18b7521eb38878822be3817270cc074ee1e22095dKenny Root/* 28b7521eb38878822be3817270cc074ee1e22095dKenny Root * Copyright (C) 2012 The Android Open Source Project 38b7521eb38878822be3817270cc074ee1e22095dKenny Root * 48b7521eb38878822be3817270cc074ee1e22095dKenny Root * Licensed under the Apache License, Version 2.0 (the "License"); 58b7521eb38878822be3817270cc074ee1e22095dKenny Root * you may not use this file except in compliance with the License. 68b7521eb38878822be3817270cc074ee1e22095dKenny Root * You may obtain a copy of the License at 78b7521eb38878822be3817270cc074ee1e22095dKenny Root * 88b7521eb38878822be3817270cc074ee1e22095dKenny Root * http://www.apache.org/licenses/LICENSE-2.0 98b7521eb38878822be3817270cc074ee1e22095dKenny Root * 108b7521eb38878822be3817270cc074ee1e22095dKenny Root * Unless required by applicable law or agreed to in writing, software 118b7521eb38878822be3817270cc074ee1e22095dKenny Root * distributed under the License is distributed on an "AS IS" BASIS, 128b7521eb38878822be3817270cc074ee1e22095dKenny Root * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 138b7521eb38878822be3817270cc074ee1e22095dKenny Root * See the License for the specific language governing permissions and 148b7521eb38878822be3817270cc074ee1e22095dKenny Root * limitations under the License. 158b7521eb38878822be3817270cc074ee1e22095dKenny Root */ 168b7521eb38878822be3817270cc074ee1e22095dKenny Root 17860d2707ce126ef8f66e3eac7ceeab6d24218cd8Kenny Rootpackage org.conscrypt; 188b7521eb38878822be3817270cc074ee1e22095dKenny Root 198b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.IOException; 208b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.ObjectInputStream; 218b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.io.ObjectOutputStream; 228b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.InvalidKeyException; 238b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.interfaces.ECPublicKey; 248b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.spec.ECParameterSpec; 258b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.security.spec.ECPoint; 2611b3e7025853f061e2f0e0ce1e248e730eca721eKenny Rootimport java.security.spec.ECPublicKeySpec; 2711b3e7025853f061e2f0e0ce1e248e730eca721eKenny Rootimport java.security.spec.InvalidKeySpecException; 288b7521eb38878822be3817270cc074ee1e22095dKenny Rootimport java.util.Arrays; 298b7521eb38878822be3817270cc074ee1e22095dKenny Root 305070bdfc6277af136b7eb5fe5d0d72ad2ff6a2ebKenny Root/** 315070bdfc6277af136b7eb5fe5d0d72ad2ff6a2ebKenny Root * An implementation of a {@link java.security.PublicKey} for EC keys based on BoringSSL. 325070bdfc6277af136b7eb5fe5d0d72ad2ff6a2ebKenny Root */ 3329916ef38dc9cb4e4c6e3fdb87d4e921546d3ef4Nathan Mittlerfinal class OpenSSLECPublicKey implements ECPublicKey, OpenSSLKeyHolder { 348b7521eb38878822be3817270cc074ee1e22095dKenny Root private static final long serialVersionUID = 3215842926808298020L; 358b7521eb38878822be3817270cc074ee1e22095dKenny Root 368b7521eb38878822be3817270cc074ee1e22095dKenny Root private static final String ALGORITHM = "EC"; 378b7521eb38878822be3817270cc074ee1e22095dKenny Root 388b7521eb38878822be3817270cc074ee1e22095dKenny Root protected transient OpenSSLKey key; 398b7521eb38878822be3817270cc074ee1e22095dKenny Root 408b7521eb38878822be3817270cc074ee1e22095dKenny Root protected transient OpenSSLECGroupContext group; 418b7521eb38878822be3817270cc074ee1e22095dKenny Root 4229916ef38dc9cb4e4c6e3fdb87d4e921546d3ef4Nathan Mittler OpenSSLECPublicKey(OpenSSLECGroupContext group, OpenSSLKey key) { 438b7521eb38878822be3817270cc074ee1e22095dKenny Root this.group = group; 448b7521eb38878822be3817270cc074ee1e22095dKenny Root this.key = key; 458b7521eb38878822be3817270cc074ee1e22095dKenny Root } 468b7521eb38878822be3817270cc074ee1e22095dKenny Root 4729916ef38dc9cb4e4c6e3fdb87d4e921546d3ef4Nathan Mittler OpenSSLECPublicKey(OpenSSLKey key) { 487dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root this.group = new OpenSSLECGroupContext(new NativeRef.EC_GROUP( 497dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root NativeCrypto.EC_KEY_get1_group(key.getNativeRef()))); 5047cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root this.key = key; 5147cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root } 5247cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root 5329916ef38dc9cb4e4c6e3fdb87d4e921546d3ef4Nathan Mittler OpenSSLECPublicKey(ECPublicKeySpec ecKeySpec) throws InvalidKeySpecException { 5411b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root try { 55d4600d69dba0f1df24e8df7328fa473632c32822Kenny Root group = OpenSSLECGroupContext.getInstance(ecKeySpec.getParams()); 56597fd4e460c114003257d1b007d1b75c53af9fd7Kenny Root OpenSSLECPointContext pubKey = OpenSSLECPointContext.getInstance(group, 57597fd4e460c114003257d1b007d1b75c53af9fd7Kenny Root ecKeySpec.getW()); 587dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root key = new OpenSSLKey(NativeCrypto.EVP_PKEY_new_EC_KEY(group.getNativeRef(), 597dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root pubKey.getNativeRef(), null)); 6011b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root } catch (Exception e) { 6111b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root throw new InvalidKeySpecException(e); 6211b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root } 6311b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root } 6411b3e7025853f061e2f0e0ce1e248e730eca721eKenny Root 6529916ef38dc9cb4e4c6e3fdb87d4e921546d3ef4Nathan Mittler static OpenSSLKey getInstance(ECPublicKey ecPublicKey) throws InvalidKeyException { 668b7521eb38878822be3817270cc074ee1e22095dKenny Root try { 678b7521eb38878822be3817270cc074ee1e22095dKenny Root OpenSSLECGroupContext group = OpenSSLECGroupContext 688b7521eb38878822be3817270cc074ee1e22095dKenny Root .getInstance(ecPublicKey.getParams()); 69597fd4e460c114003257d1b007d1b75c53af9fd7Kenny Root OpenSSLECPointContext pubKey = OpenSSLECPointContext.getInstance(group, 707dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root ecPublicKey.getW()); 717dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root return new OpenSSLKey(NativeCrypto.EVP_PKEY_new_EC_KEY(group.getNativeRef(), 727dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root pubKey.getNativeRef(), null)); 738b7521eb38878822be3817270cc074ee1e22095dKenny Root } catch (Exception e) { 748b7521eb38878822be3817270cc074ee1e22095dKenny Root throw new InvalidKeyException(e); 758b7521eb38878822be3817270cc074ee1e22095dKenny Root } 768b7521eb38878822be3817270cc074ee1e22095dKenny Root } 778b7521eb38878822be3817270cc074ee1e22095dKenny Root 788b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 798b7521eb38878822be3817270cc074ee1e22095dKenny Root public String getAlgorithm() { 808b7521eb38878822be3817270cc074ee1e22095dKenny Root return ALGORITHM; 818b7521eb38878822be3817270cc074ee1e22095dKenny Root } 828b7521eb38878822be3817270cc074ee1e22095dKenny Root 838b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 848b7521eb38878822be3817270cc074ee1e22095dKenny Root public String getFormat() { 858b7521eb38878822be3817270cc074ee1e22095dKenny Root return "X.509"; 868b7521eb38878822be3817270cc074ee1e22095dKenny Root } 878b7521eb38878822be3817270cc074ee1e22095dKenny Root 888b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 898b7521eb38878822be3817270cc074ee1e22095dKenny Root public byte[] getEncoded() { 90042a13e300915ae9db452d105293b2315cd72590David Benjamin return NativeCrypto.EVP_marshal_public_key(key.getNativeRef()); 918b7521eb38878822be3817270cc074ee1e22095dKenny Root } 928b7521eb38878822be3817270cc074ee1e22095dKenny Root 938b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 948b7521eb38878822be3817270cc074ee1e22095dKenny Root public ECParameterSpec getParams() { 958b7521eb38878822be3817270cc074ee1e22095dKenny Root return group.getECParameterSpec(); 968b7521eb38878822be3817270cc074ee1e22095dKenny Root } 978b7521eb38878822be3817270cc074ee1e22095dKenny Root 988b7521eb38878822be3817270cc074ee1e22095dKenny Root private ECPoint getPublicKey() { 998b7521eb38878822be3817270cc074ee1e22095dKenny Root final OpenSSLECPointContext pubKey = new OpenSSLECPointContext(group, 1007dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root new NativeRef.EC_POINT(NativeCrypto.EC_KEY_get_public_key(key.getNativeRef()))); 1018b7521eb38878822be3817270cc074ee1e22095dKenny Root 1028b7521eb38878822be3817270cc074ee1e22095dKenny Root return pubKey.getECPoint(); 1038b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1048b7521eb38878822be3817270cc074ee1e22095dKenny Root 1058b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1068b7521eb38878822be3817270cc074ee1e22095dKenny Root public ECPoint getW() { 1078b7521eb38878822be3817270cc074ee1e22095dKenny Root return getPublicKey(); 1088b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1098b7521eb38878822be3817270cc074ee1e22095dKenny Root 11047cc520bd63c1eabfdef23cbab10457701f2a395Kenny Root @Override 1118b7521eb38878822be3817270cc074ee1e22095dKenny Root public OpenSSLKey getOpenSSLKey() { 1128b7521eb38878822be3817270cc074ee1e22095dKenny Root return key; 1138b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1148b7521eb38878822be3817270cc074ee1e22095dKenny Root 1158b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1168b7521eb38878822be3817270cc074ee1e22095dKenny Root public boolean equals(Object o) { 1178b7521eb38878822be3817270cc074ee1e22095dKenny Root if (o == this) { 1188b7521eb38878822be3817270cc074ee1e22095dKenny Root return true; 1198b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1208b7521eb38878822be3817270cc074ee1e22095dKenny Root 121cac9de82cc0c50ff1a20d1290339776c125fc63eKenny Root if (o instanceof OpenSSLECPublicKey) { 122cac9de82cc0c50ff1a20d1290339776c125fc63eKenny Root OpenSSLECPublicKey other = (OpenSSLECPublicKey) o; 1238b7521eb38878822be3817270cc074ee1e22095dKenny Root return key.equals(other.key); 1248b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1258b7521eb38878822be3817270cc074ee1e22095dKenny Root 1268b7521eb38878822be3817270cc074ee1e22095dKenny Root if (!(o instanceof ECPublicKey)) { 1278b7521eb38878822be3817270cc074ee1e22095dKenny Root return false; 1288b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1298b7521eb38878822be3817270cc074ee1e22095dKenny Root 1308b7521eb38878822be3817270cc074ee1e22095dKenny Root final ECPublicKey other = (ECPublicKey) o; 1318b7521eb38878822be3817270cc074ee1e22095dKenny Root if (!getPublicKey().equals(other.getW())) { 1328b7521eb38878822be3817270cc074ee1e22095dKenny Root return false; 1338b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1348b7521eb38878822be3817270cc074ee1e22095dKenny Root 1358b7521eb38878822be3817270cc074ee1e22095dKenny Root final ECParameterSpec spec = getParams(); 1368b7521eb38878822be3817270cc074ee1e22095dKenny Root final ECParameterSpec otherSpec = other.getParams(); 1378b7521eb38878822be3817270cc074ee1e22095dKenny Root 1388b7521eb38878822be3817270cc074ee1e22095dKenny Root return spec.getCurve().equals(otherSpec.getCurve()) 1398b7521eb38878822be3817270cc074ee1e22095dKenny Root && spec.getGenerator().equals(otherSpec.getGenerator()) 1408b7521eb38878822be3817270cc074ee1e22095dKenny Root && spec.getOrder().equals(otherSpec.getOrder()) 1418b7521eb38878822be3817270cc074ee1e22095dKenny Root && spec.getCofactor() == otherSpec.getCofactor(); 1428b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1438b7521eb38878822be3817270cc074ee1e22095dKenny Root 1448b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1458b7521eb38878822be3817270cc074ee1e22095dKenny Root public int hashCode() { 146042a13e300915ae9db452d105293b2315cd72590David Benjamin return Arrays.hashCode(NativeCrypto.EVP_marshal_public_key(key.getNativeRef())); 1478b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1488b7521eb38878822be3817270cc074ee1e22095dKenny Root 1498b7521eb38878822be3817270cc074ee1e22095dKenny Root @Override 1508b7521eb38878822be3817270cc074ee1e22095dKenny Root public String toString() { 15137e58bbef60b18389074d8ef8a8c470e47f3d7eeKenny Root return NativeCrypto.EVP_PKEY_print_public(key.getNativeRef()); 1528b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1538b7521eb38878822be3817270cc074ee1e22095dKenny Root 1548b7521eb38878822be3817270cc074ee1e22095dKenny Root private void readObject(ObjectInputStream stream) throws IOException, ClassNotFoundException { 1558b7521eb38878822be3817270cc074ee1e22095dKenny Root stream.defaultReadObject(); 1568b7521eb38878822be3817270cc074ee1e22095dKenny Root 1575b36f6cc5f013574dc453e8938fcae13185c7732Kenny Root byte[] encoded = (byte[]) stream.readObject(); 1588b7521eb38878822be3817270cc074ee1e22095dKenny Root 159042a13e300915ae9db452d105293b2315cd72590David Benjamin key = new OpenSSLKey(NativeCrypto.EVP_parse_public_key(encoded)); 1607dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root group = new OpenSSLECGroupContext(new NativeRef.EC_GROUP( 1617dc06b9e323ba7f227709b5941324f9c3a46fe4fKenny Root NativeCrypto.EC_KEY_get1_group(key.getNativeRef()))); 1628b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1638b7521eb38878822be3817270cc074ee1e22095dKenny Root 1648b7521eb38878822be3817270cc074ee1e22095dKenny Root private void writeObject(ObjectOutputStream stream) throws IOException { 1658b7521eb38878822be3817270cc074ee1e22095dKenny Root stream.defaultWriteObject(); 1665b36f6cc5f013574dc453e8938fcae13185c7732Kenny Root stream.writeObject(getEncoded()); 1678b7521eb38878822be3817270cc074ee1e22095dKenny Root } 1688b7521eb38878822be3817270cc074ee1e22095dKenny Root} 169