Derives a data encryption key and its id from the key-encryption key, for a process that stores none.
the key-encryption key
what the DEK is for: scope, realm and class
{ id, key }
Derives a data encryption key and its id from the key-encryption key, for a process that stores none.