A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically isolated and encrypted using a unique encryption key, managed by the SaaS provider, to meet multi-tenancy security requirements. The solution should also allow for individual customer key revocation without impacting other tenants. Which encryption approach should the SaaS provider implement?
- AApplication-level encryption where the SaaS application encrypts data with unique keys per tenant before writing to DynamoDB.
- BDynamoDB encryption at rest with a separate customer managed key (CMK) per tenant.
- CDynamoDB encryption at rest with AWS owned keys for all tenants.
- DDynamoDB encryption at rest with a single AWS managed key (KMS) for all tenants.
Show answer & explanationAnswer & explanation
Correct answer: A. Application-level encryption where the SaaS application encrypts data with unique keys per tenant before writing to DynamoDB.
Application-level encryption, where the SaaS application manages unique encryption keys per tenant, provides the strongest logical isolation and allows for individual customer key revocation without affecting other tenants or requiring separate DynamoDB tables per tenant.
Why the other options are wrong
- B. While separate CMKs per tenant could provide unique keys, managing a large number of CMKs for many tenants can become complex, and it still relies on DynamoDB's encryption, which doesn't offer the same level of logical isolation as application-level encryption for multi-tenant scenarios.
- C. AWS owned keys do not provide any tenant-specific encryption or key management, failing the isolation and unique key requirements.
- D. A single AWS managed key (KMS) would encrypt all tenants' data with the same key, failing the unique key and individual key revocation requirements.
Application-Level Encryption for Multi-Tenancy
Application-level encryption involves the application encrypting data with unique, tenant-specific keys before storing it in the database. This provides strong logical isolation, granular key management, and individual key revocation capabilities for multi-tenant SaaS architectures.
- Each tenant's data is encrypted with its own distinct key.
- Keys are managed by the application, often integrating with KMS or an external HSM.
- Enables individual tenant key revocation without affecting other tenants.
- Provides the highest level of logical isolation between tenant data.
Memory trick: Application-Level Encryption Allows Awesome Isolation and A La Carte Key Control.