Class JcaSha256MerkleTreeHash
java.lang.Object
org.bouncycastle.cert.plants.jcajce.JcaSha256MerkleTreeHash
- All Implemented Interfaces:
MerkleTreeHash
JCA-side SHA-256 implementation of
MerkleTreeHash, obtained via
MessageDigest.getInstance("SHA-256") through a JcaJceHelper.
A fresh MessageDigest is created per call, so a single instance
is thread-safe and can be shared (e.g. inside an
MTCCertAuth or a
MerkleTreeCertificateValidator.ValidationParams
used by concurrent validations). The constructor fails fast if the selected
provider cannot supply SHA-256.
-
Constructor Summary
ConstructorsConstructorDescriptionJcaSha256MerkleTreeHash(String providerName) JcaSha256MerkleTreeHash(Provider provider) JcaSha256MerkleTreeHash(org.bouncycastle.jcajce.util.JcaJceHelper helper) -
Method Summary
Modifier and TypeMethodDescriptionorg.bouncycastle.asn1.x509.AlgorithmIdentifierintbyte[]hashLeaf(byte[] entry) Hash of a leaf entry: HASH(0x00 || entry).byte[]hashNode(byte[] left, byte[] right) Hash of an internal node: HASH(0x01 || left || right).byte[]hashRaw(byte[] data) Raw hash with no domain separation prefix: HASH(data).
-
Constructor Details
-
JcaSha256MerkleTreeHash
public JcaSha256MerkleTreeHash() -
JcaSha256MerkleTreeHash
-
JcaSha256MerkleTreeHash
-
JcaSha256MerkleTreeHash
public JcaSha256MerkleTreeHash(org.bouncycastle.jcajce.util.JcaJceHelper helper)
-
-
Method Details
-
getAlgorithmIdentifier
public org.bouncycastle.asn1.x509.AlgorithmIdentifier getAlgorithmIdentifier()- Specified by:
getAlgorithmIdentifierin interfaceMerkleTreeHash- Returns:
- the X.509
AlgorithmIdentifierthat names this hash function. Used byMerkleTreeCertificateValidatorto cross-check the supplied hash against thelogHashfield of the CA'sid-pe-mtcCertificationAuthorityextension.
-
getHashSize
public int getHashSize()- Specified by:
getHashSizein interfaceMerkleTreeHash- Returns:
- the hash output size in bytes
-
hashLeaf
public byte[] hashLeaf(byte[] entry) Description copied from interface:MerkleTreeHashHash of a leaf entry: HASH(0x00 || entry).- Specified by:
hashLeafin interfaceMerkleTreeHash- Parameters:
entry- the raw entry bytes- Returns:
- leaf hash
-
hashNode
public byte[] hashNode(byte[] left, byte[] right) Description copied from interface:MerkleTreeHashHash of an internal node: HASH(0x01 || left || right).- Specified by:
hashNodein interfaceMerkleTreeHash- Parameters:
left- left child hashright- right child hash- Returns:
- node hash
-
hashRaw
public byte[] hashRaw(byte[] data) Description copied from interface:MerkleTreeHashRaw hash with no domain separation prefix: HASH(data). Used for the subjectPublicKeyInfoHash in a TBSCertificateLogEntry (Section 5.3), which is computed with the log's hash function but without the leaf-node prefix.- Specified by:
hashRawin interfaceMerkleTreeHash- Parameters:
data- the input bytes- Returns:
- the hash output
-