You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

可存储对称密钥及键属性的密钥库实现方案咨询

Supported Keystore Implementations for Secret Keys + Metadata

Great question! I’ve run into this exact issue before—JKS and JCEKS are frustratingly limited when it comes to attaching metadata to secret keys, even though the KeyStore.SecretKeyEntry API technically supports Set<Attribute> (those attributes just get silently ignored by the default providers). Here are the most reliable solutions:

1. BouncyCastle Keystore Implementations (BCFKS/UBER)

The BouncyCastle security provider offers keystore formats that fully support storing and retrieving metadata alongside secret keys via the KeyStore.Entry attribute system. This is the most straightforward, production-ready option.

Example Usage:

First, register the BouncyCastle provider, then use the BCFKS format (a secure, modern keystore format from BouncyCastle):

import org.bouncycastle.jce.provider.BouncyCastleProvider;
import java.security.*;
import java.util.HashSet;
import java.util.Set;
import java.io.*;
import org.bouncycastle.asn1.*;

// Register BouncyCastle provider
Security.addProvider(new BouncyCastleProvider());

// Initialize BCFKS keystore
KeyStore ks = KeyStore.getInstance("BCFKS", "BC");
ks.load(null, "myStorePassword".toCharArray());

// Create custom metadata attributes (use your own OIDs or reuse standard ones)
Set<Attribute> metadata = new HashSet<>();
metadata.add(new Attribute(
    new ASN1ObjectIdentifier("com.yourcompany.metadata.md1"),
    new DERUTF8String("value11")
));
metadata.add(new Attribute(
    new ASN1ObjectIdentifier("com.yourcompany.metadata.md2"),
    new DERUTF8String("value12")
));

// Generate a secret key and wrap it with metadata
SecretKey aesKey = KeyGenerator.getInstance("AES").generateKey();
KeyStore.SecretKeyEntry entry = new KeyStore.SecretKeyEntry(aesKey, metadata);

// Store the entry in the keystore
ks.setEntry(
    "alias1",
    entry,
    new KeyStore.PasswordProtection("entryPassword".toCharArray())
);

// Save the keystore to disk
try (OutputStream os = new FileOutputStream("secure-keystore.bcfks")) {
    ks.store(os, "myStorePassword".toCharArray());
}

// Retrieve and verify the metadata
ks.load(new FileInputStream("secure-keystore.bcfks"), "myStorePassword".toCharArray());
KeyStore.SecretKeyEntry retrievedEntry = (KeyStore.SecretKeyEntry) ks.getEntry(
    "alias1",
    new KeyStore.PasswordProtection("entryPassword".toCharArray())
);

// Parse and use the metadata (your app can handle the key-value parsing)
Set<Attribute> retrievedMetadata = retrievedEntry.getAttributes();
for (Attribute attr : retrievedMetadata) {
    String oid = attr.getAttrType().getId();
    String value = ((DERUTF8String) attr.getAttrValues().getObjectAt(0)).getString();
    System.out.printf("%s: %s%n", oid, value);
}

You can map your custom key-value metadata to OIDs (or use a single attribute with a serialized JSON string if you prefer) — the parsing logic is entirely up to your application, as requested.

2. Custom Keystore Wrapper (For JKS/JCEKS Compatibility)

If you need to stick with JKS/JCEKS for compatibility reasons, you can build a lightweight wrapper to associate metadata with keys:

  • Store the secret key under its primary alias (e.g., alias1)
  • Serialize your metadata (e.g., to JSON or a custom format) and store it as a separate SecretKeyEntry under a derived alias (e.g., alias1.metadata)
  • When retrieving the key, fetch both the key entry and its corresponding metadata entry, then parse the metadata in your app

This approach requires manual management of the metadata entries but avoids switching keystore formats.

3. PKCS#12 with BouncyCastle

While the default JDK PKCS#12 implementation ignores attributes, BouncyCastle's PKCS#12 implementation supports storing KeyStore.Entry attributes. This is a good option if you need a widely supported format (PKCS#12 is standard across platforms) with metadata support.


内容的提问来源于stack exchange,提问作者rbnbrtls

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:43:31