Class HPKEContext
java.lang.Object
org.bouncycastle.crypto.hpke.HPKEContext
- Direct Known Subclasses:
HPKEContextWithEncapsulation
An HPKE encryption / decryption context produced by one of the
HPKE.setup*R (recipient) factory methods, or — via the
HPKEContextWithEncapsulation subclass — by one of the
HPKE.setup*S (sender) factories.
The context is stateful: each seal(byte[], byte[]) /
open(byte[], byte[]) call advances an internal sequence number that
is XOR-mixed into the AEAD nonce per RFC 9180 §5.2, allowing a single
context to encrypt or decrypt many messages in order without nonce reuse.
export(byte[], int) derives auxiliary key material from the
exporter secret and is deterministic — repeated calls with the same
(exporterContext, L) return the same bytes.
Senders should use HPKEContextWithEncapsulation.getEncapsulation()
to obtain the enc octet string that must be transmitted alongside
the first ciphertext so the receiver can run the matching setup*R.
-
Field Summary
FieldsModifier and TypeFieldDescriptionprotected final AEADprotected final byte[]protected final org.bouncycastle.crypto.hpke.HKDFprotected final byte[] -
Method Summary
Modifier and TypeMethodDescriptionbyte[]expand(byte[] prk, byte[] info, int L) byte[]export(byte[] exportContext, int L) byte[]extract(byte[] salt, byte[] ikm) byte[]open(byte[] aad, byte[] ct) byte[]open(byte[] aad, byte[] ct, int ctOffset, int ctLength) byte[]seal(byte[] aad, byte[] message) byte[]seal(byte[] aad, byte[] pt, int ptOffset, int ptLength)
-
Field Details
-
aead
-
hkdf
protected final org.bouncycastle.crypto.hpke.HKDF hkdf -
exporterSecret
protected final byte[] exporterSecret -
suiteId
protected final byte[] suiteId
-
-
Method Details
-
export
public byte[] export(byte[] exportContext, int L) -
seal
- Throws:
InvalidCipherTextException
-
seal
public byte[] seal(byte[] aad, byte[] pt, int ptOffset, int ptLength) throws InvalidCipherTextException - Throws:
InvalidCipherTextException
-
open
- Throws:
InvalidCipherTextException
-
open
public byte[] open(byte[] aad, byte[] ct, int ctOffset, int ctLength) throws InvalidCipherTextException - Throws:
InvalidCipherTextException
-
extract
public byte[] extract(byte[] salt, byte[] ikm) -
expand
public byte[] expand(byte[] prk, byte[] info, int L)
-