1. 程式人生 > >New – Server-Side Encryption for Amazon Simple Queue Service (SQS)

New – Server-Side Encryption for Amazon Simple Queue Service (SQS)

As one of the most venerable members of the AWS family of services, Amazon Simple Queue Service (SQS) is an essential part of many applications. Presentations such as Amazon SQS for Better Architecture and Massive Message Processing with Amazon SQS and Amazon DynamoDB explain how SQS can be used to build applications that are resilient and highly scalable.

Today we are making SQS even more useful by adding support for server-side encryption. You can now choose to have SQS encrypt messages stored in both Standard and FIFO queues using an encryption key provided by AWS Key Management Service (KMS). You can choose this option when you create your queue and you can also set it for an existing queue.

SSE encrypts the body of the message, but does not touch the queue metadata, the message metadata, or the per-queue metrics. Adding encryption to an existing queue does not encrypt any backlogged messages. Similarly, removing encryption leaves backlogged messages encrypted.

Creating an Encrypted Queue


The newest version of the AWS Management Console allows you to choose between Standard and FIFO queues using a handy graphic:

You can set the attributes for the queue and the optional Dead Letter Queue:

And you can now check Use SSE and select the desired key:

You can use the AWS-managed Customer Master Key (CMK) which is unique for each customer and region, or you can create and manage your own keys. If you choose to use your own keys, don’t forget to update your KMS key policies so that they allow for encryption and decryption of messages.

You can also configure the data reuse period. This interval controls how often SQS refreshes cryptographic information from KMS, and can range from 1 minute up to 24 hours. Using a shorter interval can improve your security profile, but increase your KMS costs.

Available Now
Server-side encryption is available today in the US West (Oregon) and US East (Ohio) Regions, with support for others in the works.

There is no charge for the use of encryption, but you will be charged for the calls that SQS makes to KMS. To learn more about this, read How do I Estimate My Customer Master Key (CMK) Usage Costs.

Jeff;

相關推薦

NewServer-Side Encryption for Amazon Simple Queue Service (SQS)

As one of the most venerable members of the AWS family of services, Amazon Simple Queue Service (SQS) is an essential part of many applications. P

New: Server-Side Encryption for Amazon Kinesis Streams

In this age of smart homes, big data, IoT devices, mobile phones, social networks, chatbots, and game consoles, streaming data scenarios are every

Amazon Simple Queue Service (SQS) Pricing

For Data Transfer exceeding 500TB/Month please Contact Us Except as otherwise noted, our prices are exclusive of applicable taxes an

Amazon Simple Queue Service (SQS) FAQs

Q: When should I use Amazon SQS long polling, and when should I use Amazon SQS short polling? In almost all cases, Amazon SQS lon

NewAmazon S3 Server Side Encryption for Data at Rest

A lot of technical tasks that seem simple in theory are often very complex to implement. For example, let’s say that you want to encrypt

Amazon Simple Queue Service(メッセージキューサービス)

Amazon Simple Queue Service (SQS) は、完全マネージド型のメッセージキューイングサービスで、マイクロサービス、分散システム、およびサーバーレスアプリケーションの切り離しとスケーリングが可能です。SQS では、メッセージ指向ミドルウェアの管理や運用に関連する複

Amazon Simple Queue ServiceSQS) | AWS

500 TB/月を越えるデータ転送については、お問い合わせください。 別途記載がない限り、表示される料金には VAT、売上稅その他取引に対して適用される一切の稅金等および関稅は含まれません。日本の居住者であるお客様が AWS をご利用になった場合には、料金と併せて

New P2 Instance Type for Amazon EC2 – Up to 16 GPUs

I like to watch long-term technology and business trends and watch as they shape the products and services that I get to use and to write about. A

New – Cross-Region Replication for Amazon S3

We launched Amazon S3 nine years ago as of last week! Since that time we have added dozens of features, expanded across the globe, and red

New – Your User Pools for Amazon Cognito

Amazon Cognito makes it easy for mobile and web apps to easily add authentication, user management, and data synchronization without having to wri

Amazon SQS(Simple Queue Service) 簡單介紹

因此 edit statistic 數量 消息隊列 返回 tps 五個 系統 版權聲明:本文為博主原創文章,未經博主同意

Amazon Simple Notification Service (SNS)

In this two-part series, we show you how to build a data pipeline in support of a data lake. We use key AWS services such as Amazon Kinesis Data

Amazon Simple Notification Service (SNS) Features

Event-driven computing is a model in which subscriber services automatically perform work in response to events triggered by publisher services.

Amazon Simple Storage Service (S3)

Q:  How will I be charged and billed for my use of Amazon S3? There are no set-up fees or commitments to begin using the se

Amazon Simple Notification Service (SNS) SMS Pricing

With Amazon SNS, you can send SMS (text) messages to 200+ countries and for an expanded set of use-cases such as Multi-Factor Authenticatio

Amazon Simple Notification Service (SNS) Pricing

Amazon SNS has no upfront costs and you can pay as you go. You pay based on the number of notifications you publish, the number of notifications y

Amazon Simple Workflow Service

Migrating components from the datacenter to the cloud. Business critical operations are hosted in a private datacenter but need to be moved ent

Amazon Simple Notification Service (SNS) Getting Started

In this tutorial, you will implement a fanout messaging scenario using Amazon Simple Notification Service (SNS) and Amazon Simple Queue Servic

Amazon Simple Storage Service(S3)

Q:  Amazon S3의 사용료는 어떻게 과금 및 청구됩니까? 서비스를 시작하는 데 드는 설치 수수료나 확약금이 없습니다. 월말에 사용자의 신용 카드에서 월 사용액이 자동으로 결제됩니다. Amazon Web Service

Amazon Simple Workflow Service – 클라우드 워크플로 관리

구성 요소를 데이터 센터에서 클라우드로 마이그레이션. 비즈니스 크리티컬 작업이 개인 데이터 센터에서 호스팅되고 있지만 서비스 중단 없이 전체를 클라우드로 이동해야 합니다. Amazon SWF 기반 애플리케이션은 데이터 센터에서 실행되는 구성 요소를 포함한