Interface EncapsulatedKeyManager


@Preview(name="Property Encryption") public interface EncapsulatedKeyManager
A manager for encapsulated keys.

EnvelopePropertyEncryptionProfile requires data keys to exist before they can be used for encryption. This manager provides operations for creating and managing such keys.

When creating a key, the manager uses the configured BaseKeyEncapsulationService to generate and encapsulate a new data key and registers the resulting EncapsulatedKeyRecord with the configured BaseEncapsulatedKeyRecordRepository. Both synchronous and asynchronous implementations of these services are supported.

Since:
6.3.0
See Also:
  • Method Details

    • create

      default EncapsulatedKey create()
      Creates a new encapsulated key without an alias.
      Returns:
      the encapsulated key
    • create

      default EncapsulatedKey create(String alias)
      Creates a new encapsulated key with the provided alias.
      Parameters:
      alias - the key alias, may be null
      Returns:
      the encapsulated key
    • create

      EncapsulatedKey create(String alias, KeyEncapsulationOptions encapsulationOptions)
      Creates a new encapsulated key with the provided alias and KeyEncapsulationOptions.
      Parameters:
      alias - the key alias, may be null
      encapsulationOptions - the key encapsulation options, may be null
      Returns:
      the encapsulated key
    • findByAlias

      Optional<EncapsulatedKey> findByAlias(String alias)
      Finds an encapsulated key by its alias.
      Parameters:
      alias - the key alias, must not be null
      Returns:
      Optional with the encapsulated key or Optional.empty() when no key with the given alias has been found
    • setAliasById

      void setAliasById(String id, String alias)
      Sets the alias of an encapsulated key by id. The alias must not be used by another key. To assign an alias currently used by another key, it must first be deleted from that key.
      Parameters:
      id - the key id, must not be null
      alias - the new key alias, may be null to remove the alias
    • deleteAliasById

      default void deleteAliasById(String id)
      Deletes the alias from encapsulated key by id.
      Parameters:
      id - the key id, must not be null
    • deleteById

      void deleteById(String id)
      Deletes an encapsulated key by id.
      Parameters:
      id - the key id, must not be null