Skip to content

Commit 77fad50

Browse files
committed
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java
2 parents 7e28144 + a9cd57c commit 77fad50

40 files changed

Lines changed: 1786 additions & 67 deletions

File tree

‎build.gradle‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -316,11 +316,15 @@ configure(subprojects.findAll {it.name != 'bom'}) {
316316
}
317317

318318

319-
test.dependsOn([':core:test', ':prov:test', ':prov:test11', ':prov:test15', ':prov:test17', ':pkix:test', 'pg:test', ':tls:test', 'mls:test', 'mail:test', 'jmail:test'])
319+
test.dependsOn([':core:test', ':prov:test', ':prov:test11', ':prov:test15', ':prov:test17', ':pkix:test', 'pg:test', ':tls:test', ':tls-klog:test', 'mls:test', 'mail:test', 'jmail:test'])
320320

321321
// Aggregate all published jars (main, sources, javadoc) into a top-level dist/
322322
// directory so consumers have a single place to pick up the build outputs.
323-
def distModules = ['core', 'util', 'prov', 'pkix', 'pg', 'tls', 'mls', 'mail', 'jmail']
323+
// bctls-klog is a drop-in replacement for bctls rather than an addition to it (same module name,
324+
// same packages), so it ships alongside the others here but is deliberately absent from the BOM:
325+
// resolving both onto one class path would be a duplicate-class mess, and the choice between them
326+
// is one a consumer has to make deliberately. See tls-klog/build.gradle.
327+
def distModules = ['core', 'util', 'prov', 'pkix', 'pg', 'tls', 'tls-klog', 'mls', 'mail', 'jmail']
324328

325329
distModules.each { evaluationDependsOn(":$it") }
326330

‎core/src/main/j2me/org/bouncycastle/crypto/engines/SM2Engine.java‎

Lines changed: 22 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
import java.security.SecureRandom;
55

66
import org.bouncycastle.crypto.CipherParameters;
7+
import org.bouncycastle.crypto.CryptoServicesRegistrar;
78
import org.bouncycastle.crypto.DataLengthException;
89
import org.bouncycastle.crypto.Digest;
910
import org.bouncycastle.crypto.InvalidCipherTextException;
@@ -68,28 +69,33 @@ public void init(boolean forEncryption, CipherParameters param)
6869
{
6970
this.forEncryption = forEncryption;
7071

71-
if (forEncryption)
72+
SecureRandom providedRandom = null;
73+
if (param instanceof ParametersWithRandom)
7274
{
73-
ParametersWithRandom rParam = (ParametersWithRandom)param;
75+
ParametersWithRandom withRandom = (ParametersWithRandom)param;
76+
providedRandom = withRandom.getRandom();
77+
param = withRandom.getParameters();
78+
}
7479

75-
ecKey = (ECKeyParameters)rParam.getParameters();
76-
ecParams = ecKey.getParameters();
80+
ecKey = (ECKeyParameters)param;
81+
ecParams = ecKey.getParameters();
82+
83+
if (forEncryption)
84+
{
85+
random = CryptoServicesRegistrar.getSecureRandom(providedRandom);
7786

7887
ECPoint s = ((ECPublicKeyParameters)ecKey).getQ().multiply(ecParams.getH());
7988
if (s.isInfinity())
8089
{
8190
throw new IllegalArgumentException("invalid key: [h]Q at infinity");
8291
}
83-
84-
random = rParam.getRandom();
8592
}
8693
else
8794
{
88-
ecKey = (ECKeyParameters)param;
89-
ecParams = ecKey.getParameters();
95+
random = null;
9096
}
9197

92-
curveLength = (ecParams.getCurve().getFieldSize() + 7) / 8;
98+
curveLength = ecParams.getCurve().getFieldElementEncodingLength();
9399
}
94100

95101
public byte[] processBlock(
@@ -132,22 +138,21 @@ private byte[] encrypt(byte[] in, int inOff, int inLen)
132138

133139
ECMultiplier multiplier = createBasePointMultiplier();
134140

135-
byte[] c1;
141+
BigInteger k;
136142
ECPoint kPB;
137143
do
138144
{
139-
BigInteger k = nextK();
140-
141-
ECPoint c1P = multiplier.multiply(ecParams.getG(), k).normalize();
142-
143-
c1 = c1P.getEncoded(false);
144-
145+
k = nextK();
145146
kPB = ((ECPublicKeyParameters)ecKey).getQ().multiply(k).normalize();
146147

147148
kdf(digest, kPB, c2);
148149
}
149150
while (notEncrypted(c2, in, inOff));
150151

152+
ECPoint c1P = multiplier.multiply(ecParams.getG(), k).normalize();
153+
154+
byte[] c1 = c1P.getEncoded(false);
155+
151156
byte[] c3 = new byte[digest.getDigestSize()];
152157

153158
addFieldElement(digest, kPB.getAffineXCoord());
@@ -310,8 +315,7 @@ private BigInteger nextK()
310315

311316
private void addFieldElement(Digest digest, ECFieldElement v)
312317
{
313-
byte[] p = BigIntegers.asUnsignedByteArray(curveLength, v.toBigInteger());
314-
318+
byte[] p = v.getEncoded();
315319
digest.update(p, 0, p.length);
316320
}
317321
}

‎core/src/main/java/org/bouncycastle/crypto/engines/SM2Engine.java‎

Lines changed: 20 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -74,25 +74,30 @@ public void init(boolean forEncryption, CipherParameters param)
7474
{
7575
this.forEncryption = forEncryption;
7676

77-
if (forEncryption)
77+
SecureRandom providedRandom = null;
78+
if (param instanceof ParametersWithRandom)
7879
{
79-
ParametersWithRandom rParam = (ParametersWithRandom)param;
80+
ParametersWithRandom withRandom = (ParametersWithRandom)param;
81+
providedRandom = withRandom.getRandom();
82+
param = withRandom.getParameters();
83+
}
8084

81-
ecKey = (ECKeyParameters)rParam.getParameters();
82-
ecParams = ecKey.getParameters();
85+
ecKey = (ECKeyParameters)param;
86+
ecParams = ecKey.getParameters();
87+
88+
if (forEncryption)
89+
{
90+
random = CryptoServicesRegistrar.getSecureRandom(providedRandom);
8391

8492
ECPoint s = ((ECPublicKeyParameters)ecKey).getQ().multiply(ecParams.getH());
8593
if (s.isInfinity())
8694
{
8795
throw new IllegalArgumentException("invalid key: [h]Q at infinity");
8896
}
89-
90-
random = rParam.getRandom();
9197
}
9298
else
9399
{
94-
ecKey = (ECKeyParameters)param;
95-
ecParams = ecKey.getParameters();
100+
random = null;
96101
}
97102

98103
curveLength = ecParams.getCurve().getFieldElementEncodingLength();
@@ -140,22 +145,21 @@ private byte[] encrypt(byte[] in, int inOff, int inLen)
140145

141146
ECMultiplier multiplier = createBasePointMultiplier();
142147

143-
byte[] c1;
148+
BigInteger k;
144149
ECPoint kPB;
145150
do
146151
{
147-
BigInteger k = nextK();
148-
149-
ECPoint c1P = multiplier.multiply(ecParams.getG(), k).normalize();
150-
151-
c1 = c1P.getEncoded(false);
152-
152+
k = nextK();
153153
kPB = ((ECPublicKeyParameters)ecKey).getQ().multiply(k).normalize();
154154

155155
kdf(digest, kPB, c2);
156156
}
157157
while (notEncrypted(c2, in, inOff));
158158

159+
ECPoint c1P = multiplier.multiply(ecParams.getG(), k).normalize();
160+
161+
byte[] c1 = c1P.getEncoded(false);
162+
159163
byte[] c3 = new byte[digest.getDigestSize()];
160164

161165
addFieldElement(digest, kPB.getAffineXCoord());
@@ -319,8 +323,7 @@ private BigInteger nextK()
319323

320324
private void addFieldElement(Digest digest, ECFieldElement v)
321325
{
322-
byte[] p = BigIntegers.asUnsignedByteArray(curveLength, v.toBigInteger());
323-
326+
byte[] p = v.getEncoded();
324327
digest.update(p, 0, p.length);
325328
}
326329
}

‎core/src/main/java/org/bouncycastle/crypto/params/MLDSAPrivateKeyParameters.java‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,15 @@ public MLDSAPrivateKeyParameters(MLDSAParameters params, byte[] encoding, MLDSAP
5656
super(true, params);
5757

5858
MLDSAEngine eng = MLDSAEngine.getInstance(params, null);
59+
60+
int expandedKeyLength = 2 * MLDSAEngine.SeedBytes + MLDSAEngine.TrBytes
61+
+ (eng.getDilithiumL() + eng.getDilithiumK()) * eng.getDilithiumPolyEtaPackedBytes()
62+
+ eng.getDilithiumK() * MLDSAEngine.DilithiumPolyT0PackedBytes;
63+
if (encoding.length != MLDSAEngine.SeedBytes && encoding.length != expandedKeyLength)
64+
{
65+
throw new IllegalArgumentException("'encoding' has invalid length");
66+
}
67+
5968
if (encoding.length == MLDSAEngine.SeedBytes)
6069
{
6170
byte[][] keyDetails = eng.generateKeyPairInternal(encoding);

‎core/src/main/java/org/bouncycastle/crypto/params/MLKEMPrivateKeyParameters.java‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,13 @@ public MLKEMPrivateKeyParameters(MLKEMParameters params, byte[] encoding, MLKEMP
5454
super(true, params);
5555

5656
MLKEMEngine eng = MLKEMEngine.getInstance(params);
57+
58+
if (encoding.length != MLKEMEngine.SeedBytes &&
59+
encoding.length != eng.getIndCpaSecretKeyBytes() + eng.getIndCpaPublicKeyBytes() + 2 * MLKEMEngine.SymBytes)
60+
{
61+
throw new IllegalArgumentException("'encoding' has invalid length");
62+
}
63+
5764
if (encoding.length == MLKEMEngine.SeedBytes)
5865
{
5966
byte[][] keyData = eng.generateKemKeyPairInternal(

‎core/src/main/java/org/bouncycastle/crypto/signers/HashSLHDSASigner.java‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -139,6 +139,11 @@ public void update(byte[] in, int off, int len)
139139

140140
public byte[] generateSignature() throws CryptoException, DataLengthException
141141
{
142+
if (privKey == null)
143+
{
144+
throw new IllegalStateException("HashSLHDSASigner not initialised for signature generation.");
145+
}
146+
142147
byte[] hash = new byte[digest.getDigestSize()];
143148
digest.doFinal(hash, 0);
144149

@@ -156,6 +161,11 @@ public byte[] generateSignature() throws CryptoException, DataLengthException
156161

157162
public boolean verifySignature(byte[] signature)
158163
{
164+
if (pubKey == null)
165+
{
166+
throw new IllegalStateException("HashSLHDSASigner not initialised for verification");
167+
}
168+
159169
byte[] hash = new byte[digest.getDigestSize()];
160170
digest.doFinal(hash, 0);
161171

‎core/src/main/java/org/bouncycastle/crypto/signers/SLHDSASigner.java‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,11 @@ public void init(boolean forSigning, CipherParameters param)
113113

114114
public byte[] generateSignature(byte[] message)
115115
{
116+
if (privKey == null)
117+
{
118+
throw new IllegalStateException("SLHDSASigner not initialised for signature generation.");
119+
}
120+
116121
if (random != null)
117122
{
118123
random.nextBytes(optRand);
@@ -128,6 +133,11 @@ public byte[] generateSignature(byte[] message)
128133
// Equivalent to slh_verify_internal from specs
129134
public boolean verifySignature(byte[] message, byte[] signature)
130135
{
136+
if (pubKey == null)
137+
{
138+
throw new IllegalStateException("SLHDSASigner not initialised for verification");
139+
}
140+
131141
return SLHDSAEngine.internalVerifySignature(pubKey.getParameters(), pkSeed, pkRoot, msgPrefix, message, signature);
132142
}
133143

‎core/src/main/java/org/bouncycastle/crypto/signers/slhdsa/SLHDSAEngine.java‎

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -463,8 +463,6 @@ public static AsymmetricCipherKeyPair implGenerateKeyPair(SLHDSAParameters param
463463
public static boolean internalVerifySignature(SLHDSAParameters params, byte[] pkSeed, byte[] pkRoot, byte[] msgPrefix, byte[] msg,
464464
byte[] signature)
465465
{
466-
// TODO Check init via pubKey != null
467-
468466
//# Input: Message M, signature SIG, public key PK
469467
//# Output: Boolean
470468

@@ -510,8 +508,6 @@ public static boolean internalVerifySignature(SLHDSAParameters params, byte[] pk
510508
public static byte[] internalGenerateSignature(SLHDSAParameters params, byte[] skSeed, byte[] skPrf, byte[] pkSeed, byte[] pkRoot, byte[] msgPrefix, byte[] msg,
511509
byte[] optRand)
512510
{
513-
// TODO Check init via privKey != null
514-
515511
SLHDSAEngine engine = params.getEngine();
516512
engine.init(pkSeed);
517513

‎core/src/main/java/org/bouncycastle/pqc/crypto/mldsa/MLDSAPrivateKeyParameters.java‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,15 @@ public MLDSAPrivateKeyParameters(MLDSAParameters params, byte[] encoding, MLDSAP
5454
super(true, params);
5555

5656
MLDSAEngine eng = params.getEngine(null);
57+
58+
int expandedKeyLength = 2 * MLDSAEngine.SeedBytes + MLDSAEngine.TrBytes
59+
+ (eng.getDilithiumL() + eng.getDilithiumK()) * eng.getDilithiumPolyEtaPackedBytes()
60+
+ eng.getDilithiumK() * MLDSAEngine.DilithiumPolyT0PackedBytes;
61+
if (encoding.length != MLDSAEngine.SeedBytes && encoding.length != expandedKeyLength)
62+
{
63+
throw new IllegalArgumentException("'encoding' has invalid length");
64+
}
65+
5766
if (encoding.length == MLDSAEngine.SeedBytes)
5867
{
5968
byte[][] keyDetails = eng.generateKeyPairInternal(encoding);

‎core/src/main/java/org/bouncycastle/pqc/crypto/mlkem/MLKEMPrivateKeyParameters.java‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -52,6 +52,13 @@ public MLKEMPrivateKeyParameters(MLKEMParameters params, byte[] encoding, MLKEMP
5252
super(true, params);
5353

5454
MLKEMEngine eng = params.getEngine();
55+
56+
if (encoding.length != MLKEMEngine.SeedBytes &&
57+
encoding.length != eng.getIndCpaSecretKeyBytes() + eng.getIndCpaPublicKeyBytes() + 2 * MLKEMEngine.SymBytes)
58+
{
59+
throw new IllegalArgumentException("'encoding' has invalid length");
60+
}
61+
5562
if (encoding.length == MLKEMEngine.SeedBytes)
5663
{
5764
byte[][] keyData = eng.generateKemKeyPairInternal(

0 commit comments

Comments
 (0)