Class FaestKeyPairGenerator

java.lang.Object
org.bouncycastle.pqc.crypto.faest.FaestKeyPairGenerator
All Implemented Interfaces:
AsymmetricCipherKeyPairGenerator

public class FaestKeyPairGenerator extends Object implements AsymmetricCipherKeyPairGenerator
Implementation of the FAEST asymmetric key pair generator following the FAEST signature scheme specifications.

This generator produces FaestPublicKeyParameters and FaestPrivateKeyParameters based on the FAEST algorithm parameters. The secret signing key is an AES key, while the public verification key is a plaintext–ciphertext pair obtained by encrypting a random message under the signing key. The implementation follows the specification defined in the official FAEST documentation and the reference C implementation.

References:

  • Constructor Details

    • FaestKeyPairGenerator

      public FaestKeyPairGenerator()
  • Method Details

    • init

      public void init(KeyGenerationParameters param)
      Description copied from interface: AsymmetricCipherKeyPairGenerator
      intialise the key pair generator.
      Specified by:
      init in interface AsymmetricCipherKeyPairGenerator
      Parameters:
      param - the parameters the key pair is to be initialised with.
    • generateKeyPair

      public AsymmetricCipherKeyPair generateKeyPair()
      Generate a fresh FAEST key pair.

      Side-channel note: the OWF-key validity check (low two bits not both set, matching upstream faest_param.c:39-42) is enforced by a rejection-sampling loop. The loop's iteration count therefore depends on bytes drawn from the supplied SecureRandom and is observable via timing. The information leaked is about the discarded DRBG draws, not the accepted OWF key, so the loop does not expose secret key bits. Callers that need to suppress even that signal can pass a deterministic / pre-conditioned random source.

      Specified by:
      generateKeyPair in interface AsymmetricCipherKeyPairGenerator
      Returns:
      an AsymmetricCipherKeyPair containing the generated keys.