Server-side encryption (SSE)

Simply put

Server-side encryption (SSE) is a method of encrypting data at rest on

a server or storage system. SSE ensures that data is encrypted before

it's stored on the server, thereby protecting it from unauthorized

access.


There are typically three variants of SSE:

  • SSE-S3 (Server-Side Encryption with Amazon S3): This is offered by AWS for objects stored in Amazon S3 (Simple Storage Service). With SSE-S3, Amazon S3 manages the encryption keys, providing an easy-to-use solution for encrypting data stored in S3 buckets.

  • SSE-KMS (Server-Side Encryption with AWS Key Management Service): With SSE-KMS, the keys used for encryption are managed through AWS Key Management Service (KMS). This provides additional security and control over the encryption keys, allowing for more granular access management and audit capabilities.

  • SSE-C (Server-Side Encryption with Customer-Provided Keys): SSE-C allows customers to provide their own encryption keys, which are used to encrypt and decrypt data stored in the cloud. With SSE-C, the cloud storage provider handles the encryption and decryption process, but the keys are managed by the customer, providing greater control over data security.


See

https://www.learnaws.org/2022/10/09/aws-s3-server-side-encryption/

相关推荐
IT 行者2 天前
Spring Security 7 响应头配置完全指南
java·后端·spring·security
汤愈韬4 天前
串讲实验_弹性网络
网络协议·security
indexsunny6 天前
互联网大厂Java面试实录:Spring Boot微服务在电商场景中的应用与挑战
java·spring boot·redis·mysql·security·microservices·interview
汤愈韬17 天前
防火墙双机热备01(主备模式)
网络·网络协议·网络安全·security·huawei
予枫的编程笔记17 天前
【Java进阶】Spring Security详解
java·spring security·security
汤愈韬17 天前
防火墙双机热备技术之VRRP
网络·网络协议·网络安全·security·huawei
汤愈韬20 天前
NAT策略
网络协议·网络安全·security·huawei
汤愈韬20 天前
Full Cone Nat
网络·网络协议·网络安全·security·huawei
汤愈韬20 天前
NAT ALG (应用层网关)
网络·网络协议·网络安全·security·huawei
汤愈韬21 天前
双向NAT
网络·网络协议·网络安全·security·huawei