AWS 推出 VPC 加密控制功能以强制传输中加密

AWS 推出了新的 VPC 加密控制功能,使客户能够监控和强制执行其虚拟私有云内部和跨云流量的传输中加密。该功能提供了对未加密流量的可见性,支持在兼容的 Nitro 基础设施上强制执行,并允许特定排除。AWS 强调了其在实现一致加密标准和遵守 HIPAA、PCI DSS 和 FedRAMP 等监管合规框架方面的实用性,简化了先前复杂的手动流程。虽然该功能解决了重大的合规挑战,但其在免费期后开始收费的定价模式引发了社区关于此类基础安全控制是否应该收费的讨论。控制功能提供 '监控' 和 '强制执行' 两种模式,后者要求在激活前将所有 VPC 资源迁移到符合加密要求的基础设施。该服务目前已在部分 AWS 区域可用。




AWS has recently introduced VPC encryption controls, allowing customers to validate whether traffic within and between VPCs is encrypted and to require encryption where supported. The feature provides visibility into unencrypted traffic, supports enforcement using compatible Nitro-based infrastructure, and allows exclusions for resources that cannot encrypt traffic.

According to the cloud provider, the new feature helps organizations apply consistent encryption standards across their AWS environments and demonstrate compliance with regulatory frameworks such as HIPAA, PCI DSS, and FedRAMP, which require comprehensive encryption. Sébastien Stormacq, principal developer advocate at AWS, explains:

Organizations across financial services, healthcare, government, and retail face significant operational complexity in maintaining encryption compliance across their cloud infrastructure. Traditional approaches require piecing together multiple solutions and managing complex public key infrastructure (PKI), while manually tracking encryption across different network paths using spreadsheets.

While the community reaction has been mostly positive, many initially expressed confusion about the pricing approach or questioned why a security control should be paid for at all. User kei_ichi writes:

That feature should be enabled by default and free.

Administrators can enable the feature for existing VPCs to monitor the encryption status of traffic flows and identify VPC resources that unintentionally allow plaintext traffic. Chris Farris, cloud security consultant and AWS Security Hero, writes in his re:Invent recap:

Let's start with why you should avoid this - $110 per month per non-empty VPC. This is absolutely worth it if you need "To meet stringent compliance standards like HIPAA and PCI DSS" and "demonstrate compliance with encryption standards."

VPC encryption controls are available in two operational modes: monitor and enforce. After activation, enforce mode ensures that all new resources are created only on compatible Nitro instances, and that any unencrypted traffic is dropped when incorrect protocols or ports are detected.

VPC Encryption Controls

Source: AWS blog

Administrators can enable enforce mode only after all resources are migrated to encryption-compliant infrastructure. Farris notes:

You cannot enable enforce mode if you have non-encrypted-in-transit resources in your VPC. The migration effort here will be great, but if your auditors are making you do the work by hand, this is worth the cost.

This requires upgrading to supported hardware and communication protocols first. Specific exclusions can be configured for resources such as internet or NAT gateways that do not support encryption because their traffic leaves the AWS network. In the "Understanding VPC Encryption in Transit for Modern Cloud Security" article, Anish Kumar adds:

For your cloud security posture, you can answer the question: "Is all traffic in my VPC estate encrypted in transit?" with confidence and evidence. And from a compliance audit perspective, you can show the encryption-status in your flow logs and exclusions list.

The new feature is currently available in a subset of AWS regions, including Northern Virginia, Ireland, London, and Singapore. VPC encryption controls will be free to use until March 1, after which a fixed hourly fee will apply for each non-empty VPC, starting at 0.15 USD per hour.



AI 前线

2 百万人围观的 Claude Code 实战使用指南

2026-1-13 16:07:46

AI 前线

顶尖销售,都在顺应人性

2026-1-13 16:07:55

0 条回复 A文章作者 M管理员
    暂无讨论,说说你的看法吧
个人中心
购物车
优惠劵
今日签到
有新私信 私信列表
搜索