metadata) {
+ return new InternalEncapsulatedKeyRecord(id, alias, encapsulation, metadata);
+ }
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/EnvelopePropertyEncryptionProfile.java b/driver/src/main/java/org/neo4j/driver/property_encryption/EnvelopePropertyEncryptionProfile.java
new file mode 100644
index 0000000000..595fb5e792
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/EnvelopePropertyEncryptionProfile.java
@@ -0,0 +1,140 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.security.Provider;
+import java.security.SecureRandom;
+import java.time.Duration;
+import java.util.Optional;
+import org.neo4j.driver.internal.property_encryption.InternalEnvelopePropertyEncryptionProfile;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * An encryption profile that enables Envelope Encryption for Neo4j Property Encryption.
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public sealed interface EnvelopePropertyEncryptionProfile extends PropertyEncryptionProfile
+ permits InternalEnvelopePropertyEncryptionProfile {
+ /**
+ * Returns a new builder for {@link EnvelopePropertyEncryptionProfile}.
+ * @param name the unique name of the profile instance, must not be {@literal null} or empty
+ * @param keyEncapsulationService the {@link KeyEncapsulationService} implementation, must not be {@literal null}
+ * @param keyRepository the {@link EncapsulatedKeyRecordRepository} implementation, must not be {@literal null}
+ * @return the new builder
+ */
+ static Builder builder(
+ String name,
+ KeyEncapsulationService keyEncapsulationService,
+ EncapsulatedKeyRecordRepository keyRepository) {
+ return new InternalEnvelopePropertyEncryptionProfile.Builder(name, keyEncapsulationService, keyRepository);
+ }
+
+ /**
+ * A builder for {@link EnvelopePropertyEncryptionProfile}.
+ */
+ interface Builder {
+ /**
+ * Sets {@link CryptoContext} to be used for cryptographic purposes.
+ * @param provider the {@link Provider}, must not be {@literal null}
+ * @param ivSecureRandom the {@link SecureRandom} for IV generation, must not be {@literal null} and
+ * {@link SecureRandom#getProvider()} must resolve to the provider param
+ * @return this builder
+ */
+ Builder withCryptoContext(Provider provider, SecureRandom ivSecureRandom);
+
+ /**
+ * Sets cache config for key cache.
+ *
+ * The key cache is responsible for keeping key id resolution to decapsulated key.
+ *
+ * The cache is enabled by default with the maximum size of {@literal 100} entries and {@literal 15} minutes TTL.
+ *
+ * @param maxSize the maximum cache size, must be equal or greater than 1
+ * @param ttl the entry TTL, must not be {@literal null}
+ * @return this builder
+ */
+ Builder withKeyCache(int maxSize, Duration ttl);
+
+ /**
+ * Disables key cache.
+ * @return this builder
+ */
+ Builder withoutKeyCache();
+
+ /**
+ * Sets cache config for key alias cache.
+ *
+ * The key alias cache is responsible for keeping key alias resolution to key id.
+ *
+ * The cache is enabled by default with the maximum size of {@literal 100} entries and {@literal 15} seconds TTL.
+ *
+ * @param maxSize the maximum cache size, must be equal or greater than 1
+ * @param ttl the entry TTL, must not be {@literal null}
+ * @return this builder
+ */
+ Builder withKeyAliasCache(int maxSize, Duration ttl);
+
+ /**
+ * Disables the key alias cache.
+ * @return this builder
+ */
+ Builder withoutKeyAliasCache();
+
+ /**
+ * Returns a new instance of {@link EnvelopePropertyEncryptionProfile}.
+ * @return the new instance of profile
+ */
+ EnvelopePropertyEncryptionProfile build();
+ }
+
+ /**
+ * Returns the {@link KeyEncapsulationService} used by this profile.
+ * @return the encapsulation service
+ */
+ KeyEncapsulationService keyEncapsulationService();
+
+ /**
+ * Returns the {@link EncapsulatedKeyRecordRepository} used by this profile.
+ * @return the key repository
+ */
+ EncapsulatedKeyRecordRepository keyRepository();
+
+ /**
+ * Returns {@link CryptoContext} if set.
+ * @return the crypto context
+ */
+ Optional cryptoContext();
+
+ /**
+ * Returns key cache {@link CacheConfig} if enabled.
+ *
+ * The cache is enabled by default with the maximum size of {@literal 100} entries and {@literal 15} minutes TTL.
+ *
+ * @return the cache config
+ */
+ Optional keyCacheConfig();
+
+ /**
+ * Returns key alias cache {@link CacheConfig} if enabled.
+ *
+ * The cache is enabled by default with the maximum size of {@literal 100} entries and {@literal 15} seconds TTL.
+ *
+ * @return the cache config
+ */
+ Optional keyAliasCacheConfig();
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationOptions.java b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationOptions.java
new file mode 100644
index 0000000000..ba66cd5182
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationOptions.java
@@ -0,0 +1,36 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.util.Map;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * Options required by {@link KeyEncapsulationService} in order to encapsulate and decapsulate keys.
+ * Most service implementations are expected have a dedicated subtype for options.
+ * @see KeyEncapsulationService
+ * @see EncapsulatedKey
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface KeyEncapsulationOptions {
+ /**
+ * Returns the options as a {@link Map}.
+ * @return the options as a map
+ */
+ Map toMap();
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationResult.java b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationResult.java
new file mode 100644
index 0000000000..163df1c707
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationResult.java
@@ -0,0 +1,46 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.util.Map;
+import javax.crypto.SecretKey;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A key encapsulation result.
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface KeyEncapsulationResult {
+ /**
+ * Returns the encapsulation bytes.
+ * @return the encapsulation bytes
+ */
+ byte[] encapsulation();
+
+ /**
+ * Returns the encapsulation metadata.
+ * @return the encapsulation metadata
+ */
+ Map metadata();
+
+ /**
+ * Returns the key.
+ * @return the key
+ */
+ SecretKey key();
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationResults.java b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationResults.java
new file mode 100644
index 0000000000..b6cdb4ce8b
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationResults.java
@@ -0,0 +1,43 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.util.Map;
+import javax.crypto.SecretKey;
+import org.neo4j.driver.internal.property_encryption.InternalKeyEncapsulationResult;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A factory for {@link KeyEncapsulationResult}.
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public final class KeyEncapsulationResults {
+ private KeyEncapsulationResults() {}
+
+ /**
+ * Creates a new encapsulation result.
+ *
+ * @param encapsulation the encapsulation bytes, must not be {@literal null}
+ * @param metadata the encapsulation metadata, must not be {@literal null}
+ * @param key the new key, must not be {@literal null}
+ * @return the new encapsulation result
+ */
+ public static KeyEncapsulationResult create(byte[] encapsulation, Map metadata, SecretKey key) {
+ return new InternalKeyEncapsulationResult(encapsulation, metadata, key);
+ }
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationService.java b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationService.java
new file mode 100644
index 0000000000..747c6c137e
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationService.java
@@ -0,0 +1,46 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.util.Map;
+import java.util.concurrent.CompletionStage;
+import javax.crypto.SecretKey;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A service responsible for encapsulating and decapsulating keys.
+ * @see KeyEncapsulationOptions
+ * @see EncapsulatedKey
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface KeyEncapsulationService {
+ /**
+ * Creates a new key, encapsulates it and returns the result.
+ * @param options the encapsulation options
+ * @return the encapsulation result
+ */
+ CompletionStage encapsulate(KeyEncapsulationOptions options);
+
+ /**
+ * Decapsulates encapsulated bytes.
+ * @param encapsulation the encapsulated bytes
+ * @param metadata the key metadata
+ * @return the key
+ */
+ CompletionStage decapsulate(byte[] encapsulation, Map metadata);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationServices.java b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationServices.java
new file mode 100644
index 0000000000..6e35f838dc
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/KeyEncapsulationServices.java
@@ -0,0 +1,61 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.security.NoSuchAlgorithmException;
+import java.security.Provider;
+import java.security.SecureRandom;
+import javax.crypto.SecretKey;
+import org.neo4j.driver.internal.property_encryption.LocalKeyEncapsulationService;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A factory for {@link KeyEncapsulationService} implementation provided with the driver.
+ *
+ * Note that additional implementations are possible.
+ * @see KeyEncapsulationService
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public final class KeyEncapsulationServices {
+ private KeyEncapsulationServices() {}
+
+ /**
+ * Returns a new {@link KeyEncapsulationService} implementation that uses the provided AES-256 {@link SecretKey}
+ * as a master key for encrypting and decrypting data keys.
+ * @param masterKey the master key
+ * @return the new implementation
+ * @throws NoSuchAlgorithmException if no AES algorithm is found
+ */
+ public static KeyEncapsulationService local(SecretKey masterKey) throws NoSuchAlgorithmException {
+ return new LocalKeyEncapsulationService(masterKey, null, null);
+ }
+
+ /**
+ * Returns a new {@link KeyEncapsulationService} implementation that uses the provided AES-256 {@link SecretKey}
+ * as a master key for encrypting and decrypting data keys.
+ * @param masterKey the master key
+ * @param provider the {@link Provider} to use for cryptographic operations, must not be {@literal null}
+ * @param secureRandomIV the {@link SecureRandom} to use for IV generation, must not be {@literal null}
+ * @return the new implementation
+ * @throws NoSuchAlgorithmException if no AES algorithm is found
+ */
+ public static KeyEncapsulationService local(SecretKey masterKey, Provider provider, SecureRandom secureRandomIV)
+ throws NoSuchAlgorithmException {
+ return new LocalKeyEncapsulationService(masterKey, provider, secureRandomIV);
+ }
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyDecryptionRequest.java b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyDecryptionRequest.java
new file mode 100644
index 0000000000..f33c26caed
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyDecryptionRequest.java
@@ -0,0 +1,212 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.time.LocalDate;
+import java.time.LocalTime;
+import java.time.OffsetTime;
+import java.util.UUID;
+import org.neo4j.driver.Value;
+import org.neo4j.driver.Values;
+import org.neo4j.driver.internal.property_encryption.InternalPropertyDecryptionRequest;
+import org.neo4j.driver.types.Point;
+import org.neo4j.driver.types.TypeSystem;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A Neo4j Property decryption request.
+ * @since 6.3.0
+ * @see PropertyEncryption
+ * @see org.neo4j.driver.property_encryption.async.AsyncPropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactive.ReactivePropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactivePropertyEncryption
+ */
+@Preview(name = "Property Encryption")
+public interface PropertyDecryptionRequest {
+ /**
+ * Returns a new instance of a build stage for {@link PropertyDecryptionRequest}.
+ * @return a new instance of a build stage
+ */
+ static PropertyDecryptionRequest.ValueStep builder() {
+ return new InternalPropertyDecryptionRequest();
+ }
+
+ /**
+ * A builder step for setting value.
+ */
+ interface ValueStep {
+ /**
+ * Sets the value to decrypt.
+ * @param value the value to decrypt
+ * @return the next builder step
+ */
+ AADStep fromValue(byte[] value);
+ }
+
+ /**
+ * A builder step for setting AAD.
+ */
+ interface AADStep {
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * Note that only a subset of types is supported for AAD, they are listed below:
+ *
+ * - {@link TypeSystem#BOOLEAN()}
+ * - {@link TypeSystem#BYTES()}
+ * - {@link TypeSystem#STRING()}
+ * - {@link TypeSystem#INTEGER()}
+ * - {@link TypeSystem#POINT()}
+ * - {@link TypeSystem#DATE()}
+ * - {@link TypeSystem#TIME()}
+ * - {@link TypeSystem#LOCAL_TIME()}
+ * - {@link TypeSystem#UUID()}
+ *
+ *
+ * @param aad the AAD value, both {@literal null} and {@link TypeSystem#NULL()} disable AAD
+ * @return the next builder step
+ */
+ BuildStep withAAD(Value aad);
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default BuildStep withAAD(boolean aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(LocalDate aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(OffsetTime aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(LocalTime aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default BuildStep withAAD(double aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default BuildStep withAAD(int aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default BuildStep withAAD(long aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(Point aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(String aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(UUID aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for decryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default BuildStep withAAD(byte[] aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Enables using the persisted AAD.
+ * @return the next builder step
+ */
+ BuildStep withPersistedAAD();
+ }
+
+ /**
+ * A builder step for building {@link PropertyDecryptionRequest}.
+ */
+ interface BuildStep {
+ /**
+ * Builds and returns a new {@link PropertyDecryptionRequest} instance.
+ * @return the new request instance
+ */
+ PropertyDecryptionRequest build();
+ }
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryption.java b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryption.java
new file mode 100644
index 0000000000..6971d24350
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryption.java
@@ -0,0 +1,59 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import org.neo4j.driver.Value;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A Neo4j Property encryption.
+ * @see org.neo4j.driver.property_encryption.async.AsyncPropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactive.ReactivePropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactivePropertyEncryption
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface PropertyEncryption extends BasePropertyEncryption {
+ /**
+ * Handles the provided {@link PropertyEncryptionRequest}.
+ * @param encryptRequest the request, must not be {@literal null}
+ * @return the encrypted bytes
+ */
+ byte[] encryptToBytes(PropertyEncryptionRequest encryptRequest);
+
+ /**
+ * Handles the provided {@link PropertyDecryptionRequest}.
+ * @param decryptRequest the request, must not be {@literal null}
+ * @return the decrypted value
+ */
+ Value decrypt(PropertyDecryptionRequest decryptRequest);
+
+ /**
+ * Returns key manager.
+ * @return key manager
+ */
+ default EncapsulatedKeyManager keyManager() {
+ return keyManager(null);
+ }
+
+ /**
+ * Returns key manager for a given profile name.
+ * @param profileName the profile name
+ * @return key manager, may be {@literal null} when only a single profile is available
+ */
+ EncapsulatedKeyManager keyManager(String profileName);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryptionProfile.java b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryptionProfile.java
new file mode 100644
index 0000000000..fec769c264
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryptionProfile.java
@@ -0,0 +1,38 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A profile for Neo4j Property Encryption.
+ *
+ * Each profile instance represents a specific encryption configuration that MUST have a unique name, which is also
+ * used for cross-driver interoperability.
+ *
+ * While there may be several profile types in the future, only {@link EnvelopePropertyEncryptionProfile} is supported
+ * for now.
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public sealed interface PropertyEncryptionProfile permits EnvelopePropertyEncryptionProfile {
+ /**
+ * Returns the unique profile name.
+ * @return the profile name
+ */
+ String name();
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryptionRequest.java b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryptionRequest.java
new file mode 100644
index 0000000000..8941c48d59
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/PropertyEncryptionRequest.java
@@ -0,0 +1,517 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption;
+
+import java.time.Duration;
+import java.time.LocalDate;
+import java.time.LocalDateTime;
+import java.time.LocalTime;
+import java.time.OffsetDateTime;
+import java.time.OffsetTime;
+import java.time.Period;
+import java.time.ZonedDateTime;
+import java.util.UUID;
+import org.neo4j.driver.Value;
+import org.neo4j.driver.Values;
+import org.neo4j.driver.internal.property_encryption.InternalPropertyEncryptionRequest;
+import org.neo4j.driver.types.IsoDuration;
+import org.neo4j.driver.types.Point;
+import org.neo4j.driver.types.TypeSystem;
+import org.neo4j.driver.types.Vector;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A Neo4j Property encryption request.
+ * @since 6.3.0
+ * @see PropertyEncryption
+ * @see org.neo4j.driver.property_encryption.async.AsyncPropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactive.ReactivePropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactivePropertyEncryption
+ */
+@Preview(name = "Property Encryption")
+public interface PropertyEncryptionRequest {
+ /**
+ * Returns a new instance of a build stage for {@link PropertyEncryptionRequest}.
+ * @return a new instance of a build stage
+ */
+ static ValueStep builder() {
+ return new InternalPropertyEncryptionRequest();
+ }
+
+ /**
+ * A builder step for setting value.
+ */
+ interface ValueStep {
+ /**
+ * Sets the value to encrypt.
+ *
+ * Note that the value MUST be of a supported Neo4j Property Type.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ AADStep fromValue(Value value);
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(boolean value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(LocalDate value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(OffsetTime value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(LocalTime value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(LocalDateTime value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(OffsetDateTime value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(ZonedDateTime value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(Period value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(Duration value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(IsoDuration value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(double value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(int value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(long value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(Point value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(char value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(String value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(Vector value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the value to encrypt.
+ *
+ * @param value the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(UUID value) {
+ return fromValue(Values.value(value));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the values to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(byte... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(String... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(boolean... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(char... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(short... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(int... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(long... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(float... values) {
+ return fromValue(Values.value(values));
+ }
+
+ /**
+ * Sets the values to encrypt.
+ *
+ * @param values the value to encrypt
+ * @return the next builder step
+ */
+ default AADStep fromValue(double... values) {
+ return fromValue(Values.value(values));
+ }
+ }
+
+ /**
+ * A builder step for setting AAD.
+ */
+ interface AADStep extends ProfileStep {
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * Note that only a subset of types is supported for AAD, they are listed below:
+ *
+ * - {@link TypeSystem#BOOLEAN()}
+ * - {@link TypeSystem#BYTES()}
+ * - {@link TypeSystem#STRING()}
+ * - {@link TypeSystem#INTEGER()}
+ * - {@link TypeSystem#POINT()}
+ * - {@link TypeSystem#DATE()}
+ * - {@link TypeSystem#TIME()}
+ * - {@link TypeSystem#LOCAL_TIME()}
+ * - {@link TypeSystem#UUID()}
+ *
+ *
+ * @param aad the AAD value, both {@literal null} and {@link TypeSystem#NULL()} disable AAD
+ * @return the next builder step
+ */
+ ProfileStep withAAD(Value aad);
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(boolean aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(LocalDate aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(OffsetTime aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(LocalTime aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(double aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(int aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(long aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(Point aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(String aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(UUID aad) {
+ return withAAD(Values.value(aad));
+ }
+
+ /**
+ * Adds the supplied value as AAD for encryption request.
+ *
+ * @param aad the AAD value, {@literal null} disables AAD
+ * @return the next builder step
+ */
+ default ProfileStep withAAD(byte[] aad) {
+ return withAAD(Values.value(aad));
+ }
+ }
+
+ /**
+ * A builder step for selection encryption profile.
+ */
+ interface ProfileStep extends EncryptionKeyReferenceStep {
+ /**
+ * Sets the profile name to use.
+ * @param profileName the profile name
+ * @return the next builder step
+ */
+ EncryptionKeyReferenceStep usingProfile(String profileName);
+ }
+
+ /**
+ * A builder step for selecting key.
+ */
+ interface EncryptionKeyReferenceStep {
+ /**
+ * Sets the key id to use.
+ * @param keyId the key id
+ * @return the next builder step
+ */
+ BuildStep usingKeyId(String keyId);
+
+ /**
+ * Sets the key alias to use.
+ * @param keyAlias the key alias
+ * @return the next builder step
+ */
+ BuildStep usingKeyAlias(String keyAlias);
+ }
+
+ /**
+ * A builder step for building {@link PropertyEncryptionRequest}.
+ */
+ interface BuildStep {
+ /**
+ * Builds and returns a new {@link PropertyEncryptionRequest} instance.
+ * @return the new request instance
+ */
+ PropertyEncryptionRequest build();
+ }
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/async/AsyncEncapsulatedKeyManager.java b/driver/src/main/java/org/neo4j/driver/property_encryption/async/AsyncEncapsulatedKeyManager.java
new file mode 100644
index 0000000000..df2d11f99f
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/async/AsyncEncapsulatedKeyManager.java
@@ -0,0 +1,89 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.async;
+
+import java.util.Optional;
+import java.util.concurrent.CompletionStage;
+import org.neo4j.driver.property_encryption.EncapsulatedKey;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * An asynchronous manager for encapsulated keys.
+ * @see org.neo4j.driver.property_encryption.EncapsulatedKeyManager
+ * @see org.neo4j.driver.property_encryption.reactive.ReactiveEncapsulatedKeyManager
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactiveEncapsulatedKeyManager
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface AsyncEncapsulatedKeyManager {
+ /**
+ * Creates a new encapsulated key without key alias.
+ * @return the encapsulated key
+ */
+ default CompletionStage createAsync() {
+ return createAsync(null);
+ }
+
+ /**
+ * Creates a new encapsulated key with the provided key alias.
+ * @param alias the key alias, may be {@literal null}
+ * @return the encapsulated key
+ */
+ default CompletionStage createAsync(String alias) {
+ return createAsync(alias, null);
+ }
+
+ /**
+ * Creates a new encapsulated key with the provided key alias and {@link KeyEncapsulationOptions}.
+ * @param alias the key alias, may be {@literal null}
+ * @param encapsulationOptions the key encapsulation options, may be {@literal null}
+ * @return the encapsulated key
+ */
+ CompletionStage createAsync(String alias, KeyEncapsulationOptions encapsulationOptions);
+
+ /**
+ * Finds encapsulated key by its alias.
+ * @param alias the key alias, must not be {@literal null}
+ * @return the encapsulated key or {@link Optional#empty()} otherwise
+ */
+ CompletionStage findByAliasAsync(String alias);
+
+ /**
+ * Updates encapsulated key alias by id.
+ * @param id the key id, must not be {@literal null}
+ * @param alias the new key alias, may be {@literal null}
+ * @return {@link Void}
+ */
+ CompletionStage updateAliasByIdAsync(String id, String alias);
+
+ /**
+ * Deletes encapsulated key alias by id.
+ * @param id the key id, must not be {@literal null}
+ * @return {@link Void}
+ */
+ default CompletionStage deleteAliasByIdAsync(String id) {
+ return updateAliasByIdAsync(id, null);
+ }
+
+ /**
+ * Deletes encapsulated key by id.
+ * @param id the key id, must not be {@literal null}
+ * @return {@link Void}
+ */
+ CompletionStage deleteByIdAsync(String id);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/async/AsyncPropertyEncryption.java b/driver/src/main/java/org/neo4j/driver/property_encryption/async/AsyncPropertyEncryption.java
new file mode 100644
index 0000000000..83b73f14d2
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/async/AsyncPropertyEncryption.java
@@ -0,0 +1,63 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.async;
+
+import java.util.concurrent.CompletionStage;
+import org.neo4j.driver.Value;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
+import org.neo4j.driver.property_encryption.PropertyDecryptionRequest;
+import org.neo4j.driver.property_encryption.PropertyEncryptionRequest;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * An asynchronous Neo4j Property encryption.
+ * @see org.neo4j.driver.property_encryption.PropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactive.ReactivePropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactivePropertyEncryption
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface AsyncPropertyEncryption extends BasePropertyEncryption {
+ /**
+ * Handles the provided {@link PropertyEncryptionRequest}.
+ * @param encryptRequest the request, must not be {@literal null}
+ * @return the encrypted bytes
+ */
+ CompletionStage encryptToBytesAsync(PropertyEncryptionRequest encryptRequest);
+
+ /**
+ * Handles the provided {@link PropertyDecryptionRequest}.
+ * @param decryptRequest the request, must not be {@literal null}
+ * @return the decrypted value
+ */
+ CompletionStage decryptAsync(PropertyDecryptionRequest decryptRequest);
+
+ /**
+ * Returns key manager.
+ * @return key manager
+ */
+ default AsyncEncapsulatedKeyManager keyManager() {
+ return keyManager(null);
+ }
+
+ /**
+ * Returns key manager for a given profile name.
+ * @param profileName the profile name
+ * @return key manager, may be {@literal null} when only a single profile is available
+ */
+ AsyncEncapsulatedKeyManager keyManager(String profileName);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/reactive/ReactiveEncapsulatedKeyManager.java b/driver/src/main/java/org/neo4j/driver/property_encryption/reactive/ReactiveEncapsulatedKeyManager.java
new file mode 100644
index 0000000000..b7a722f812
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/reactive/ReactiveEncapsulatedKeyManager.java
@@ -0,0 +1,90 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.reactive;
+
+import java.util.Optional;
+import java.util.concurrent.Flow.Publisher;
+import org.neo4j.driver.property_encryption.EncapsulatedKey;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A reactive manager for encapsulated keys.
+ *
+ * @see org.neo4j.driver.property_encryption.EncapsulatedKeyManager
+ * @see org.neo4j.driver.property_encryption.async.AsyncEncapsulatedKeyManager
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactiveEncapsulatedKeyManager
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface ReactiveEncapsulatedKeyManager {
+ /**
+ * Creates a new encapsulated key without key alias.
+ * @return the encapsulated key
+ */
+ default Publisher create() {
+ return create(null);
+ }
+
+ /**
+ * Creates a new encapsulated key with the provided key alias.
+ * @param alias the key alias, may be {@literal null}
+ * @return the encapsulated key
+ */
+ default Publisher create(String alias) {
+ return create(alias, null);
+ }
+
+ /**
+ * Creates a new encapsulated key with the provided key alias and {@link KeyEncapsulationOptions}.
+ * @param alias the key alias, may be {@literal null}
+ * @param encapsulationOptions the key encapsulation options, may be {@literal null}
+ * @return the encapsulated key
+ */
+ Publisher create(String alias, KeyEncapsulationOptions encapsulationOptions);
+
+ /**
+ * Finds encapsulated key by its alias.
+ * @param alias the key alias, must not be {@literal null}
+ * @return the encapsulated key or {@link Optional#empty()} otherwise
+ */
+ Publisher findByAlias(String alias);
+
+ /**
+ * Updates encapsulated key alias by id.
+ * @param id the key id, must not be {@literal null}
+ * @param alias the new key alias, may be {@literal null}
+ * @return {@link Void}
+ */
+ Publisher updateAliasById(String id, String alias);
+
+ /**
+ * Deletes encapsulated key alias by id.
+ * @param id the key id, must not be {@literal null}
+ * @return {@link Void}
+ */
+ default Publisher deleteAliasById(String id) {
+ return updateAliasById(id, null);
+ }
+
+ /**
+ * Deletes encapsulated key by id.
+ * @param id the key id, must not be {@literal null}
+ * @return {@link Void}
+ */
+ Publisher deleteById(String id);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/reactive/ReactivePropertyEncryption.java b/driver/src/main/java/org/neo4j/driver/property_encryption/reactive/ReactivePropertyEncryption.java
new file mode 100644
index 0000000000..062e7436e5
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/reactive/ReactivePropertyEncryption.java
@@ -0,0 +1,63 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.reactive;
+
+import java.util.concurrent.Flow.Publisher;
+import org.neo4j.driver.Value;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
+import org.neo4j.driver.property_encryption.PropertyDecryptionRequest;
+import org.neo4j.driver.property_encryption.PropertyEncryptionRequest;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * A reactive Neo4j Property encryption.
+ * @see org.neo4j.driver.property_encryption.PropertyEncryption
+ * @see org.neo4j.driver.property_encryption.async.AsyncPropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactivestreams.ReactivePropertyEncryption
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface ReactivePropertyEncryption extends BasePropertyEncryption {
+ /**
+ * Handles the provided {@link PropertyEncryptionRequest}.
+ * @param encryptRequest the request, must not be {@literal null}
+ * @return the encrypted bytes
+ */
+ Publisher encryptToBytes(PropertyEncryptionRequest encryptRequest);
+
+ /**
+ * Handles the provided {@link PropertyDecryptionRequest}.
+ * @param decryptRequest the request, must not be {@literal null}
+ * @return the decrypted value
+ */
+ Publisher decrypt(PropertyDecryptionRequest decryptRequest);
+
+ /**
+ * Returns key manager.
+ * @return key manager
+ */
+ default ReactiveEncapsulatedKeyManager keyManager() {
+ return keyManager(null);
+ }
+
+ /**
+ * Returns key manager for a given profile name.
+ * @param profileName the profile name
+ * @return key manager, may be {@literal null} when only a single profile is available
+ */
+ ReactiveEncapsulatedKeyManager keyManager(String profileName);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/reactivestreams/ReactiveEncapsulatedKeyManager.java b/driver/src/main/java/org/neo4j/driver/property_encryption/reactivestreams/ReactiveEncapsulatedKeyManager.java
new file mode 100644
index 0000000000..e92445e7d0
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/reactivestreams/ReactiveEncapsulatedKeyManager.java
@@ -0,0 +1,90 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.reactivestreams;
+
+import java.util.Optional;
+import org.neo4j.driver.property_encryption.EncapsulatedKey;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.util.Preview;
+import org.reactivestreams.Publisher;
+
+/**
+ * A reactive manager for encapsulated keys.
+ *
+ * @see org.neo4j.driver.property_encryption.EncapsulatedKeyManager
+ * @see org.neo4j.driver.property_encryption.async.AsyncEncapsulatedKeyManager
+ * @see org.neo4j.driver.property_encryption.reactive.ReactiveEncapsulatedKeyManager
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface ReactiveEncapsulatedKeyManager {
+ /**
+ * Creates a new encapsulated key without key alias.
+ * @return the encapsulated key
+ */
+ default Publisher create() {
+ return create(null);
+ }
+
+ /**
+ * Creates a new encapsulated key with the provided key alias.
+ * @param alias the key alias, may be {@literal null}
+ * @return the encapsulated key
+ */
+ default Publisher create(String alias) {
+ return create(alias, null);
+ }
+
+ /**
+ * Creates a new encapsulated key with the provided key alias and {@link KeyEncapsulationOptions}.
+ * @param alias the key alias, may be {@literal null}
+ * @param encapsulationOptions the key encapsulation options, may be {@literal null}
+ * @return the encapsulated key
+ */
+ Publisher create(String alias, KeyEncapsulationOptions encapsulationOptions);
+
+ /**
+ * Finds encapsulated key by its alias.
+ * @param alias the key alias, must not be {@literal null}
+ * @return the encapsulated key or {@link Optional#empty()} otherwise
+ */
+ Publisher findByAlias(String alias);
+
+ /**
+ * Updates encapsulated key alias by id.
+ * @param id the key id, must not be {@literal null}
+ * @param alias the new key alias, may be {@literal null}
+ * @return {@link Void}
+ */
+ Publisher updateAliasById(String id, String alias);
+
+ /**
+ * Deletes encapsulated key alias by id.
+ * @param id the key id, must not be {@literal null}
+ * @return {@link Void}
+ */
+ default Publisher deleteAliasById(String id) {
+ return updateAliasById(id, null);
+ }
+
+ /**
+ * Deletes encapsulated key by id.
+ * @param id the key id, must not be {@literal null}
+ * @return {@link Void}
+ */
+ Publisher deleteById(String id);
+}
diff --git a/driver/src/main/java/org/neo4j/driver/property_encryption/reactivestreams/ReactivePropertyEncryption.java b/driver/src/main/java/org/neo4j/driver/property_encryption/reactivestreams/ReactivePropertyEncryption.java
new file mode 100644
index 0000000000..dbef77bda0
--- /dev/null
+++ b/driver/src/main/java/org/neo4j/driver/property_encryption/reactivestreams/ReactivePropertyEncryption.java
@@ -0,0 +1,63 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.reactivestreams;
+
+import org.neo4j.driver.Value;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
+import org.neo4j.driver.property_encryption.PropertyDecryptionRequest;
+import org.neo4j.driver.property_encryption.PropertyEncryptionRequest;
+import org.neo4j.driver.util.Preview;
+import org.reactivestreams.Publisher;
+
+/**
+ * A reactive Neo4j Property encryption.
+ * @see org.neo4j.driver.property_encryption.PropertyEncryption
+ * @see org.neo4j.driver.property_encryption.async.AsyncPropertyEncryption
+ * @see org.neo4j.driver.property_encryption.reactive.ReactivePropertyEncryption
+ * @since 6.3.0
+ */
+@Preview(name = "Property Encryption")
+public interface ReactivePropertyEncryption extends BasePropertyEncryption {
+ /**
+ * Handles the provided {@link PropertyEncryptionRequest}.
+ * @param encryptRequest the request, must not be {@literal null}
+ * @return the encrypted bytes
+ */
+ Publisher encryptToBytes(PropertyEncryptionRequest encryptRequest);
+
+ /**
+ * Handles the provided {@link PropertyDecryptionRequest}.
+ * @param decryptRequest the request, must not be {@literal null}
+ * @return the decrypted value
+ */
+ Publisher decrypt(PropertyDecryptionRequest decryptRequest);
+
+ /**
+ * Returns key manager.
+ * @return key manager
+ */
+ default ReactiveEncapsulatedKeyManager keyManager() {
+ return keyManager(null);
+ }
+
+ /**
+ * Returns key manager for a given profile name.
+ * @param profileName the profile name
+ * @return key manager, may be {@literal null} when only a single profile is available
+ */
+ ReactiveEncapsulatedKeyManager keyManager(String profileName);
+}
diff --git a/driver/src/test/java/org/neo4j/driver/ConfigTest.java b/driver/src/test/java/org/neo4j/driver/ConfigTest.java
index 254cb5bd10..c20f2f1048 100644
--- a/driver/src/test/java/org/neo4j/driver/ConfigTest.java
+++ b/driver/src/test/java/org/neo4j/driver/ConfigTest.java
@@ -30,6 +30,7 @@
import java.io.File;
import java.io.IOException;
import java.io.Serializable;
+import java.util.HashSet;
import java.util.Set;
import java.util.concurrent.TimeUnit;
import java.util.logging.Level;
@@ -46,6 +47,8 @@
import org.neo4j.driver.internal.observation.DriverObservationProvider;
import org.neo4j.driver.net.ServerAddressResolver;
import org.neo4j.driver.observation.ObservationProvider;
+import org.neo4j.driver.property_encryption.EnvelopePropertyEncryptionProfile;
+import org.neo4j.driver.property_encryption.PropertyEncryptionProfile;
import org.neo4j.driver.testutil.TestUtil;
class ConfigTest {
@@ -568,4 +571,59 @@ void shouldAllowNullObservationProvider() {
assertTrue(config.observationProvider().isEmpty());
}
+
+ @Test
+ void shouldHaveNoEncryptionProfilesByDefault() {
+ // Given
+ var config = Config.defaultConfig();
+
+ // When & Then
+ assertTrue(config.propertyEncryptionProfiles().isEmpty());
+ }
+
+ @Test
+ void shouldSetEncryptionProfiles() {
+ // Given
+ var profiles = Set.of(
+ EnvelopePropertyEncryptionProfile.builder("profile-0", mock(), mock())
+ .build(),
+ EnvelopePropertyEncryptionProfile.builder("profile-1", mock(), mock())
+ .build());
+ var config = Config.builder()
+ .withPropertyEncryptionProfiles(profiles.toArray(PropertyEncryptionProfile[]::new))
+ .build();
+
+ // When
+ var actualProfiles = config.propertyEncryptionProfiles();
+
+ // Then
+ assertEquals(profiles, actualProfiles);
+ }
+
+ @Test
+ void shouldRejectDuplicateEncryptionProfileNames() {
+ // Given
+ var profiles = Set.of(
+ EnvelopePropertyEncryptionProfile.builder("profile-0", mock(), mock())
+ .build(),
+ EnvelopePropertyEncryptionProfile.builder("profile-1", mock(), mock())
+ .build());
+
+ // When & Then
+ assertThrows(IllegalArgumentException.class, () -> Config.builder()
+ .withPropertyEncryptionProfiles(profiles.toArray(PropertyEncryptionProfile[]::new)));
+ }
+
+ @Test
+ void shouldRejectNullEncryptionProfileElement() {
+ // Given
+ var profiles = new HashSet();
+ profiles.add(EnvelopePropertyEncryptionProfile.builder("profile-0", mock(), mock())
+ .build());
+ profiles.add(null);
+
+ // When & Then
+ assertThrows(NullPointerException.class, () -> Config.builder()
+ .withPropertyEncryptionProfiles(profiles.toArray(PropertyEncryptionProfile[]::new)));
+ }
}
diff --git a/driver/src/test/java/org/neo4j/driver/internal/InternalDriverTest.java b/driver/src/test/java/org/neo4j/driver/internal/InternalDriverTest.java
index e94065345c..1bf2d86553 100644
--- a/driver/src/test/java/org/neo4j/driver/internal/InternalDriverTest.java
+++ b/driver/src/test/java/org/neo4j/driver/internal/InternalDriverTest.java
@@ -18,6 +18,7 @@
import static java.util.concurrent.CompletableFuture.failedFuture;
import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertInstanceOf;
import static org.junit.jupiter.api.Assertions.assertNotNull;
import static org.junit.jupiter.api.Assertions.assertNull;
import static org.junit.jupiter.api.Assertions.assertThrows;
@@ -29,13 +30,20 @@
import static org.neo4j.driver.testutil.TestUtil.await;
import java.util.Collections;
+import java.util.Map;
import java.util.concurrent.CompletableFuture;
import org.junit.jupiter.api.Test;
+import org.junit.jupiter.params.ParameterizedTest;
+import org.junit.jupiter.params.provider.ValueSource;
import org.neo4j.driver.Config;
import org.neo4j.driver.QueryConfig;
import org.neo4j.driver.exceptions.ServiceUnavailableException;
import org.neo4j.driver.internal.observation.NoopObservationProvider;
import org.neo4j.driver.internal.security.BoltSecurityPlanManager;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
+import org.neo4j.driver.property_encryption.PropertyEncryption;
+import org.neo4j.driver.property_encryption.async.AsyncPropertyEncryption;
+import org.neo4j.driver.property_encryption.reactive.ReactivePropertyEncryption;
class InternalDriverTest {
@Test
@@ -100,13 +108,48 @@ void shouldCreateExecutableQuery() {
assertEquals(QueryConfig.defaultConfig(), executableQuery.config());
}
+ @Test
+ void shouldReturnPropertyEncryption() {
+ // Given
+ var driver = newDriver();
+
+ // When
+ var propertyEncryption = driver.propertyEncryption();
+
+ // Then
+ assertNotNull(propertyEncryption);
+ assertInstanceOf(PropertyEncryption.class, propertyEncryption);
+ }
+
+ @ParameterizedTest
+ @ValueSource(
+ classes = {
+ PropertyEncryption.class,
+ AsyncPropertyEncryption.class,
+ ReactivePropertyEncryption.class,
+ org.neo4j.driver.property_encryption.reactivestreams.ReactivePropertyEncryption.class
+ })
+ void shouldReturnPropertyEncryption(Class propertyEncryptionClass) {
+ // Given
+ var driver = newDriver();
+
+ // When
+ var propertyEncryption = driver.propertyEncryption(propertyEncryptionClass);
+
+ // Then
+ assertNotNull(propertyEncryption);
+ assertInstanceOf(propertyEncryptionClass, propertyEncryption);
+ }
+
private static InternalDriver newDriver(SessionFactory sessionFactory) {
return new InternalDriver(
BoltSecurityPlanManager.insecure(),
sessionFactory,
true,
DEV_NULL_LOGGING,
- NoopObservationProvider.getInstance());
+ NoopObservationProvider.getInstance(),
+ Map.of(),
+ mock());
}
private static SessionFactory sessionFactoryMock() {
@@ -124,6 +167,8 @@ private static InternalDriver newDriver() {
sessionFactory,
true,
DEV_NULL_LOGGING,
- NoopObservationProvider.getInstance());
+ NoopObservationProvider.getInstance(),
+ Map.of(),
+ mock());
}
}
diff --git a/encryption/LICENSES.txt b/encryption/LICENSES.txt
new file mode 100644
index 0000000000..f8e0fd3292
--- /dev/null
+++ b/encryption/LICENSES.txt
@@ -0,0 +1,5 @@
+This file contains the full license text of the included third party
+libraries. For an overview of the licenses see the NOTICE.txt file.
+
+
+
diff --git a/encryption/NOTICE.txt b/encryption/NOTICE.txt
new file mode 100644
index 0000000000..c3bf48c6fc
--- /dev/null
+++ b/encryption/NOTICE.txt
@@ -0,0 +1,20 @@
+Copyright (c) "Neo4j"
+Neo4j Sweden AB [https://neo4j.com]
+
+This file is part of Neo4j.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+
+Full license texts are found in LICENSES.txt.
+
+
+Third-party licenses
+--------------------
+
diff --git a/encryption/aws-kms/LICENSES.txt b/encryption/aws-kms/LICENSES.txt
new file mode 100644
index 0000000000..73ffe5dc7e
--- /dev/null
+++ b/encryption/aws-kms/LICENSES.txt
@@ -0,0 +1,292 @@
+This file contains the full license text of the included third party
+libraries. For an overview of the licenses see the NOTICE.txt file.
+
+
+------------------------------------------------------------------------------
+Apache Software License, Version 2.0
+ AWS Event Stream
+ AWS Java SDK :: Annotations
+ AWS Java SDK :: Auth
+ AWS Java SDK :: AWS Core
+ AWS Java SDK :: Checksums
+ AWS Java SDK :: Checksums SPI
+ AWS Java SDK :: Core :: Protocols :: AWS Json Protocol
+ AWS Java SDK :: Core :: Protocols :: Json Utils
+ AWS Java SDK :: Core :: Protocols :: Protocol Core
+ AWS Java SDK :: Endpoints SPI
+ AWS Java SDK :: HTTP Auth
+ AWS Java SDK :: HTTP Auth AWS
+ AWS Java SDK :: HTTP Auth Event Stream
+ AWS Java SDK :: HTTP Auth SPI
+ AWS Java SDK :: HTTP Client Interface
+ AWS Java SDK :: Identity SPI
+ AWS Java SDK :: Metrics SPI
+ AWS Java SDK :: Profiles
+ AWS Java SDK :: Regions
+ AWS Java SDK :: Retries
+ AWS Java SDK :: Retries API
+ AWS Java SDK :: SDK Core
+ AWS Java SDK :: Services :: AWS KMS
+ AWS Java SDK :: Third Party :: Jackson-core
+ AWS Java SDK :: Utilities
+ AWS Java SDK :: Utils Lite
+------------------------------------------------------------------------------
+
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
+
+
+
+------------------------------------------------------------------------------
+MIT License
+ SLF4J API Module
+------------------------------------------------------------------------------
+
+The MIT License
+
+Copyright (c)
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in
+all copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
+THE SOFTWARE.
+
+
+
+------------------------------------------------------------------------------
+MIT No Attribution License
+ reactive-streams
+------------------------------------------------------------------------------
+
+MIT No Attribution
+
+Copyright
+
+Permission is hereby granted, free of charge, to any person obtaining a copy of this
+software and associated documentation files (the "Software"), to deal in the Software
+without restriction, including without limitation the rights to use, copy, modify,
+merge, publish, distribute, sublicense, and/or sell copies of the Software, and to
+permit persons to whom the Software is furnished to do so.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
+INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
+PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
+HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
+OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
+SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+
+
+
+
diff --git a/encryption/aws-kms/NOTICE.txt b/encryption/aws-kms/NOTICE.txt
new file mode 100644
index 0000000000..7224d32537
--- /dev/null
+++ b/encryption/aws-kms/NOTICE.txt
@@ -0,0 +1,54 @@
+Copyright (c) "Neo4j"
+Neo4j Sweden AB [https://neo4j.com]
+
+This file is part of Neo4j.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+
+Full license texts are found in LICENSES.txt.
+
+
+Third-party licenses
+--------------------
+
+Apache Software License, Version 2.0
+ AWS Event Stream
+ AWS Java SDK :: Annotations
+ AWS Java SDK :: Auth
+ AWS Java SDK :: AWS Core
+ AWS Java SDK :: Checksums
+ AWS Java SDK :: Checksums SPI
+ AWS Java SDK :: Core :: Protocols :: AWS Json Protocol
+ AWS Java SDK :: Core :: Protocols :: Json Utils
+ AWS Java SDK :: Core :: Protocols :: Protocol Core
+ AWS Java SDK :: Endpoints SPI
+ AWS Java SDK :: HTTP Auth
+ AWS Java SDK :: HTTP Auth AWS
+ AWS Java SDK :: HTTP Auth Event Stream
+ AWS Java SDK :: HTTP Auth SPI
+ AWS Java SDK :: HTTP Client Interface
+ AWS Java SDK :: Identity SPI
+ AWS Java SDK :: Metrics SPI
+ AWS Java SDK :: Profiles
+ AWS Java SDK :: Regions
+ AWS Java SDK :: Retries
+ AWS Java SDK :: Retries API
+ AWS Java SDK :: SDK Core
+ AWS Java SDK :: Services :: AWS KMS
+ AWS Java SDK :: Third Party :: Jackson-core
+ AWS Java SDK :: Utilities
+ AWS Java SDK :: Utils Lite
+
+MIT License
+ SLF4J API Module
+
+MIT No Attribution License
+ reactive-streams
+
diff --git a/encryption/aws-kms/pom.xml b/encryption/aws-kms/pom.xml
new file mode 100644
index 0000000000..f120181492
--- /dev/null
+++ b/encryption/aws-kms/pom.xml
@@ -0,0 +1,68 @@
+
+ 4.0.0
+
+
+ org.neo4j.driver
+ neo4j-java-driver-parent
+ 6.3-SNAPSHOT
+ ../../pom.xml
+
+
+ neo4j-java-driver-encryption-aws-kms
+
+ Neo4j Java Driver (AWS KMS)
+ The Neo4j Java Driver Encryption module providing encryption using AWS KMS.
+
+
+ false
+ false
+
+
+
+
+ org.neo4j.driver
+ neo4j-java-driver
+ ${project.version}
+ provided
+
+
+ software.amazon.awssdk
+ kms
+
+
+ org.junit.jupiter
+ junit-jupiter
+ test
+
+
+
+
+
+
+ software.amazon.awssdk
+ bom
+ 2.40.4
+ pom
+ import
+
+
+
+
+
+
+
+ org.apache.maven.plugins
+ maven-javadoc-plugin
+
+
+
+
+
+ scm:git:git://github.com/neo4j/neo4j-java-driver.git
+ scm:git:git@github.com:neo4j/neo4j-java-driver.git
+ https://github.com/neo4j/neo4j-java-driver
+
+
+
diff --git a/encryption/aws-kms/src/main/java/org/neo4j/driver/property_encryption/aws_kms/AWSKeyEncapsulationService.java b/encryption/aws-kms/src/main/java/org/neo4j/driver/property_encryption/aws_kms/AWSKeyEncapsulationService.java
new file mode 100644
index 0000000000..340e1a78ee
--- /dev/null
+++ b/encryption/aws-kms/src/main/java/org/neo4j/driver/property_encryption/aws_kms/AWSKeyEncapsulationService.java
@@ -0,0 +1,72 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.aws_kms;
+
+import java.security.NoSuchAlgorithmException;
+import java.util.Map;
+import java.util.Objects;
+import java.util.concurrent.CompletionStage;
+import javax.crypto.KeyGenerator;
+import javax.crypto.SecretKey;
+import javax.crypto.spec.SecretKeySpec;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResult;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResults;
+import org.neo4j.driver.property_encryption.KeyEncapsulationService;
+import software.amazon.awssdk.core.SdkBytes;
+import software.amazon.awssdk.services.kms.KmsAsyncClient;
+import software.amazon.awssdk.services.kms.model.DecryptRequest;
+import software.amazon.awssdk.services.kms.model.EncryptRequest;
+
+public final class AWSKeyEncapsulationService implements KeyEncapsulationService {
+ private final KmsAsyncClient kms;
+ private final AwsKeyEncapsulationOptions defaultOptions;
+ private final KeyGenerator keyGenerator;
+
+ public AWSKeyEncapsulationService(AwsKeyEncapsulationOptions defaultOptions) throws NoSuchAlgorithmException {
+ this.kms = KmsAsyncClient.create();
+ this.defaultOptions = Objects.requireNonNull(defaultOptions);
+ this.keyGenerator = KeyGenerator.getInstance("AES");
+ this.keyGenerator.init(256);
+ }
+
+ @Override
+ public CompletionStage encapsulate(KeyEncapsulationOptions options) {
+ var encapsulationOptions = Objects.requireNonNullElse(options, defaultOptions);
+ var kmsKeyId = ((AwsKeyEncapsulationOptions) encapsulationOptions).keyId();
+ var key = keyGenerator.generateKey();
+ var req = EncryptRequest.builder()
+ .keyId(kmsKeyId)
+ .plaintext(SdkBytes.fromByteArray(key.getEncoded()))
+ .build();
+ return kms.encrypt(req)
+ .thenApply(encryptResponse -> KeyEncapsulationResults.create(
+ encryptResponse.ciphertextBlob().asByteArray(), encapsulationOptions.toMap(), key));
+ }
+
+ @Override
+ public CompletionStage decapsulate(byte[] ciphertext, Map metadata) {
+ var options = AwsKeyEncapsulationOptions.of(metadata);
+ var req = DecryptRequest.builder()
+ .keyId(options.keyId())
+ .ciphertextBlob(SdkBytes.fromByteArray(ciphertext))
+ .build();
+ return kms.decrypt(req)
+ .thenApply(decryptResponse ->
+ new SecretKeySpec(decryptResponse.plaintext().asByteArray(), "AES"));
+ }
+}
diff --git a/encryption/aws-kms/src/main/java/org/neo4j/driver/property_encryption/aws_kms/AwsKeyEncapsulationOptions.java b/encryption/aws-kms/src/main/java/org/neo4j/driver/property_encryption/aws_kms/AwsKeyEncapsulationOptions.java
new file mode 100644
index 0000000000..797ded51c2
--- /dev/null
+++ b/encryption/aws-kms/src/main/java/org/neo4j/driver/property_encryption/aws_kms/AwsKeyEncapsulationOptions.java
@@ -0,0 +1,49 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.aws_kms;
+
+import java.util.Map;
+import java.util.Objects;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+
+public final class AwsKeyEncapsulationOptions implements KeyEncapsulationOptions {
+ public static final String KMS_KEY_ID = "kmsKeyId";
+
+ public static AwsKeyEncapsulationOptions of(String keyId) {
+ return new AwsKeyEncapsulationOptions(keyId);
+ }
+
+ public static AwsKeyEncapsulationOptions of(Map metadata) {
+ var keyId = metadata.get(KMS_KEY_ID);
+ return new AwsKeyEncapsulationOptions(keyId);
+ }
+
+ private final String keyId;
+
+ private AwsKeyEncapsulationOptions(String keyId) {
+ this.keyId = Objects.requireNonNull(keyId);
+ }
+
+ public String keyId() {
+ return keyId;
+ }
+
+ @Override
+ public Map toMap() {
+ return Map.of(KMS_KEY_ID, keyId);
+ }
+}
diff --git a/encryption/azure-keyvault/LICENSES.txt b/encryption/azure-keyvault/LICENSES.txt
new file mode 100644
index 0000000000..e783e6585e
--- /dev/null
+++ b/encryption/azure-keyvault/LICENSES.txt
@@ -0,0 +1,302 @@
+This file contains the full license text of the included third party
+libraries. For an overview of the licenses see the NOTICE.txt file.
+
+
+------------------------------------------------------------------------------
+Apache Software License, Version 2.0
+ Core functionality for the Reactor Netty library
+ HTTP functionality for the Reactor Netty library
+ Jackson datatype: JSR310
+ Jackson-annotations
+ Jackson-core
+ jackson-databind
+ Java Native Access
+ Java Native Access Platform
+ Netty/Buffer
+ Netty/Codec
+ Netty/Codec/Base
+ Netty/Codec/Compression
+ Netty/Codec/DNS
+ Netty/Codec/HTTP
+ Netty/Codec/HTTP2
+ Netty/Codec/Marshalling
+ Netty/Codec/Protobuf
+ Netty/Codec/Socks
+ Netty/Common
+ Netty/Handler
+ Netty/Handler/Proxy
+ Netty/Resolver
+ Netty/Resolver/DNS
+ Netty/TomcatNative [BoringSSL - Static]
+ Netty/TomcatNative [OpenSSL - Classes]
+ Netty/Transport
+ Netty/Transport/Native/Unix/Common
+ Non-Blocking Reactive Foundation for the JVM
+------------------------------------------------------------------------------
+
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
+
+
+
+------------------------------------------------------------------------------
+MIT License
+ Microsoft Azure client library for Identity
+ Microsoft Azure client library for KeyVault Keys
+ Microsoft Azure Java Core Library
+ Microsoft Azure Java JSON Library
+ Microsoft Azure Java XML Library
+ Microsoft Azure Netty HTTP Client Library
+ msal4j
+ msal4j-persistence-extension
+ SLF4J API Module
+------------------------------------------------------------------------------
+
+The MIT License
+
+Copyright (c)
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in
+all copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
+THE SOFTWARE.
+
+
+
+------------------------------------------------------------------------------
+MIT No Attribution License
+ reactive-streams
+------------------------------------------------------------------------------
+
+MIT No Attribution
+
+Copyright
+
+Permission is hereby granted, free of charge, to any person obtaining a copy of this
+software and associated documentation files (the "Software"), to deal in the Software
+without restriction, including without limitation the rights to use, copy, modify,
+merge, publish, distribute, sublicense, and/or sell copies of the Software, and to
+permit persons to whom the Software is furnished to do so.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
+INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
+PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
+HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
+OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
+SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+
+
+
+
diff --git a/encryption/azure-keyvault/NOTICE.txt b/encryption/azure-keyvault/NOTICE.txt
new file mode 100644
index 0000000000..1904a567d9
--- /dev/null
+++ b/encryption/azure-keyvault/NOTICE.txt
@@ -0,0 +1,64 @@
+Copyright (c) "Neo4j"
+Neo4j Sweden AB [https://neo4j.com]
+
+This file is part of Neo4j.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+
+Full license texts are found in LICENSES.txt.
+
+
+Third-party licenses
+--------------------
+
+Apache Software License, Version 2.0
+ Core functionality for the Reactor Netty library
+ HTTP functionality for the Reactor Netty library
+ Jackson datatype: JSR310
+ Jackson-annotations
+ Jackson-core
+ jackson-databind
+ Java Native Access
+ Java Native Access Platform
+ Netty/Buffer
+ Netty/Codec
+ Netty/Codec/Base
+ Netty/Codec/Compression
+ Netty/Codec/DNS
+ Netty/Codec/HTTP
+ Netty/Codec/HTTP2
+ Netty/Codec/Marshalling
+ Netty/Codec/Protobuf
+ Netty/Codec/Socks
+ Netty/Common
+ Netty/Handler
+ Netty/Handler/Proxy
+ Netty/Resolver
+ Netty/Resolver/DNS
+ Netty/TomcatNative [BoringSSL - Static]
+ Netty/TomcatNative [OpenSSL - Classes]
+ Netty/Transport
+ Netty/Transport/Native/Unix/Common
+ Non-Blocking Reactive Foundation for the JVM
+
+MIT License
+ Microsoft Azure client library for Identity
+ Microsoft Azure client library for KeyVault Keys
+ Microsoft Azure Java Core Library
+ Microsoft Azure Java JSON Library
+ Microsoft Azure Java XML Library
+ Microsoft Azure Netty HTTP Client Library
+ msal4j
+ msal4j-persistence-extension
+ SLF4J API Module
+
+MIT No Attribution License
+ reactive-streams
+
diff --git a/encryption/azure-keyvault/pom.xml b/encryption/azure-keyvault/pom.xml
new file mode 100644
index 0000000000..dfe0c543b9
--- /dev/null
+++ b/encryption/azure-keyvault/pom.xml
@@ -0,0 +1,72 @@
+
+ 4.0.0
+
+
+ org.neo4j.driver
+ neo4j-java-driver-parent
+ 6.3-SNAPSHOT
+ ../../pom.xml
+
+
+ neo4j-java-driver-encryption-azure-keyvault
+
+ Neo4j Java Driver (Azure Key Vault)
+ The Neo4j Java Driver Encryption module providing encryption using Azure Key Vault.
+
+
+ false
+ false
+
+
+
+
+ org.neo4j.driver
+ neo4j-java-driver
+ ${project.version}
+ provided
+
+
+ com.azure
+ azure-security-keyvault-keys
+
+
+ com.azure
+ azure-identity
+
+
+ org.junit.jupiter
+ junit-jupiter
+ test
+
+
+
+
+
+
+ com.azure
+ azure-sdk-bom
+ 1.3.3
+ pom
+ import
+
+
+
+
+
+
+
+ org.apache.maven.plugins
+ maven-javadoc-plugin
+
+
+
+
+
+ scm:git:git://github.com/neo4j/neo4j-java-driver.git
+ scm:git:git@github.com:neo4j/neo4j-java-driver.git
+ https://github.com/neo4j/neo4j-java-driver
+
+
+
diff --git a/encryption/azure-keyvault/src/main/java/org/neo4j/driver/property_encryption/azure_keyvault/AzureEncapsulationOptions.java b/encryption/azure-keyvault/src/main/java/org/neo4j/driver/property_encryption/azure_keyvault/AzureEncapsulationOptions.java
new file mode 100644
index 0000000000..a03b615a7f
--- /dev/null
+++ b/encryption/azure-keyvault/src/main/java/org/neo4j/driver/property_encryption/azure_keyvault/AzureEncapsulationOptions.java
@@ -0,0 +1,49 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.azure_keyvault;
+
+import java.util.Map;
+import java.util.Objects;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+
+public final class AzureEncapsulationOptions implements KeyEncapsulationOptions {
+ public static final String KEY_VAULT_KEY_ID = "keyVaultKeyId";
+
+ public static AzureEncapsulationOptions of(String keyId) {
+ return new AzureEncapsulationOptions(keyId);
+ }
+
+ public static AzureEncapsulationOptions of(Map metadata) {
+ var keyId = metadata.get(KEY_VAULT_KEY_ID);
+ return new AzureEncapsulationOptions(keyId);
+ }
+
+ private final String keyId;
+
+ private AzureEncapsulationOptions(String keyId) {
+ this.keyId = Objects.requireNonNull(keyId);
+ }
+
+ public String keyId() {
+ return keyId;
+ }
+
+ @Override
+ public Map toMap() {
+ return Map.of(KEY_VAULT_KEY_ID, keyId);
+ }
+}
diff --git a/encryption/azure-keyvault/src/main/java/org/neo4j/driver/property_encryption/azure_keyvault/AzureKeyEncapsulationService.java b/encryption/azure-keyvault/src/main/java/org/neo4j/driver/property_encryption/azure_keyvault/AzureKeyEncapsulationService.java
new file mode 100644
index 0000000000..78ac375779
--- /dev/null
+++ b/encryption/azure-keyvault/src/main/java/org/neo4j/driver/property_encryption/azure_keyvault/AzureKeyEncapsulationService.java
@@ -0,0 +1,72 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.azure_keyvault;
+
+import com.azure.identity.DefaultAzureCredentialBuilder;
+import com.azure.security.keyvault.keys.cryptography.CryptographyAsyncClient;
+import com.azure.security.keyvault.keys.cryptography.CryptographyClientBuilder;
+import com.azure.security.keyvault.keys.cryptography.models.EncryptionAlgorithm;
+import java.security.NoSuchAlgorithmException;
+import java.util.Map;
+import java.util.Objects;
+import java.util.concurrent.CompletionStage;
+import javax.crypto.KeyGenerator;
+import javax.crypto.SecretKey;
+import javax.crypto.spec.SecretKeySpec;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResult;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResults;
+import org.neo4j.driver.property_encryption.KeyEncapsulationService;
+
+public final class AzureKeyEncapsulationService implements KeyEncapsulationService {
+ private final KeyGenerator keyGenerator;
+ private final AzureEncapsulationOptions defaultOptions;
+
+ public AzureKeyEncapsulationService(AzureEncapsulationOptions defaultOptions) throws NoSuchAlgorithmException {
+ this.defaultOptions = Objects.requireNonNull(defaultOptions);
+ this.keyGenerator = KeyGenerator.getInstance("AES");
+ this.keyGenerator.init(256);
+ }
+
+ @Override
+ public CompletionStage encapsulate(KeyEncapsulationOptions options) {
+ var encapsulationOptions = Objects.requireNonNullElse(options, defaultOptions);
+ var kmsKeyId = ((AzureEncapsulationOptions) encapsulationOptions).keyId();
+ var key = keyGenerator.generateKey();
+ return forKey(kmsKeyId)
+ .encrypt(EncryptionAlgorithm.RSA_OAEP, key.getEncoded())
+ .toFuture()
+ .thenApply(encryptResult -> KeyEncapsulationResults.create(
+ encryptResult.getCipherText(), encapsulationOptions.toMap(), key));
+ }
+
+ @Override
+ public CompletionStage decapsulate(byte[] ciphertext, Map metadata) {
+ var options = AzureEncapsulationOptions.of(metadata);
+ return forKey(options.keyId())
+ .decrypt(EncryptionAlgorithm.RSA_OAEP, ciphertext)
+ .toFuture()
+ .thenApply(decryptResult -> new SecretKeySpec(decryptResult.getPlainText(), "AES"));
+ }
+
+ private static CryptographyAsyncClient forKey(String keyVaultKeyId) {
+ return new CryptographyClientBuilder()
+ .credential(new DefaultAzureCredentialBuilder().build())
+ .keyIdentifier(keyVaultKeyId)
+ .buildAsyncClient();
+ }
+}
diff --git a/encryption/google-cloud-kms/LICENSES.txt b/encryption/google-cloud-kms/LICENSES.txt
new file mode 100644
index 0000000000..c777ab0548
--- /dev/null
+++ b/encryption/google-cloud-kms/LICENSES.txt
@@ -0,0 +1,1041 @@
+This file contains the full license text of the included third party
+libraries. For an overview of the licenses see the NOTICE.txt file.
+
+
+------------------------------------------------------------------------------
+Apache Software License, Version 2.0
+ Apache HttpClient
+ Apache HttpCore
+ AutoValue Annotations
+ error-prone annotations
+ FindBugs-jsr305
+ Google Cloud KMS
+ Google HTTP Client Library for Java
+ Gson
+ GSON extensions to the Google HTTP Client Library for Java.
+ Guava InternalFutureFailureAccess and InternalFutures
+ Guava ListenableFuture only
+ Guava: Google Core Libraries for Java
+ io.grpc:grpc-alts
+ io.grpc:grpc-api
+ io.grpc:grpc-auth
+ io.grpc:grpc-context
+ io.grpc:grpc-core
+ io.grpc:grpc-grpclb
+ io.grpc:grpc-inprocess
+ io.grpc:grpc-netty-shaded
+ io.grpc:grpc-protobuf
+ io.grpc:grpc-stub
+ J2ObjC Annotations
+ JSpecify annotations
+ OpenCensus
+ org.conscrypt:conscrypt-openjdk-uber
+ proto-google-cloud-kms-v1
+ proto-google-common-protos
+ proto-google-iam-v1
+------------------------------------------------------------------------------
+
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
+
+
+
+------------------------------------------------------------------------------
+BSD License
+ API Common
+ GAX (Google Api eXtensions) for Java (Core)
+ GAX (Google Api eXtensions) for Java (gRPC)
+ GAX (Google Api eXtensions) for Java (HTTP JSON)
+ Google Auth Library for Java - Credentials
+ Protocol Buffers [Core]
+ Protocol Buffers [Util]
+ ThreeTen backport
+------------------------------------------------------------------------------
+
+Copyright (c) ,
+All rights reserved.
+
+Redistribution and use in source and binary forms, with or without
+modification, are permitted provided that the following conditions are met:
+ * Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+ * Redistributions in binary form must reproduce the above copyright
+ notice, this list of conditions and the following disclaimer in the
+ documentation and/or other materials provided with the distribution.
+ * Neither the name of the nor the
+ names of its contributors may be used to endorse or promote products
+ derived from this software without specific prior written permission.
+
+THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
+ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
+WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
+DISCLAIMED. IN NO EVENT SHALL BE LIABLE FOR ANY
+DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
+LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
+SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+
+
+
+------------------------------------------------------------------------------
+Common Development and Distribution License Version 1.1
+ javax.annotation API
+------------------------------------------------------------------------------
+
+COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.1
+
+1. Definitions.
+
+ 1.1. "Contributor" means each individual or entity that creates or
+ contributes to the creation of Modifications.
+
+ 1.2. "Contributor Version" means the combination of the Original
+ Software, prior Modifications used by a Contributor (if any), and the
+ Modifications made by that particular Contributor.
+
+ 1.3. "Covered Software" means (a) the Original Software, or (b)
+ Modifications, or (c) the combination of files containing Original
+ Software with files containing Modifications, in each case including
+ portions thereof.
+
+ 1.4. "Executable" means the Covered Software in any form other than
+ Source Code.
+
+ 1.5. "Initial Developer" means the individual or entity that first makes
+ Original Software available under this License.
+
+ 1.6. "Larger Work" means a work which combines Covered Software or
+ portions thereof with code not governed by the terms of this License.
+
+ 1.7. "License" means this document.
+
+ 1.8. "Licensable" means having the right to grant, to the maximum extent
+ possible, whether at the time of the initial grant or subsequently
+ acquired, any and all of the rights conveyed herein.
+
+ 1.9. "Modifications" means the Source Code and Executable form of any of
+ the following:
+
+ A. Any file that results from an addition to, deletion from or
+ modification of the contents of a file containing Original Software or
+ previous Modifications;
+
+ B. Any new file that contains any part of the Original Software or
+ previous Modification; or
+
+ C. Any new file that is contributed or otherwise made available under
+ the terms of this License.
+
+ 1.10. "Original Software" means the Source Code and Executable form of
+ computer software code that is originally released under this License.
+
+ 1.11. "Patent Claims" means any patent claim(s), now owned or hereafter
+ acquired, including without limitation, method, process, and apparatus
+ claims, in any patent Licensable by grantor.
+
+ 1.12. "Source Code" means (a) the common form of computer software code
+ in which modifications are made and (b) associated documentation
+ included in or with such code.
+
+ 1.13. "You" (or "Your") means an individual or a legal entity exercising
+ rights under, and complying with all of the terms of, this License. For
+ legal entities, "You" includes any entity which controls, is controlled
+ by, or is under common control with You. For purposes of this
+ definition, "control" means (a) the power, direct or indirect, to cause
+ the direction or management of such entity, whether by contract or
+ otherwise, or (b) ownership of more than fifty percent (50%) of the
+ outstanding shares or beneficial ownership of such entity.
+
+2. License Grants.
+
+ 2.1. The Initial Developer Grant.
+
+ Conditioned upon Your compliance with Section 3.1 below and subject to
+ third party intellectual property claims, the Initial Developer hereby
+ grants You a world-wide, royalty-free, non-exclusive license:
+
+ (a) under intellectual property rights (other than patent or trademark)
+ Licensable by Initial Developer, to use, reproduce, modify, display,
+ perform, sublicense and distribute the Original Software (or portions
+ thereof), with or without Modifications, and/or as part of a Larger
+ Work; and
+
+ (b) under Patent Claims infringed by the making, using or selling of
+ Original Software, to make, have made, use, practice, sell, and offer
+ for sale, and/or otherwise dispose of the Original Software (or portions
+ thereof).
+
+ (c) The licenses granted in Sections 2.1(a) and (b) are effective on the
+ date Initial Developer first distributes or otherwise makes the Original
+ Software available to a third party under the terms of this License.
+
+ (d) Notwithstanding Section 2.1(b) above, no patent license is granted:
+ (1) for code that You delete from the Original Software, or (2) for
+ infringements caused by: (i) the modification of the Original Software,
+ or (ii) the combination of the Original Software with other software or
+ devices.
+
+ 2.2. Contributor Grant.
+
+ Conditioned upon Your compliance with Section 3.1 below and subject to
+ third party intellectual property claims, each Contributor hereby grants
+ You a world-wide, royalty-free, non-exclusive license:
+
+ (a) under intellectual property rights (other than patent or trademark)
+ Licensable by Contributor to use, reproduce, modify, display, perform,
+ sublicense and distribute the Modifications created by such Contributor
+ (or portions thereof), either on an unmodified basis, with other
+ Modifications, as Covered Software and/or as part of a Larger Work; and
+
+ (b) under Patent Claims infringed by the making, using, or selling of
+ Modifications made by that Contributor either alone and/or in
+ combination with its Contributor Version (or portions of such
+ combination), to make, use, sell, offer for sale, have made, and/or
+ otherwise dispose of: (1) Modifications made by that Contributor (or
+ portions thereof); and (2) the combination of Modifications made by that
+ Contributor with its Contributor Version (or portions of such
+ combination).
+
+ (c) The licenses granted in Sections 2.2(a) and 2.2(b) are effective on
+ the date Contributor first distributes or otherwise makes the
+ Modifications available to a third party.
+
+ (d) Notwithstanding Section 2.2(b) above, no patent license is granted:
+ (1) for any code that Contributor has deleted from the Contributor
+ Version; (2) for infringements caused by: (i) third party modifications
+ of Contributor Version, or (ii) the combination of Modifications made by
+ that Contributor with other software (except as part of the Contributor
+ Version) or other devices; or (3) under Patent Claims infringed by
+ Covered Software in the absence of Modifications made by that
+ Contributor.
+
+3. Distribution Obligations.
+
+ 3.1. Availability of Source Code.
+
+ Any Covered Software that You distribute or otherwise make available in
+ Executable form must also be made available in Source Code form and that
+ Source Code form must be distributed only under the terms of this
+ License. You must include a copy of this License with every copy of the
+ Source Code form of the Covered Software You distribute or otherwise
+ make available. You must inform recipients of any such Covered Software
+ in Executable form as to how they can obtain such Covered Software in
+ Source Code form in a reasonable manner on or through a medium
+ customarily used for software exchange.
+
+ 3.2. Modifications.
+
+ The Modifications that You create or to which You contribute are
+ governed by the terms of this License. You represent that You believe
+ Your Modifications are Your original creation(s) and/or You have
+ sufficient rights to grant the rights conveyed by this License.
+
+ 3.3. Required Notices.
+
+ You must include a notice in each of Your Modifications that identifies
+ You as the Contributor of the Modification. You may not remove or alter
+ any copyright, patent or trademark notices contained within the Covered
+ Software, or any notices of licensing or any descriptive text giving
+ attribution to any Contributor or the Initial Developer.
+
+ 3.4. Application of Additional Terms.
+
+ You may not offer or impose any terms on any Covered Software in Source
+ Code form that alters or restricts the applicable version of this
+ License or the recipients' rights hereunder. You may choose to offer,
+ and to charge a fee for, warranty, support, indemnity or liability
+ obligations to one or more recipients of Covered Software. However, you
+ may do so only on Your own behalf, and not on behalf of the Initial
+ Developer or any Contributor. You must make it absolutely clear that any
+ such warranty, support, indemnity or liability obligation is offered by
+ You alone, and You hereby agree to indemnify the Initial Developer and
+ every Contributor for any liability incurred by the Initial Developer or
+ such Contributor as a result of warranty, support, indemnity or
+ liability terms You offer.
+
+ 3.5. Distribution of Executable Versions.
+
+ You may distribute the Executable form of the Covered Software under the
+ terms of this License or under the terms of a license of Your choice,
+ which may contain terms different from this License, provided that You
+ are in compliance with the terms of this License and that the license
+ for the Executable form does not attempt to limit or alter the
+ recipient's rights in the Source Code form from the rights set forth in
+ this License. If You distribute the Covered Software in Executable form
+ under a different license, You must make it absolutely clear that any
+ terms which differ from this License are offered by You alone, not by
+ the Initial Developer or Contributor. You hereby agree to indemnify the
+ Initial Developer and every Contributor for any liability incurred by
+ the Initial Developer or such Contributor as a result of any such terms
+ You offer.
+
+ 3.6. Larger Works.
+
+ You may create a Larger Work by combining Covered Software with other
+ code not governed by the terms of this License and distribute the Larger
+ Work as a single product. In such a case, You must make sure the
+ requirements of this License are fulfilled for the Covered Software.
+
+4. Versions of the License.
+
+ 4.1. New Versions.
+
+ Oracle is the initial license steward and may publish revised and/or new
+ versions of this License from time to time. Each version will be given a
+ distinguishing version number. Except as provided in Section 4.3, no one
+ other than the license steward has the right to modify this License.
+
+ 4.2. Effect of New Versions.
+
+ You may always continue to use, distribute or otherwise make the Covered
+ Software available under the terms of the version of the License under
+ which You originally received the Covered Software. If the Initial
+ Developer includes a notice in the Original Software prohibiting it from
+ being distributed or otherwise made available under any subsequent
+ version of the License, You must distribute and make the Covered
+ Software available under the terms of the version of the License under
+ which You originally received the Covered Software. Otherwise, You may
+ also choose to use, distribute or otherwise make the Covered Software
+ available under the terms of any subsequent version of the License
+ published by the license steward.
+
+ 4.3. Modified Versions.
+
+ When You are an Initial Developer and You want to create a new license
+ for Your Original Software, You may create and use a modified version of
+ this License if You: (a) rename the license and remove any references to
+ the name of the license steward (except to note that the license differs
+ from this License); and (b) otherwise make it clear that the license
+ contains terms which differ from this License.
+
+5. DISCLAIMER OF WARRANTY.
+
+ COVERED SOFTWARE IS PROVIDED UNDER THIS LICENSE ON AN "AS IS" BASIS,
+ WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING,
+ WITHOUT LIMITATION, WARRANTIES THAT THE COVERED SOFTWARE IS FREE OF
+ DEFECTS, MERCHANTABLE, FIT FOR A PARTICULAR PURPOSE OR NON-INFRINGING.
+ THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE COVERED
+ SOFTWARE IS WITH YOU. SHOULD ANY COVERED SOFTWARE PROVE DEFECTIVE IN ANY
+ RESPECT, YOU (NOT THE INITIAL DEVELOPER OR ANY OTHER CONTRIBUTOR) ASSUME
+ THE COST OF ANY NECESSARY SERVICING, REPAIR OR CORRECTION. THIS
+ DISCLAIMER OF WARRANTY CONSTITUTES AN ESSENTIAL PART OF THIS LICENSE. NO
+ USE OF ANY COVERED SOFTWARE IS AUTHORIZED HEREUNDER EXCEPT UNDER THIS
+ DISCLAIMER.
+
+6. TERMINATION.
+
+ 6.1. This License and the rights granted hereunder will terminate
+ automatically if You fail to comply with terms herein and fail to cure
+ such breach within 30 days of becoming aware of the breach. Provisions
+ which, by their nature, must remain in effect beyond the termination of
+ this License shall survive.
+
+ 6.2. If You assert a patent infringement claim (excluding declaratory
+ judgment actions) against Initial Developer or a Contributor (the
+ Initial Developer or Contributor against whom You assert such claim is
+ referred to as "Participant") alleging that the Participant Software
+ (meaning the Contributor Version where the Participant is a Contributor
+ or the Original Software where the Participant is the Initial Developer)
+ directly or indirectly infringes any patent, then any and all rights
+ granted directly or indirectly to You by such Participant, the Initial
+ Developer (if the Initial Developer is not the Participant) and all
+ Contributors under Sections 2.1 and/or 2.2 of this License shall, upon
+ 60 days notice from Participant terminate prospectively and
+ automatically at the expiration of such 60 day notice period, unless if
+ within such 60 day period You withdraw Your claim with respect to the
+ Participant Software against such Participant either unilaterally or
+ pursuant to a written agreement with Participant.
+
+ 6.3. If You assert a patent infringement claim against Participant
+ alleging that the Participant Software directly or indirectly infringes
+ any patent where such claim is resolved (such as by license or
+ settlement) prior to the initiation of patent infringement litigation,
+ then the reasonable value of the licenses granted by such Participant
+ under Sections 2.1 or 2.2 shall be taken into account in determining the
+ amount or value of any payment or license.
+
+ 6.4. In the event of termination under Sections 6.1 or 6.2 above, all
+ end user licenses that have been validly granted by You or any
+ distributor hereunder prior to termination (excluding licenses granted
+ to You by any distributor) shall survive termination.
+
+7. LIMITATION OF LIABILITY.
+
+ UNDER NO CIRCUMSTANCES AND UNDER NO LEGAL THEORY, WHETHER TORT
+ (INCLUDING NEGLIGENCE), CONTRACT, OR OTHERWISE, SHALL YOU, THE INITIAL
+ DEVELOPER, ANY OTHER CONTRIBUTOR, OR ANY DISTRIBUTOR OF COVERED
+ SOFTWARE, OR ANY SUPPLIER OF ANY OF SUCH PARTIES, BE LIABLE TO ANY
+ PERSON FOR ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES
+ OF ANY CHARACTER INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF
+ GOODWILL, WORK STOPPAGE, COMPUTER FAILURE OR MALFUNCTION, OR ANY AND ALL
+ OTHER COMMERCIAL DAMAGES OR LOSSES, EVEN IF SUCH PARTY SHALL HAVE BEEN
+ INFORMED OF THE POSSIBILITY OF SUCH DAMAGES. THIS LIMITATION OF
+ LIABILITY SHALL NOT APPLY TO LIABILITY FOR DEATH OR PERSONAL INJURY
+ RESULTING FROM SUCH PARTY'S NEGLIGENCE TO THE EXTENT APPLICABLE LAW
+ PROHIBITS SUCH LIMITATION. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION
+ OR LIMITATION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THIS EXCLUSION
+ AND LIMITATION MAY NOT APPLY TO YOU.
+
+8. U.S. GOVERNMENT END USERS.
+
+ The Covered Software is a "commercial item," as that term is defined in
+ 48 C.F.R. 2.101 (Oct. 1995), consisting of "commercial computer
+ software" (as that term is defined at 48 C.F.R. § 252.227-7014(a)(1))
+ and "commercial computer software documentation" as such terms are used
+ in 48 C.F.R. 12.212 (Sept. 1995). Consistent with 48 C.F.R. 12.212 and
+ 48 C.F.R. 227.7202-1 through 227.7202-4 (June 1995), all U.S. Government
+ End Users acquire Covered Software with only those rights set forth
+ herein. This U.S. Government Rights clause is in lieu of, and
+ supersedes, any other FAR, DFAR, or other clause or provision that
+ addresses Government rights in computer software under this License.
+
+9. MISCELLANEOUS.
+
+ This License represents the complete agreement concerning subject matter
+ hereof. If any provision of this License is held to be unenforceable,
+ such provision shall be reformed only to the extent necessary to make it
+ enforceable. This License shall be governed by the law of the
+ jurisdiction specified in a notice contained within the Original
+ Software (except to the extent applicable law, if any, provides
+ otherwise), excluding such jurisdiction's conflict-of-law provisions.
+ Any litigation relating to this License shall be subject to the
+ jurisdiction of the courts located in the jurisdiction and venue
+ specified in a notice contained within the Original Software, with the
+ losing party responsible for costs, including, without limitation, court
+ costs and reasonable attorneys' fees and expenses. The application of
+ the United Nations Convention on Contracts for the International Sale of
+ Goods is expressly excluded. Any law or regulation which provides that
+ the language of a contract shall be construed against the drafter shall
+ not apply to this License. You agree that You alone are responsible for
+ compliance with the United States export administration regulations (and
+ the export control laws and regulation of any other countries) when You
+ use, distribute or otherwise make available any Covered Software.
+
+10. RESPONSIBILITY FOR CLAIMS.
+
+ As between Initial Developer and the Contributors, each party is
+ responsible for claims and damages arising, directly or indirectly, out
+ of its utilization of rights under this License and You agree to work
+ with Initial Developer and Contributors to distribute such
+ responsibility on an equitable basis. Nothing herein is intended or
+ shall be deemed to constitute any admission of liability.
+
+NOTICE PURSUANT TO SECTION 9 OF THE COMMON DEVELOPMENT AND DISTRIBUTION
+LICENSE (CDDL)
+
+The code released under the CDDL shall be governed by the laws of the
+State of California (excluding conflict-of-law provisions). Any
+litigation relating to this License shall be subject to the jurisdiction
+of the Federal Courts of the Northern District of California and the
+state courts of the State of California, with venue lying in Santa Clara
+County, California.
+
+
+
+------------------------------------------------------------------------------
+GNU General Public License, version 2 with the Classpath Exception
+ javax.annotation API
+------------------------------------------------------------------------------
+
+The GNU General Public License (GPL) Version 2, June 1991
+
+Copyright (C) 1989, 1991 Free Software Foundation, Inc. 59 Temple Place,
+Suite 330, Boston, MA 02111-1307 USA
+
+Everyone is permitted to copy and distribute verbatim copies of this
+license document, but changing it is not allowed.
+
+Preamble
+
+The licenses for most software are designed to take away your freedom to
+share and change it. By contrast, the GNU General Public License is
+intended to guarantee your freedom to share and change free software--to
+make sure the software is free for all its users. This General Public
+License applies to most of the Free Software Foundation's software and
+to any other program whose authors commit to using it. (Some other Free
+Software Foundation software is covered by the GNU Library General
+Public License instead.) You can apply it to your programs, too.
+
+When we speak of free software, we are referring to freedom, not price.
+Our General Public Licenses are designed to make sure that you have the
+freedom to distribute copies of free software (and charge for this
+service if you wish), that you receive source code or can get it if you
+want it, that you can change the software or use pieces of it in new
+free programs; and that you know you can do these things.
+
+To protect your rights, we need to make restrictions that forbid anyone
+to deny you these rights or to ask you to surrender the rights. These
+restrictions translate to certain responsibilities for you if you
+distribute copies of the software, or if you modify it.
+
+For example, if you distribute copies of such a program, whether gratis
+or for a fee, you must give the recipients all the rights that you have.
+You must make sure that they, too, receive or can get the source code.
+And you must show them these terms so they know their rights.
+
+We protect your rights with two steps: (1) copyright the software, and
+(2) offer you this license which gives you legal permission to copy,
+distribute and/or modify the software.
+
+Also, for each author's protection and ours, we want to make certain
+that everyone understands that there is no warranty for this free
+software. If the software is modified by someone else and passed on, we
+want its recipients to know that what they have is not the original, so
+that any problems introduced by others will not reflect on the original
+authors' reputations.
+
+Finally, any free program is threatened constantly by software patents.
+We wish to avoid the danger that redistributors of a free program will
+individually obtain patent licenses, in effect making the program
+proprietary. To prevent this, we have made it clear that any patent must
+be licensed for everyone's free use or not licensed at all.
+
+The precise terms and conditions for copying, distribution and
+modification follow.
+
+TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
+
+0. This License applies to any program or other work which contains a
+notice placed by the copyright holder saying it may be distributed under
+the terms of this General Public License. The "Program", below, refers
+to any such program or work, and a "work based on the Program" means
+either the Program or any derivative work under copyright law: that is
+to say, a work containing the Program or a portion of it, either
+verbatim or with modifications and/or translated into another language.
+(Hereinafter, translation is included without limitation in the term
+"modification".) Each licensee is addressed as "you".
+
+Activities other than copying, distribution and modification are not
+covered by this License; they are outside its scope. The act of running
+the Program is not restricted, and the output from the Program is
+covered only if its contents constitute a work based on the Program
+(independent of having been made by running the Program). Whether that
+is true depends on what the Program does.
+
+1. You may copy and distribute verbatim copies of the Program's source
+code as you receive it, in any medium, provided that you conspicuously
+and appropriately publish on each copy an appropriate copyright notice
+and disclaimer of warranty; keep intact all the notices that refer to
+this License and to the absence of any warranty; and give any other
+recipients of the Program a copy of this License along with the Program.
+
+You may charge a fee for the physical act of transferring a copy, and
+you may at your option offer warranty protection in exchange for a fee.
+
+2. You may modify your copy or copies of the Program or any portion of
+it, thus forming a work based on the Program, and copy and distribute
+such modifications or work under the terms of Section 1 above, provided
+that you also meet all of these conditions:
+
+ a) You must cause the modified files to carry prominent notices stating
+ that you changed the files and the date of any change.
+
+ b) You must cause any work that you distribute or publish, that in whole
+ or in part contains or is derived from the Program or any part thereof,
+ to be licensed as a whole at no charge to all third parties under the
+ terms of this License.
+
+ c) If the modified program normally reads commands interactively when
+ run, you must cause it, when started running for such interactive use in
+ the most ordinary way, to print or display an announcement including an
+ appropriate copyright notice and a notice that there is no warranty (or
+ else, saying that you provide a warranty) and that users may
+ redistribute the program under these conditions, and telling the user
+ how to view a copy of this License. (Exception: if the Program itself is
+ interactive but does not normally print such an announcement, your work
+ based on the Program is not required to print an announcement.)
+
+These requirements apply to the modified work as a whole. If
+identifiable sections of that work are not derived from the Program, and
+can be reasonably considered independent and separate works in
+themselves, then this License, and its terms, do not apply to those
+sections when you distribute them as separate works. But when you
+distribute the same sections as part of a whole which is a work based on
+the Program, the distribution of the whole must be on the terms of this
+License, whose permissions for other licensees extend to the entire
+whole, and thus to each and every part regardless of who wrote it.
+
+Thus, it is not the intent of this section to claim rights or contest
+your rights to work written entirely by you; rather, the intent is to
+exercise the right to control the distribution of derivative or
+collective works based on the Program.
+
+In addition, mere aggregation of another work not based on the Program
+with the Program (or with a work based on the Program) on a volume of a
+storage or distribution medium does not bring the other work under the
+scope of this License.
+
+3. You may copy and distribute the Program (or a work based on it, under
+Section 2) in object code or executable form under the terms of Sections
+1 and 2 above provided that you also do one of the following:
+
+ a) Accompany it with the complete corresponding machine-readable source
+ code, which must be distributed under the terms of Sections 1 and 2
+ above on a medium customarily used for software interchange; or,
+
+ b) Accompany it with a written offer, valid for at least three years, to
+ give any third party, for a charge no more than your cost of physically
+ performing source distribution, a complete machine-readable copy of the
+ corresponding source code, to be distributed under the terms of Sections
+ 1 and 2 above on a medium customarily used for software interchange; or,
+
+ c) Accompany it with the information you received as to the offer to
+ distribute corresponding source code. (This alternative is allowed only
+ for noncommercial distribution and only if you received the program in
+ object code or executable form with such an offer, in accord with
+ Subsection b above.)
+
+The source code for a work means the preferred form of the work for
+making modifications to it. For an executable work, complete source code
+means all the source code for all modules it contains, plus any
+associated interface definition files, plus the scripts used to control
+compilation and installation of the executable. However, as a special
+exception, the source code distributed need not include anything that is
+normally distributed (in either source or binary form) with the major
+components (compiler, kernel, and so on) of the operating system on
+which the executable runs, unless that component itself accompanies the
+executable.
+
+If distribution of executable or object code is made by offering access
+to copy from a designated place, then offering equivalent access to copy
+the source code from the same place counts as distribution of the source
+code, even though third parties are not compelled to copy the source
+along with the object code.
+
+4. You may not copy, modify, sublicense, or distribute the Program
+except as expressly provided under this License. Any attempt otherwise
+to copy, modify, sublicense or distribute the Program is void, and will
+automatically terminate your rights under this License. However, parties
+who have received copies, or rights, from you under this License will
+not have their licenses terminated so long as such parties remain in
+full compliance.
+
+5. You are not required to accept this License, since you have not
+signed it. However, nothing else grants you permission to modify or
+distribute the Program or its derivative works. These actions are
+prohibited by law if you do not accept this License. Therefore, by
+modifying or distributing the Program (or any work based on the
+Program), you indicate your acceptance of this License to do so, and all
+its terms and conditions for copying, distributing or modifying the
+Program or works based on it.
+
+6. Each time you redistribute the Program (or any work based on the
+Program), the recipient automatically receives a license from the
+original licensor to copy, distribute or modify the Program subject to
+these terms and conditions. You may not impose any further restrictions
+on the recipients' exercise of the rights granted herein. You are not
+responsible for enforcing compliance by third parties to this License.
+
+7. If, as a consequence of a court judgment or allegation of patent
+infringement or for any other reason (not limited to patent issues),
+conditions are imposed on you (whether by court order, agreement or
+otherwise) that contradict the conditions of this License, they do not
+excuse you from the conditions of this License. If you cannot distribute
+so as to satisfy simultaneously your obligations under this License and
+any other pertinent obligations, then as a consequence you may not
+distribute the Program at all. For example, if a patent license would
+not permit royalty-free redistribution of the Program by all those who
+receive copies directly or indirectly through you, then the only way you
+could satisfy both it and this License would be to refrain entirely from
+distribution of the Program.
+
+If any portion of this section is held invalid or unenforceable under
+any particular circumstance, the balance of the section is intended to
+apply and the section as a whole is intended to apply in other
+circumstances.
+
+It is not the purpose of this section to induce you to infringe any
+patents or other property right claims or to contest validity of any
+such claims; this section has the sole purpose of protecting the
+integrity of the free software distribution system, which is implemented
+by public license practices. Many people have made generous
+contributions to the wide range of software distributed through that
+system in reliance on consistent application of that system; it is up to
+the author/donor to decide if he or she is willing to distribute
+software through any other system and a licensee cannot impose that
+choice.
+
+This section is intended to make thoroughly clear what is believed to be
+a consequence of the rest of this License.
+
+8. If the distribution and/or use of the Program is restricted in
+certain countries either by patents or by copyrighted interfaces, the
+original copyright holder who places the Program under this License may
+add an explicit geographical distribution limitation excluding those
+countries, so that distribution is permitted only in or among countries
+not thus excluded. In such case, this License incorporates the
+limitation as if written in the body of this License.
+
+9. The Free Software Foundation may publish revised and/or new versions
+of the General Public License from time to time. Such new versions will
+be similar in spirit to the present version, but may differ in detail to
+address new problems or concerns.
+
+Each version is given a distinguishing version number. If the Program
+specifies a version number of this License which applies to it and "any
+later version", you have the option of following the terms and
+conditions either of that version or of any later version published by
+the Free Software Foundation. If the Program does not specify a version
+number of this License, you may choose any version ever published by the
+Free Software Foundation.
+
+10. If you wish to incorporate parts of the Program into other free
+programs whose distribution conditions are different, write to the
+author to ask for permission. For software which is copyrighted by the
+Free Software Foundation, write to the Free Software Foundation; we
+sometimes make exceptions for this. Our decision will be guided by the
+two goals of preserving the free status of all derivatives of our free
+software and of promoting the sharing and reuse of software generally.
+
+NO WARRANTY
+
+11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
+FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
+OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
+PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER
+EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
+WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE
+ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH
+YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL
+NECESSARY SERVICING, REPAIR OR CORRECTION.
+
+12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN
+WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY
+AND/OR REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR
+DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL
+DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM
+(INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED
+INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF
+THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR
+OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
+
+END OF TERMS AND CONDITIONS
+
+How to Apply These Terms to Your New Programs
+
+If you develop a new program, and you want it to be of the greatest
+possible use to the public, the best way to achieve this is to make it
+free software which everyone can redistribute and change under these
+terms.
+
+To do so, attach the following notices to the program. It is safest to
+attach them to the start of each source file to most effectively convey
+the exclusion of warranty; and each file should have at least the
+"copyright" line and a pointer to where the full notice is found.
+
+ One line to give the program's name and a brief idea of what it does.
+ Copyright (C)
+
+ This program is free software; you can redistribute it and/or modify it
+ under the terms of the GNU General Public License as published by the
+ Free Software Foundation; either version 2 of the License, or (at your
+ option) any later version.
+
+ This program is distributed in the hope that it will be useful, but
+ WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+ Public License for more details.
+
+ You should have received a copy of the GNU General Public License along
+ with this program; if not, write to the Free Software Foundation, Inc.,
+ 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+
+Also add information on how to contact you by electronic and paper mail.
+
+If the program is interactive, make it output a short notice like this
+when it starts in an interactive mode:
+
+ Gnomovision version 69, Copyright (C) year name of author Gnomovision
+ comes with ABSOLUTELY NO WARRANTY; for details type `show w'. This is
+ free software, and you are welcome to redistribute it under certain
+ conditions; type `show c' for details.
+
+The hypothetical commands `show w' and `show c' should show the
+appropriate parts of the General Public License. Of course, the commands
+you use may be called something other than `show w' and `show c'; they
+could even be mouse-clicks or menu items--whatever suits your program.
+
+You should also get your employer (if you work as a programmer) or your
+school, if any, to sign a "copyright disclaimer" for the program, if
+necessary. Here is a sample; alter the names:
+
+ Yoyodyne, Inc., hereby disclaims all copyright interest in the program
+ `Gnomovision' (which makes passes at compilers) written by James Hacker.
+
+ signature of Ty Coon, 1 April 1989
+ Ty Coon, President of Vice
+
+This General Public License does not permit incorporating your program
+into proprietary programs. If your program is a subroutine library, you
+may consider it more useful to permit linking proprietary applications
+with the library. If this is what you want to do, use the GNU Library
+General Public License instead of this License.
+
+#
+
+"CLASSPATH" EXCEPTION TO THE GPL VERSION 2
+
+Certain source files distributed by Oracle are subject to the following
+clarification and special exception to the GPL Version 2, but only where
+Oracle has expressly included in the particular source file's header the
+words "Oracle designates this particular file as subject to the
+"Classpath" exception as provided by Oracle in the License file that
+accompanied this code."
+
+Linking this library statically or dynamically with other modules is
+making a combined work based on this library. Thus, the terms and
+conditions of the GNU General Public License Version 2 cover the whole
+combination.
+
+As a special exception, the copyright holders of this library give you
+permission to link this library with independent modules to produce an
+executable, regardless of the license terms of these independent
+modules, and to copy and distribute the resulting executable under terms
+of your choice, provided that you also meet, for each linked independent
+module, the terms and conditions of the license of that module. An
+independent module is a module which is not derived from or based on
+this library. If you modify this library, you may extend this exception
+to your version of the library, but you are not obligated to do so. If
+you do not wish to do so, delete this exception statement from your
+version.
+
+
+
+------------------------------------------------------------------------------
+MIT License
+ Animal Sniffer Annotations
+------------------------------------------------------------------------------
+
+The MIT License
+
+Copyright (c)
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in
+all copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
+THE SOFTWARE.
+
+
+
+
+Dependencies with multiple licenses
+-----------------------------------
+
+javax.annotation API
+ Common Development and Distribution License Version 1.1
+ GNU General Public License, version 2 with the Classpath Exception
+
diff --git a/encryption/google-cloud-kms/NOTICE.txt b/encryption/google-cloud-kms/NOTICE.txt
new file mode 100644
index 0000000000..197589c0db
--- /dev/null
+++ b/encryption/google-cloud-kms/NOTICE.txt
@@ -0,0 +1,77 @@
+Copyright (c) "Neo4j"
+Neo4j Sweden AB [https://neo4j.com]
+
+This file is part of Neo4j.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+
+Full license texts are found in LICENSES.txt.
+
+
+Third-party licenses
+--------------------
+
+Apache Software License, Version 2.0
+ Apache HttpClient
+ Apache HttpCore
+ AutoValue Annotations
+ error-prone annotations
+ FindBugs-jsr305
+ Google Cloud KMS
+ Google HTTP Client Library for Java
+ Gson
+ GSON extensions to the Google HTTP Client Library for Java.
+ Guava InternalFutureFailureAccess and InternalFutures
+ Guava ListenableFuture only
+ Guava: Google Core Libraries for Java
+ io.grpc:grpc-alts
+ io.grpc:grpc-api
+ io.grpc:grpc-auth
+ io.grpc:grpc-context
+ io.grpc:grpc-core
+ io.grpc:grpc-grpclb
+ io.grpc:grpc-inprocess
+ io.grpc:grpc-netty-shaded
+ io.grpc:grpc-protobuf
+ io.grpc:grpc-stub
+ J2ObjC Annotations
+ JSpecify annotations
+ OpenCensus
+ org.conscrypt:conscrypt-openjdk-uber
+ proto-google-cloud-kms-v1
+ proto-google-common-protos
+ proto-google-iam-v1
+
+BSD License
+ API Common
+ GAX (Google Api eXtensions) for Java (Core)
+ GAX (Google Api eXtensions) for Java (gRPC)
+ GAX (Google Api eXtensions) for Java (HTTP JSON)
+ Google Auth Library for Java - Credentials
+ Protocol Buffers [Core]
+ Protocol Buffers [Util]
+ ThreeTen backport
+
+Common Development and Distribution License Version 1.1
+ javax.annotation API
+
+GNU General Public License, version 2 with the Classpath Exception
+ javax.annotation API
+
+MIT License
+ Animal Sniffer Annotations
+
+Dependencies with multiple licenses
+-----------------------------------
+
+javax.annotation API
+ Common Development and Distribution License Version 1.1
+ GNU General Public License, version 2 with the Classpath Exception
+
diff --git a/encryption/google-cloud-kms/pom.xml b/encryption/google-cloud-kms/pom.xml
new file mode 100644
index 0000000000..4860307052
--- /dev/null
+++ b/encryption/google-cloud-kms/pom.xml
@@ -0,0 +1,68 @@
+
+ 4.0.0
+
+
+ org.neo4j.driver
+ neo4j-java-driver-parent
+ 6.3-SNAPSHOT
+ ../../pom.xml
+
+
+ neo4j-java-driver-encryption-google-cloud-kms
+
+ Neo4j Java Driver (Google Cloud KMS)
+ The Neo4j Java Driver Encryption module providing encryption using Google Cloud KMS.
+
+
+ false
+ false
+
+
+
+
+ org.neo4j.driver
+ neo4j-java-driver
+ ${project.version}
+ provided
+
+
+ com.google.cloud
+ google-cloud-kms
+
+
+ org.junit.jupiter
+ junit-jupiter
+ test
+
+
+
+
+
+
+ com.google.cloud
+ libraries-bom
+ 26.72.0
+ pom
+ import
+
+
+
+
+
+
+
+ org.apache.maven.plugins
+ maven-javadoc-plugin
+
+
+
+
+
+ scm:git:git://github.com/neo4j/neo4j-java-driver.git
+ scm:git:git@github.com:neo4j/neo4j-java-driver.git
+ https://github.com/neo4j/neo4j-java-driver
+
+
+
diff --git a/encryption/google-cloud-kms/src/main/java/org/neo4j/driver/property_encryption/google_cloud_kms/CloudKmsKeyEncapsulationOptions.java b/encryption/google-cloud-kms/src/main/java/org/neo4j/driver/property_encryption/google_cloud_kms/CloudKmsKeyEncapsulationOptions.java
new file mode 100644
index 0000000000..2e91fc5606
--- /dev/null
+++ b/encryption/google-cloud-kms/src/main/java/org/neo4j/driver/property_encryption/google_cloud_kms/CloudKmsKeyEncapsulationOptions.java
@@ -0,0 +1,64 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.google_cloud_kms;
+
+import com.google.cloud.kms.v1.CryptoKeyName;
+import java.util.Map;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+
+public final class CloudKmsKeyEncapsulationOptions implements KeyEncapsulationOptions {
+ private static final String PROJECT = "project";
+ private static final String LOCATION = "location";
+ private static final String KEY_RING = "keyRing";
+ private static final String CRYPTO_KEY = "cryptoKey";
+
+ public static CloudKmsKeyEncapsulationOptions of(
+ String project, String location, String keyRing, String cryptoKey) {
+ return new CloudKmsKeyEncapsulationOptions(project, location, keyRing, cryptoKey);
+ }
+
+ public static CloudKmsKeyEncapsulationOptions of(Map metadata) {
+ var project = metadata.get(PROJECT);
+ var location = metadata.get(LOCATION);
+ var keyRing = metadata.get(KEY_RING);
+ var cryptoKey = metadata.get(CRYPTO_KEY);
+ return new CloudKmsKeyEncapsulationOptions(project, location, keyRing, cryptoKey);
+ }
+
+ private final CryptoKeyName keyName;
+
+ private CloudKmsKeyEncapsulationOptions(String project, String location, String keyRing, String cryptoKey) {
+ this.keyName = CryptoKeyName.of(project, location, keyRing, cryptoKey);
+ }
+
+ public CryptoKeyName keyName() {
+ return keyName;
+ }
+
+ @Override
+ public Map toMap() {
+ return Map.of(
+ PROJECT,
+ keyName.getProject(),
+ LOCATION,
+ keyName().getLocation(),
+ KEY_RING,
+ keyName().getKeyRing(),
+ CRYPTO_KEY,
+ keyName().getCryptoKey());
+ }
+}
diff --git a/encryption/google-cloud-kms/src/main/java/org/neo4j/driver/property_encryption/google_cloud_kms/GoogleCloudKeyEncapsulationService.java b/encryption/google-cloud-kms/src/main/java/org/neo4j/driver/property_encryption/google_cloud_kms/GoogleCloudKeyEncapsulationService.java
new file mode 100644
index 0000000000..78c799c8ac
--- /dev/null
+++ b/encryption/google-cloud-kms/src/main/java/org/neo4j/driver/property_encryption/google_cloud_kms/GoogleCloudKeyEncapsulationService.java
@@ -0,0 +1,102 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.google_cloud_kms;
+
+import com.google.api.core.ApiFuture;
+import com.google.cloud.kms.v1.DecryptRequest;
+import com.google.cloud.kms.v1.EncryptRequest;
+import com.google.cloud.kms.v1.KeyManagementServiceClient;
+import com.google.common.util.concurrent.MoreExecutors;
+import com.google.protobuf.ByteString;
+import java.io.IOException;
+import java.security.NoSuchAlgorithmException;
+import java.util.Map;
+import java.util.Objects;
+import java.util.concurrent.CompletableFuture;
+import java.util.concurrent.CompletionStage;
+import javax.crypto.KeyGenerator;
+import javax.crypto.SecretKey;
+import javax.crypto.spec.SecretKeySpec;
+import org.neo4j.driver.exceptions.ClientException;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResult;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResults;
+import org.neo4j.driver.property_encryption.KeyEncapsulationService;
+
+public final class GoogleCloudKeyEncapsulationService implements KeyEncapsulationService {
+ private final KeyManagementServiceClient keyManagementServiceClient;
+ private final CloudKmsKeyEncapsulationOptions defaultOptions;
+ private final KeyGenerator keyGenerator;
+
+ public GoogleCloudKeyEncapsulationService(CloudKmsKeyEncapsulationOptions defaultOptions)
+ throws IOException, NoSuchAlgorithmException {
+ this.keyManagementServiceClient = KeyManagementServiceClient.create();
+ this.defaultOptions = Objects.requireNonNull(defaultOptions);
+ this.keyGenerator = KeyGenerator.getInstance("AES");
+ this.keyGenerator.init(256);
+ }
+
+ @Override
+ public CompletionStage encapsulate(KeyEncapsulationOptions options) {
+ var encapsulationOptions = Objects.requireNonNullElse(options, defaultOptions);
+ if (encapsulationOptions instanceof CloudKmsKeyEncapsulationOptions cloudOptions) {
+ var key = keyGenerator.generateKey();
+ var req = EncryptRequest.newBuilder()
+ .setName(cloudOptions.keyName().toString())
+ .setPlaintext(ByteString.copyFrom(key.getEncoded()))
+ .build();
+ return toCompletionStage(
+ keyManagementServiceClient.encryptCallable().futureCall(req))
+ .thenApply(resp -> KeyEncapsulationResults.create(
+ resp.getCiphertext().toByteArray(), encapsulationOptions.toMap(), key));
+ } else {
+ return CompletableFuture.failedStage(new ClientException("Unsupported options"));
+ }
+ }
+
+ @Override
+ public CompletionStage decapsulate(byte[] encapsulation, Map metadata) {
+ if (metadata == null) {
+ return CompletableFuture.failedStage(new ClientException("Missing options"));
+ }
+ var cloudOptions = CloudKmsKeyEncapsulationOptions.of(metadata);
+ var keyName = cloudOptions.keyName();
+ var request = DecryptRequest.newBuilder()
+ .setName(keyName.toString())
+ .setCiphertext(ByteString.copyFrom(encapsulation))
+ .build();
+
+ return toCompletionStage(keyManagementServiceClient.decryptCallable().futureCall(request))
+ .thenApply(resp -> new SecretKeySpec(resp.getPlaintext().toByteArray(), "AES"));
+ }
+
+ private record EnvelopeCiphertext(byte[] encryptedDek, byte[] iv, byte[] ciphertext, byte[] tag) {}
+
+ private static CompletionStage toCompletionStage(ApiFuture apiFuture) {
+ var cf = new CompletableFuture();
+ apiFuture.addListener(
+ () -> {
+ try {
+ cf.complete(apiFuture.get());
+ } catch (Exception e) {
+ cf.completeExceptionally(e);
+ }
+ },
+ MoreExecutors.directExecutor());
+ return cf;
+ }
+}
diff --git a/encryption/kyber/LICENSES.txt b/encryption/kyber/LICENSES.txt
new file mode 100644
index 0000000000..4d53dd227d
--- /dev/null
+++ b/encryption/kyber/LICENSES.txt
@@ -0,0 +1,37 @@
+This file contains the full license text of the included third party
+libraries. For an overview of the licenses see the NOTICE.txt file.
+
+
+------------------------------------------------------------------------------
+Bouncy Castle License
+ Bouncy Castle Provider
+------------------------------------------------------------------------------
+
+Please note: our license is an adaptation of the MIT X11 License and should be
+read as such.
+
+LICENSE
+
+Copyright (c) 2000 - 2011 The Legion Of The Bouncy Castle
+(http://www.bouncycastle.org)
+
+Permission is hereby granted, free of charge, to any person obtaining a copy of
+this software and associated documentation files (the "Software"), to deal in
+the Software without restriction, including without limitation the rights to
+use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
+the Software, and to permit persons to whom the Software is furnished to do so,
+subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in all
+copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
+FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
+COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
+IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
+CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+
+
+
+
diff --git a/encryption/kyber/NOTICE.txt b/encryption/kyber/NOTICE.txt
new file mode 100644
index 0000000000..7a8f5432cf
--- /dev/null
+++ b/encryption/kyber/NOTICE.txt
@@ -0,0 +1,23 @@
+Copyright (c) "Neo4j"
+Neo4j Sweden AB [https://neo4j.com]
+
+This file is part of Neo4j.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+
+Full license texts are found in LICENSES.txt.
+
+
+Third-party licenses
+--------------------
+
+Bouncy Castle License
+ Bouncy Castle Provider
+
diff --git a/encryption/kyber/pom.xml b/encryption/kyber/pom.xml
new file mode 100644
index 0000000000..1cb6214efa
--- /dev/null
+++ b/encryption/kyber/pom.xml
@@ -0,0 +1,58 @@
+
+ 4.0.0
+
+
+ org.neo4j.driver
+ neo4j-java-driver-parent
+ 6.3-SNAPSHOT
+ ../../pom.xml
+
+
+ neo4j-java-driver-encryption-kyber
+
+ Neo4j Java Driver (Kyber)
+ The Neo4j Java Driver Encryption module providing encryption using kyber key.
+
+
+ false
+ false
+
+
+
+
+ org.neo4j.driver
+ neo4j-java-driver
+ ${project.version}
+ provided
+
+
+ org.bouncycastle
+ bcprov-jdk18on
+ 1.83
+ compile
+
+
+ org.junit.jupiter
+ junit-jupiter
+ test
+
+
+
+
+
+
+ org.apache.maven.plugins
+ maven-javadoc-plugin
+
+
+
+
+
+ scm:git:git://github.com/neo4j/neo4j-java-driver.git
+ scm:git:git@github.com:neo4j/neo4j-java-driver.git
+ https://github.com/neo4j/neo4j-java-driver
+
+
+
diff --git a/encryption/kyber/src/main/java/org/neo4j/driver/property_encryption/kyber/KyberEncapsulationService.java b/encryption/kyber/src/main/java/org/neo4j/driver/property_encryption/kyber/KyberEncapsulationService.java
new file mode 100644
index 0000000000..8ff3a32050
--- /dev/null
+++ b/encryption/kyber/src/main/java/org/neo4j/driver/property_encryption/kyber/KyberEncapsulationService.java
@@ -0,0 +1,138 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.property_encryption.kyber;
+
+import java.security.SecureRandom;
+import java.security.Security;
+import java.util.Arrays;
+import java.util.Map;
+import java.util.concurrent.CompletableFuture;
+import java.util.concurrent.CompletionStage;
+import javax.crypto.SecretKey;
+import javax.crypto.spec.SecretKeySpec;
+import org.bouncycastle.crypto.digests.SHA256Digest;
+import org.bouncycastle.crypto.generators.HKDFBytesGenerator;
+import org.bouncycastle.crypto.params.HKDFParameters;
+import org.bouncycastle.jcajce.SecretKeyWithEncapsulation;
+import org.bouncycastle.jcajce.spec.KEMExtractSpec;
+import org.bouncycastle.jcajce.spec.KEMGenerateSpec;
+import org.bouncycastle.pqc.jcajce.interfaces.KyberPrivateKey;
+import org.bouncycastle.pqc.jcajce.interfaces.KyberPublicKey;
+import org.bouncycastle.pqc.jcajce.provider.BouncyCastlePQCProvider;
+import org.neo4j.driver.exceptions.ClientException;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResult;
+import org.neo4j.driver.property_encryption.KeyEncapsulationResults;
+import org.neo4j.driver.property_encryption.KeyEncapsulationService;
+
+public final class KyberEncapsulationService implements KeyEncapsulationService {
+
+ static {
+ Security.addProvider(new BouncyCastlePQCProvider());
+ }
+
+ private static final int AES_256_KEY_SIZE = 32;
+
+ private final KyberPublicKey publicKey;
+ private final KyberPrivateKey privateKey;
+ private final SecureRandom secureRandom;
+ private final byte[] info;
+
+ public KyberEncapsulationService(KyberPublicKey publicKey, KyberPrivateKey privateKey) {
+ if (publicKey == null || privateKey == null) {
+ throw new IllegalArgumentException("Both public and private keys are required");
+ }
+ this.publicKey = publicKey;
+ this.privateKey = privateKey;
+ this.secureRandom = new SecureRandom();
+ this.info = "aes-256-key".getBytes();
+ }
+
+ @Override
+ public CompletionStage encapsulate(KeyEncapsulationOptions options) {
+ return CompletableFuture.supplyAsync(() -> {
+ try {
+ // 🔹 Create generator for Kyber KEM
+ javax.crypto.KeyGenerator kg = javax.crypto.KeyGenerator.getInstance("Kyber", "BCPQC");
+
+ // 🔹 Build generation spec (recipient public key + info)
+ KEMGenerateSpec genSpec = new KEMGenerateSpec(publicKey, "AES", AES_256_KEY_SIZE * 8);
+
+ // 🔹 Initialize generator with spec
+ kg.init(genSpec);
+
+ // 🔹 Generate the key (returns SecretKeyWithEncapsulation)
+ SecretKeyWithEncapsulation skwe = (SecretKeyWithEncapsulation) kg.generateKey();
+
+ // 🔹 Derive AES key from shared secret
+ byte[] shared = skwe.getEncoded();
+ SecretKey aes = deriveAesKey(shared);
+ zeroize(shared);
+
+ // 🔹 Return encapsulation bytes and AES key
+ byte[] encapsulation = skwe.getEncapsulation();
+ return KeyEncapsulationResults.create(encapsulation, Map.of(), aes);
+ } catch (Exception e) {
+ throw new ClientException("Failed to encapsulate with Kyber", e);
+ }
+ });
+ }
+
+ @Override
+ public CompletionStage decapsulate(byte[] encapsulation, Map metadata) {
+ return CompletableFuture.supplyAsync(() -> {
+ try {
+ // 🔹 Create generator for Kyber KEM
+ javax.crypto.KeyGenerator kg = javax.crypto.KeyGenerator.getInstance("Kyber", "BCPQC");
+
+ // 🔹 Build extraction spec (private key + encapsulation + info)
+ KEMExtractSpec extSpec = new KEMExtractSpec(privateKey, encapsulation, "AES");
+
+ // 🔹 Initialize generator with extraction spec
+ kg.init(extSpec);
+
+ // 🔹 Generate the key (returns SecretKeyWithEncapsulation)
+ SecretKeyWithEncapsulation skwe = (SecretKeyWithEncapsulation) kg.generateKey();
+
+ // 🔹 Derive AES key from shared secret
+ byte[] shared = skwe.getEncoded();
+ SecretKey aes = deriveAesKey(shared);
+ zeroize(shared);
+ return new SecretKeySpec(aes.getEncoded(), "AES");
+ } catch (Exception e) {
+ throw new RuntimeException("Failed to decapsulate Kyber key", e);
+ }
+ });
+ }
+
+ private SecretKey deriveAesKey(byte[] secret) {
+ byte[] keyBytes = hkdfSha256(secret, info, AES_256_KEY_SIZE);
+ return new SecretKeySpec(keyBytes, "AES");
+ }
+
+ private static byte[] hkdfSha256(byte[] ikm, byte[] info, int length) {
+ HKDFBytesGenerator hkdf = new HKDFBytesGenerator(new SHA256Digest());
+ hkdf.init(new HKDFParameters(ikm, null, info));
+ byte[] out = new byte[length];
+ hkdf.generateBytes(out, 0, out.length);
+ return out;
+ }
+
+ private static void zeroize(byte[] data) {
+ if (data != null) Arrays.fill(data, (byte) 0);
+ }
+}
diff --git a/encryption/pom.xml b/encryption/pom.xml
new file mode 100644
index 0000000000..31fdc8165a
--- /dev/null
+++ b/encryption/pom.xml
@@ -0,0 +1,31 @@
+
+ 4.0.0
+
+
+ org.neo4j.driver
+ neo4j-java-driver-parent
+ 6.3-SNAPSHOT
+
+
+ neo4j-java-driver-encryption
+
+ pom
+ Neo4j Java Driver (Encryption)
+ Parent project for encryption implementations.
+
+
+ google-cloud-kms
+ aws-kms
+ azure-keyvault
+ kyber
+
+
+
+ scm:git:git://github.com/neo4j/neo4j-java-driver.git
+ scm:git:git@github.com:neo4j/neo4j-java-driver.git
+ https://github.com/neo4j/neo4j-java-driver
+
+
+
diff --git a/examples/LICENSES.txt b/examples/LICENSES.txt
index 0a33b0b1a2..efb0343a0f 100644
--- a/examples/LICENSES.txt
+++ b/examples/LICENSES.txt
@@ -8,6 +8,7 @@ Apache Software License, Version 2.0
Neo4j Bolt Connection (Pooled Source impl)
Neo4j Bolt Connection (Provider SPI)
Neo4j Bolt Connection (Routed Source impl)
+ Neo4j Bolt Connection Codec
Netty/Buffer
Netty/Codec/Base
Netty/Common
diff --git a/examples/NOTICE.txt b/examples/NOTICE.txt
index fb63e48755..992ed8c53c 100644
--- a/examples/NOTICE.txt
+++ b/examples/NOTICE.txt
@@ -23,6 +23,7 @@ Apache Software License, Version 2.0
Neo4j Bolt Connection (Pooled Source impl)
Neo4j Bolt Connection (Provider SPI)
Neo4j Bolt Connection (Routed Source impl)
+ Neo4j Bolt Connection Codec
Netty/Buffer
Netty/Codec/Base
Netty/Common
diff --git a/examples/pom.xml b/examples/pom.xml
index 5c4ff53e2b..b9eacdc97d 100644
--- a/examples/pom.xml
+++ b/examples/pom.xml
@@ -6,7 +6,7 @@
org.neo4j.driver
neo4j-java-driver-parent
- 6.2-SNAPSHOT
+ 6.3-SNAPSHOT
org.neo4j.doc.driver
diff --git a/observation/metrics/pom.xml b/observation/metrics/pom.xml
index 8b32092841..b039be637b 100644
--- a/observation/metrics/pom.xml
+++ b/observation/metrics/pom.xml
@@ -6,7 +6,7 @@
org.neo4j.driver
neo4j-java-driver-parent
- 6.2-SNAPSHOT
+ 6.3-SNAPSHOT
../../pom.xml
diff --git a/observation/metrics/src/main/java/org/neo4j/driver/observation/metrics/internal/DriverMetricsObservationProvider.java b/observation/metrics/src/main/java/org/neo4j/driver/observation/metrics/internal/DriverMetricsObservationProvider.java
index b22b369a8e..c72e31d97a 100644
--- a/observation/metrics/src/main/java/org/neo4j/driver/observation/metrics/internal/DriverMetricsObservationProvider.java
+++ b/observation/metrics/src/main/java/org/neo4j/driver/observation/metrics/internal/DriverMetricsObservationProvider.java
@@ -35,6 +35,7 @@
import org.neo4j.driver.internal.observation.Observation;
import org.neo4j.driver.observation.metrics.Metrics;
import org.neo4j.driver.observation.metrics.MetricsObservationProvider;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
import org.neo4j.driver.types.MapAccessor;
public final class DriverMetricsObservationProvider implements MetricsObservationProvider, DriverObservationProvider {
@@ -121,6 +122,36 @@ public Observation resultRecords(Class> resultType) {
return NoopObservation.getInstance();
}
+ @Override
+ public Observation encryptToBytes(Class extends BasePropertyEncryption> propertyEncryptionType) {
+ return NoopObservation.getInstance();
+ }
+
+ @Override
+ public Observation decrypt(Class extends BasePropertyEncryption> propertyEncryptionType) {
+ return NoopObservation.getInstance();
+ }
+
+ @Override
+ public Observation createEncapsulatedKey(Class> encapsulatedKeyManagerType, String alias) {
+ return NoopObservation.getInstance();
+ }
+
+ @Override
+ public Observation findEncapsulatedKeyByAlias(Class> encapsulatedKeyManagerType, String alias) {
+ return NoopObservation.getInstance();
+ }
+
+ @Override
+ public Observation updateEncapsulatedKeyAlias(Class> encapsulatedKeyManagerType, String id, String alias) {
+ return NoopObservation.getInstance();
+ }
+
+ @Override
+ public Observation deleteEncapsulatedKey(Class> encapsulatedKeyManagerType, String id) {
+ return NoopObservation.getInstance();
+ }
+
@Override
public Observation connectionPoolCreate(String id, URI uri, int maxSize) {
return new PoolCreateObservation(metrics, id);
diff --git a/observation/micrometer/pom.xml b/observation/micrometer/pom.xml
index c063ae0197..94754909f3 100644
--- a/observation/micrometer/pom.xml
+++ b/observation/micrometer/pom.xml
@@ -6,7 +6,7 @@
org.neo4j.driver
neo4j-java-driver-parent
- 6.2-SNAPSHOT
+ 6.3-SNAPSHOT
../../pom.xml
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/CreateEncapsulatedKeyContext.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/CreateEncapsulatedKeyContext.java
new file mode 100644
index 0000000000..5ddf10fe5a
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/CreateEncapsulatedKeyContext.java
@@ -0,0 +1,44 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import java.util.Objects;
+import java.util.Optional;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class CreateEncapsulatedKeyContext extends Observation.Context {
+ private final Class> encapsulatedKeyManagerType;
+ private final String alias;
+
+ public CreateEncapsulatedKeyContext(Class> encapsulatedKeyManagerType, String alias) {
+ this.encapsulatedKeyManagerType = Objects.requireNonNull(encapsulatedKeyManagerType);
+ this.alias = alias;
+ }
+
+ public Class> encapsulatedKeyManagerType() {
+ return encapsulatedKeyManagerType;
+ }
+
+ public Optional alias() {
+ return Optional.ofNullable(alias);
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/CreateEncapsulatedKeyConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/CreateEncapsulatedKeyConvention.java
new file mode 100644
index 0000000000..961748ef2b
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/CreateEncapsulatedKeyConvention.java
@@ -0,0 +1,32 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import io.micrometer.observation.ObservationConvention;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public interface CreateEncapsulatedKeyConvention extends ObservationConvention {
+ @Override
+ default boolean supportsContext(Observation.Context context) {
+ return context instanceof CreateEncapsulatedKeyContext;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DecryptContext.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DecryptContext.java
new file mode 100644
index 0000000000..93418c1256
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DecryptContext.java
@@ -0,0 +1,38 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import java.util.Objects;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DecryptContext extends Observation.Context {
+ private final Class extends BasePropertyEncryption> propertyEncryptionType;
+
+ public DecryptContext(Class extends BasePropertyEncryption> propertyEncryptionType) {
+ this.propertyEncryptionType = Objects.requireNonNull(propertyEncryptionType);
+ }
+
+ public Class extends BasePropertyEncryption> propertyEncryptionType() {
+ return propertyEncryptionType;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DecryptConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DecryptConvention.java
new file mode 100644
index 0000000000..78c0a15fde
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DecryptConvention.java
@@ -0,0 +1,32 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import io.micrometer.observation.ObservationConvention;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public interface DecryptConvention extends ObservationConvention {
+ @Override
+ default boolean supportsContext(Observation.Context context) {
+ return context instanceof DecryptContext;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultCreateEncapsulatedKeyConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultCreateEncapsulatedKeyConvention.java
new file mode 100644
index 0000000000..bf640ecfc1
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultCreateEncapsulatedKeyConvention.java
@@ -0,0 +1,65 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.common.KeyValue;
+import io.micrometer.common.KeyValues;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DefaultCreateEncapsulatedKeyConvention implements CreateEncapsulatedKeyConvention {
+ private static final KeyValue DB_SYSTEM_NAME =
+ Neo4jDriverDocumentation.CreateEncapsulatedKeyLowCardinalityKeyNames.DB_SYSTEM_NAME.withValue(
+ KeyValuesUtil.DB_SYSTEM_NAME);
+ static final DefaultCreateEncapsulatedKeyConvention INSTANCE = new DefaultCreateEncapsulatedKeyConvention();
+
+ public DefaultCreateEncapsulatedKeyConvention() {}
+
+ @Override
+ public String getName() {
+ return "neo4j.db.client.property.encryption.create.encapsulated.key.duration";
+ }
+
+ @Override
+ public String getContextualName(CreateEncapsulatedKeyContext context) {
+ return "create encapsulated key";
+ }
+
+ @Override
+ public KeyValues getLowCardinalityKeyValues(CreateEncapsulatedKeyContext context) {
+ return KeyValues.of(DB_SYSTEM_NAME, encapsulatedKeyManagerType(context));
+ }
+
+ @Override
+ public KeyValues getHighCardinalityKeyValues(CreateEncapsulatedKeyContext context) {
+ return KeyValues.of(alias(context));
+ }
+
+ private KeyValue encapsulatedKeyManagerType(CreateEncapsulatedKeyContext context) {
+ return Neo4jDriverDocumentation.CreateEncapsulatedKeyLowCardinalityKeyNames.ENCAPSULATED_KEY_MANAGER_TYPE
+ .withValue(context.encapsulatedKeyManagerType().getSimpleName());
+ }
+
+ private KeyValue alias(CreateEncapsulatedKeyContext context) {
+ // todo deal with none value
+ return Neo4jDriverDocumentation.CreateEncapsulatedKeyHighCardinalityKeyNames.KEY_ALIAS.withValue(
+ context.alias().orElse(KeyValue.NONE_VALUE));
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultDecryptConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultDecryptConvention.java
new file mode 100644
index 0000000000..6754e741e3
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultDecryptConvention.java
@@ -0,0 +1,54 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.common.KeyValue;
+import io.micrometer.common.KeyValues;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DefaultDecryptConvention implements DecryptConvention {
+ private static final KeyValue DB_SYSTEM_NAME =
+ Neo4jDriverDocumentation.DecryptLowCardinalityKeyNames.DB_SYSTEM_NAME.withValue(
+ KeyValuesUtil.DB_SYSTEM_NAME);
+ static final DefaultDecryptConvention INSTANCE = new DefaultDecryptConvention();
+
+ public DefaultDecryptConvention() {}
+
+ @Override
+ public String getName() {
+ return "neo4j.db.client.property.encryption.decrypt.duration";
+ }
+
+ @Override
+ public String getContextualName(DecryptContext context) {
+ return "decrypt";
+ }
+
+ @Override
+ public KeyValues getLowCardinalityKeyValues(DecryptContext context) {
+ return KeyValues.of(DB_SYSTEM_NAME, propertyEncryptionType(context));
+ }
+
+ private KeyValue propertyEncryptionType(DecryptContext context) {
+ return Neo4jDriverDocumentation.DecryptLowCardinalityKeyNames.PROPERTY_ENCRYPTION_TYPE.withValue(
+ context.propertyEncryptionType().getSimpleName());
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultDeleteEncapsulatedKeyConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultDeleteEncapsulatedKeyConvention.java
new file mode 100644
index 0000000000..bdea5bfe67
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultDeleteEncapsulatedKeyConvention.java
@@ -0,0 +1,58 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.common.KeyValue;
+import io.micrometer.common.KeyValues;
+
+public class DefaultDeleteEncapsulatedKeyConvention implements DeleteEncapsulatedKeyConvention {
+ private static final KeyValue DB_SYSTEM_NAME =
+ Neo4jDriverDocumentation.DeleteEncapsulatedKeyLowCardinalityKeyNames.DB_SYSTEM_NAME.withValue(
+ KeyValuesUtil.DB_SYSTEM_NAME);
+ static final DefaultDeleteEncapsulatedKeyConvention INSTANCE = new DefaultDeleteEncapsulatedKeyConvention();
+
+ public DefaultDeleteEncapsulatedKeyConvention() {}
+
+ @Override
+ public String getName() {
+ return "neo4j.db.client.property.encryption.delete.encapsulated.key.duration";
+ }
+
+ @Override
+ public String getContextualName(DeleteEncapsulatedKeyContext context) {
+ return "delete encapsulated key";
+ }
+
+ @Override
+ public KeyValues getLowCardinalityKeyValues(DeleteEncapsulatedKeyContext context) {
+ return KeyValues.of(DB_SYSTEM_NAME, encapsulatedKeyManagerType(context));
+ }
+
+ @Override
+ public KeyValues getHighCardinalityKeyValues(DeleteEncapsulatedKeyContext context) {
+ return KeyValues.of(id(context));
+ }
+
+ private KeyValue encapsulatedKeyManagerType(DeleteEncapsulatedKeyContext context) {
+ return Neo4jDriverDocumentation.DeleteEncapsulatedKeyLowCardinalityKeyNames.ENCAPSULATED_KEY_MANAGER_TYPE
+ .withValue(context.encapsulatedKeyManagerType().getSimpleName());
+ }
+
+ private KeyValue id(DeleteEncapsulatedKeyContext context) {
+ return Neo4jDriverDocumentation.DeleteEncapsulatedKeyHighCardinalityKeyNames.KEY_ID.withValue(context.id());
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultEncryptToBytesConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultEncryptToBytesConvention.java
new file mode 100644
index 0000000000..482cbc8af8
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultEncryptToBytesConvention.java
@@ -0,0 +1,54 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.common.KeyValue;
+import io.micrometer.common.KeyValues;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DefaultEncryptToBytesConvention implements EncryptToBytesConvention {
+ private static final KeyValue DB_SYSTEM_NAME =
+ Neo4jDriverDocumentation.EncryptToBytesLowCardinalityKeyNames.DB_SYSTEM_NAME.withValue(
+ KeyValuesUtil.DB_SYSTEM_NAME);
+ static final DefaultEncryptToBytesConvention INSTANCE = new DefaultEncryptToBytesConvention();
+
+ public DefaultEncryptToBytesConvention() {}
+
+ @Override
+ public String getName() {
+ return "neo4j.db.client.property.encryption.encrypt.to.bytes.duration";
+ }
+
+ @Override
+ public String getContextualName(EncryptToBytesContext context) {
+ return "encrypt to bytes";
+ }
+
+ @Override
+ public KeyValues getLowCardinalityKeyValues(EncryptToBytesContext context) {
+ return KeyValues.of(DB_SYSTEM_NAME, propertyEncryptionType(context));
+ }
+
+ private KeyValue propertyEncryptionType(EncryptToBytesContext context) {
+ return Neo4jDriverDocumentation.EncryptToBytesLowCardinalityKeyNames.PROPERTY_ENCRYPTION_TYPE.withValue(
+ context.propertyEncryptionType().getSimpleName());
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultFindEncapsulatedKeyByAliasConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultFindEncapsulatedKeyByAliasConvention.java
new file mode 100644
index 0000000000..56317f089b
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultFindEncapsulatedKeyByAliasConvention.java
@@ -0,0 +1,65 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.common.KeyValue;
+import io.micrometer.common.KeyValues;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DefaultFindEncapsulatedKeyByAliasConvention implements FindEncapsulatedKeyByAliasConvention {
+ private static final KeyValue DB_SYSTEM_NAME =
+ Neo4jDriverDocumentation.FindEncapsulatedKeyByAliasLowCardinalityKeyNames.DB_SYSTEM_NAME.withValue(
+ KeyValuesUtil.DB_SYSTEM_NAME);
+ static final DefaultFindEncapsulatedKeyByAliasConvention INSTANCE =
+ new DefaultFindEncapsulatedKeyByAliasConvention();
+
+ public DefaultFindEncapsulatedKeyByAliasConvention() {}
+
+ @Override
+ public String getName() {
+ return "neo4j.db.client.property.encryption.find.encapsulated.key.by.alias.duration";
+ }
+
+ @Override
+ public String getContextualName(FindEncapsulatedKeyByAliasContext context) {
+ return "find encapsulated key by alias";
+ }
+
+ @Override
+ public KeyValues getLowCardinalityKeyValues(FindEncapsulatedKeyByAliasContext context) {
+ return KeyValues.of(DB_SYSTEM_NAME, encapsulatedKeyManagerType(context));
+ }
+
+ @Override
+ public KeyValues getHighCardinalityKeyValues(FindEncapsulatedKeyByAliasContext context) {
+ return KeyValues.of(alias(context));
+ }
+
+ private KeyValue encapsulatedKeyManagerType(FindEncapsulatedKeyByAliasContext context) {
+ return Neo4jDriverDocumentation.FindEncapsulatedKeyByAliasLowCardinalityKeyNames.ENCAPSULATED_KEY_MANAGER_TYPE
+ .withValue(context.encapsulatedKeyManagerType().getSimpleName());
+ }
+
+ private KeyValue alias(FindEncapsulatedKeyByAliasContext context) {
+ return Neo4jDriverDocumentation.FindEncapsulatedKeyByAliasHighCardinalityKeyNames.KEY_ALIAS.withValue(
+ context.alias());
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultUpdateEncapsulatedKeyAliasConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultUpdateEncapsulatedKeyAliasConvention.java
new file mode 100644
index 0000000000..be914c5c44
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DefaultUpdateEncapsulatedKeyAliasConvention.java
@@ -0,0 +1,70 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.common.KeyValue;
+import io.micrometer.common.KeyValues;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DefaultUpdateEncapsulatedKeyAliasConvention implements UpdateEncapsulatedKeyAliasConvention {
+ private static final KeyValue DB_SYSTEM_NAME =
+ Neo4jDriverDocumentation.UpdateEncapsulatedKeyAliasLowCardinalityKeyNames.DB_SYSTEM_NAME.withValue(
+ KeyValuesUtil.DB_SYSTEM_NAME);
+ static final DefaultUpdateEncapsulatedKeyAliasConvention INSTANCE =
+ new DefaultUpdateEncapsulatedKeyAliasConvention();
+
+ public DefaultUpdateEncapsulatedKeyAliasConvention() {}
+
+ @Override
+ public String getName() {
+ return "neo4j.db.client.property.encryption.update.encapsulated.key.alias.duration";
+ }
+
+ @Override
+ public String getContextualName(UpdateEncapsulatedKeyAliasContext context) {
+ return "update encapsulated key alias";
+ }
+
+ @Override
+ public KeyValues getLowCardinalityKeyValues(UpdateEncapsulatedKeyAliasContext context) {
+ return KeyValues.of(DB_SYSTEM_NAME, encapsulatedKeyManagerType(context));
+ }
+
+ @Override
+ public KeyValues getHighCardinalityKeyValues(UpdateEncapsulatedKeyAliasContext context) {
+ return KeyValues.of(id(context), alias(context));
+ }
+
+ private KeyValue encapsulatedKeyManagerType(UpdateEncapsulatedKeyAliasContext context) {
+ return Neo4jDriverDocumentation.UpdateEncapsulatedKeyAliasLowCardinalityKeyNames.ENCAPSULATED_KEY_MANAGER_TYPE
+ .withValue(context.encapsulatedKeyManagerType().getSimpleName());
+ }
+
+ private KeyValue id(UpdateEncapsulatedKeyAliasContext context) {
+ return Neo4jDriverDocumentation.UpdateEncapsulatedKeyAliasHighCardinalityKeyNames.KEY_ID.withValue(
+ context.id());
+ }
+
+ private KeyValue alias(UpdateEncapsulatedKeyAliasContext context) {
+ return Neo4jDriverDocumentation.UpdateEncapsulatedKeyAliasHighCardinalityKeyNames.KEY_ALIAS.withValue(
+ context.alias().orElse(KeyValue.NONE_VALUE));
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DeleteEncapsulatedKeyContext.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DeleteEncapsulatedKeyContext.java
new file mode 100644
index 0000000000..890658492c
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DeleteEncapsulatedKeyContext.java
@@ -0,0 +1,43 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import java.util.Objects;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class DeleteEncapsulatedKeyContext extends Observation.Context {
+ private final Class> encapsulatedKeyManagerType;
+ private final String id;
+
+ public DeleteEncapsulatedKeyContext(Class> encapsulatedKeyManagerType, String id) {
+ this.encapsulatedKeyManagerType = Objects.requireNonNull(encapsulatedKeyManagerType);
+ this.id = Objects.requireNonNull(id);
+ }
+
+ public Class> encapsulatedKeyManagerType() {
+ return encapsulatedKeyManagerType;
+ }
+
+ public String id() {
+ return id;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DeleteEncapsulatedKeyConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DeleteEncapsulatedKeyConvention.java
new file mode 100644
index 0000000000..1b2d30363c
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DeleteEncapsulatedKeyConvention.java
@@ -0,0 +1,32 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import io.micrometer.observation.ObservationConvention;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+interface DeleteEncapsulatedKeyConvention extends ObservationConvention {
+ @Override
+ default boolean supportsContext(Observation.Context context) {
+ return context instanceof DeleteEncapsulatedKeyContext;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DriverMicrometerObservationProvider.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DriverMicrometerObservationProvider.java
index cb338241f8..132909bcca 100644
--- a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DriverMicrometerObservationProvider.java
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/DriverMicrometerObservationProvider.java
@@ -32,6 +32,7 @@
import org.neo4j.driver.internal.observation.DriverObservationProvider;
import org.neo4j.driver.internal.observation.HttpExchangeObservation;
import org.neo4j.driver.internal.observation.Observation;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
import org.neo4j.driver.types.MapAccessor;
final class DriverMicrometerObservationProvider implements MicrometerObservationProvider, DriverObservationProvider {
@@ -128,6 +129,44 @@ public Observation resultRecords(Class> resultType) {
return from(DefaultResultRecordsConvention.INSTANCE, () -> new ResultRecordsContext(resultType));
}
+ @Override
+ public Observation encryptToBytes(Class extends BasePropertyEncryption> propertyEncryptionType) {
+ return from(DefaultEncryptToBytesConvention.INSTANCE, () -> new EncryptToBytesContext(propertyEncryptionType));
+ }
+
+ @Override
+ public Observation decrypt(Class extends BasePropertyEncryption> propertyEncryptionType) {
+ return from(DefaultDecryptConvention.INSTANCE, () -> new DecryptContext(propertyEncryptionType));
+ }
+
+ @Override
+ public Observation createEncapsulatedKey(Class> encapsulatedKeyManagerType, String alias) {
+ return from(
+ DefaultCreateEncapsulatedKeyConvention.INSTANCE,
+ () -> new CreateEncapsulatedKeyContext(encapsulatedKeyManagerType, alias));
+ }
+
+ @Override
+ public Observation findEncapsulatedKeyByAlias(Class> encapsulatedKeyManagerType, String alias) {
+ return from(
+ DefaultFindEncapsulatedKeyByAliasConvention.INSTANCE,
+ () -> new FindEncapsulatedKeyByAliasContext(encapsulatedKeyManagerType, alias));
+ }
+
+ @Override
+ public Observation updateEncapsulatedKeyAlias(Class> encapsulatedKeyManagerType, String id, String alias) {
+ return from(
+ DefaultUpdateEncapsulatedKeyAliasConvention.INSTANCE,
+ () -> new UpdateEncapsulatedKeyAliasContext(encapsulatedKeyManagerType, id, alias));
+ }
+
+ @Override
+ public Observation deleteEncapsulatedKey(Class> encapsulatedKeyManagerType, String id) {
+ return from(
+ DefaultDeleteEncapsulatedKeyConvention.INSTANCE,
+ () -> new DeleteEncapsulatedKeyContext(encapsulatedKeyManagerType, id));
+ }
+
@Override
public Observation connectionPoolCreate(String id, URI uri, int maxSize) {
return from(
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/EncryptToBytesContext.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/EncryptToBytesContext.java
new file mode 100644
index 0000000000..ca39947217
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/EncryptToBytesContext.java
@@ -0,0 +1,38 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import java.util.Objects;
+import org.neo4j.driver.property_encryption.BasePropertyEncryption;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class EncryptToBytesContext extends Observation.Context {
+ private final Class extends BasePropertyEncryption> propertyEncryptionType;
+
+ public EncryptToBytesContext(Class extends BasePropertyEncryption> propertyEncryptionType) {
+ this.propertyEncryptionType = Objects.requireNonNull(propertyEncryptionType);
+ }
+
+ public Class extends BasePropertyEncryption> propertyEncryptionType() {
+ return propertyEncryptionType;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/EncryptToBytesConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/EncryptToBytesConvention.java
new file mode 100644
index 0000000000..9564126f29
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/EncryptToBytesConvention.java
@@ -0,0 +1,32 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import io.micrometer.observation.ObservationConvention;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public interface EncryptToBytesConvention extends ObservationConvention {
+ @Override
+ default boolean supportsContext(Observation.Context context) {
+ return context instanceof EncryptToBytesContext;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/FindEncapsulatedKeyByAliasContext.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/FindEncapsulatedKeyByAliasContext.java
new file mode 100644
index 0000000000..08f00ef8f9
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/FindEncapsulatedKeyByAliasContext.java
@@ -0,0 +1,43 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import java.util.Objects;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class FindEncapsulatedKeyByAliasContext extends Observation.Context {
+ private final Class> encapsulatedKeyManagerType;
+ private final String alias;
+
+ public FindEncapsulatedKeyByAliasContext(Class> encapsulatedKeyManagerType, String alias) {
+ this.encapsulatedKeyManagerType = Objects.requireNonNull(encapsulatedKeyManagerType);
+ this.alias = Objects.requireNonNull(alias);
+ }
+
+ public Class> encapsulatedKeyManagerType() {
+ return encapsulatedKeyManagerType;
+ }
+
+ public String alias() {
+ return alias;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/FindEncapsulatedKeyByAliasConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/FindEncapsulatedKeyByAliasConvention.java
new file mode 100644
index 0000000000..327c2ebee2
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/FindEncapsulatedKeyByAliasConvention.java
@@ -0,0 +1,32 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import io.micrometer.observation.ObservationConvention;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public interface FindEncapsulatedKeyByAliasConvention extends ObservationConvention {
+ @Override
+ default boolean supportsContext(Observation.Context context) {
+ return context instanceof FindEncapsulatedKeyByAliasContext;
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/Neo4jDriverDocumentation.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/Neo4jDriverDocumentation.java
index 2ee931d616..6cd5d3931e 100644
--- a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/Neo4jDriverDocumentation.java
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/Neo4jDriverDocumentation.java
@@ -25,6 +25,11 @@
import org.neo4j.driver.Session;
import org.neo4j.driver.Transaction;
import org.neo4j.driver.TransactionCallback;
+import org.neo4j.driver.property_encryption.EncapsulatedKeyManager;
+import org.neo4j.driver.property_encryption.KeyEncapsulationOptions;
+import org.neo4j.driver.property_encryption.PropertyDecryptionRequest;
+import org.neo4j.driver.property_encryption.PropertyEncryption;
+import org.neo4j.driver.property_encryption.PropertyEncryptionRequest;
import org.neo4j.driver.reactivestreams.ReactiveResult;
enum Neo4jDriverDocumentation implements ObservationDocumentation {
@@ -274,6 +279,123 @@ public KeyName[] getLowCardinalityKeyNames() {
return ResultConsumeLowCardinalityKeyNames.values();
}
},
+ /**
+ * Observes {@link PropertyEncryption#encryptToBytes(PropertyEncryptionRequest)} execution.
+ *
+ * This also applies to the alternative property encryption types.
+ */
+ PROPERTY_ENCRYPTION_ENCRYPT_TO_BYTES {
+ @Override
+ public Class extends ObservationConvention extends Observation.Context>> getDefaultConvention() {
+ return DefaultEncryptToBytesConvention.class;
+ }
+
+ @Override
+ public KeyName[] getLowCardinalityKeyNames() {
+ return EncryptToBytesLowCardinalityKeyNames.values();
+ }
+ },
+ /**
+ * Observes {@link PropertyEncryption#decrypt(PropertyDecryptionRequest)} execution.
+ *
+ * This also applies to the alternative property encryption types.
+ */
+ PROPERTY_ENCRYPTION_DECRYPT {
+ @Override
+ public Class extends ObservationConvention extends Observation.Context>> getDefaultConvention() {
+ return DefaultDecryptConvention.class;
+ }
+
+ @Override
+ public KeyName[] getLowCardinalityKeyNames() {
+ return DecryptLowCardinalityKeyNames.values();
+ }
+ },
+ /**
+ * Observes {@link EncapsulatedKeyManager#create(String, KeyEncapsulationOptions)} execution.
+ *
+ * This also applies to the other variants of this method, including those of the alternative encapsulated key
+ * manager types.
+ */
+ CREATE_ENCAPSULATED_KEY {
+ @Override
+ public Class extends ObservationConvention extends Observation.Context>> getDefaultConvention() {
+ return DefaultCreateEncapsulatedKeyConvention.class;
+ }
+
+ @Override
+ public KeyName[] getLowCardinalityKeyNames() {
+ return CreateEncapsulatedKeyLowCardinalityKeyNames.values();
+ }
+
+ @Override
+ public KeyName[] getHighCardinalityKeyNames() {
+ return CreateEncapsulatedKeyHighCardinalityKeyNames.values();
+ }
+ },
+ /**
+ * Observes {@link EncapsulatedKeyManager#findByAlias(String)} execution.
+ *
+ * This also applies to the alternative encapsulated key manager types.
+ */
+ FIND_ENCAPSULATED_KEY {
+ @Override
+ public Class extends ObservationConvention extends Observation.Context>> getDefaultConvention() {
+ return DefaultFindEncapsulatedKeyByAliasConvention.class;
+ }
+
+ @Override
+ public KeyName[] getLowCardinalityKeyNames() {
+ return FindEncapsulatedKeyByAliasLowCardinalityKeyNames.values();
+ }
+
+ @Override
+ public KeyName[] getHighCardinalityKeyNames() {
+ return FindEncapsulatedKeyByAliasHighCardinalityKeyNames.values();
+ }
+ },
+ /**
+ * Observes {@link EncapsulatedKeyManager#updateAliasById(String, String)} execution.
+ *
+ * This also applies to the alternative encapsulated key manager types.
+ */
+ UPDATE_ENCAPSULATED_KEY_ALIAS {
+ @Override
+ public Class extends ObservationConvention extends Observation.Context>> getDefaultConvention() {
+ return DefaultUpdateEncapsulatedKeyAliasConvention.class;
+ }
+
+ @Override
+ public KeyName[] getLowCardinalityKeyNames() {
+ return UpdateEncapsulatedKeyAliasLowCardinalityKeyNames.values();
+ }
+
+ @Override
+ public KeyName[] getHighCardinalityKeyNames() {
+ return UpdateEncapsulatedKeyAliasHighCardinalityKeyNames.values();
+ }
+ },
+ /**
+ * Observes {@link EncapsulatedKeyManager#findByAlias(String)} execution.
+ *
+ * This also applies to the alternative encapsulated key manager types.
+ */
+ DELETE_ENCAPSULATED_KEY {
+ @Override
+ public Class extends ObservationConvention extends Observation.Context>> getDefaultConvention() {
+ return DefaultDeleteEncapsulatedKeyConvention.class;
+ }
+
+ @Override
+ public KeyName[] getLowCardinalityKeyNames() {
+ return DeleteEncapsulatedKeyLowCardinalityKeyNames.values();
+ }
+
+ @Override
+ public KeyName[] getHighCardinalityKeyNames() {
+ return DeleteEncapsulatedKeyHighCardinalityKeyNames.values();
+ }
+ },
/**
* Observes a new connection pool creation.
*/
@@ -790,6 +912,204 @@ public String asString() {
}
}
+ enum EncryptToBytesLowCardinalityKeyNames implements KeyName {
+ /**
+ * The DBMS product name. It is always neo4j.
+ */
+ DB_SYSTEM_NAME {
+ @Override
+ public String asString() {
+ return "db.system.name";
+ }
+ },
+ /**
+ * The property encryption type.
+ */
+ PROPERTY_ENCRYPTION_TYPE {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.type";
+ }
+ }
+ }
+
+ enum DecryptLowCardinalityKeyNames implements KeyName {
+ /**
+ * The DBMS product name. It is always neo4j.
+ */
+ DB_SYSTEM_NAME {
+ @Override
+ public String asString() {
+ return "db.system.name";
+ }
+ },
+ /**
+ * The property encryption type.
+ */
+ PROPERTY_ENCRYPTION_TYPE {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.type";
+ }
+ }
+ }
+
+ enum CreateEncapsulatedKeyLowCardinalityKeyNames implements KeyName {
+ /**
+ * The DBMS product name. It is always neo4j.
+ */
+ DB_SYSTEM_NAME {
+ @Override
+ public String asString() {
+ return "db.system.name";
+ }
+ },
+ /**
+ * The encapsulated key manager type.
+ */
+ ENCAPSULATED_KEY_MANAGER_TYPE {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.manager.type";
+ }
+ }
+ }
+
+ enum CreateEncapsulatedKeyHighCardinalityKeyNames implements KeyName {
+ /**
+ * The key alias if available.
+ */
+ KEY_ALIAS {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.alias";
+ }
+
+ @Override
+ public boolean isRequired() {
+ return false;
+ }
+ }
+ }
+
+ enum FindEncapsulatedKeyByAliasLowCardinalityKeyNames implements KeyName {
+ /**
+ * The DBMS product name. It is always neo4j.
+ */
+ DB_SYSTEM_NAME {
+ @Override
+ public String asString() {
+ return "db.system.name";
+ }
+ },
+ /**
+ * The encapsulated key manager type.
+ */
+ ENCAPSULATED_KEY_MANAGER_TYPE {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.manager.type";
+ }
+ }
+ }
+
+ enum FindEncapsulatedKeyByAliasHighCardinalityKeyNames implements KeyName {
+ /**
+ * The key alias if available.
+ */
+ KEY_ALIAS {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.alias";
+ }
+
+ @Override
+ public boolean isRequired() {
+ return false;
+ }
+ }
+ }
+
+ enum DeleteEncapsulatedKeyLowCardinalityKeyNames implements KeyName {
+ /**
+ * The DBMS product name. It is always neo4j.
+ */
+ DB_SYSTEM_NAME {
+ @Override
+ public String asString() {
+ return "db.system.name";
+ }
+ },
+ /**
+ * The encapsulated key manager type.
+ */
+ ENCAPSULATED_KEY_MANAGER_TYPE {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.manager.type";
+ }
+ }
+ }
+
+ enum DeleteEncapsulatedKeyHighCardinalityKeyNames implements KeyName {
+ /**
+ * The key id.
+ */
+ KEY_ID {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.id";
+ }
+ }
+ }
+
+ enum UpdateEncapsulatedKeyAliasLowCardinalityKeyNames implements KeyName {
+ /**
+ * The DBMS product name. It is always neo4j.
+ */
+ DB_SYSTEM_NAME {
+ @Override
+ public String asString() {
+ return "db.system.name";
+ }
+ },
+ /**
+ * The encapsulated key manager type.
+ */
+ ENCAPSULATED_KEY_MANAGER_TYPE {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.manager.type";
+ }
+ }
+ }
+
+ enum UpdateEncapsulatedKeyAliasHighCardinalityKeyNames implements KeyName {
+ /**
+ * The key id.
+ */
+ KEY_ID {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.id";
+ }
+ },
+ /**
+ * The key alias if available.
+ */
+ KEY_ALIAS {
+ @Override
+ public String asString() {
+ return "neo4j.property.encryption.encapsulated.key.alias";
+ }
+
+ @Override
+ public boolean isRequired() {
+ return false;
+ }
+ }
+ }
+
enum ConnectionPoolCloseLowCardinalityKeyNames implements KeyName {
/**
* The DBMS product name. It is always neo4j.
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/UpdateEncapsulatedKeyAliasContext.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/UpdateEncapsulatedKeyAliasContext.java
new file mode 100644
index 0000000000..2eebcfca6a
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/UpdateEncapsulatedKeyAliasContext.java
@@ -0,0 +1,50 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import java.util.Objects;
+import java.util.Optional;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public class UpdateEncapsulatedKeyAliasContext extends Observation.Context {
+ private final Class> encapsulatedKeyManagerType;
+ private final String id;
+ private final String alias;
+
+ public UpdateEncapsulatedKeyAliasContext(Class> encapsulatedKeyManagerType, String id, String alias) {
+ this.encapsulatedKeyManagerType = Objects.requireNonNull(encapsulatedKeyManagerType);
+ this.id = Objects.requireNonNull(id);
+ this.alias = alias;
+ }
+
+ public Class> encapsulatedKeyManagerType() {
+ return encapsulatedKeyManagerType;
+ }
+
+ public String id() {
+ return id;
+ }
+
+ public Optional alias() {
+ return Optional.ofNullable(alias);
+ }
+}
diff --git a/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/UpdateEncapsulatedKeyAliasConvention.java b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/UpdateEncapsulatedKeyAliasConvention.java
new file mode 100644
index 0000000000..b03c855aa2
--- /dev/null
+++ b/observation/micrometer/src/main/java/org/neo4j/driver/observation/micrometer/UpdateEncapsulatedKeyAliasConvention.java
@@ -0,0 +1,32 @@
+/*
+ * Copyright (c) "Neo4j"
+ * Neo4j Sweden AB [https://neo4j.com]
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.neo4j.driver.observation.micrometer;
+
+import io.micrometer.observation.Observation;
+import io.micrometer.observation.ObservationConvention;
+import org.neo4j.driver.util.Preview;
+
+/**
+ * @since 6.3.0
+ */
+@Preview(name = "Observability")
+public interface UpdateEncapsulatedKeyAliasConvention extends ObservationConvention {
+ @Override
+ default boolean supportsContext(Observation.Context context) {
+ return context instanceof UpdateEncapsulatedKeyAliasContext;
+ }
+}
diff --git a/observation/pom.xml b/observation/pom.xml
index 5fe6051646..46efe92cda 100644
--- a/observation/pom.xml
+++ b/observation/pom.xml
@@ -6,7 +6,7 @@
org.neo4j.driver
neo4j-java-driver-parent
- 6.2-SNAPSHOT
+ 6.3-SNAPSHOT
neo4j-java-driver-observation
diff --git a/pom.xml b/pom.xml
index a53fff4455..a67724d7b0 100644
--- a/pom.xml
+++ b/pom.xml
@@ -5,7 +5,7 @@
org.neo4j.driver
neo4j-java-driver-parent
- 6.2-SNAPSHOT
+ 6.3-SNAPSHOT
pom
Neo4j Java Driver Project
@@ -35,12 +35,12 @@
true
- 12.0.0
+ 12.1-SNAPSHOT
1.0.4
- 4.2.16.Final
+ 4.2.17.Final
@@ -48,7 +48,7 @@
2.0.18
3.0
5.23.0
- 6.1.2
+ 6.1.3
7.12.0
1.2.0
@@ -76,6 +76,7 @@
driver
bundle
observation
+ encryption
driver-it
examples
testkit-backend
diff --git a/testkit-backend/LICENSES.txt b/testkit-backend/LICENSES.txt
index 9949059506..dcfdbc7847 100644
--- a/testkit-backend/LICENSES.txt
+++ b/testkit-backend/LICENSES.txt
@@ -11,6 +11,7 @@ Apache Software License, Version 2.0
Neo4j Bolt Connection (Pooled Source impl)
Neo4j Bolt Connection (Provider SPI)
Neo4j Bolt Connection (Routed Source impl)
+ Neo4j Bolt Connection Codec
Netty/Buffer
Netty/Codec/Base
Netty/Common
@@ -226,6 +227,38 @@ Apache Software License, Version 2.0
+------------------------------------------------------------------------------
+Bouncy Castle License
+ Bouncy Castle Provider (FIPS Distribution)
+------------------------------------------------------------------------------
+
+Please note: our license is an adaptation of the MIT X11 License and should be
+read as such.
+
+LICENSE
+
+Copyright (c) 2000 - 2011 The Legion Of The Bouncy Castle
+(http://www.bouncycastle.org)
+
+Permission is hereby granted, free of charge, to any person obtaining a copy of
+this software and associated documentation files (the "Software"), to deal in
+the Software without restriction, including without limitation the rights to
+use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
+the Software, and to permit persons to whom the Software is furnished to do so,
+subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in all
+copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
+FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
+COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
+IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
+CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+
+
+
------------------------------------------------------------------------------
MIT No Attribution License
reactive-streams
diff --git a/testkit-backend/NOTICE.txt b/testkit-backend/NOTICE.txt
index 0b4ad33765..4c41fac1c5 100644
--- a/testkit-backend/NOTICE.txt
+++ b/testkit-backend/NOTICE.txt
@@ -26,6 +26,7 @@ Apache Software License, Version 2.0
Neo4j Bolt Connection (Pooled Source impl)
Neo4j Bolt Connection (Provider SPI)
Neo4j Bolt Connection (Routed Source impl)
+ Neo4j Bolt Connection Codec
Netty/Buffer
Netty/Codec/Base
Netty/Common
@@ -36,6 +37,9 @@ Apache Software License, Version 2.0
Netty/Transport/Native/Unix/Common
Non-Blocking Reactive Foundation for the JVM
+Bouncy Castle License
+ Bouncy Castle Provider (FIPS Distribution)
+
MIT No Attribution License
reactive-streams
diff --git a/testkit-backend/pom.xml b/testkit-backend/pom.xml
index e382cfe516..dc23fd862b 100644
--- a/testkit-backend/pom.xml
+++ b/testkit-backend/pom.xml
@@ -7,7 +7,7 @@
neo4j-java-driver-parent
org.neo4j.driver
- 6.2-SNAPSHOT
+ 6.3-SNAPSHOT
testkit-backend
@@ -49,6 +49,11 @@
org.projectlombok
lombok