Download the PHP package meritech/encryption-bundle without Composer
On this page you can find all versions of the php package meritech/encryption-bundle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Table of contents
Download meritech/encryption-bundle
More information about meritech/encryption-bundle
Files in meritech/encryption-bundle
Download meritech/encryption-bundle
More information about meritech/encryption-bundle
Files in meritech/encryption-bundle
Vendor meritech
Package encryption-bundle
Short Description Symfony bundle for transparent Doctrine column encryption with DBAL types and blind index support for searchable encrypted data.
License MIT
Homepage https://github.com/meritech/encryption-bundle
Package encryption-bundle
Short Description Symfony bundle for transparent Doctrine column encryption with DBAL types and blind index support for searchable encrypted data.
License MIT
Homepage https://github.com/meritech/encryption-bundle
Please rate this library. Is it a good library?
Informations about the package encryption-bundle
Encryption Bundle
Symfony bundle for transparent Doctrine column encryption using custom DBAL types. Supports AES-256-GCM encryption with blind indexes for searchable encrypted data.
Features
- DBAL Types:
encrypted_string,encrypted_text,encrypted_json,encrypted_string_deterministic - Blind Indexes: HMAC-based searchable encryption with configurable bit length
- Key Rotation: Multi-key support for seamless key rotation
- Modern PHP: Requires PHP 8.2+, uses readonly classes and modern syntax
Requirements
- PHP 8.2+
- Symfony 6.4+ or 7.x
- Doctrine ORM 2.15+ or 3.x
- OpenSSL extension
Installation
Generate an encryption key (32 bytes, base64-encoded):
Set the key in your environment:
Configuration
Register the bundle (if not using Symfony Flex):
Usage
Basic Encrypted Columns
Use DBAL types in your entity mappings:
Searchable Encryption with Blind Index
For columns that need WHERE clause searches, use blind indexes:
Querying with Blind Index
DBAL Types
| Type | Description |
|---|---|
encrypted_string |
Randomized AES-256-GCM encryption for strings |
encrypted_text |
Alias for encrypted_string (semantic) |
encrypted_json |
Encrypts arrays/objects as JSON |
encrypted_string_deterministic |
Same plaintext = same ciphertext (allows equality comparison) |
blind_index |
Simple VARCHAR for storing pre-computed blind indexes |
Blind Index Configuration
The #[BlindIndex] attribute supports:
| Option | Default | Description |
|---|---|---|
indexProperty |
(required) | Property name for storing the blind index |
context |
ClassName.propertyName |
HMAC domain separation context |
bits |
64 | Output bits (16-256). Lower = more collisions = more privacy |
caseInsensitive |
true | Lowercase before hashing |
Security Notes
- Randomized encryption (default): Same plaintext produces different ciphertext each time. Most secure but cannot be searched.
- Deterministic encryption: Same plaintext = same ciphertext. Leaks equality relationships. Use only when exact-match search is needed.
- Blind indexes: Truncated HMAC allows WHERE clause searches while preserving some privacy. Shorter bit length = more false positives = more privacy.
- Key separation: Use a separate
blind_index_keyso that compromising the blind index key doesn't reveal encrypted data.
Key Rotation
- Generate a new key and assign it a new ID
- Add the current key to
rotated_keys - Update
key.valueandkey.idwith the new key - Deploy - new data encrypted with new key, old data decrypted with rotated keys
- Run migration to re-encrypt old data (implement in your application)
License
MIT
All versions of encryption-bundle with dependencies
PHP Build Version
Package Version
Requires
php Version
^8.2
ext-openssl Version *
doctrine/dbal Version ^3.6 || ^4.0
doctrine/doctrine-bundle Version ^2.7
doctrine/orm Version ^2.15 || ^3.0
symfony/framework-bundle Version ^6.4 || ^7.0
ext-openssl Version *
doctrine/dbal Version ^3.6 || ^4.0
doctrine/doctrine-bundle Version ^2.7
doctrine/orm Version ^2.15 || ^3.0
symfony/framework-bundle Version ^6.4 || ^7.0
The package meritech/encryption-bundle contains the following files
Loading the files please wait ...