# Help - Need suggestions for storing (encryption) key in O3

**URL:** <https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570>\
**Category:** Development\
**Tags:** developers-forum, o3\
**Created:** [September 22, 2022, 8:00am UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570 "2022-09-22T08:00:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hamzakaizar](https://talk.openmrs.org/letter_avatar/hamzakaizar/32/5_5575768a8748004e209b776fc1b2916d.png) [@hamzakaizar](https://talk.openmrs.org/u/hamzakaizar)\
**Post date:** [September 22, 2022, 8:00am UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570/1 "2022-09-22T08:00:14Z")

</div>

There is an encryption / decryption task that needs to be run while creating or retrieving data in the application. The task is executed by the main thread and the service worker thread. **The task would need access to an encryption key**. The encryption key would be a long lived key that would need to exist till the user explicitly logs out.

The encryption key **needs to be stored in a place that is accessible by both threads**. The key should not be stored in IndexedDB. Session storage is not an option since it is newly created for every tab that the user opens. Local storage seems like a feasible option at the moment. The key **should not be stored in a place where it’s easily accessible by a threat.**

What are our options for storing this key?

---

<div class="post-metadata">

**Author:** ![burke](https://talk.openmrs.org/user_avatar/talk.openmrs.org/burke/32/17_2.png) [@burke](https://talk.openmrs.org/u/burke)\
**Post date:** [September 22, 2022, 6:27pm UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570/2 "2022-09-22T18:27:54Z")

</div>

> [@hamzakaizar](#):
>
> What are our options for storing this key?

Would a user property work?

If you need to be able to access the key in offline mode, I suspect your only “secure” option would be to use a reversible hash locked by the user’s password.

---

<div class="post-metadata">

**Author:** ![dkayiwa](https://talk.openmrs.org/user_avatar/talk.openmrs.org/dkayiwa/32/179_2.png) [@dkayiwa](https://talk.openmrs.org/u/dkayiwa)\
**Post date:** [September 22, 2022, 8:21pm UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570/3 "2022-09-22T20:21:25Z")

</div>

> [@burke](#):
>
> Would a user property work?

Isn’t he looking for client side storage?

---

<div class="post-metadata">

**Author:** ![hamzakaizar](https://talk.openmrs.org/letter_avatar/hamzakaizar/32/5_5575768a8748004e209b776fc1b2916d.png) [@hamzakaizar](https://talk.openmrs.org/u/hamzakaizar)\
**Post date:** [September 23, 2022, 5:44am UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570/4 "2022-09-23T05:44:47Z")

</div>

Yes. We are looking at client side storage.

For now, this key would be a reversible hash that is locked by the user password as suggested by @burke. That’s the idea. However, what we wanted to know is where we can store this hashed string.

---

<div class="post-metadata">

**Author:** ![miirochristopher](https://talk.openmrs.org/user_avatar/talk.openmrs.org/miirochristopher/32/22546_2.png) [@miirochristopher](https://talk.openmrs.org/u/miirochristopher)\
**Post date:** [September 26, 2022, 3:39pm UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570/5 "2022-09-26T15:39:53Z")

</div>

Hi, @hamzakaizar you might want to consider [HashiCorp Vault](https://www.vaultproject.io/docs/what-is-vault) for your key storage needs. See [Official Website](https://www.vaultproject.io/docs/what-is-vault) and Spring integration [guides](https://spring.io/guides/gs/vault-config/).

---

<div class="post-metadata">

**Author:** ![bistenes](https://talk.openmrs.org/user_avatar/talk.openmrs.org/bistenes/32/18573_2.png) [@bistenes](https://talk.openmrs.org/u/bistenes)\
**Post date:** [September 26, 2022, 4:29pm UTC](https://talk.openmrs.org/t/help-need-suggestions-for-storing-encryption-key-in-o3/37570/6 "2022-09-26T16:29:20Z")

</div>

It sounds like you know what your options are—IndexDB, session storage, local storage, or a cookie. Local storage is specific to the origin—local storage for one origin cannot be accessed from another. Cookies follow the same rules but also have mechanisms for explicitly allowing or disallowing domains or paths to access the cookie.

There’s nothing specific to O3 that will help you here.

> The key **should not be stored in a place where it’s easily accessible by a threat.**

You may want to develop a clearer idea of your threat model. It’s hard to develop a good security strategy if you’re not sure what you’re defending against.
