Interface KeyEncapsulationService

All Superinterfaces:
BaseKeyEncapsulationService

@Preview(name="Property Encryption") public non-sealed interface KeyEncapsulationService extends BaseKeyEncapsulationService
A service responsible for encapsulating and decapsulating keys.

Implementations may perform blocking operations. The driver adapts synchronous operations to its asynchronous execution model using the executor().

Implementations MUST supply 256-bit AES keys only.

Since:
6.3.0
See Also:
  • Method Details

    • encapsulate

      Creates a new key, encapsulates it and returns the result.
      Parameters:
      options - the encapsulation options
      Returns:
      the encapsulation result
    • decapsulate

      SecretKey decapsulate(byte[] encapsulation, Map<String,String> metadata)
      Decapsulates encapsulated bytes.
      Parameters:
      encapsulation - the encapsulated bytes, must not be null
      metadata - the key metadata, must not be null
      Returns:
      the decapsulated key
    • executor

      default Executor executor()
      Returns the Executor used by the driver when adapting this synchronous service to its asynchronous execution model.

      Implementations performing blocking operations may override this method to provide an executor appropriate for those operations.

      Returns:
      the executor