skip to content

Cryptography (JCA/JCE)

The JCA/JCE design: provider-backed getInstance factories and engine classes for hashing, encryption, key generation, signatures and secure randomness, wired together by transformation strings. Interviewers care that you can pick the right engine and parameters, not that you can implement a cipher.

part ofJavaoverview, primer and where to startread it →
on this pageshow

explore

questions

page 2 of 2

PBKDF2 ships with the JDK, so why pull in a library for bcrypt, scrypt, or Argon2, and how do you use them on the JVM?

level: seniorimportance: should knowfreq 55%

basics

~20 s

PBKDF2 only stresses CPU, so it's cheap to crack on GPUs/ASICs. bcrypt, scrypt, and Argon2 are also memory-hard, raising attacker cost much more. The JDK has no built-in for them, so you add a library like Spring Security's PasswordEncoder, jBCrypt, or Bouncy Castle.

open as a page

What are the common correctness and security pitfalls when implementing PBKDF2 with SecretKeyFactory in Java?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Watch for: keyLength in bits not bytes, passing the password as char[] and wiping it, a fresh random salt per user, a high iteration count, handling NoSuchAlgorithmException/InvalidKeySpecException, and comparing hashes in constant time. Also store the parameters so you can upgrade later.

open as a page

What is the difference between new SecureRandom() (the default instance) and SecureRandom.getInstanceStrong(), and when would you use each?

level: seniorimportance: should knowfreq 55%

basics

~10 s

new SecureRandom() gives a strong, non-blocking generator good for almost everything. getInstanceStrong() returns a platform-configured 'strong' algorithm that may block waiting for entropy; reserve it for rare, very high-value secrets like long-lived keys.

open as a page

How do KeyPair, KeyPairGenerator, and the Signature API fit together, and how do you persist/transport the keys?

level: seniorimportance: should knowfreq 38%

basics

~20 s

A KeyPairGenerator makes a KeyPair (a PrivateKey + PublicKey). The private key goes into Signature.initSign to sign; the public key goes into Signature.initVerify to check. To store/send keys you encode them (X.509 for public, PKCS#8 for private) and rebuild them with a KeyFactory.

open as a page

What are the common security and correctness pitfalls when using the Java Signature API, and how do you avoid them?

level: seniorimportance: should knowfreq 30%

basics

~20 s

Watch for: ignoring or misreading the verify() boolean (always check it), feeding different bytes/encoding on each side, using weak algorithms (SHA-1/MD5, 1024-bit RSA), leaking the private key, and reusing a Signature object across threads. Verify with the trusted public key, not one supplied by the attacker.

open as a page

How does Java surface padding errors during decryption, and why is exposing BadPaddingException dangerous (padding-oracle)?

level: seniorimportance: should knowfreq 45%

basics

~20 s

When decryption with CBC/PKCS5Padding finds invalid padding, cipher.doFinal throws BadPaddingException (GCM throws the AEADBadTagException subclass). If your app tells an attacker whether padding was valid, they can decrypt data byte by byte — a padding-oracle attack. Reject all decrypt failures identically.

open as a page

When designing a system, when is RSA encryption the right asymmetric primitive in Java, and what alternatives or pitfalls should drive that decision?

level: principalimportance: should knowfreq 30%

basics

~20 s

Use RSA when you must encrypt a small secret (like a symmetric key) to someone's public key. For most data, use hybrid encryption, and for modern systems consider elliptic-curve options (ECDH/ECIES) which are smaller and faster.

open as a page

In production, how would you organize keystores vs truststores and protect private key material — and what are the trade-offs of file-based KeyStores versus an HSM/KMS?

level: principalimportance: should knowfreq 35%

basics

~20 s

Keep your own private keys in a keystore and the certificates you trust in a separate truststore. File-based stores are simple but the key bytes live in process memory; an HSM or cloud KMS keeps keys in hardware so they never leave, at the cost of latency and complexity.

open as a page

How do transformation strings interact with security providers, and how do you ensure portable, deterministic Cipher behavior across JDKs and FIPS?

level: principalimportance: should knowfreq 30%

basics

~20 s

Cipher.getInstance asks the JCA provider list for an implementation of your transformation. Different providers (SunJCE, BouncyCastle, FIPS) may support different transformations or defaults, so always use full transformation strings, don't hardcode a provider unless required, and test on the JDK/provider you deploy on.

open as a page

What are SecureRandom 'algorithms' like NativePRNG, SHA1PRNG, and DRBG, and how does platform/provider selection affect portability and reproducibility?

level: principalimportance: nice to knowfreq 35%

basics

~20 s

SecureRandom is provided by named algorithms (NativePRNG reads the OS source, SHA1PRNG is a self-contained generator, DRBG is the modern NIST design). Which you get depends on the platform/provider, so behavior can differ across OSes unless you request one explicitly.

open as a page

showing 31–40 of 40