Wrapper decrypter = new AESWrapEngine();
decrypter.init(false, new KeyParameter(kek.getEncoded()));
// decrypt
try {
byte[] cekBytes = decrypter.unwrap(encryptedCEK, 0, encryptedCEK.length);
return new SecretKeySpec(cekBytes, "AES");
} catch (Exception e) {
// java.lang.IllegalStateException
// org.bouncycastle.crypto.InvalidCipherTextException