Encryption at Rest
In short
Encryption at rest keeps stored data, such as disks, databases and backups, encrypted, so a stolen drive or copied file is unreadable without the key.
What is encryption at rest?
Data at rest is data sitting in storage: files on a disk, rows in a database, objects in cloud storage, backups and snapshots. Encryption at rest keeps it encrypted there, usually with AES, and decrypts it only when an authorized program reads it. It protects against threats to the storage itself, such as a lost laptop, a stolen or discarded drive, a leaked backup or someone with physical access to a data center.
It can be applied at several levels. Full-disk encryption, such as BitLocker, FileVault or LUKS, protects a whole device, and cloud services encrypt volumes and objects; Amazon S3, for example, has encrypted all new objects by default since 2023. Databases offer transparent data encryption (TDE), which encrypts data files without changing queries, while application-level encryption encrypts sensitive fields, such as ID numbers, before they ever reach the database.
The hard part is managing keys. Most systems use envelope encryption: each piece of data is encrypted with its own data key, and that key is itself encrypted, or wrapped, by a master key that never leaves a key management service (KMS) or hardware security module (HSM). Like office keys kept in one guarded key cabinet, the data keys are useless without the master key, every use of it is logged, and destroying it makes the data unreadable for good. Standards such as PCI DSS require stored card numbers to be unreadable, and encryption at rest is a common way to meet that.
Encryption at rest is often confused with encryption in transit. TLS protects data while it moves across a network, encryption at rest protects it while it is stored, and in between the application works with decrypted data in memory, so systems need both. Disk and database encryption also don't stop an attacker who steals the database password or exploits SQL injection, because the database decrypts data for any query it accepts; application-level or end-to-end encryption narrows that gap.
Key takeaways
- Encryption at rest protects data stored on disks, in databases and in backups.
- It defends against stolen drives, leaked backups and physical access.
- It can work at the disk, storage, database or application level.
- Envelope encryption keeps the master keys in a KMS or HSM.
- It complements encryption in transit and doesn't stop attacks through the running app.
Example
import os, boto3
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
kms = boto3.client("kms")
# KMS returns a fresh data key twice: in plaintext and wrapped by the master key
key = kms.generate_data_key(KeyId="alias/app-data", KeySpec="AES_256")
nonce = os.urandom(12)
ciphertext = AESGCM(key["Plaintext"]).encrypt(nonce, b"passport U1234567", None)
# Store only the wrapped key next to the data; the plaintext key is discarded
record = {"data": ciphertext, "nonce": nonce, "wrapped_key": key["CiphertextBlob"]}
# Reading it later: KMS unwraps the key, checks permissions and logs the call
data_key = kms.decrypt(CiphertextBlob=record["wrapped_key"])["Plaintext"]
print(AESGCM(data_key).decrypt(record["nonce"], record["data"], None))Readers ask
What is the difference between encryption at rest and encryption in transit?
Encryption in transit, usually TLS, protects data while it travels between systems. Encryption at rest protects it while it is stored on disks, in databases or in backups. They cover different moments, so sensitive systems use both.
Does encryption at rest protect against hackers?
Only against some attacks. It protects stolen drives, backups and snapshots, but an attacker who gets in through the application or with valid database credentials sees the data already decrypted, so access control, least privilege and secure code are still needed.
Is cloud data encrypted at rest by default?
On the major cloud platforms, yes: services such as Amazon S3, Google Cloud Storage and Azure Storage encrypt stored data automatically with keys the provider manages. Customer-managed keys in a KMS add control over who can use the keys and a record of every use.
See also
- EncryptionSecurity, p. 15Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- TLSSecurity, p. 52TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- Symmetric EncryptionSecurity, p. 51Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- Secrets ManagementSecurity, p. 43Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
- End-to-End EncryptionSecurity, p. 17End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
- DatabaseDatabases, p. 7A database is an organized collection of data stored on a computer, managed by software that lets applications save, search, and update it efficiently.
Sources
Spotted a mistake or something missing on this page?Suggest an edit