Class InternalEnvelopePropertyEncryptionProfile.Builder
- All Implemented Interfaces:
EnvelopePropertyEncryptionProfile.Builder
- Enclosing class:
InternalEnvelopePropertyEncryptionProfile
-
Constructor Summary
ConstructorsConstructorDescriptionBuilder(String name, BaseKeyEncapsulationService keyEncapsulationService, BaseEncapsulatedKeyRecordRepository keyRepository) -
Method Summary
Modifier and TypeMethodDescriptionbuild()Returns a new instance ofEnvelopePropertyEncryptionProfile.withCryptoContext(Provider provider, SecureRandom ivSecureRandom) Configures theCryptoContextto be used for cryptographic operations.withKeyAliasIndex(int maxSize, Duration ttl) Configures the key alias index.withKeyCache(int maxSize, Duration ttl) Configures the key cache.Disables the key alias index.Disables the key cache.
-
Constructor Details
-
Builder
public Builder(String name, BaseKeyEncapsulationService keyEncapsulationService, BaseEncapsulatedKeyRecordRepository keyRepository)
-
-
Method Details
-
withCryptoContext
public InternalEnvelopePropertyEncryptionProfile.Builder withCryptoContext(Provider provider, SecureRandom ivSecureRandom) Description copied from interface:EnvelopePropertyEncryptionProfile.BuilderConfigures theCryptoContextto be used for cryptographic operations.The supplied
Provideris used to create theCipherfor "AES/GCM/NoPadding". The provider must support this cipher transformation. The suppliedSecureRandomis used as the source of the 12-byte initialization vectors (IVs) required for encryption.- Specified by:
withCryptoContextin interfaceEnvelopePropertyEncryptionProfile.Builder- Parameters:
provider- theProvider, must not be nullivSecureRandom- theSecureRandomfor IV generation, must not be null andSecureRandom.getProvider()must resolve to the provider parameter- Returns:
- this builder
-
withKeyCache
Description copied from interface:EnvelopePropertyEncryptionProfile.BuilderConfigures the key cache.The key cache stores mappings from key ids to decapsulated keys. This is especially useful when the configured key repository or key encapsulation service requires network exchanges.
The cache is enabled by default with a maximum size of 100 entries and an entry TTL of 15 minutes. When adding a new entry, expired entries are purged first. If the cache is still at its maximum size, the least recently used entry is evicted.
Key ids are expected to be globally unique, so the TTL can be configured to be longer if avoiding repeated key decapsulation is preferred. A longer TTL also means that decapsulated keys remain in memory for longer and are not refreshed or removed from the cache as frequently.
- Specified by:
withKeyCachein interfaceEnvelopePropertyEncryptionProfile.Builder- Parameters:
maxSize- the maximum cache size, must be greater than 0ttl- the entry TTL, must not be null,Duration.isNegative()orDuration.isZero()- Returns:
- this builder
-
withoutKeyCache
Description copied from interface:EnvelopePropertyEncryptionProfile.BuilderDisables the key cache.Disabling the key cache also disables the key alias index.
- Specified by:
withoutKeyCachein interfaceEnvelopePropertyEncryptionProfile.Builder- Returns:
- this builder
-
withKeyAliasIndex
public InternalEnvelopePropertyEncryptionProfile.Builder withKeyAliasIndex(int maxSize, Duration ttl) Description copied from interface:EnvelopePropertyEncryptionProfile.BuilderConfigures the key alias index.The key alias index stores mappings from key aliases to key ids. This is especially useful when the configured key repository or key encapsulation service requires network exchanges. The key alias index can only be enabled when the key cache is enabled.
The index is enabled by default with a maximum size of 100 entries and an entry TTL of 15 seconds.
A shorter TTL allows an alias to be removed from one key and assigned to another key while limiting the period during which a driver may use a cached mapping to the previous key, allowing for predictable alias reassignment.
- Specified by:
withKeyAliasIndexin interfaceEnvelopePropertyEncryptionProfile.Builder- Parameters:
maxSize- the maximum cache size, must be greater than 0ttl- the entry TTL, must not be null,Duration.isNegative()orDuration.isZero()- Returns:
- this builder
-
withoutKeyAliasIndex
Description copied from interface:EnvelopePropertyEncryptionProfile.BuilderDisables the key alias index.- Specified by:
withoutKeyAliasIndexin interfaceEnvelopePropertyEncryptionProfile.Builder- Returns:
- this builder
-
build
Description copied from interface:EnvelopePropertyEncryptionProfile.BuilderReturns a new instance ofEnvelopePropertyEncryptionProfile.- Specified by:
buildin interfaceEnvelopePropertyEncryptionProfile.Builder- Returns:
- the new instance of profile
-