Frames | No Frames |
1: /* DiffieHellmanKeyAgreement.java -- 2: Copyright (C) 2003, 2006 Free Software Foundation, Inc. 3: 4: This file is a part of GNU Classpath. 5: 6: GNU Classpath is free software; you can redistribute it and/or modify 7: it under the terms of the GNU General Public License as published by 8: the Free Software Foundation; either version 2 of the License, or (at 9: your option) any later version. 10: 11: GNU Classpath is distributed in the hope that it will be useful, but 12: WITHOUT ANY WARRANTY; without even the implied warranty of 13: MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU 14: General Public License for more details. 15: 16: You should have received a copy of the GNU General Public License 17: along with GNU Classpath; if not, write to the Free Software 18: Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 19: USA 20: 21: Linking this library statically or dynamically with other modules is 22: making a combined work based on this library. Thus, the terms and 23: conditions of the GNU General Public License cover the whole 24: combination. 25: 26: As a special exception, the copyright holders of this library give you 27: permission to link this library with independent modules to produce an 28: executable, regardless of the license terms of these independent 29: modules, and to copy and distribute the resulting executable under 30: terms of your choice, provided that you also meet, for each linked 31: independent module, the terms and conditions of the license of that 32: module. An independent module is a module which is not derived from 33: or based on this library. If you modify this library, you may extend 34: this exception to your version of the library, but you are not 35: obligated to do so. If you do not wish to do so, delete this 36: exception statement from your version. */ 37: 38: 39: package gnu.javax.crypto.key.dh; 40: 41: import gnu.java.security.Registry; 42: import gnu.java.security.util.Util; 43: 44: import gnu.javax.crypto.key.BaseKeyAgreementParty; 45: import gnu.javax.crypto.key.KeyAgreementException; 46: 47: import java.math.BigInteger; 48: 49: import javax.crypto.interfaces.DHPrivateKey; 50: 51: /** 52: * The basic version of the Diffie-Hellman key agreement is described in the 53: * Handbook of Applied Cryptography [HAC] as follows: 54: * <ul> 55: * <li>An appropriate prime p and generator g of Z<sub>p</sub><sup>*</sup> 56: * (2 <= g <= p-2) are selected and published.</li> 57: * <li>A and B each send the other one message over an open channel; as a 58: * result, they both can then compute a shared secret key K which they can use 59: * to protect their future communication.</li> 60: * <li>A chooses a random secret x, 1 <= x <= p-2, and sends B message 61: * (1) which is g^x mod p.</li> 62: * <li>B chooses a random secret y, 1 <= y <= p-2, and sends A message 63: * (2) which is g^y mod p.</li> 64: * <li>B receives message (1) and computes the shared key as K = (g^x)^y mod p. 65: * </li> 66: * <li>A receives message (2) and computes the shared key as K = (g^y)^x mod p. 67: * </li> 68: * </ul> 69: * <p> 70: * RFC-2631 describes a <i>Static-Static Mode</i> of operations with 71: * Diffie-Hellman keypairs as follows: 72: * <pre> 73: * "In Static-Static mode, both the sender and the recipient have a 74: * static (and certified) key pair. Since the sender's and recipient's 75: * keys are therefore the same for each message, ZZ will be the same for 76: * each message. Thus, partyAInfo MUST be used (and different for each 77: * message) in order to ensure that different messages use different 78: * KEKs. Implementations MAY implement Static-Static mode." 79: * </pre> 80: * 81: * <p> 82: * Reference: 83: * <ol> 84: * <li><a href="http://www.ietf.org/rfc/rfc2631.txt">Diffie-Hellman Key 85: * Agreement Method</a><br> 86: * Eric Rescorla.</li> 87: * <li><a href="http://www.cacr.math.uwaterloo.ca/hac">[HAC]</a>: Handbook of 88: * Applied Cryptography.<br> 89: * CRC Press, Inc. ISBN 0-8493-8523-7, 1997<br> 90: * Menezes, A., van Oorschot, P. and S. Vanstone.</li> 91: * </ol> 92: */ 93: public abstract class DiffieHellmanKeyAgreement 94: extends BaseKeyAgreementParty 95: { 96: public static final String SOURCE_OF_RANDOMNESS = "gnu.crypto.dh.ka.prng"; 97: public static final String KA_DIFFIE_HELLMAN_OWNER_PRIVATE_KEY = 98: "gnu.crypto.dh.ka.owner.private.key"; 99: /** The key agreement party's private key. */ 100: protected DHPrivateKey ownerKey; 101: /** The shared secret key. */ 102: protected BigInteger ZZ; 103: 104: protected DiffieHellmanKeyAgreement() 105: { 106: super(Registry.DH_KA); 107: } 108: 109: protected byte[] engineSharedSecret() throws KeyAgreementException 110: { 111: return Util.trim(ZZ); 112: } 113: 114: protected void engineReset() 115: { 116: ownerKey = null; 117: ZZ = null; 118: } 119: }