Class DSTU7624Mac

java.lang.Object
org.bouncycastle.crypto.macs.DSTU7624Mac
All Implemented Interfaces:
Mac

public class DSTU7624Mac extends Object implements Mac
Implementation of DSTU7624 MAC mode.

This is a CBC-MAC variant (a CBC chain whose final block is masked with kDelta = E(0) before the last encryption) and, like raw CBC-MAC, it is defined only for input that is a whole number of blocks: doFinal(byte[], int) rejects a trailing partial block with "input must be a multiple of blocksize". The restriction is deliberate and is not relaxed by zero-padding the final block. The MAC binds no message length, so zero-padding a partial block would make the tag of an N-byte message collide with that of a longer message sharing the same final block once padded (the documented ambiguity of ISO/IEC 9797-1 padding method 1). DSTU 7624:2014 specifies no partial-block padding for this MAC and publishes no vector for one, so any padding scheme BC chose (zero-pad, or the unambiguous 10* / ISO 9797-1 method 2 that CMAC uses) would be non-conformant and non-interoperable. Callers needing to authenticate arbitrary-length input should pad to a block boundary with an agreed scheme before calling update, or use a length-binding MAC such as KGMac. See github #287.

  • Constructor Details

    • DSTU7624Mac

      public DSTU7624Mac(int blockBitLength, int q)
  • Method Details

    • init

      public void init(CipherParameters params) throws IllegalArgumentException
      Description copied from interface: Mac
      Initialise the MAC.
      Specified by:
      init in interface Mac
      Parameters:
      params - the key and other data required by the MAC.
      Throws:
      IllegalArgumentException - if the params argument is inappropriate.
    • getAlgorithmName

      public String getAlgorithmName()
      Description copied from interface: Mac
      Return the name of the algorithm the MAC implements.
      Specified by:
      getAlgorithmName in interface Mac
      Returns:
      the name of the algorithm the MAC implements.
    • getMacSize

      public int getMacSize()
      Description copied from interface: Mac
      Return the block size for this MAC (in bytes).
      Specified by:
      getMacSize in interface Mac
      Returns:
      the block size for this MAC in bytes.
    • update

      public void update(byte in)
      Description copied from interface: Mac
      add a single byte to the mac for processing.
      Specified by:
      update in interface Mac
      Parameters:
      in - the byte to be processed.
    • update

      public void update(byte[] in, int inOff, int len)
      Specified by:
      update in interface Mac
      Parameters:
      in - the array containing the input.
      inOff - the index in the array the data begins at.
      len - the length of the input starting at inOff.
    • doFinal

      public int doFinal(byte[] out, int outOff) throws DataLengthException, IllegalStateException
      Description copied from interface: Mac
      Compute the final stage of the MAC writing the output to the out parameter.

      doFinal leaves the MAC in the same state it was after the last init.

      Specified by:
      doFinal in interface Mac
      Parameters:
      out - the array the MAC is to be output to.
      outOff - the offset into the out buffer the output is to start at.
      Throws:
      DataLengthException - if there isn't enough space in out.
      IllegalStateException - if the MAC is not initialised.
    • reset

      public void reset()
      Description copied from interface: Mac
      Reset the MAC. At the end of resetting the MAC should be in the in the same state it was after the last init (if there was one).
      Specified by:
      reset in interface Mac