Class KeyEncapsulationServices

java.lang.Object
org.neo4j.driver.encryption.KeyEncapsulationServices

@Preview(name="Property Encryption") public final class KeyEncapsulationServices extends Object
A factory for BaseKeyEncapsulationService implementations.

Implementations are not limited to those provided by this factory.

Since:
6.3.0
See Also:
  • Method Details

    • local

      public static AsyncKeyEncapsulationService local(SecretKey masterKey) throws NoSuchAlgorithmException
      Returns a new AsyncKeyEncapsulationService implementation that uses the provided AES-256 SecretKey as a master key for encapsulating and decapsulating data keys.

      The encapsulation uses AES-GCM ("AES/GCM/NoPadding") with the provided master key. The resulting encapsulation contains a 256-bit AES data encryption key protected by the master key, together with a 96-bit (12-byte) initialization vector (IV) and a 128-bit (16-byte) authentication tag.

      The Java runtime determines and provides the Provider and SecureRandom according to its configuration. The provider is used for AES key generation and AES-GCM operations, while the SecureRandom is used as the source of initialization vectors.

      Parameters:
      masterKey - the AES-256 master key, must not be null
      Returns:
      the new key encapsulation service
      Throws:
      NoSuchAlgorithmException - if the required AES algorithm is not available
    • local

      public static AsyncKeyEncapsulationService local(SecretKey masterKey, Provider provider, SecureRandom ivSecureRandom) throws NoSuchAlgorithmException
      Returns a new AsyncKeyEncapsulationService implementation that uses the provided AES-256 SecretKey as a master key for encapsulating and decapsulating data keys.

      The encapsulation uses AES-GCM ("AES/GCM/NoPadding") with the provided master key. The resulting encapsulation contains a 256-bit AES data encryption key protected by the master key, together with a 96-bit (12-byte) initialization vector (IV), sourced from the provided SecureRandom, and a 128-bit (16-byte) authentication tag.

      The supplied Provider is used for AES key generation and AES-GCM operations. The supplied SecureRandom is used as the source of initialization vectors.

      Parameters:
      masterKey - the AES-256 master key, must not be null
      provider - the Provider to use for cryptographic operations, must not be null
      ivSecureRandom - the SecureRandom to use for IV generation, must not be null and SecureRandom.getProvider() must resolve to the provider parameter
      Returns:
      the new key encapsulation service
      Throws:
      NoSuchAlgorithmException - if the required AES algorithm is not available