Decrypts a value encryptWithDek() wrote, and counts it.
encryptWithDek()
the DEK the value names (the caller looked it up by dekIdOf())
dekIdOf()
the stored form
what it is, for the accounting
the plaintext
Error for a value this service did not write, an unknown version, or the wrong key
Decrypts a value
encryptWithDek()wrote, and counts it.