18b7521eb38878822be3817270cc074ee1e22095dKenny Root/* 28b7521eb38878822be3817270cc074ee1e22095dKenny Root * Copyright (C) 2012 The Android Open Source Project 38b7521eb38878822be3817270cc074ee1e22095dKenny Root * 48b7521eb38878822be3817270cc074ee1e22095dKenny Root * Licensed under the Apache License, Version 2.0 (the "License"); 58b7521eb38878822be3817270cc074ee1e22095dKenny Root * you may not use this file except in compliance with the License. 68b7521eb38878822be3817270cc074ee1e22095dKenny Root * You may obtain a copy of the License at 78b7521eb38878822be3817270cc074ee1e22095dKenny Root * 88b7521eb38878822be3817270cc074ee1e22095dKenny Root * http://www.apache.org/licenses/LICENSE-2.0 98b7521eb38878822be3817270cc074ee1e22095dKenny Root * 108b7521eb38878822be3817270cc074ee1e22095dKenny Root * Unless required by applicable law or agreed to in writing, software 118b7521eb38878822be3817270cc074ee1e22095dKenny Root * distributed under the License is distributed on an "AS IS" BASIS, 128b7521eb38878822be3817270cc074ee1e22095dKenny Root * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 138b7521eb38878822be3817270cc074ee1e22095dKenny Root * See the License for the specific language governing permissions and 148b7521eb38878822be3817270cc074ee1e22095dKenny Root * limitations under the License. 158b7521eb38878822be3817270cc074ee1e22095dKenny Root */ 168b7521eb38878822be3817270cc074ee1e22095dKenny Root 17860d2707ce126ef8f66e3eac7ceeab6d24218cd8Kenny Rootpackage org.conscrypt; 188b7521eb38878822be3817270cc074ee1e22095dKenny Root 198b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.IOException; 208b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.NotSerializableException; 218b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.ObjectInputStream; 228b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.ObjectOutputStream; 238b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.InvalidKeyException; 248b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.interfaces.ECPublicKey; 258b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.spec.ECParameterSpec; 268b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.spec.ECPoint; 2711b3e7025853f061e2f0e0ce1e248e730eca721eKenny Rootimport java.security.spec.ECPublicKeySpec; 2811b3e7025853f061e2f0e0ce1e248e730eca721eKenny Rootimport java.security.spec.InvalidKeySpecException; 298b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.util.Arrays; 308b7521eb38878822be3817270cc074ee1e22095dKenny Root 3147cc520bd63c1eabfdef23cbab10457701f2a395Kenny Rootpublic final class OpenSSLECPublicKey implements ECPublicKey, OpenSSLKeyHolder { 328b7521eb38878822be3817270cc074ee1e22095dKenny Root private static final long serialVersionUID = 3215842926808298020L; 338b7521eb38878822be3817270cc074ee1e22095dKenny Root 348b7521eb38878822be3817270cc074ee1e22095dKenny Root private static final String ALGORITHM = "EC"; 358b7521eb38878822be3817270cc074ee1e22095dKenny Root 368b7521eb38878822be3817270cc074ee1e22095dKenny Root protected transient OpenSSLKey key; 378b7521eb38878822be3817270cc074ee1e22095dKenny Root 388b7521eb38878822be3817270cc074ee1e22095dKenny Root protected transient OpenSSLECGroupContext group; 398b7521eb38878822be3817270cc074ee1e22095dKenny Root 408b7521eb38878822be3817270cc074ee1e22095dKenny Root public OpenSSLECPublicKey(OpenSSLECGroupContext group, OpenSSLKey key) { 418b7521eb38878822be3817270cc074ee1e22095dKenny Root this.group = group; 428b7521eb38878822be3817270cc074ee1e22095dKenny Root this.key = key; 438b7521eb38878822be3817270cc074ee1e22095dKenny Root } 448b7521eb38878822be3817270cc074ee1e22095dKenny Root 4547cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root public OpenSSLECPublicKey(OpenSSLKey key) { 4638c70d393f14cf0963a289caefb72e6ac14e23d3Joel Dice final long origGroup = NativeCrypto.EC_KEY_get0_group(key.getPkeyContext()); 4747cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root this.group = new OpenSSLECGroupContext(NativeCrypto.EC_GROUP_dup(origGroup)); 4847cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root this.key = key; 4947cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root } 5047cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root 5111b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root public OpenSSLECPublicKey(ECPublicKeySpec ecKeySpec) throws InvalidKeySpecException { 5211b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root try { 53d4600d69dba0f1df24e8df7328fa473632c32822Kenny Root group = OpenSSLECGroupContext.getInstance(ecKeySpec.getParams()); 5411b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root OpenSSLECPointContext pubKey = OpenSSLECPointContext.getInstance( 5511b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root NativeCrypto.get_EC_GROUP_type(group.getContext()), group, ecKeySpec.getW()); 5611b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root key = new OpenSSLKey(NativeCrypto.EVP_PKEY_new_EC_KEY(group.getContext(), 5711b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root pubKey.getContext(), null)); 5811b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root } catch (Exception e) { 5911b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root throw new InvalidKeySpecException(e); 6011b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root } 6111b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root } 6211b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root 638b7521eb38878822be3817270cc074ee1e22095dKenny Root public static OpenSSLKey getInstance(ECPublicKey ecPublicKey) throws InvalidKeyException { 648b7521eb38878822be3817270cc074ee1e22095dKenny Root try { 658b7521eb38878822be3817270cc074ee1e22095dKenny Root OpenSSLECGroupContext group = OpenSSLECGroupContext 668b7521eb38878822be3817270cc074ee1e22095dKenny Root .getInstance(ecPublicKey.getParams()); 678b7521eb38878822be3817270cc074ee1e22095dKenny Root OpenSSLECPointContext pubKey = OpenSSLECPointContext.getInstance( 688b7521eb38878822be3817270cc074ee1e22095dKenny Root NativeCrypto.get_EC_GROUP_type(group.getContext()), group, ecPublicKey.getW()); 698b7521eb38878822be3817270cc074ee1e22095dKenny Root return new OpenSSLKey(NativeCrypto.EVP_PKEY_new_EC_KEY(group.getContext(), 708b7521eb38878822be3817270cc074ee1e22095dKenny Root pubKey.getContext(), null)); 718b7521eb38878822be3817270cc074ee1e22095dKenny Root } catch (Exception e) { 728b7521eb38878822be3817270cc074ee1e22095dKenny Root throw new InvalidKeyException(e); 738b7521eb38878822be3817270cc074ee1e22095dKenny Root } 748b7521eb38878822be3817270cc074ee1e22095dKenny Root } 758b7521eb38878822be3817270cc074ee1e22095dKenny Root 768b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 778b7521eb38878822be3817270cc074ee1e22095dKenny Root public String getAlgorithm() { 788b7521eb38878822be3817270cc074ee1e22095dKenny Root return ALGORITHM; 798b7521eb38878822be3817270cc074ee1e22095dKenny Root } 808b7521eb38878822be3817270cc074ee1e22095dKenny Root 818b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 828b7521eb38878822be3817270cc074ee1e22095dKenny Root public String getFormat() { 838b7521eb38878822be3817270cc074ee1e22095dKenny Root return "X.509"; 848b7521eb38878822be3817270cc074ee1e22095dKenny Root } 858b7521eb38878822be3817270cc074ee1e22095dKenny Root 868b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 878b7521eb38878822be3817270cc074ee1e22095dKenny Root public byte[] getEncoded() { 888b7521eb38878822be3817270cc074ee1e22095dKenny Root return NativeCrypto.i2d_PUBKEY(key.getPkeyContext()); 898b7521eb38878822be3817270cc074ee1e22095dKenny Root } 908b7521eb38878822be3817270cc074ee1e22095dKenny Root 918b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 928b7521eb38878822be3817270cc074ee1e22095dKenny Root public ECParameterSpec getParams() { 938b7521eb38878822be3817270cc074ee1e22095dKenny Root return group.getECParameterSpec(); 948b7521eb38878822be3817270cc074ee1e22095dKenny Root } 958b7521eb38878822be3817270cc074ee1e22095dKenny Root 968b7521eb38878822be3817270cc074ee1e22095dKenny Root private ECPoint getPublicKey() { 978b7521eb38878822be3817270cc074ee1e22095dKenny Root final OpenSSLECPointContext pubKey = new OpenSSLECPointContext(group, 988b7521eb38878822be3817270cc074ee1e22095dKenny Root NativeCrypto.EC_KEY_get_public_key(key.getPkeyContext())); 998b7521eb38878822be3817270cc074ee1e22095dKenny Root 1008b7521eb38878822be3817270cc074ee1e22095dKenny Root return pubKey.getECPoint(); 1018b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1028b7521eb38878822be3817270cc074ee1e22095dKenny Root 1038b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1048b7521eb38878822be3817270cc074ee1e22095dKenny Root public ECPoint getW() { 1058b7521eb38878822be3817270cc074ee1e22095dKenny Root return getPublicKey(); 1068b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1078b7521eb38878822be3817270cc074ee1e22095dKenny Root 10847cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root @Override 1098b7521eb38878822be3817270cc074ee1e22095dKenny Root public OpenSSLKey getOpenSSLKey() { 1108b7521eb38878822be3817270cc074ee1e22095dKenny Root return key; 1118b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1128b7521eb38878822be3817270cc074ee1e22095dKenny Root 1138b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1148b7521eb38878822be3817270cc074ee1e22095dKenny Root public boolean equals(Object o) { 1158b7521eb38878822be3817270cc074ee1e22095dKenny Root if (o == this) { 1168b7521eb38878822be3817270cc074ee1e22095dKenny Root return true; 1178b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1188b7521eb38878822be3817270cc074ee1e22095dKenny Root 1198b7521eb38878822be3817270cc074ee1e22095dKenny Root if (o instanceof OpenSSLECPrivateKey) { 1208b7521eb38878822be3817270cc074ee1e22095dKenny Root OpenSSLECPrivateKey other = (OpenSSLECPrivateKey) o; 1218b7521eb38878822be3817270cc074ee1e22095dKenny Root return key.equals(other.key); 1228b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1238b7521eb38878822be3817270cc074ee1e22095dKenny Root 1248b7521eb38878822be3817270cc074ee1e22095dKenny Root if (!(o instanceof ECPublicKey)) { 1258b7521eb38878822be3817270cc074ee1e22095dKenny Root return false; 1268b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1278b7521eb38878822be3817270cc074ee1e22095dKenny Root 1288b7521eb38878822be3817270cc074ee1e22095dKenny Root final ECPublicKey other = (ECPublicKey) o; 1298b7521eb38878822be3817270cc074ee1e22095dKenny Root if (!getPublicKey().equals(other.getW())) { 1308b7521eb38878822be3817270cc074ee1e22095dKenny Root return false; 1318b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1328b7521eb38878822be3817270cc074ee1e22095dKenny Root 1338b7521eb38878822be3817270cc074ee1e22095dKenny Root final ECParameterSpec spec = getParams(); 1348b7521eb38878822be3817270cc074ee1e22095dKenny Root final ECParameterSpec otherSpec = other.getParams(); 1358b7521eb38878822be3817270cc074ee1e22095dKenny Root 1368b7521eb38878822be3817270cc074ee1e22095dKenny Root return spec.getCurve().equals(otherSpec.getCurve()) 1378b7521eb38878822be3817270cc074ee1e22095dKenny Root && spec.getGenerator().equals(otherSpec.getGenerator()) 1388b7521eb38878822be3817270cc074ee1e22095dKenny Root && spec.getOrder().equals(otherSpec.getOrder()) 1398b7521eb38878822be3817270cc074ee1e22095dKenny Root && spec.getCofactor() == otherSpec.getCofactor(); 1408b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1418b7521eb38878822be3817270cc074ee1e22095dKenny Root 1428b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1438b7521eb38878822be3817270cc074ee1e22095dKenny Root public int hashCode() { 1448b7521eb38878822be3817270cc074ee1e22095dKenny Root return Arrays.hashCode(NativeCrypto.i2d_PUBKEY(key.getPkeyContext())); 1458b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1468b7521eb38878822be3817270cc074ee1e22095dKenny Root 1478b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1488b7521eb38878822be3817270cc074ee1e22095dKenny Root public String toString() { 1498b7521eb38878822be3817270cc074ee1e22095dKenny Root return NativeCrypto.EVP_PKEY_print_public(key.getPkeyContext()); 1508b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1518b7521eb38878822be3817270cc074ee1e22095dKenny Root 1528b7521eb38878822be3817270cc074ee1e22095dKenny Root private void readObject(ObjectInputStream stream) throws IOException, ClassNotFoundException { 1538b7521eb38878822be3817270cc074ee1e22095dKenny Root stream.defaultReadObject(); 1548b7521eb38878822be3817270cc074ee1e22095dKenny Root 1555b36f6cc5f013574dc453e8938fcae13185c7732Kenny Root byte[] encoded = (byte[]) stream.readObject(); 1568b7521eb38878822be3817270cc074ee1e22095dKenny Root 1575b36f6cc5f013574dc453e8938fcae13185c7732Kenny Root key = new OpenSSLKey(NativeCrypto.d2i_PUBKEY(encoded)); 1588b7521eb38878822be3817270cc074ee1e22095dKenny Root 15938c70d393f14cf0963a289caefb72e6ac14e23d3Joel Dice final long origGroup = NativeCrypto.EC_KEY_get0_group(key.getPkeyContext()); 1605b36f6cc5f013574dc453e8938fcae13185c7732Kenny Root group = new OpenSSLECGroupContext(NativeCrypto.EC_GROUP_dup(origGroup)); 1618b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1628b7521eb38878822be3817270cc074ee1e22095dKenny Root 1638b7521eb38878822be3817270cc074ee1e22095dKenny Root private void writeObject(ObjectOutputStream stream) throws IOException { 1648b7521eb38878822be3817270cc074ee1e22095dKenny Root if (key.isEngineBased()) { 1658b7521eb38878822be3817270cc074ee1e22095dKenny Root throw new NotSerializableException("engine-based keys can not be serialized"); 1668b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1678b7521eb38878822be3817270cc074ee1e22095dKenny Root 1688b7521eb38878822be3817270cc074ee1e22095dKenny Root stream.defaultWriteObject(); 1695b36f6cc5f013574dc453e8938fcae13185c7732Kenny Root stream.writeObject(getEncoded()); 1708b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1718b7521eb38878822be3817270cc074ee1e22095dKenny Root} 172