aws / aws/amazon-s3-encryption-client-java
S3 Encryption Client payload interoperability
- Dominant language
- Java
- Stars
- 34
- Forks
- 21
- PR merge metrics
- No merged PRs in 30d
Description
### Problem:
My organisation currently uses S3 Encryption Client for client-side encryption of our S3 objects.
We need to support multiple blob storages (such as GCS) with client-side encryption.
S3 Encryption Client is only compatible with S3. We're looking to have a solution that will be multi-storage.
### Solution:
One option we are evaluating is relying on S3 Encryption Client internals such as CipherSubscriber/CipherProvider (a couple more) and building a thin agnostic wrapper around it such that we can continue to use it for all our existing S3 objects.
However being internal API we are hesistant. Would it be possible to promote some of the internal API to public?
We have also considered AWS Encryption SDK, but it isn't interoperable with the payloads due to its framed format. We'd also appreciate any other suggestions! Re-encryption to a new format would also be very expensive.
Contributor guide
Research direction
Start by reviewing the S3 Encryption Client internals named in the issue, especially CipherSubscriber and CipherProvider, and compare their payload format with the AWS Encryption SDK's framed format. No files or tests are identified; done would require an agreed public, storage-agnostic API or another interoperability approach that preserves existing S3-encrypted payloads.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, java
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100