Term Kind Topic What it is
Data Key Caching Key Reuse Window, Envelope Key Caching practice Key Management Reusing one generated data key across a bounded number of objects, bytes and seconds, so that envelope encryption does not make one key-service request per record.
Envelope Encryption pattern Key Management Encrypting data with a locally generated data key, then encrypting that key with a master key held in a key management service.
Hardware Security Module HSM tool Key Management A tamper-resistant device that generates and stores keys and performs cryptographic operations without the key material ever being extractable.
Key Rotation practice Key Management Periodically replacing a cryptographic key with a new one while retaining the old for decrypting existing data, so exposure from any single key is bounded.
Signing Boundary Policy Policy at the HSM, Constrained Signing pattern Key Management Enforcing transaction policy at the hardware signing boundary rather than in application code, so that a compromised application cannot obtain an arbitrary signature.