Class FaestKeyPairGenerator
- java.lang.Object
-
- org.bouncycastle.pqc.crypto.faest.FaestKeyPairGenerator
-
- All Implemented Interfaces:
AsymmetricCipherKeyPairGenerator
public class FaestKeyPairGenerator extends java.lang.Object implements AsymmetricCipherKeyPairGenerator
Implementation of the FAEST asymmetric key pair generator following the FAEST signature scheme specifications.This generator produces
FaestPublicKeyParametersandFaestPrivateKeyParametersbased on the FAEST algorithm parameters. The secret signing key is an AES key, while the public verification key is a plaintext–ciphertext pair obtained by encrypting a random message under the signing key. The implementation follows the specification defined in the official FAEST documentation and the reference C implementation.References:
-
-
Constructor Summary
Constructors Constructor Description FaestKeyPairGenerator()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description AsymmetricCipherKeyPairgenerateKeyPair()Generate a fresh FAEST key pair.voidinit(KeyGenerationParameters param)intialise the key pair generator.
-
-
-
Method Detail
-
init
public void init(KeyGenerationParameters param)
Description copied from interface:AsymmetricCipherKeyPairGeneratorintialise the key pair generator.- Specified by:
initin interfaceAsymmetricCipherKeyPairGenerator- Parameters:
param- the parameters the key pair is to be initialised with.
-
generateKeyPair
public AsymmetricCipherKeyPair generateKeyPair()
Generate a fresh FAEST key pair.Side-channel note: the OWF-key validity check (low two bits not both set, matching upstream
faest_param.c:39-42) is enforced by a rejection-sampling loop. The loop's iteration count therefore depends on bytes drawn from the suppliedSecureRandomand is observable via timing. The information leaked is about the discarded DRBG draws, not the accepted OWF key, so the loop does not expose secret key bits. Callers that need to suppress even that signal can pass a deterministic / pre-conditioned random source.- Specified by:
generateKeyPairin interfaceAsymmetricCipherKeyPairGenerator- Returns:
- an AsymmetricCipherKeyPair containing the generated keys.
-
-