Interface MerkleTreeHash

All Known Implementing Classes:
BcSha256MerkleTreeHash, JcaSha256MerkleTreeHash

public interface MerkleTreeHash
Operator interface for the hash function used in the Merkle tree, as defined by Section 4 of draft-ietf-plants-merkle-tree-certs.

JCA-free and lightweight-crypto-free. Concrete SHA-256 bindings: org.bouncycastle.cert.plants.bc.BcSha256MerkleTreeHash (lightweight) and org.bouncycastle.cert.plants.jcajce.JcaSha256MerkleTreeHash (JCA).

  • Method Summary

    Modifier and Type
    Method
    Description
    org.bouncycastle.asn1.x509.AlgorithmIdentifier
     
    int
     
    byte[]
    hashLeaf(byte[] entry)
    Hash of a leaf entry: HASH(0x00 || entry).
    byte[]
    hashNode(byte[] left, byte[] right)
    Hash of an internal node: HASH(0x01 || left || right).
    byte[]
    hashRaw(byte[] data)
    Raw hash with no domain separation prefix: HASH(data).
  • Method Details

    • getAlgorithmIdentifier

      org.bouncycastle.asn1.x509.AlgorithmIdentifier getAlgorithmIdentifier()
      Returns:
      the X.509 AlgorithmIdentifier that names this hash function. Used by MerkleTreeCertificateValidator to cross-check the supplied hash against the logHash field of the CA's id-pe-mtcCertificationAuthority extension.
    • getHashSize

      int getHashSize()
      Returns:
      the hash output size in bytes
    • hashLeaf

      byte[] hashLeaf(byte[] entry)
      Hash of a leaf entry: HASH(0x00 || entry).
      Parameters:
      entry - the raw entry bytes
      Returns:
      leaf hash
    • hashNode

      byte[] hashNode(byte[] left, byte[] right)
      Hash of an internal node: HASH(0x01 || left || right).
      Parameters:
      left - left child hash
      right - right child hash
      Returns:
      node hash
    • hashRaw

      byte[] hashRaw(byte[] data)
      Raw hash with no domain separation prefix: HASH(data). Used for the subjectPublicKeyInfoHash in a TBSCertificateLogEntry (Section 5.3), which is computed with the log's hash function but without the leaf-node prefix.
      Parameters:
      data - the input bytes
      Returns:
      the hash output