Interface EnvelopePropertyEncryptionProfile.Builder

All Known Implementing Classes:
InternalEnvelopePropertyEncryptionProfile.Builder
Enclosing interface:
EnvelopePropertyEncryptionProfile

public static interface EnvelopePropertyEncryptionProfile.Builder
Since:
6.3.0
  • Method Details

    • withCryptoContext

      EnvelopePropertyEncryptionProfile.Builder withCryptoContext(Provider provider, SecureRandom ivSecureRandom)
      Configures the CryptoContext to be used for cryptographic operations.

      The supplied Provider is used to create the Cipher for "AES/GCM/NoPadding". The provider must support this cipher transformation. The supplied SecureRandom is used as the source of the 12-byte initialization vectors (IVs) required for encryption.

      Parameters:
      provider - the Provider, must not be null
      ivSecureRandom - the SecureRandom for IV generation, must not be null and SecureRandom.getProvider() must resolve to the provider parameter
      Returns:
      this builder
    • withKeyCache

      EnvelopePropertyEncryptionProfile.Builder withKeyCache(int maxSize, Duration ttl)
      Configures the key cache.

      The key cache stores mappings from key ids to decapsulated keys. This is especially useful when the configured key repository or key encapsulation service requires network exchanges.

      The cache is enabled by default with a maximum size of 100 entries and an entry TTL of 15 minutes. When adding a new entry, expired entries are purged first. If the cache is still at its maximum size, the least recently used entry is evicted.

      Key ids are expected to be globally unique, so the TTL can be configured to be longer if avoiding repeated key decapsulation is preferred. A longer TTL also means that decapsulated keys remain in memory for longer and are not refreshed or removed from the cache as frequently.

      Parameters:
      maxSize - the maximum cache size, must be greater than 0
      ttl - the entry TTL, must not be null, Duration.isNegative() or Duration.isZero()
      Returns:
      this builder
    • withoutKeyCache

      Disables the key cache.

      Disabling the key cache also disables the key alias index.

      Returns:
      this builder
    • withKeyAliasIndex

      EnvelopePropertyEncryptionProfile.Builder withKeyAliasIndex(int maxSize, Duration ttl)
      Configures the key alias index.

      The key alias index stores mappings from key aliases to key ids. This is especially useful when the configured key repository or key encapsulation service requires network exchanges. The key alias index can only be enabled when the key cache is enabled.

      The index is enabled by default with a maximum size of 100 entries and an entry TTL of 15 seconds.

      A shorter TTL allows an alias to be removed from one key and assigned to another key while limiting the period during which a driver may use a cached mapping to the previous key, allowing for predictable alias reassignment.

      Parameters:
      maxSize - the maximum cache size, must be greater than 0
      ttl - the entry TTL, must not be null, Duration.isNegative() or Duration.isZero()
      Returns:
      this builder
    • withoutKeyAliasIndex

      Disables the key alias index.
      Returns:
      this builder
    • build

      Returns a new instance of EnvelopePropertyEncryptionProfile.
      Returns:
      the new instance of profile