awslabs / aws-encryption-sdk-specification

AWS Encryption SDK Specification
Other
29 stars 27 forks source link

Update specification to add key commitment #231

Open robin-aws opened 3 years ago

robin-aws commented 3 years ago

Version 2.0 of the various ESDK implementations have added key commitment as another dimension of variability for algorithms suites: https://aws.amazon.com/blogs/security/improved-client-side-encryption-explicit-keyids-and-key-commitment/

At a minimum we need to update the information on the available algorithm suites and especially the fact that the default algorithm suite now depends on your commitment policy: https://github.com/awslabs/aws-encryption-sdk-specification/blob/4b1c0e06435d385fc0593a5619ce686cf2cb79e8/framework/algorithm-suites.md#supported-algorithm-suites