Class PSSSigner
- All Implemented Interfaces:
Signer
Note: the usual value for the salt length is the number of bytes in the hash function.
The createRawSigner(AsymmetricBlockCipher, Digest) family builds a signer that
operates on a pre-computed message hash (mHash) rather than the message itself.
RFC 8017 (PKCS#1 v2.2) sec. 9.1 EMSA-PSS first hashes the message M to mHash and then
salts and re-hashes; these factories replace only that first hash with a
Prehash pass-through, so the caller supplies
mHash via update(...) and the signer still performs the salt / M' / second-hash /
masking steps. The bytes supplied must be exactly the content digest's output length,
otherwise signing or verification fails with "Incorrect prehash size". This is the
lightweight-API equivalent of a "sign/verify pre-computed hash" entry point
(github #1145). See org.bouncycastle.crypto.examples.RSAPSSPreComputedHashExample.
-
Field Summary
Fields -
Constructor Summary
ConstructorsConstructorDescriptionPSSSigner(AsymmetricBlockCipher cipher, Digest digest, byte[] salt) PSSSigner(AsymmetricBlockCipher cipher, Digest digest, int sLen) basic constructorPSSSigner(AsymmetricBlockCipher cipher, Digest digest, int sLen, byte trailer) PSSSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, byte[] salt) PSSSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, byte[] salt, byte trailer) PSSSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, int sLen) PSSSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, int sLen, byte trailer) -
Method Summary
Modifier and TypeMethodDescriptionstatic PSSSignercreateRawSigner(AsymmetricBlockCipher cipher, Digest digest) Create a PSS signer/verifier that consumes a pre-computed message hash.static PSSSignercreateRawSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, byte[] salt, byte trailer) Create a PSS signer/verifier that consumes a pre-computed message hash, using a fixed salt (chiefly for known-answer testing where the salt must be reproducible).static PSSSignercreateRawSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, int sLen, byte trailer) Create a PSS signer/verifier that consumes a pre-computed message hash, with the MGF digest, salt length and trailer specified explicitly.byte[]generate a signature for the message we've been loaded with using the key we were initialised with.voidinit(boolean forSigning, CipherParameters param) Initialise the signer for signing or verification.voidreset()reset the internal statevoidupdate(byte b) update the internal digest with the byte bvoidupdate(byte[] in, int off, int len) update the internal digest with the byte array inbooleanverifySignature(byte[] signature) return true if the internal state represents the signature described in the passed in array.
-
Field Details
-
TRAILER_IMPLICIT
public static final byte TRAILER_IMPLICIT- See Also:
-
-
Constructor Details
-
PSSSigner
basic constructor- Parameters:
cipher- the asymmetric cipher to use.digest- the digest to use.sLen- the length of the salt to use (in bytes).
-
PSSSigner
-
PSSSigner
-
PSSSigner
public PSSSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, int sLen, byte trailer) -
PSSSigner
-
PSSSigner
-
PSSSigner
public PSSSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, byte[] salt, byte trailer)
-
-
Method Details
-
createRawSigner
Create a PSS signer/verifier that consumes a pre-computed message hash. The caller feeds exactlydigest.getDigestSize()bytes (the hash of the message underdigest) throughupdate(...)beforegenerateSignature()/verifySignature(...);digestis also used for the EMSA-PSS second hash and the MGF1 mask, and the salt length defaults to the digest output length with the implicit (0xBC) trailer.- Parameters:
cipher- the asymmetric cipher to use (e.g. a configured RSAEngine).digest- the digest the supplied hash was produced with.
-
createRawSigner
public static PSSSigner createRawSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, int sLen, byte trailer) Create a PSS signer/verifier that consumes a pre-computed message hash, with the MGF digest, salt length and trailer specified explicitly. The caller feeds exactlycontentDigest.getDigestSize()bytes (the pre-computed hash) throughupdate(...);contentDigestperforms the EMSA-PSS second hash andmgfDigestdrives the MGF1 mask.- Parameters:
cipher- the asymmetric cipher to use.contentDigest- the digest the supplied hash was produced with, also used for the second hash.mgfDigest- the digest to use for the MGF1 mask generation function.sLen- the length of the salt to use (in bytes).trailer- the trailer byte (usuallyTRAILER_IMPLICIT).
-
createRawSigner
public static PSSSigner createRawSigner(AsymmetricBlockCipher cipher, Digest contentDigest, Digest mgfDigest, byte[] salt, byte trailer) Create a PSS signer/verifier that consumes a pre-computed message hash, using a fixed salt (chiefly for known-answer testing where the salt must be reproducible). The caller feeds exactlycontentDigest.getDigestSize()bytes (the pre-computed hash) throughupdate(...).- Parameters:
cipher- the asymmetric cipher to use.contentDigest- the digest the supplied hash was produced with, also used for the second hash.mgfDigest- the digest to use for the MGF1 mask generation function.salt- the fixed salt to use.trailer- the trailer byte (usuallyTRAILER_IMPLICIT).
-
init
Description copied from interface:SignerInitialise the signer for signing or verification. -
update
-
update
-
reset
-
generateSignature
generate a signature for the message we've been loaded with using the key we were initialised with.- Specified by:
generateSignaturein interfaceSigner- Throws:
CryptoExceptionDataLengthException
-
verifySignature
public boolean verifySignature(byte[] signature) return true if the internal state represents the signature described in the passed in array.- Specified by:
verifySignaturein interfaceSigner
-