Class MLDSASigner

java.lang.Object
org.bouncycastle.crypto.signers.MLDSASigner
All Implemented Interfaces:
Signer

public class MLDSASigner extends Object implements Signer
ML-DSA (FIPS 204) signer/verifier.

verifySignature(byte[]) (and verifyMuSignature(byte[], byte[])) return false uniformly for a cryptographically wrong signature and for one that is structurally malformed per FIPS 204 Algorithm 8 (wrong length, an out-of-order or duplicate hint index, or a hint weight exceeding the parameter set's omega) - the two cases are not distinguished, and neither ever throws for a decode failure. This differs from some other implementations (e.g. the JDK's own SUN ML-DSA provider), which signal a decode failure separately from a cryptographic mismatch; see github #2367.

  • Constructor Details

    • MLDSASigner

      public MLDSASigner()
  • Method Details

    • init

      public void init(boolean forSigning, CipherParameters param)
      Description copied from interface: Signer
      Initialise the signer for signing or verification.
      Specified by:
      init in interface Signer
      Parameters:
      forSigning - true if for signing, false otherwise
      param - necessary parameters.
    • update

      public void update(byte b)
      Description copied from interface: Signer
      update the internal digest with the byte b
      Specified by:
      update in interface Signer
    • update

      public void update(byte[] in, int off, int len)
      Description copied from interface: Signer
      update the internal digest with the byte array in
      Specified by:
      update in interface Signer
    • generateMu

      public byte[] generateMu() throws CryptoException, DataLengthException
      Throws:
      CryptoException
      DataLengthException
    • generateMuSignature

      public byte[] generateMuSignature(byte[] mu) throws CryptoException, DataLengthException
      Throws:
      CryptoException
      DataLengthException
    • generateSignature

      public byte[] generateSignature() throws CryptoException, DataLengthException
      Description copied from interface: Signer
      generate a signature for the message we've been loaded with using the key we were initialised with.
      Specified by:
      generateSignature in interface Signer
      Throws:
      CryptoException
      DataLengthException
    • verifyMu

      public boolean verifyMu(byte[] mu)
    • verifySignature

      public boolean verifySignature(byte[] signature)
      Description copied from interface: Signer
      return true if the internal state represents the signature described in the passed in array.
      Specified by:
      verifySignature in interface Signer
    • verifyMuSignature

      public boolean verifyMuSignature(byte[] mu, byte[] signature)
    • reset

      public void reset()
      Description copied from interface: Signer
      reset the internal state
      Specified by:
      reset in interface Signer
    • internalGenerateSignature

      protected byte[] internalGenerateSignature(byte[] message, byte[] random)
    • internalVerifySignature

      protected boolean internalVerifySignature(byte[] message, byte[] signature)