Chisato · · 5 min read What Is Envelope Encryption? Data Keys and KEKs Explained
Envelope encryption encrypts data with a data key, then encrypts that key with a master key held in a KMS. How it works, why clouds use it, and key rotation.
Topic
15 posts tagged “Cryptography”.
Chisato · · 5 min read Envelope encryption encrypts data with a data key, then encrypts that key with a master key held in a KMS. How it works, why clouds use it, and key rotation.
Chisato · · 4 min read A side-channel attack recovers secrets from a system's physical behavior — timing, power draw, cache access — rather than breaking its algorithm directly.
Chisato · · 5 min read A padding oracle attack exploits error messages during decryption to recover plaintext byte by byte, without ever breaking the cipher itself.
Chisato · · 5 min read TOTP generates a new six-digit code every 30 seconds from a shared secret and the current time. How authenticator apps use it, and where it falls short.
Chisato · · 4 min read A hardware security module is a dedicated device that generates, stores, and uses cryptographic keys so private keys never leave secure hardware.
Chisato · · 4 min read A rainbow table is a precomputed lookup of hash chains that speeds up cracking unsalted password hashes. How it works and why salting defeats it.
Chisato · · 5 min read Symmetric encryption uses one shared key; asymmetric uses a public/private key pair. How each works, why most real systems use both, and when to pick one.
Chisato · · 4 min read PKI is the system of keys, certificates, and certificate authorities that lets strangers trust each other's public keys online. How it actually works.
Chisato · · 4 min read Homomorphic encryption lets you compute on encrypted data without ever decrypting it, so a third party can process data it can never actually read.
Chisato · · 4 min read OCSP and CRL are the two mechanisms browsers use to check if a TLS certificate has been revoked before its expiry date. Here's how each works.
Chisato · · 4 min read A zero-knowledge proof lets one party prove a statement is true without revealing why — the basis of privacy-preserving verification systems.
Chisato · · 4 min read A timing attack infers secret data by measuring how long an operation takes to run. How timing side channels leak information and how to close them.
The Lycoris Team · · 5 min read A digital signature uses a private key to prove a message's origin and integrity, and a public key lets anyone verify it — no shared secret required.
Chisato · · 4 min read HMAC combines a secret key with a hash function to prove a message wasn't altered and came from someone who holds the key. Here's how it works.
Chisato · · 4 min read Quantum computers threaten RSA and ECC. The NIST post-quantum standards are finalized — here's what they replace, what's already deployed, and how to prepare.