Key Management Service” (DSSE-KMS for short).
In simple terms, DSSE-KMS allows for two separate layers of encryption (or security) to be applied to the data you store in Amazon S3. This means that your data is doubly protected, making it even harder for unauthorized users to access it. This double layer of protection meets high security standards set by national and international guidelines.
What sets Amazon S3’s feature apart is that it allows customers to apply this double encryption to each individual piece of data (or object) they store. Additionally, Amazon S3 gives customers control over the keys used for both layers of encryption, ensuring that customers have greater control over their data security.
A key benefit of DSSE-KMS is that it simplifies the process of applying this double layer of security to your data. It removes the need for customers to have their own complex encryption systems in place. DSSE-KMS uses a strong security method known as the 256-bit Advanced Encryption Standard with Galois Counter Mode (AES-GCM) for each layer of encryption.
Furthermore, with DSSE-KMS, customers can also make use of the AWS Key Management Service (KMS) to generate data keys. This means customers can decide who has access to their keys and when these keys should be replaced with new ones. With these features in place, customers can easily analyze their securely stored data with other AWS services such as Amazon Athena and Amazon SageMaker.
However, it’s important to note that this added layer of security comes at an extra cost and is available in all regions where AWS services are provided. For a better understanding of these costs, customers can visit the Amazon S3 and AWS KMS pricing pages. For more information on encryption options available on Amazon S3 and DSSE-KMS, customers can refer to the S3 User Guide and the AWS News Blog respectively.
With the introduction of the dual-layer encryption feature, Amazon S3 continues to prioritize the security of customers’ stored data. This new feature offers customers greater control and security, enhancing their experience with Amazon S3’s cloud storage services.