Skip to main content

Jasypt(Java Simplified Encryption) with hibernate 3

Jasypt is a java library which allows the developer to add basic encryption capabilities to his/her projects with minimum effort, and without the need of having deep knowledge on how cryptography works.

Features:

  • Jasypt follows the RSA standards for password-based cryptography, and provides you with both unidirectional and bidirectional encryption techniques.
  • Open API for use with any JCE provider, and not only the default Java VM one. Jasypt can be easily used with well-known providers like Bouncy Castle. Learn more.
  • Higher security for your users' passwords. Learn more.
  • Binary encryption support. Jasypt allows the digest and encryption of binaries (byte arrays). Encrypt your objects or files when needed (for being sent over the net, for example).

  • Number encryption support. Besides texts and binaries, it allows the digest and encryption of numeric values (BigInteger and BigDecimal, other numeric types are supported when encrypting for Hibernate persistence). Learn more.
  • Completely thread-safe.
  • Provides both easy, no-configuration encryption tools for users new to encryption, and also highly configurable standard encryption tools, for power-users.
  • Hibernate 3 optional integration for persisting fields of your mapped entities in an encrypted manner. Encryption of fields is defined in the Hibernate mapping files, and it remains transparent for the rest of the application (useful for sensitive personal data, databases with many read-enabled users...). Encrypt texts, binaries, numbers, booleans, dates... Learn more.
  • Seamlessly integrable into a Spring application. All the digesters and encryptors in jasypt are designed to be easily used (instantiated, dependency-injected...) from Spring. And, because of their being thread-safe, they can be used without synchronization worries in a singleton-oriented environment like Spring. Learn more.
  • Spring Security (former Acegi Security) optional integration for performing password encryption and matching tasks for the security framework, improving the security of your users' passwords by using safer password encryption mechanisms and providing you with a higher degree of configuration and control. Learn more.
  • Provides advanced functionality for encrypting all or part of an application's configuration files, including sensitive information like database passwords. Seamlessly integrate encrypted configuration into plain, Spring-based and/or Hibernate-enabled applications. Learn more.
  • Provides easy to use CLI (Command Line Interface) tools to allow developers initialize their encrypted data and include encryption/decryption/digest operations in maintenance tasks or scripts. Learn more.
  • Integrates into Apache Wicket, for more robust encryption of URLs in your secure applications.
  • Comprehensive guides and javadoc documentation, to allow developers to better understand what they are really doing to their data.
  • Robust charset support, designed to adequately encrypt and digest texts whichever the original charset is. Complete support for languages like Japanese, Korean, Arabic... with no encoding or platform issues.
  • Very high level of configuration capabilities: The developer can implement tricks like instructing an "encryptor" to ask a, for example, remote HTTPS server for the password to be used for encryption. It lets you meet your security needs. Learn more.

Steps to integrate jasypt with Hibernate:>

Assume we are using annotation based hibernate.


Configuring the Hibernate mapping

step1: @TypeDef(name ="encryptedString", typeClass = EncryptedStringType.class,
parameters = {
@Parameter(name = "encryptorRegisteredName", value="strongHibernateStringEncryptor")
}
)
entry on youjr domain class.


step2: @Type(type = "encryptedString"): put it like given on the fields to whom you want to encrypt(the records of the particular field will store in the derfined encrypted format in database)

step3: Providing the encryptor to Hibernate

you can make it in two ways: Using springs:


class="org.jasypt.encryption.pbe.StandardPBEStringEncryptor">

PBEWithMD5AndTripleDES


jasypt




class="org.jasypt.hibernate.encryptor.HibernatePBEStringEncryptor">

strongHibernateStringEncryptor






without using springs:
StandardPBEStringEncryptor strongEncryptor = new StandardPBEStringEncryptor();
...
HibernatePBEEncryptorRegistry registry =
HibernatePBEEncryptorRegistry.getInstance();
registry.registerPBEStringEncryptor("strongHibernateStringEncryptor", strongEncryptor);

step 4:

download the JCE(Java Cryptogrphy Extension files) from sun java site and replace(US_export_policy, local_policy) files with the existed jar
files in directory --> Java>jre1.5.0_16>lib>security><>

download Java Cryptogrphy Extension files
Now you can run your application.




Comments

Popular posts from this blog

JSF Lifecycle Phases

JSF Lifecycle Phases JSF follows MVC design pattern to handle request-response process. Basically JSF handles three types of requests. Non-Faces Request Generates Faces Response Faces Request Generates Non-Faces Response Faces Request Generates Faces Response In another case of course non-jsf to non-jsf is there but in this case there is no involvement of JSF action here, so this is not a part of jsf lifecycle process. A JavaServer Faces page is represented by a tree of UI components, called a view . When a client makes a request for the page, the life cycle starts. During the life cycle, the JavaServer Faces implementation must build the view while considering state saved from a previous submission of the page. When the client submits a page, the JavaServer Faces implementation must perform several tasks, such as validating the data input of components in the view and converting input data to types specified on the server side. The JavaServer Faces implementation performs a...

Flex Component Life Cycle

Flex Component Life Cycle Flex component life cycle is useful when you want to create your own component to suit your application requirement. The entire process has been divided into three broad categories. 1. Initialization phase 2. Update Phase 3. Destruction Phase Initialization Phase: The first phase of component life cycle. Again it contains four stages. 1. construction Stage 2. Configuration Stage 3. Attachment Stage 4. Initialization Stage Construction Stage: The constructor of the component is called by the MXML component tag or by using the new operator of Action script class. This is the very first stage where the component life cycle begins. Constructor of the component calls the super () to invoke the super class constructor. Commonly we create out custom component by extending the UIComponent class, as it is base class for all display components of flex framework. The stage is used to: i) set some initial values for component properties ii) add event listener to the...

Flash Lite Application Set Up

Steps to develop an mobile application on flash lite and deploy the same on some device. Step 1: Download Adobe Flash CS4 from net step 2 : Follow the instructions to execute the Adobe flash set up. After every thing installed successfully, follow the below instructions to develop your first Flash Lite Application Hello Mobile World: Creating Your First Flash Lite Project This section contains step-by-step instructions to walk you through the creation of your first Flash Lite Project. This section assumes that you have downloaded and installed Flash CS3 Professional which includes Adobe Device Central. 1.Start Flash CS3 Professional 2.File > New > Flash File (Mobile) 3.Adobe Device Central starts up to allow you to choose the main target device 4.In the 'Device Sets' panel choose 'Flash Lite 2.1 32 240x320'. This is the generic mobile device profile provided by Adobe for a Flash Lite 2.1 device. 5.Click the 'Create' button at the bottom right of Device Ce...