public abstract class AbstractCipherSpi extends CipherSpi
com.sun.crypto.provider.CipherCore.| Modifier | Constructor and Description |
|---|---|
protected |
AbstractCipherSpi(int blockSize) |
protected |
AbstractCipherSpi(int blockSize,
int unitBytes,
int cipherMode) |
| Modifier and Type | Method and Description |
|---|---|
static int |
addExact(int x,
int y)
Returns the sum of its arguments, throwing an exception if the result overflows an
int. |
protected abstract int |
decrypt(byte[] cipher,
int cipherOffset,
int cipherLen,
byte[] plain,
int plainOffset,
boolean doFinal)
Performs decryption operation.
|
protected abstract int |
encrypt(byte[] plain,
int plainOffset,
int plainLen,
byte[] cipher,
int cipherOffset,
boolean doFinal)
Performs encryption operation.
|
protected byte[] |
engineDoFinal(byte[] input,
int inputOffset,
int inputLen)
Encrypts or decrypts data in a single-part operation, or finishes a multiple-part operation.
|
protected int |
engineDoFinal(byte[] input,
int inputOffset,
int inputLen,
byte[] output,
int outputOffset)
Encrypts or decrypts data in a single-part operation, or finishes a multiple-part operation.
|
protected int |
engineGetBlockSize()
Returns the block size (in bytes).
|
protected int |
engineGetOutputSize(int inputLen)
Returns the length in bytes that an output buffer would need to be in order to hold the result of the next
update or doFinal operation, given the input length inputLen (in bytes). |
protected abstract void |
engineInit(boolean decrypting,
String algorithm,
SecretKey key,
byte[] iv,
int tagLen)
Initializes the cipher in the specified mode with the given key and iv.
|
protected void |
engineInit(int opmode,
Key key,
AlgorithmParameterSpec params,
SecureRandom random)
Initializes this cipher with a key, a set of algorithm parameters, and a source of randomness.
|
protected void |
engineInit(int opmode,
Key key,
SecureRandom random)
Initializes this cipher with a key and a source of randomness.
|
protected abstract void |
engineSetIV(byte[] iv)
Sets the initial vector.
|
protected byte[] |
engineUpdate(byte[] input,
int inputOffset,
int inputLen)
Continues a multiple-part encryption or decryption operation (depending on how this cipher was initialized),
processing another data part.
|
protected int |
engineUpdate(byte[] input,
int inputOffset,
int inputLen,
byte[] output,
int outputOffset)
Continues a multiple-part encryption or decryption operation (depending on how this cipher was initialized),
processing another data part.
|
protected void |
engineUpdateAAD(byte[] src,
int offset,
int len)
Continues a multi-part update of the Additional Authentication Data (AAD), using a subset of the provided buffer.
|
protected abstract int |
getBufferedLength()
TODO
|
protected abstract void |
updateAAD(byte[] src,
int offset,
int len)
Continues a multi-part update of the Additional Authentication Data (AAD), using a subset of the provided buffer.
|
engineGetIV, engineUnwrap, engineWrapprotected AbstractCipherSpi(int blockSize)
protected AbstractCipherSpi(int blockSize,
int unitBytes,
int cipherMode)
public static int addExact(int x,
int y)
int.x - the first valuey - the second valueArithmeticException - if the result overflows an intprotected abstract int decrypt(byte[] cipher,
int cipherOffset,
int cipherLen,
byte[] plain,
int plainOffset,
boolean doFinal)
The input cipher, starting at cipherOffset and ending at
(cipherOffset+cipherLen-1), is decrypted. The result is stored in plain, starting at
plainOffset.
The subclass that implements Cipher should ensure that init has been called before this method is
called.
cipher - the input buffer with the data to be decryptedcipherOffset - the offset in ciphercipherLen - the length of the input dataplain - the buffer for the decryption resultplainOffset - the offset in plainplainprotected abstract int encrypt(byte[] plain,
int plainOffset,
int plainLen,
byte[] cipher,
int cipherOffset,
boolean doFinal)
The input plain, starting at plainOffset and ending at
(plainOffset+plainLen-1), is encrypted. The result is stored in cipher, starting at
cipherOffset.
The subclass that implements Cipher should ensure that init has been called before this method is
called.
plain - the input buffer with the data to be encryptedplainOffset - the offset in plainplainLen - the length of the input datacipher - the buffer for the encryption resultcipherOffset - the offset in ciphercipherprotected byte[] engineDoFinal(byte[] input,
int inputOffset,
int inputLen)
throws IllegalBlockSizeException,
BadPaddingException
CipherSpi
The first inputLen bytes in the input buffer, starting at inputOffset
inclusive, and any input bytes that may have been buffered during a previous update operation, are
processed, with padding (if requested) being applied. If an AEAD mode such as GCM/CCM is being used, the
authentication tag is appended in the case of encryption, or verified in the case of decryption. The result is
stored in a new buffer.
Upon finishing, this method resets this cipher object to the state it was in when previously initialized via a
call to engineInit. That is, the object is reset and available to encrypt or decrypt (depending on
the operation mode that was specified in the call to engineInit) more data.
Note: if any exception is thrown, this cipher object may need to be reset before it can be used again.
engineDoFinal in class CipherSpiinput - the input bufferinputOffset - the offset in input where the input startsinputLen - the input lengthIllegalBlockSizeException - if this cipher is a block cipher, no padding has been requested (only in encryption mode), and the
total input length of the data processed by this cipher is not a multiple of block size; or if
this encryption algorithm is unable to process the input data provided.BadPaddingException - if this cipher is in decryption mode, and (un)padding has been requested, but the decrypted data
is not bounded by the appropriate padding bytesAEADBadTagException - if this cipher is decrypting in an AEAD mode (such as GCM/CCM), and the received authentication
tag does not match the calculated valueprotected int engineDoFinal(byte[] input,
int inputOffset,
int inputLen,
byte[] output,
int outputOffset)
throws ShortBufferException,
IllegalBlockSizeException,
BadPaddingException
CipherSpi
The first inputLen bytes in the input buffer, starting at inputOffset
inclusive, and any input bytes that may have been buffered during a previous update operation, are
processed, with padding (if requested) being applied. If an AEAD mode such as GCM/CCM is being used, the
authentication tag is appended in the case of encryption, or verified in the case of decryption. The result is
stored in the output buffer, starting at outputOffset inclusive.
If the output buffer is too small to hold the result, a ShortBufferException is thrown.
Upon finishing, this method resets this cipher object to the state it was in when previously initialized via a
call to engineInit. That is, the object is reset and available to encrypt or decrypt (depending on
the operation mode that was specified in the call to engineInit) more data.
Note: if any exception is thrown, this cipher object may need to be reset before it can be used again.
engineDoFinal in class CipherSpiinput - the input bufferinputOffset - the offset in input where the input startsinputLen - the input lengthoutput - the buffer for the resultoutputOffset - the offset in output where the result is storedoutputShortBufferException - if the given output buffer is too small to hold the resultIllegalBlockSizeException - if this cipher is a block cipher, no padding has been requested (only in encryption mode), and the
total input length of the data processed by this cipher is not a multiple of block size; or if
this encryption algorithm is unable to process the input data provided.BadPaddingException - if this cipher is in decryption mode, and (un)padding has been requested, but the decrypted data
is not bounded by the appropriate padding bytesAEADBadTagException - if this cipher is decrypting in an AEAD mode (such as GCM/CCM), and the received authentication
tag does not match the calculated valueprotected int engineGetBlockSize()
CipherSpiengineGetBlockSize in class CipherSpiprotected int engineGetOutputSize(int inputLen)
CipherSpiupdate or doFinal operation, given the input length inputLen (in bytes).
This call takes into account any unprocessed (buffered) data from a previous update call, padding,
and AEAD tagging.
The actual output length of the next update or doFinal call may be smaller than the
length returned by this method.
engineGetOutputSize in class CipherSpiinputLen - the input length (in bytes)protected abstract void engineInit(boolean decrypting,
String algorithm,
SecretKey key,
byte[] iv,
int tagLen)
throws InvalidKeyException,
InvalidAlgorithmParameterException
decrypting - flag indicating encryption or decryption modealgorithm - the algorithm name (never null)key - the key (never null)iv - the iv (either null or blockSize bytes long)tagLen - the tag Length (only for GCM)InvalidKeyException - if the given key is inappropriate for initializing this cipherInvalidAlgorithmParameterException - if the given algorithm parameters are inappropriate for this cipher.protected void engineInit(int opmode,
Key key,
AlgorithmParameterSpec params,
SecureRandom random)
throws InvalidKeyException,
InvalidAlgorithmParameterException
CipherSpi
The cipher is initialized for one of the following four operations: encryption, decryption, key wrapping or key
unwrapping, depending on the value of opmode.
If this cipher requires any algorithm parameters and params is null, the underlying cipher
implementation is supposed to generate the required parameters itself (using provider-specific default or random
values) if it is being initialized for encryption or key wrapping, and raise an
InvalidAlgorithmParameterException if it is being initialized for decryption or key unwrapping. The
generated parameters can be retrieved using engineGetParameters or engineGetIV (if the parameter is an IV).
If this cipher requires algorithm parameters that cannot be derived from the input parameters, and there are no reasonable provider-specific default values, initialization will necessarily fail.
If this cipher (including its underlying feedback or padding scheme) requires any random bytes (e.g., for
parameter generation), it will get them from random.
Note that when a Cipher object is initialized, it loses all previously-acquired state. In other words, initializing a Cipher is equivalent to creating a new instance of that Cipher and initializing it.
engineInit in class CipherSpiopmode - the operation mode of this cipher (this is one of the following: ENCRYPT_MODE,
DECRYPT_MODE, WRAP_MODE or UNWRAP_MODE)key - the encryption keyparams - the algorithm parametersrandom - the source of randomnessInvalidKeyException - if the given key is inappropriate for initializing this cipherInvalidAlgorithmParameterException - if the given algorithm parameters are inappropriate for this cipher, or if this cipher requires
algorithm parameters and params is null.protected void engineInit(int opmode,
Key key,
SecureRandom random)
throws InvalidKeyException
CipherSpi
The cipher is initialized for one of the following four operations: encryption, decryption, key wrapping or key
unwrapping, depending on the value of opmode.
If this cipher requires any algorithm parameters that cannot be derived from the given key, the
underlying cipher implementation is supposed to generate the required parameters itself (using provider-specific
default or random values) if it is being initialized for encryption or key wrapping, and raise an
InvalidKeyException if it is being initialized for decryption or key unwrapping. The generated
parameters can be retrieved using engineGetParameters or engineGetIV
(if the parameter is an IV).
If this cipher requires algorithm parameters that cannot be derived from the input parameters, and there are no reasonable provider-specific default values, initialization will necessarily fail.
If this cipher (including its underlying feedback or padding scheme) requires any random bytes (e.g., for
parameter generation), it will get them from random.
Note that when a Cipher object is initialized, it loses all previously-acquired state. In other words, initializing a Cipher is equivalent to creating a new instance of that Cipher and initializing it.
engineInit in class CipherSpiopmode - the operation mode of this cipher (this is one of the following: ENCRYPT_MODE,
DECRYPT_MODE, WRAP_MODE or UNWRAP_MODE)key - the encryption keyrandom - the source of randomnessInvalidKeyException - if the given key is inappropriate for initializing this cipher, or requires algorithm parameters
that cannot be determined from the given key.protected abstract void engineSetIV(byte[] iv)
iv - the iv (either null or blockSize bytes long)protected byte[] engineUpdate(byte[] input,
int inputOffset,
int inputLen)
CipherSpi
The first inputLen bytes in the input buffer, starting at inputOffset
inclusive, are processed, and the result is stored in a new buffer.
engineUpdate in class CipherSpiinput - the input bufferinputOffset - the offset in input where the input startsinputLen - the input lengthprotected int engineUpdate(byte[] input,
int inputOffset,
int inputLen,
byte[] output,
int outputOffset)
throws ShortBufferException
CipherSpi
The first inputLen bytes in the input buffer, starting at inputOffset
inclusive, are processed, and the result is stored in the output buffer, starting at
outputOffset inclusive.
If the output buffer is too small to hold the result, a ShortBufferException is thrown.
engineUpdate in class CipherSpiinput - the input bufferinputOffset - the offset in input where the input startsinputLen - the input lengthoutput - the buffer for the resultoutputOffset - the offset in output where the result is storedoutputShortBufferException - if the given output buffer is too small to hold the resultprotected void engineUpdateAAD(byte[] src,
int offset,
int len)
CipherSpi
Calls to this method provide AAD to the cipher when operating in modes such as AEAD (GCM/CCM). If this cipher is
operating in either GCM or CCM mode, all AAD must be supplied before beginning operations on the ciphertext (via
the update and doFinal methods).
engineUpdateAAD in class CipherSpisrc - the buffer containing the AADoffset - the offset in src where the AAD input startslen - the number of AAD bytesprotected abstract int getBufferedLength()
protected abstract void updateAAD(byte[] src,
int offset,
int len)
Calls to this method provide AAD to the cipher when operating in modes such as AEAD (GCM/CCM). If this cipher is
operating in either GCM or CCM mode, all AAD must be supplied before beginning operations on the ciphertext (via
the update and doFinal methods).
src - the buffer containing the AADoffset - the offset in src where the AAD input startslen - the number of AAD bytesIllegalStateException - if this cipher is in a wrong state (e.g., has not been initialized), does not accept AAD, or if
operating in either GCM or CCM mode and one of the update methods has already been called for
the active encryption/decryption operationUnsupportedOperationException - if this method has not been overridden by an implementation