logo

How AWS KMS and AWS Encryption SDK overcome symmetric encryption bounds

ID: 0a802cec-b5e6-5bdd-8dc3-ce315ea57f39

STIX ID: report--0a802cec-b5e6-5bdd-8dc3-ce315ea57f39

Feed Name: AWS Security Blog

Date Published: 2026-04-03

Date Updated: 2026-04-27

Author: Panos Kampanakis

...
...

This AWS technical post explains AES-GCM encryption limits and how AWS KMS and the AWS Encryption SDK mitigate those limits by deriving a unique per-invocation key using KDFs (SP 800-108 and HKDF) and careful IV/frame sizing; it covers nonce and IV sizes, frame/plaintext limits, data-key caching considerations, and the security rationale for avoiding manual tracking of AES-GCM bounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.