You can now control and accept only requests originating from Amazon API Gateway.
Connectikpeople.co recalls that, henceforth you can generate client-side
SSL certificates in Amazon API Gateway and use the
public key to verify that HTTP requests to your backend systems originated from
Amazon API Gateway.
The goal is to allow you to control and accept only requests originating
from Amazon API Gateway, even if your HTTP backend is publicly accessible. You can
learn more about using client-side SSL certificates in the Amazon API Gateway
Developer Guide.