October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk7 min

How to Manage Encryption Keys for Field-Level Encryption

A practical lifecycle for field-level encryption keys: separate DEKs from KEKs, store wrapping keys in a KMS, preserve decryption metadata, and rehearse rotation and recovery before production.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use envelope encryption: encrypt each protected field with a data encryption key (DEK), then protect that DEK with a key-encryption key (KEK) held in a remote key management service (KMS) or key vault. Store the ciphertext, wrapped DEK, and the key reference or version needed to decrypt it—but never store a plaintext DEK beside the data. Before production, define who can use keys, how rotation and recovery work, and when old key versions can safely be retired.

What field-level encryption protects—and what it does not

Field-level encryption protects selected values at the application or client layer before they are stored. That differs from storage encryption, which a database or cloud service may apply to disks, files, or backups. The two controls can complement each other: storage encryption protects underlying media, while field encryption can keep selected stored values encrypted from components that do not have the application’s decryption capability.

Field encryption does not make plaintext disappear from a system. An authorized application must decrypt data to use it, so plaintext may exist in application memory or be exposed by a compromised client, workload, or identity with decryption access. Encryption also does not automatically hide metadata, access patterns, or all information revealed by querying encrypted fields. Decide which components need plaintext and check how the chosen encryption mode affects queries and indexes.

MongoDB Client-Side Field Level Encryption (CSFLE) is one database-specific example, not a universal implementation recipe. Its Database Manual v7.0 describes encryption schemas and key-vault references; confirm compatibility and query constraints for the actual server, driver, and application versions you deploy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How the key hierarchy works

Data encryption keys protect field values

A DEK encrypts the field data. Generate keys with a cryptographically secure random generator, use a vetted encryption library with authenticated encryption, and keep keys for different purposes independent. Do not design your own cipher or key format. Google Cloud’s envelope-encryption guidance recommends AES-256-GCM in its example; use an algorithm and configuration supported by your platform’s vetted library and applicable requirements rather than copying that choice blindly.

Key-encryption keys protect DEKs

A KEK—also called a customer-managed key (CMK) in some services—wraps or encrypts DEKs. Keep it in a KMS or key vault separate from the application data where the deployment supports one. The KMS can perform wrapping-key operations without making the KEK available to the application; the application may still need permission to request those operations.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Keep the hierarchy simple enough to operate. For every encrypted record or field, retain a reliable way to identify the wrapped DEK and the relevant key reference or version. Key granularity is a design choice: weigh data sensitivity, tenant boundaries, volume, and recovery needs. Google Cloud’s documented pattern generates DEKs locally, stores them encrypted at rest, and recommends generating a new DEK on each write. Treat that as provider guidance, not a universal rule for every workload.

Set up field-level key management

  1. Choose fields and map plaintext access. Identify the values that require protection, which application components must read them, and which queries or indexes need to continue working. Validate the selected encryption mode’s query behavior and leakage characteristics against your database and driver versions.
  2. Select a supported KMS or key vault. Choose a service compatible with the database, driver, and application-side encryption library. MongoDB CSFLE documentation lists AWS KMS, Azure Key Vault, Google Cloud KMS, and KMIP-compatible systems as remote providers; it identifies its local key provider as for testing. Verify current integration details for your deployment.
  3. Create workload-specific access. Give the workload identity only the cryptographic operations it needs, such as wrapping and unwrapping keys. Separate routine application use from key administration and destructive permissions where feasible. Review service identity, policy scope, cross-account access, audit events, regional placement, availability, and recovery arrangements.
  4. Keep secrets out of application artifacts. Do not commit plaintext keys to source control or place them in binaries, container images, or ordinary configuration files. Keep the wrapping key in the remote service and restrict access to key material and key metadata.
  5. Encrypt, wrap, and persist. Encrypt field data with the DEK using the selected library, then wrap the DEK with the KEK. Persist the ciphertext, wrapped DEK, and the stable key identifier or version information needed to find the correct key later. Never persist a plaintext DEK with the data.
  6. Test normal reads and restores. Confirm that authorized workloads can decrypt data and that unauthorized identities cannot perform key operations. Test restore procedures using the ciphertext, wrapped DEKs, metadata, and key versions that would actually be available after a failure.

Store enough metadata to decrypt later

Every encrypted value needs a durable association to the wrapped DEK and the key version or key-vault reference that can unwrap it. Preserve that association through record updates, exports, migrations, replicas, and backup restores. Do not assume that changing the active KEK automatically updates old wrapped DEKs or makes old data decryptable with only the newest key version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

In MongoDB CSFLE, DEKs are held in a key-vault collection. MongoDB Database Manual v7.0 documents alternate names for dynamic key references and requires a partial unique index before using those alternate names. The manual also documents rewrapManyDataKey; MongoDB states that it is available in mongosh version 1.5 and later. Verify command behavior and prerequisites against the MongoDB, driver, and shell versions in use.

Plan rotation without losing access to existing data

Rotation is a lifecycle decision, not a single button press. Set a documented schedule and event-based triggers based on the threat model, data sensitivity, key size, provider behavior, and applicable requirements. OWASP guidance does not establish one mandatory interval for every key; rotate or replace keys after suspected compromise or when a cryptographic migration requires it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Know which operation you need

  • Rotate a KEK or CMK: create or activate a replacement wrapping-key version. Existing wrapped DEKs may still depend on the previous version for unwrapping.
  • Rewrap DEKs: unwrap existing DEKs and wrap those same DEKs with a new KEK. This changes the DEK wrapping, not the DEK or the ciphertext it protects.
  • Replace a DEK: encrypt the data again with a new DEK. This is a data migration; merely changing a KMS key does not replace the DEK or re-encrypt the fields.
  • Retire or destroy an old version: do so only after verifying that live data, replicas, exports, and backups no longer need it, and after testing recovery.

Run rotation as a controlled change

  1. Identify the affected key versions, workloads, encrypted records, and backups.
  2. Provision or activate the replacement key and confirm the intended workload can use it.
  3. Choose whether to use the new key for future DEKs, rewrap existing DEKs, or replace DEKs and re-encrypt data. Record the scope and expected completion criteria.
  4. Run the change in a controlled rollout, monitor key-service operations and decryption failures, and verify that representative old and new records remain readable.
  5. Keep prior key versions available until data and recovery copies no longer depend on them. Record approval and evidence before any destructive retirement step.

Provider behavior matters. Google Cloud states that key rotation does not automatically re-encrypt data or destroy old versions. MongoDB’s rewrapManyDataKey operation re-encrypts selected data keys under a specified CMK and updates the key vault; it does not mean field ciphertext has been re-encrypted under replacement DEKs.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Back up, monitor, and rehearse recovery

Back up ciphertext and the metadata that associates it with wrapped DEKs and key versions consistently. Maintain a secure recovery path for key-service configuration and the required key versions. A backup is useful only if the restored environment can obtain the keys needed to unwrap DEKs and decrypt fields.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Restore a representative backup into a clean environment and verify decryption with the identities and key versions available to recovery operations.
  • Log key use and review anomalous access, policy changes, rotation approvals, and destruction requests.
  • Restrict destructive actions and separate them from routine application permissions.
  • Include KMS unavailability, lost credentials, suspected compromise, and accidental key-version destruction in incident exercises.

Lost or destroyed keys can make encrypted data unrecoverable. Google Cloud warns that destroying a key version still in use can cause permanent data loss. MongoDB’s CSFLE documentation likewise warns that deleting a DEK makes all fields encrypted with it permanently unreadable. Do not remove a key or version until its dependencies and recovery path have been checked.

Choose a provider against operational requirements

For MongoDB CSFLE, documented remote-provider choices include AWS KMS, Azure Key Vault, Google Cloud KMS, and KMIP-compatible systems. The right choice depends on the deployment, not on a universal ranking. Compare each candidate on the same operational questions:

  • Does it integrate with the exact database, driver, and application-side encryption library?
  • Can workload identities receive narrowly scoped cryptographic permissions, with administration separated where practical?
  • Which key-use, policy-change, rotation, and destruction events can be audited and alerted on?
  • How do availability, recovery, backup, replication, and cross-region needs work for this deployment?
  • Does the service meet data-residency, customer-control, or external and hardware-backed custody requirements?
  • What exactly does rotation change, and which prior versions or wrapped DEKs remain necessary?
  • What are the current costs and operational responsibilities for the specific region, key type, and integration?

Official guidance establishes these provider options and documents some provider-specific lifecycle behavior, but it does not establish a neutral current pricing or service-level comparison. Check the selected provider’s current documentation for the exact product and configuration.

Key-management mistakes to avoid

  • Treating disk or backup encryption as equivalent to application-level protection of selected fields.
  • Keeping KEKs beside ciphertext, or committing plaintext keys to a repository or build artifact.
  • Assuming automatic KMS rotation re-encrypts existing data or eliminates the need for old key versions.
  • Destroying an old version as soon as a replacement is created, before checking live and backup dependencies.
  • Reusing a DEK across unrelated customers without a deliberate, reviewed design, or assuming that replacing a DEK does not require re-encryption.
  • Giving a general application identity key-administration or destructive permissions when it only needs cryptographic operations.
  • Deleting a DEK from a MongoDB key vault without identifying every field that uses it.
  • Applying a provider-specific feature, cryptoperiod example, or compliance statement as a universal requirement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.