Interface EnvelopePropertyEncryptionProfile.Builder
- All Known Implementing Classes:
InternalEnvelopePropertyEncryptionProfile.Builder
- Enclosing interface:
EnvelopePropertyEncryptionProfile
EnvelopePropertyEncryptionProfile.- Since:
- 6.3.0
-
Method Summary
Modifier and TypeMethodDescriptionbuild()Returns a new instance ofEnvelopePropertyEncryptionProfile.withCryptoContext(Provider provider, SecureRandom ivSecureRandom) Configures theCryptoContextto be used for cryptographic operations.withKeyAliasIndex(int maxSize, Duration ttl) Configures the key alias index.withKeyCache(int maxSize, Duration ttl) Configures the key cache.Disables the key alias index.Disables the key cache.
-
Method Details
-
withCryptoContext
EnvelopePropertyEncryptionProfile.Builder withCryptoContext(Provider provider, SecureRandom ivSecureRandom) Configures theCryptoContextto be used for cryptographic operations.The supplied
Provideris used to create theCipherfor "AES/GCM/NoPadding". The provider must support this cipher transformation. The suppliedSecureRandomis used as the source of the 12-byte initialization vectors (IVs) required for encryption.- Parameters:
provider- theProvider, must not be nullivSecureRandom- theSecureRandomfor IV generation, must not be null andSecureRandom.getProvider()must resolve to the provider parameter- Returns:
- this builder
-
withKeyCache
Configures the key cache.The key cache stores mappings from key ids to decapsulated keys. This is especially useful when the configured key repository or key encapsulation service requires network exchanges.
The cache is enabled by default with a maximum size of 100 entries and an entry TTL of 15 minutes. When adding a new entry, expired entries are purged first. If the cache is still at its maximum size, the least recently used entry is evicted.
Key ids are expected to be globally unique, so the TTL can be configured to be longer if avoiding repeated key decapsulation is preferred. A longer TTL also means that decapsulated keys remain in memory for longer and are not refreshed or removed from the cache as frequently.
- Parameters:
maxSize- the maximum cache size, must be greater than 0ttl- the entry TTL, must not be null,Duration.isNegative()orDuration.isZero()- Returns:
- this builder
-
withoutKeyCache
EnvelopePropertyEncryptionProfile.Builder withoutKeyCache()Disables the key cache.Disabling the key cache also disables the key alias index.
- Returns:
- this builder
-
withKeyAliasIndex
Configures the key alias index.The key alias index stores mappings from key aliases to key ids. This is especially useful when the configured key repository or key encapsulation service requires network exchanges. The key alias index can only be enabled when the key cache is enabled.
The index is enabled by default with a maximum size of 100 entries and an entry TTL of 15 seconds.
A shorter TTL allows an alias to be removed from one key and assigned to another key while limiting the period during which a driver may use a cached mapping to the previous key, allowing for predictable alias reassignment.
- Parameters:
maxSize- the maximum cache size, must be greater than 0ttl- the entry TTL, must not be null,Duration.isNegative()orDuration.isZero()- Returns:
- this builder
-
withoutKeyAliasIndex
EnvelopePropertyEncryptionProfile.Builder withoutKeyAliasIndex()Disables the key alias index.- Returns:
- this builder
-
build
Returns a new instance ofEnvelopePropertyEncryptionProfile.- Returns:
- the new instance of profile
-