Envelope Encryption at Rest Lab (Interactive)
Encrypt payloads through KMS directly versus local DEKs wrapped by a KEK. Run encrypt-and-upload traces from 2 KB objects to 100 GB files, comparing bytes through the KMS, the 4 KB plaintext limit, AES-NI throughput, and cost.
Envelope Encryption vs Direct KMS
Grow the payload, pick an encryption path, and watch bytes-through-KMS, wall-clock time, and the 4 KB control-plane limit collide.
Bytes through KMS
456 B
Wall time
1.002 s
Local AES-256-GCM
1.00 s
KMS request cost
$0.000003
Envelope lifecycle trace — run encrypt or read
KEK never leaves the FIPS 140-2 L3 HSM; only 32-byte DEKs cross the wire. Choose an action to trace the DEK/KEK handshake.
GCM is AEAD: the auth tag fails decryption on any bit-flip of ciphertext, so confidentiality and integrity arrive together. The fatal caveat of this whole design is key custody — delete the KEK and every wrapped DEK, hence every stored object, is unrecoverable in seconds (which, as the crypto-shredding lab shows, is also a GDPR superpower).
How It Works Under the Hood
Encryption at rest is mandatory; the architecture question is where the boundary object key actually performs crypto. Calling AWS KMS for every payload is audit-clean but capped at 4 KB of plaintext, throttles under load, and bills per request, so nobody bulk-encrypts that way. Envelope encryption generates a random data encryption key locally, uses AES-256-GCM with AES-NI at roughly a gigabyte per second in-process, and stores only the small wrapped DEK (about 456 bytes) alongside the ciphertext, while the key encryption key never leaves the HSM. The lab contrasts both strategies on large objects, shows the cold-read unwrap path, and connects the design to forward secrecy in transit (TLS 1.3 ECDHE) and zeroization on decommission.
Core Architectural Principles
- Direct-KMS mode fails on payloads beyond the 4 KB API limit and routes every byte through the HSM.
- Envelope mode moves 1 GB at AES-NI speed while only the wrapped DEK transits the KMS.
- Cold reads perform one KMS UnwrapKey per object key, then decrypt locally.
Draw the two-tier key picture: a KEK anchored in an HSM wraps per-object DEKs that do the bulk crypto. Volunteer the 4 KB KMS payload limit and per-request billing as why direct encryption does not scale, then connect it to S3 SSE-KMS, TLS 1.3 forward secrecy, and cryptographic erase for compliance deletion.
Envelope encryption trades one extra unwrap hop and key-ciphertext coupling for unlimited payload size and local AES throughput.