Class SM2Signer

java.lang.Object
org.bouncycastle.crypto.signers.SM2Signer
All Implemented Interfaces:
Signer, ECConstants

public class SM2Signer extends Object implements Signer, ECConstants
The SM2 Digital Signature algorithm.
  • Constructor Details

    • SM2Signer

      public SM2Signer()
    • SM2Signer

      public SM2Signer(Digest digest)
    • SM2Signer

      public SM2Signer(DSAEncoding encoding)
    • SM2Signer

      public SM2Signer(DSAEncoding encoding, Digest digest)
  • Method Details

    • init

      public void init(boolean forSigning, CipherParameters param)
      Description copied from interface: Signer
      Initialise the signer for signing or verification.
      Specified by:
      init in interface Signer
      Parameters:
      forSigning - true if for signing, false otherwise
      param - necessary parameters.
    • update

      public void update(byte b)
      Description copied from interface: Signer
      update the internal digest with the byte b
      Specified by:
      update in interface Signer
    • update

      public void update(byte[] in, int off, int len)
      Description copied from interface: Signer
      update the internal digest with the byte array in
      Specified by:
      update in interface Signer
    • verifySignature

      public boolean verifySignature(byte[] signature)
      Description copied from interface: Signer
      return true if the internal state represents the signature described in the passed in array.
      Specified by:
      verifySignature in interface Signer
    • reset

      public void reset()
      Description copied from interface: Signer
      reset the internal state
      Specified by:
      reset in interface Signer
    • generateSignature

      public byte[] generateSignature() throws CryptoException
      Description copied from interface: Signer
      generate a signature for the message we've been loaded with using the key we were initialised with.
      Specified by:
      generateSignature in interface Signer
      Throws:
      CryptoException
    • getZ

      protected byte[] getZ(byte[] userID)
      Compute the SM2 Z value - H(ENTL || ID || a || b || xG || yG || xA || yA) as given in 5.1.4.4 of the draft RFC "SM2 Public Key Algorithms". This is called once from init with the digest freshly reset, and the value returned is prepended to the message before e is calculated.

      An override must leave the digest empty on return - this implementation feeds the digest and then consumes it with a doFinal(). Returning a zero-length array leaves the message unprefixed, so a signer constructed with a NullDigest will then sign and verify a caller-supplied pre-hashed e as passed in, for the case where Z and the message hash are calculated elsewhere.

      Parameters:
      userID - the SM2 user ID passed in at init, or the default one if none was given.
      Returns:
      the Z value the message is to be prefixed with.
    • createBasePointMultiplier

      protected ECMultiplier createBasePointMultiplier()
    • calculateE

      protected BigInteger calculateE(BigInteger n, byte[] message)