A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically separated and encrypted using a unique encryption key derived from their individual customer ID. This ensures that a compromise of one key does not affect other customers' data. The solution needs to be scalable and efficient for a large number of tenants. Which data protection approach should be used?
- ACreate a separate DynamoDB table for each customer, each encrypted with a unique AWS KMS CMK.
- BUtilize AWS KMS Multi-Region keys, and encrypt customer data with these keys based on their geographic region.
- CImplement application-level encryption where the application encrypts each customer's data using a unique key per customer before writing to DynamoDB.
- DUse DynamoDB encryption at rest with a single AWS KMS CMK and apply item-level access control.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement application-level encryption where the application encrypts each customer's data using a unique key per customer before writing to DynamoDB.
Application-level encryption (also known as client-side encryption for DynamoDB) allows the SaaS application to encrypt each customer's data with a unique key derived from their customer ID before storing it in DynamoDB. This ensures logical separation and tenant-specific key management, providing strong isolation and preventing a single key compromise from affecting other tenants, which is essential for multi-tenancy.
Why the other options are wrong
- A. Creating a separate DynamoDB table for each customer is not scalable or cost-effective for a large number of tenants, and doesn't explicitly state the key derivation for individual customer IDs.
- B. Multi-Region keys are for data residency and disaster recovery across regions, not for unique per-tenant encryption within a single application or table.
- D. A single KMS CMK for all data does not provide unique encryption per customer, failing the 'unique encryption key derived from their individual customer ID' requirement.
Application-Level Encryption for Multi-Tenancy
Encrypting data within a multi-tenant application using keys unique to each tenant (or even per-item per tenant) before storing it in a shared database or storage, ensuring strong logical separation and preventing cross-tenant data compromise.
- Keys are derived and managed by the application.
- Provides granular data isolation for multi-tenant architectures.
- Often implemented client-side before data leaves the application.
Memory trick: Unique IDs, unique keys, secure tenants for all days.