org.bouncycastle.jcajce.provider.asymmetric.rsa
Class RSAKEMCipherSpi
java.lang.Object
javax.crypto.CipherSpi
org.bouncycastle.jcajce.provider.asymmetric.rsa.RSAKEMCipherSpi
- public class RSAKEMCipherSpi
- extends javax.crypto.CipherSpi
Cipher SPI implementing the ISO 18033-2 / RFC 9690 RSA-KEM key-transport scheme,
registered under the JCE service name and aliased
against the object identifier (1.0.18033.2.2.4).
Driven by the CMS pipeline through
org.bouncycastle.cms.jcajce.JceKEMRecipientInfoGenerator (wrap) and
org.bouncycastle.cms.jcajce.JceKEMEnvelopedRecipient (unwrap) when the
recipient holds an RSA key; the analogous peer for ML-KEM is
MLKEMCipherSpi.
Cipher operates in / only and requires a
KTSParameterSpec carrying the KDF (KDF2 / KDF3 / HKDF per RFC 9690
§4) and the AES-Wrap variant. Wrap output is the RSA-KEM ciphertext
(modulus-byte length) concatenated with the AES-wrapped CEK; the CMS caller
splits them based on the modulus length.
|
Method Summary |
protected byte[] |
engineDoFinal(byte[] bytes,
int i,
int i1)
|
protected int |
engineDoFinal(byte[] bytes,
int i,
int i1,
byte[] bytes1,
int i2)
|
protected int |
engineGetBlockSize()
|
protected byte[] |
engineGetIV()
|
protected int |
engineGetKeySize(java.security.Key key)
|
protected int |
engineGetOutputSize(int inputLen)
|
protected java.security.AlgorithmParameters |
engineGetParameters()
|
protected void |
engineInit(int opmode,
java.security.Key key,
java.security.spec.AlgorithmParameterSpec paramSpec,
java.security.SecureRandom random)
|
protected void |
engineInit(int opmode,
java.security.Key key,
java.security.AlgorithmParameters algorithmParameters,
java.security.SecureRandom random)
|
protected void |
engineInit(int opmode,
java.security.Key key,
java.security.SecureRandom random)
|
protected void |
engineSetMode(java.lang.String mode)
|
protected void |
engineSetPadding(java.lang.String padding)
|
protected java.security.Key |
engineUnwrap(byte[] wrappedKey,
java.lang.String wrappedKeyAlgorithm,
int wrappedKeyType)
|
protected byte[] |
engineUpdate(byte[] bytes,
int i,
int i1)
|
protected int |
engineUpdate(byte[] bytes,
int i,
int i1,
byte[] bytes1,
int i2)
|
protected byte[] |
engineWrap(java.security.Key key)
|
| Methods inherited from class java.lang.Object |
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait |
RSAKEMCipherSpi
public RSAKEMCipherSpi()
engineSetMode
protected void engineSetMode(java.lang.String mode)
throws java.security.NoSuchAlgorithmException
- Throws:
java.security.NoSuchAlgorithmException
engineSetPadding
protected void engineSetPadding(java.lang.String padding)
throws javax.crypto.NoSuchPaddingException
- Throws:
javax.crypto.NoSuchPaddingException
engineGetKeySize
protected int engineGetKeySize(java.security.Key key)
engineGetBlockSize
protected int engineGetBlockSize()
engineGetOutputSize
protected int engineGetOutputSize(int inputLen)
engineGetIV
protected byte[] engineGetIV()
engineGetParameters
protected java.security.AlgorithmParameters engineGetParameters()
engineInit
protected void engineInit(int opmode,
java.security.Key key,
java.security.SecureRandom random)
throws java.security.InvalidKeyException
- Throws:
java.security.InvalidKeyException
engineInit
protected void engineInit(int opmode,
java.security.Key key,
java.security.spec.AlgorithmParameterSpec paramSpec,
java.security.SecureRandom random)
throws java.security.InvalidKeyException,
java.security.InvalidAlgorithmParameterException
- Throws:
java.security.InvalidKeyException
java.security.InvalidAlgorithmParameterException
engineInit
protected void engineInit(int opmode,
java.security.Key key,
java.security.AlgorithmParameters algorithmParameters,
java.security.SecureRandom random)
throws java.security.InvalidKeyException,
java.security.InvalidAlgorithmParameterException
- Throws:
java.security.InvalidKeyException
java.security.InvalidAlgorithmParameterException
engineUpdate
protected byte[] engineUpdate(byte[] bytes,
int i,
int i1)
engineUpdate
protected int engineUpdate(byte[] bytes,
int i,
int i1,
byte[] bytes1,
int i2)
throws javax.crypto.ShortBufferException
- Throws:
javax.crypto.ShortBufferException
engineDoFinal
protected byte[] engineDoFinal(byte[] bytes,
int i,
int i1)
throws javax.crypto.IllegalBlockSizeException,
javax.crypto.BadPaddingException
- Throws:
javax.crypto.IllegalBlockSizeException
javax.crypto.BadPaddingException
engineDoFinal
protected int engineDoFinal(byte[] bytes,
int i,
int i1,
byte[] bytes1,
int i2)
throws javax.crypto.ShortBufferException,
javax.crypto.IllegalBlockSizeException,
javax.crypto.BadPaddingException
- Throws:
javax.crypto.ShortBufferException
javax.crypto.IllegalBlockSizeException
javax.crypto.BadPaddingException
engineWrap
protected byte[] engineWrap(java.security.Key key)
throws javax.crypto.IllegalBlockSizeException,
java.security.InvalidKeyException
- Throws:
javax.crypto.IllegalBlockSizeException
java.security.InvalidKeyException
engineUnwrap
protected java.security.Key engineUnwrap(byte[] wrappedKey,
java.lang.String wrappedKeyAlgorithm,
int wrappedKeyType)
throws java.security.InvalidKeyException,
java.security.NoSuchAlgorithmException
- Throws:
java.security.InvalidKeyException
java.security.NoSuchAlgorithmException