Package org.conscrypt
Class HpkeImpl
java.lang.Object
org.conscrypt.HpkeImpl
- All Implemented Interfaces:
HpkeSpi
- Direct Known Subclasses:
HpkeImpl.MlKem1024HkdfSha256Aes128Gcm,HpkeImpl.MlKem1024HkdfSha256Aes256Gcm,HpkeImpl.MlKem1024HkdfSha256ChaCha20Poly1305,HpkeImpl.MlKem768HkdfSha256Aes128Gcm,HpkeImpl.MlKem768HkdfSha256Aes256Gcm,HpkeImpl.MlKem768HkdfSha256ChaCha20Poly1305,HpkeImpl.X25519_AES_128,HpkeImpl.X25519_AES_256,HpkeImpl.X25519_CHACHA20,HpkeImpl.XwingHkdfSha256Aes128Gcm,HpkeImpl.XwingHkdfSha256Aes256Gcm,HpkeImpl.XwingHkdfSha256ChaCha20Poly1305
Implementation of
HpkeSpi. Should not be used directly, but rather by one
of the subclasses of HpkeContext.-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic classImplementation of MLKEM_1024/HKDF_SHA256/AES_128_GCM.static classImplementation of MLKEM_1024/HKDF_SHA256/AES_256_GCM.static classImplementation of MLKEM_1024/HKDF_SHA256/CHACHA20_POLY1305.static classImplementation of MLKEM_768/HKDF_SHA256/AES_128_GCM.static classImplementation of MLKEM_768/HKDF_SHA256/AES_256_GCM.static classImplementation of MLKEM_768/HKDF_SHA256/CHACHA20_POLY1305.static classImplementation of X25519/HKDF_SHA256/AES_128_GCM.static classImplementation of X25519/HKDF_SHA256/AES_256_GCM.static classImplementation of X25519/HKDF_SHA256/CHACHA20_POLY1305.static classImplementation of XWING/HKDF_SHA256/AES_128_GCM.static classImplementation of XWING/HKDF_SHA256/AES_256_GCM.static classImplementation of XWING/HKDF_SHA256/CHACHA20_POLY1305. -
Field Summary
Fields inherited from interface org.conscrypt.HpkeSpi
DEFAULT_PSK, DEFAULT_PSK_ID -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbyte[]engineExport(int length, byte[] exporterContext) Exports secret key material from this SPI as described in RFC 9180.voidengineInitRecipient(byte[] encapsulated, PrivateKey recipientKey, byte[] info, PublicKey senderKey, byte[] psk, byte[] psk_id) Initialises an HPKE recipient SPI.voidengineInitSender(PublicKey recipientKey, byte[] info, PrivateKey senderKey, byte[] psk, byte[] psk_id) Initialises an HPKE sender SPI.voidengineInitSenderForTesting(PublicKey recipientKey, byte[] info, PrivateKey senderKey, byte[] psk, byte[] psk_id, byte[] sKe) Initialises an HPKE sender SPI.byte[]engineOpen(byte[] ciphertext, byte[] aad) Opens a message, using the internal key schedule maintained by an HPKE recipient.byte[]engineSeal(byte[] plaintext, byte[] aad) Seals a message, using the internal key schedule maintained by an HPKE sender.byte[]Returns the encapsulated key material for an HPKE sender.
-
Constructor Details
-
HpkeImpl
-
-
Method Details
-
engineInitSender
public void engineInitSender(PublicKey recipientKey, byte[] info, PrivateKey senderKey, byte[] psk, byte[] psk_id) throws InvalidKeyException Description copied from interface:HpkeSpiInitialises an HPKE sender SPI.- Specified by:
engineInitSenderin interfaceHpkeSpi- Parameters:
recipientKey- public key of the recipientinfo- application-supplied information, may be null or emptysenderKey- private key of the sender, for symmetric auth modes only, else nullpsk- pre-shared key, for PSK auth modes only, else nullpsk_id- pre-shared key ID, for PSK auth modes only, else null- Throws:
InvalidKeyException- if recipientKey is null or an unsupported key format
-
engineInitSenderForTesting
public void engineInitSenderForTesting(PublicKey recipientKey, byte[] info, PrivateKey senderKey, byte[] psk, byte[] psk_id, byte[] sKe) throws InvalidKeyException Description copied from interface:HpkeSpiInitialises an HPKE sender SPI.- Specified by:
engineInitSenderForTestingin interfaceHpkeSpi- Parameters:
recipientKey- public key of the recipientinfo- application-supplied information, may be null or emptysenderKey- private key of the sender, for symmetric auth modes only, else nullpsk- pre-shared key, for PSK auth modes only, else nullpsk_id- pre-shared key ID, for PSK auth modes only, else nullsKe- optional random seed, should be null for all uses except for validation against known test vectors- Throws:
InvalidKeyException- if recipientKey is null or an unsupported key format or senderKey is an unsupported key format
-
engineInitRecipient
public void engineInitRecipient(byte[] encapsulated, PrivateKey recipientKey, byte[] info, PublicKey senderKey, byte[] psk, byte[] psk_id) throws InvalidKeyException Description copied from interface:HpkeSpiInitialises an HPKE recipient SPI.- Specified by:
engineInitRecipientin interfaceHpkeSpi- Parameters:
encapsulated- encapsulated ephemeral key from a senderrecipientKey- private key of the recipientinfo- application-supplied information, may be null or emptysenderKey- public key of sender, for asymmetric auth modes only, else nullpsk- pre-shared key, for PSK auth modes only, else nullpsk_id- pre-shared key ID, for PSK auth modes only, else null- Throws:
InvalidKeyException- if recipientKey is null or an unsupported key format or senderKey is an unsupported key format
-
engineSeal
public byte[] engineSeal(byte[] plaintext, byte[] aad) Description copied from interface:HpkeSpiSeals a message, using the internal key schedule maintained by an HPKE sender.- Specified by:
engineSealin interfaceHpkeSpi- Parameters:
plaintext- the plaintextaad- optional associated data, may be null or empty- Returns:
- the ciphertext
-
engineExport
public byte[] engineExport(int length, byte[] exporterContext) Description copied from interface:HpkeSpiExports secret key material from this SPI as described in RFC 9180.- Specified by:
engineExportin interfaceHpkeSpi- Parameters:
length- expected output lengthexporterContext- optional context string, may be null or empty- Returns:
- exported value
-
engineOpen
Description copied from interface:HpkeSpiOpens a message, using the internal key schedule maintained by an HPKE recipient.- Specified by:
engineOpenin interfaceHpkeSpi- Parameters:
ciphertext- the ciphertextaad- optional associated data, may be null or empty- Returns:
- the plaintext
- Throws:
GeneralSecurityException- on decryption failures
-
getEncapsulated
public byte[] getEncapsulated()Description copied from interface:HpkeSpiReturns the encapsulated key material for an HPKE sender.- Specified by:
getEncapsulatedin interfaceHpkeSpi- Returns:
- the key material
-