Frames | No Frames |
1: /* DiffieHellmanSender.java -- 2: Copyright (C) 2003, 2006 Free Software Foundation, Inc. 3: 4: This file is a part of GNU Classpath. 5: 6: GNU Classpath is free software; you can redistribute it and/or modify 7: it under the terms of the GNU General Public License as published by 8: the Free Software Foundation; either version 2 of the License, or (at 9: your option) any later version. 10: 11: GNU Classpath is distributed in the hope that it will be useful, but 12: WITHOUT ANY WARRANTY; without even the implied warranty of 13: MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU 14: General Public License for more details. 15: 16: You should have received a copy of the GNU General Public License 17: along with GNU Classpath; if not, write to the Free Software 18: Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 19: USA 20: 21: Linking this library statically or dynamically with other modules is 22: making a combined work based on this library. Thus, the terms and 23: conditions of the GNU General Public License cover the whole 24: combination. 25: 26: As a special exception, the copyright holders of this library give you 27: permission to link this library with independent modules to produce an 28: executable, regardless of the license terms of these independent 29: modules, and to copy and distribute the resulting executable under 30: terms of your choice, provided that you also meet, for each linked 31: independent module, the terms and conditions of the license of that 32: module. An independent module is a module which is not derived from 33: or based on this library. If you modify this library, you may extend 34: this exception to your version of the library, but you are not 35: obligated to do so. If you do not wish to do so, delete this 36: exception statement from your version. */ 37: 38: 39: package gnu.javax.crypto.key.dh; 40: 41: import gnu.java.security.prng.IRandom; 42: 43: import gnu.javax.crypto.key.KeyAgreementException; 44: import gnu.javax.crypto.key.IncomingMessage; 45: import gnu.javax.crypto.key.OutgoingMessage; 46: 47: import java.math.BigInteger; 48: import java.security.SecureRandom; 49: import java.util.Map; 50: 51: import javax.crypto.interfaces.DHPrivateKey; 52: 53: /** 54: * This implementation is the sender's part of the basic version of the 55: * Diffie-Hellman key agreement exchange (A in [HAC]). 56: * 57: * @see DiffieHellmanKeyAgreement 58: */ 59: public class DiffieHellmanSender 60: extends DiffieHellmanKeyAgreement 61: { 62: private BigInteger x; // the sender's random secret 63: 64: // default 0-arguments constructor 65: 66: protected void engineInit(Map attributes) throws KeyAgreementException 67: { 68: Object random = attributes.get(SOURCE_OF_RANDOMNESS); 69: rnd = null; 70: irnd = null; 71: if (random instanceof SecureRandom) 72: rnd = (SecureRandom) random; 73: else if (random instanceof IRandom) 74: irnd = (IRandom) random; 75: ownerKey = (DHPrivateKey) attributes.get(KA_DIFFIE_HELLMAN_OWNER_PRIVATE_KEY); 76: if (ownerKey == null) 77: throw new KeyAgreementException("missing owner's private key"); 78: } 79: 80: protected OutgoingMessage engineProcessMessage(IncomingMessage in) 81: throws KeyAgreementException 82: { 83: switch (step) 84: { 85: case 0: 86: return sendRandomSecret(in); 87: case 1: 88: return computeSharedSecret(in); 89: default: 90: throw new IllegalStateException("unexpected state"); 91: } 92: } 93: 94: private OutgoingMessage sendRandomSecret(IncomingMessage in) 95: throws KeyAgreementException 96: { 97: BigInteger p = ownerKey.getParams().getP(); 98: BigInteger g = ownerKey.getParams().getG(); 99: // A chooses a random integer x, 1 <= x <= p-2 100: // rfc-2631 restricts x to only be in [2, p-1] 101: BigInteger p_minus_2 = p.subtract(TWO); 102: byte[] xBytes = new byte[(p_minus_2.bitLength() + 7) / 8]; 103: do 104: { 105: nextRandomBytes(xBytes); 106: x = new BigInteger(1, xBytes); 107: } 108: while (! (x.compareTo(TWO) >= 0 && x.compareTo(p_minus_2) <= 0)); 109: // A sends B the message: g^x mod p 110: OutgoingMessage result = new OutgoingMessage(); 111: result.writeMPI(g.modPow(x, p)); 112: return result; 113: } 114: 115: private OutgoingMessage computeSharedSecret(IncomingMessage in) 116: throws KeyAgreementException 117: { 118: BigInteger m1 = in.readMPI(); 119: if (m1 == null) 120: throw new KeyAgreementException("missing message (2)"); 121: BigInteger p = ownerKey.getParams().getP(); 122: ZZ = m1.modPow(x, p); // ZZ = (yb ^ xa) mod p 123: complete = true; 124: return null; 125: } 126: }