Skip to main content

Command Palette

Search for a command to run...

Java Serialization

Updated
•4 min read•View as Markdown
Java Serialization

1. What is Java Serialization

Java Serialization is a mechanism that converts an object into a byte stream so that it can be:

  • saved to a file

  • transmitted over a network

  • cached or persisted

  • transferred between JVMs

The reverse process is called Deserialization, which reconstructs the object from the byte stream.

In simple terms:

Object  →  Byte Stream  →  File / Network / Storage

And later:

Byte Stream  →  Object

Serialization is commonly used in:

  • distributed systems

  • caching frameworks

  • message passing

  • file persistence


2. Serializable Interface

In Java, a class must implement the Serializable interface to allow its objects to be serialized.

Serializable is a marker interface, which means it does not contain any methods.

It simply signals to the JVM that the class is allowed to be serialized.

2.1. Example

import java.io.Serializable;

class User implements Serializable {

    String username;

    String email;
}

Now objects of User can be serialized.

Example object

User user = new User();
user.username = "ej";
user.email = "ej@example.com";

3. Serializing an Object

To serialize an object, Java provides ObjectOutputStream.

3.1. Example

import java.io.FileOutputStream;
import java.io.ObjectOutputStream;
import java.io.Serializable;

class User implements Serializable {

    String username;
    String email;

    User(String username, String email) {
        this.username = username;
        this.email = email;
    }
}

public class SerializeExample {

    public static void main(String[] args) throws Exception {

        User user = new User("ej", "ej@example.com");

        ObjectOutputStream out =
            new ObjectOutputStream(new FileOutputStream("user.ser"));

        out.writeObject(user);
        out.close();

        System.out.println("Object serialized");
    }
}

A file named user.ser will be created containing the serialized object.


4. Deserializing an Object

Deserialization reconstructs the object using ObjectInputStream.

4.1. Example

import java.io.FileInputStream;
import java.io.ObjectInputStream;

public class DeserializeExample {

    public static void main(String[] args) throws Exception {

        ObjectInputStream in =
            new ObjectInputStream(new FileInputStream("user.ser"));

        User user = (User) in.readObject();
        in.close();

        System.out.println(user.username); // Output: ej
        System.out.println(user.email);    // Output: ej@example.com
    }
}

The object has been successfully reconstructed from the byte stream.


5. The transient Keyword

Sometimes certain fields should not be serialized, such as:

  • passwords

  • security tokens

  • temporary cache values

Java provides the transient keyword to exclude fields from serialization.

5.1. Example

import java.io.Serializable;

class User implements Serializable {

    String username;

    transient String password;
}

During serialization:

username → stored
password → ignored

After deserialization:

username = "ej"
password = null

This helps prevent sensitive information from being persisted.


6. serialVersionUID

When a class is serialized, the JVM associates it with a version identifier called serialVersionUID.

If serialVersionUID is not explicitly declared, the JVM automatically generates one based on the class structure. This can lead to compatibility issues when the class definition changes.

To avoid this issue, it is recommended to explicitly define serialVersionUID.

If serialVersionUID is not explicitly declared, the JVM automatically generates one based on the class structure. This can lead to compatibility issues when the class definition changes.

6.1. Example

import java.io.Serializable;

class User implements Serializable {

    private static final long serialVersionUID = 1L;

    String username;

    transient String password;
}

Benefits of defining serialVersionUID:

  • ensures version compatibility

  • prevents InvalidClassException

  • gives developers control over serialization versions


7. When Serialization Is Used

Serialization is frequently used in:

Use Case Example
Network communication RMI, distributed systems
Caching Redis, distributed caches
Persistence saving objects to disk
Messaging systems sending objects across services

However, modern systems often prefer JSON or Protocol Buffers instead of Java native serialization.


✨ Conclusion

Java Serialization allows objects to be converted into byte streams so they can be stored, transmitted, or reconstructed later.

To enable serialization:

  1. a class must implement Serializable

  2. objects can be written using ObjectOutputStream

  3. objects can be reconstructed using ObjectInputStream

  4. sensitive fields can be excluded using transient

  5. version compatibility can be managed using serialVersionUID

Although Java serialization is powerful, modern applications often prefer alternative formats such as JSON for better interoperability.


🔗 References