|
4 | 4 | import java.security.SecureRandom; |
5 | 5 |
|
6 | 6 | import org.bouncycastle.crypto.CipherParameters; |
| 7 | +import org.bouncycastle.crypto.CryptoServicesRegistrar; |
7 | 8 | import org.bouncycastle.crypto.DataLengthException; |
8 | 9 | import org.bouncycastle.crypto.Digest; |
9 | 10 | import org.bouncycastle.crypto.InvalidCipherTextException; |
@@ -68,28 +69,33 @@ public void init(boolean forEncryption, CipherParameters param) |
68 | 69 | { |
69 | 70 | this.forEncryption = forEncryption; |
70 | 71 |
|
71 | | - if (forEncryption) |
| 72 | + SecureRandom providedRandom = null; |
| 73 | + if (param instanceof ParametersWithRandom) |
72 | 74 | { |
73 | | - ParametersWithRandom rParam = (ParametersWithRandom)param; |
| 75 | + ParametersWithRandom withRandom = (ParametersWithRandom)param; |
| 76 | + providedRandom = withRandom.getRandom(); |
| 77 | + param = withRandom.getParameters(); |
| 78 | + } |
74 | 79 |
|
75 | | - ecKey = (ECKeyParameters)rParam.getParameters(); |
76 | | - ecParams = ecKey.getParameters(); |
| 80 | + ecKey = (ECKeyParameters)param; |
| 81 | + ecParams = ecKey.getParameters(); |
| 82 | + |
| 83 | + if (forEncryption) |
| 84 | + { |
| 85 | + random = CryptoServicesRegistrar.getSecureRandom(providedRandom); |
77 | 86 |
|
78 | 87 | ECPoint s = ((ECPublicKeyParameters)ecKey).getQ().multiply(ecParams.getH()); |
79 | 88 | if (s.isInfinity()) |
80 | 89 | { |
81 | 90 | throw new IllegalArgumentException("invalid key: [h]Q at infinity"); |
82 | 91 | } |
83 | | - |
84 | | - random = rParam.getRandom(); |
85 | 92 | } |
86 | 93 | else |
87 | 94 | { |
88 | | - ecKey = (ECKeyParameters)param; |
89 | | - ecParams = ecKey.getParameters(); |
| 95 | + random = null; |
90 | 96 | } |
91 | 97 |
|
92 | | - curveLength = (ecParams.getCurve().getFieldSize() + 7) / 8; |
| 98 | + curveLength = ecParams.getCurve().getFieldElementEncodingLength(); |
93 | 99 | } |
94 | 100 |
|
95 | 101 | public byte[] processBlock( |
@@ -132,22 +138,21 @@ private byte[] encrypt(byte[] in, int inOff, int inLen) |
132 | 138 |
|
133 | 139 | ECMultiplier multiplier = createBasePointMultiplier(); |
134 | 140 |
|
135 | | - byte[] c1; |
| 141 | + BigInteger k; |
136 | 142 | ECPoint kPB; |
137 | 143 | do |
138 | 144 | { |
139 | | - BigInteger k = nextK(); |
140 | | - |
141 | | - ECPoint c1P = multiplier.multiply(ecParams.getG(), k).normalize(); |
142 | | - |
143 | | - c1 = c1P.getEncoded(false); |
144 | | - |
| 145 | + k = nextK(); |
145 | 146 | kPB = ((ECPublicKeyParameters)ecKey).getQ().multiply(k).normalize(); |
146 | 147 |
|
147 | 148 | kdf(digest, kPB, c2); |
148 | 149 | } |
149 | 150 | while (notEncrypted(c2, in, inOff)); |
150 | 151 |
|
| 152 | + ECPoint c1P = multiplier.multiply(ecParams.getG(), k).normalize(); |
| 153 | + |
| 154 | + byte[] c1 = c1P.getEncoded(false); |
| 155 | + |
151 | 156 | byte[] c3 = new byte[digest.getDigestSize()]; |
152 | 157 |
|
153 | 158 | addFieldElement(digest, kPB.getAffineXCoord()); |
@@ -310,8 +315,7 @@ private BigInteger nextK() |
310 | 315 |
|
311 | 316 | private void addFieldElement(Digest digest, ECFieldElement v) |
312 | 317 | { |
313 | | - byte[] p = BigIntegers.asUnsignedByteArray(curveLength, v.toBigInteger()); |
314 | | - |
| 318 | + byte[] p = v.getEncoded(); |
315 | 319 | digest.update(p, 0, p.length); |
316 | 320 | } |
317 | 321 | } |
0 commit comments