A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically separated and encrypted with a unique key derived from their individual tenant ID, to meet multi-tenancy isolation requirements and demonstrate strong data segregation. The solution must be scalable and minimize the performance impact on DynamoDB operations. Which encryption strategy should be implemented?
- AConfigure DynamoDB encryption at rest using an AWS KMS customer managed key (CMK) for the entire table.
- BUtilize DynamoDB encryption at rest with an AWS owned key for the entire table to ensure data is encrypted.
- CStore customer data in separate DynamoDB tables, each encrypted with a unique AWS KMS customer managed key (CMK).
- DImplement application-level encryption where the application encrypts each item using a unique key derived from the tenant ID before writing to DynamoDB.
Show answer & explanationAnswer & explanation
Correct answer: D. Implement application-level encryption where the application encrypts each item using a unique key derived from the tenant ID before writing to DynamoDB.
Application-level encryption, where the application uses a unique key (derived from the tenant ID) to encrypt each item before storage, provides the strongest logical separation and isolation required for multi-tenancy. This ensures that even if the underlying DynamoDB encryption is compromised, individual tenant data remains protected by their unique key.
Why the other options are wrong
- A. Encrypting the entire table with a single CMK does not provide unique key derivation per tenant or logical isolation at the item level. All tenants' data would be encrypted with the same key.
- B. AWS owned keys provide encryption at rest but offer no customer control or tenant-specific key derivation. This does not meet the requirement for unique key per tenant.
- C. While separate tables provide strong physical separation, it can lead to significant operational complexity and cost overhead for a large number of tenants. Application-level encryption is more scalable for multi-tenancy with unique keys.
Application-Level Encryption for Multi-Tenancy
Encrypting individual data items within an application using unique, tenant-specific keys before storing them in a shared database, ensuring strong logical separation and isolation for multi-tenant architectures.
- Provides granular data protection per tenant.
- Keys are derived or managed per tenant, not per database or table.
- Offers stronger isolation than database-level encryption for multi-tenant data segregation.
- Requires application code changes for encryption/decryption.
Memory trick: App-Level Keys Isolate Tenants.