How AWS KMS and AWS Encryption SDK overcome symmetric encryption bounds
ID: 0a802cec-b5e6-5bdd-8dc3-ce315ea57f39
STIX ID: report--0a802cec-b5e6-5bdd-8dc3-ce315ea57f39
Feed Name: AWS Security Blog
This AWS technical post explains AES-GCM encryption limits and how AWS KMS and the AWS Encryption SDK mitigate those limits by deriving a unique per-invocation key using KDFs (SP 800-108 and HKDF) and careful IV/frame sizing; it covers nonce and IV sizes, frame/plaintext limits, data-key caching considerations, and the security rationale for avoiding manual tracking of AES-GCM bounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
