TLS ensures that stream was not altered. Any further checksums are redundant.
I'm sure that they have reasons for this whole request signature scheme over traditional "Authorization: Bearer $token" header, but I never understood it.
However, the s3 pre-signed requests functionality was launched in 2011, but the Bearer token RFC 6750 wasn't standardised until 2012...
https://youtube.com/watch?v=tPr1AgGkvc4, about 10 minutes in I think.