Amazon solves this with shared keys, and is filepicker's up coming solution. You might want to look into doing it like that.
Edit: The Filepicker.io email seems to indicate a PKI-style solution, but I can only sort of guess at the implementation.
What you're interested in is:
"signature" - "A signature value that authorizes the form and proves that only you could have created it. This value is calculated by signing the Base64-encoded policy document with your AWS Secret Key, a process that I will demonstrate below."
I suppose that's solved by serving the form over https. Perhaps that's just what I was missing.