Class DSTU7624Mac
- All Implemented Interfaces:
Mac
This is a CBC-MAC variant (a CBC chain whose final block is masked with kDelta = E(0) before the
last encryption) and, like raw CBC-MAC, it is defined only for input that is a whole number of
blocks: doFinal(byte[], int) rejects a trailing partial block with "input must be a multiple of
blocksize". The restriction is deliberate and is not relaxed by zero-padding the final
block. The MAC binds no message length, so zero-padding a partial block would make the tag of an
N-byte message collide with that of a longer message sharing the same final block once padded
(the documented ambiguity of ISO/IEC 9797-1 padding method 1). DSTU 7624:2014 specifies no
partial-block padding for this MAC and publishes no vector for one, so any padding scheme BC chose
(zero-pad, or the unambiguous 10* / ISO 9797-1 method 2 that CMAC uses) would be non-conformant
and non-interoperable. Callers needing to authenticate arbitrary-length input should pad to a
block boundary with an agreed scheme before calling update, or use a length-binding MAC such as
KGMac. See github #287.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionintdoFinal(byte[] out, int outOff) Compute the final stage of the MAC writing the output to the out parameter.Return the name of the algorithm the MAC implements.intReturn the block size for this MAC (in bytes).voidinit(CipherParameters params) Initialise the MAC.voidreset()Reset the MAC.voidupdate(byte in) add a single byte to the mac for processing.voidupdate(byte[] in, int inOff, int len)
-
Constructor Details
-
DSTU7624Mac
public DSTU7624Mac(int blockBitLength, int q)
-
-
Method Details
-
init
Description copied from interface:MacInitialise the MAC.- Specified by:
initin interfaceMac- Parameters:
params- the key and other data required by the MAC.- Throws:
IllegalArgumentException- if the params argument is inappropriate.
-
getAlgorithmName
Description copied from interface:MacReturn the name of the algorithm the MAC implements.- Specified by:
getAlgorithmNamein interfaceMac- Returns:
- the name of the algorithm the MAC implements.
-
getMacSize
public int getMacSize()Description copied from interface:MacReturn the block size for this MAC (in bytes).- Specified by:
getMacSizein interfaceMac- Returns:
- the block size for this MAC in bytes.
-
update
-
update
-
doFinal
Description copied from interface:MacCompute the final stage of the MAC writing the output to the out parameter.doFinal leaves the MAC in the same state it was after the last init.
- Specified by:
doFinalin interfaceMac- Parameters:
out- the array the MAC is to be output to.outOff- the offset into the out buffer the output is to start at.- Throws:
DataLengthException- if there isn't enough space in out.IllegalStateException- if the MAC is not initialised.
-
reset
-