You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java AWS S3加密客户端问题:V2无法解密文件,V1可正常使用

问题

需要用Java检索S3中由AWS SES通过KMS加密的文件。使用AmazonS3EncryptionV2客户端按文档配置后,检索时抛出错误:

Provided encryption materials do not match information retrieved from the encrypted object

改用已弃用的V1客户端(AmazonS3EncryptionClient),几乎相同的配置却能正常工作,希望解决V2客户端的问题,不再依赖弃用版本。

V2客户端配置代码:

AmazonS3EncryptionClientV2Builder.standard()
        .withCryptoConfiguration(new CryptoConfigurationV2(CryptoMode.AuthenticatedEncryption))
        .withEncryptionMaterialsProvider(new KMSEncryptionMaterialsProvider("key id goes here"))
        .withRegion("us-east-1")
        .withKmsClient(AWSKMSClientBuilder.defaultClient())
        .build();

V1客户端配置代码:

AmazonS3EncryptionClientBuilder.standard()
        .withCryptoConfiguration(new CryptoConfiguration(CryptoMode.AuthenticatedEncryption))
        .withEncryptionMaterials(new KMSEncryptionMaterialsProvider("key id goes here"))
        .withRegion("us-east-1")
        .withKmsClient(AWSKMSClientBuilder.defaultClient())
        .build();
解决方案

1. 确保使用KMS密钥完整ARN

V2客户端对密钥匹配的校验比V1严格,SES加密文件时,S3对象元数据中存储的是KMS密钥的完整ARN,而非别名或短ID。将配置中的密钥ID替换为完整ARN(格式如arn:aws:kms:us-east-1:123456789012:key/xxxx-xxxx-xxxx-xxxx)。

2. 调整加密模式为EncryptionOnly

SES采用的信封加密逻辑与V2的AuthenticatedEncryption模式不兼容,改为EncryptionOnly模式即可匹配SES的加密方式:

AmazonS3EncryptionClientV2Builder.standard()
        .withCryptoConfiguration(new CryptoConfigurationV2(CryptoMode.EncryptionOnly))
        .withEncryptionMaterialsProvider(new KMSEncryptionMaterialsProvider("你的KMS密钥完整ARN"))
        .withRegion("us-east-1")
        .withKmsClient(AWSKMSClientBuilder.defaultClient())
        .build();

3. 验证IAM权限

确认执行代码的IAM身份(角色/用户)拥有以下KMS权限:

  • kms:Decrypt:用于解密信封加密的密钥
  • kms:DescribeKey:用于验证密钥信息与对象元数据匹配

4. 检查SDK版本

确保使用的aws-java-sdk-s3-encryption模块为最新稳定版,旧版本可能存在V2客户端与KMS交互的兼容性问题。


内容的提问来源于stack exchange,提问作者Kel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 21:40:16