public class CMSAlgorithmProtection
extends iaik.asn1.structures.AttributeValue
The CMSAlgorithmProtection attribute is specified to protect the digest algorithm and mac or signature algorithm identifiers of CMS AuthenticatedData or CMS SignedData/SignerInfo structures by including them into the signed attributes. Depending of used with AuthenticatedData or SignedData/SignerInfo either mac algorithm identifier or signature algorithm identifier (but not both together) must be present (see RFC 6211):
CMSAlgorithmProtection ::= SEQUENCE {
digestAlgorithm DigestAlgorithmIdentifier,
signatureAlgorithm [1] SignatureAlgorithmIdentifier OPTIONAL,
macAlgorithm [2] MessageAuthenticationCodeAlgorithm
OPTIONAL
}
(WITH COMPONENTS { signatureAlgorithm PRESENT,
macAlgorithm ABSENT } |
WITH COMPONENTS { signatureAlgorithm ABSENT,
macAlgorithm PRESENT })
When creating a CMSAlgorithmProtection attribute digest
and mac/signature algorithm may be set manually or directly got from the
AuthenticatedData or SignerInfo object (e.g. for SignerInfo):
SignerInfo signerInfo = ...; Attribute[] attributes = new Attribute[..]; .. CMSAlgorithmProtection cmsAlgorithmProtection = new CMSAlgorithmProtection(signerInfo); attributes[..] = new Attribute(cmsAlgorithmProtection); ... // set the attributes signerInfo.setSignedAttributes(attributes);When parsing an AuthernticatedData/SignerInfo the
CMSAlgorithmProtection attribute
may be queried for validating the AuthernticatedData/SignerInfo digest and mac/signature
algorithms, e.g.:
SignerInfo signerInfo = ...;
CMSAlgorithmProtection cmsAlgorithmProtection = (CMSAlgorithmProtection)signerInfo.getSignedAttributeValue(CMSAlgorithmProtection.oid);
if (cmsAlgorithmProtection != null) {
cmsAlgorithmProtection.validateSignerInfo(signerInfo);
}
SignerInfo,
AuthenticatedData| Modifier and Type | Field and Description |
|---|---|
static iaik.asn1.ObjectID |
oid
The attributeType object identifier of the CMS ContentType attribute.
|
| Constructor and Description |
|---|
CMSAlgorithmProtection()
Empty default constructor.
|
CMSAlgorithmProtection(iaik.asn1.structures.AlgorithmID digestAlgorithm)
Creates a CMSAlgorithmProtection attribute from the given digest algorithm.
|
CMSAlgorithmProtection(iaik.asn1.ASN1Object obj)
Creates an CMS CMSAlgorithmProtection from its ASN.1 representation.
|
CMSAlgorithmProtection(AuthenticatedDataStream authenticatedData)
Creates a CMSAlgorithmProtection attribute for the given CMS AuthenticatedData.
|
CMSAlgorithmProtection(SignerInfo signerInfo)
Creates a CMSAlgorithmProtection attribute for the given CMS SignerInfo.
|
| Modifier and Type | Method and Description |
|---|---|
void |
decode(iaik.asn1.ASN1Object obj)
Decodes the given ASN.1
CMAlgorihmProtecion object for parsing
the internal structure. |
boolean |
equals(java.lang.Object obj)
Compares this
CMSAlgorithmProtection to the specified object. |
iaik.asn1.ObjectID |
getAttributeType()
Returns the OID identifying the CMAlgorihmProtecion attribute type.
|
iaik.asn1.structures.AlgorithmID |
getDigestAlgorithm()
Gets the digest algorithm.
|
iaik.asn1.structures.AlgorithmID |
getMacAlgorithm()
Gets the AuthenticatedData mac algorithm.
|
iaik.asn1.structures.AlgorithmID |
getSignatureAlgorithm()
Gets the SignerInfo signature algorithm.
|
int |
hashCode()
Returns a hashcode for this object.
|
boolean |
multipleAllowed()
Returns
false since only one AttributeValue is
allowed in the SET OF AttributeValue of an CMAlgorihmProtecion attribute. |
void |
setMacAlgorithm(iaik.asn1.structures.AlgorithmID macAlgorithm)
Sets the AuthenticatedData mac algorithm.
|
void |
setSignatureAlgorithm(iaik.asn1.structures.AlgorithmID signatureAlgorithm)
Sets the SignerInfo signature algorithm.
|
iaik.asn1.ASN1Object |
toASN1Object()
Returns this CMAlgorihmProtecion as ASN1Object.
|
java.lang.String |
toString()
Returns a string representation of this CMAlgorihmProtecion.
|
void |
validateAuthenticatedData(AuthenticatedDataStream authenticatedData)
Validates the given AuthenticatedData against this CMSAlgorithmProtection attribute.
|
void |
validateSignerInfo(SignerInfo signerInfo)
Validates the given SignerInfo against this CMSAlgorithmProtection attribute.
|
public static final iaik.asn1.ObjectID oid
public CMSAlgorithmProtection()
public CMSAlgorithmProtection(iaik.asn1.structures.AlgorithmID digestAlgorithm)
digestAlgorithm - the digest algorithmpublic CMSAlgorithmProtection(SignerInfo signerInfo)
signerInfo - the CMS SignerInfopublic CMSAlgorithmProtection(AuthenticatedDataStream authenticatedData)
authenticatedData - the CMS AuthenticatedDatapublic CMSAlgorithmProtection(iaik.asn1.ASN1Object obj)
throws iaik.asn1.CodingException
obj - the CMS CMSAlgorithmProtection as ASN1Objectiaik.asn1.CodingException - if an error occurs when parsing the ASN.1 objectpublic iaik.asn1.structures.AlgorithmID getDigestAlgorithm()
public void setSignatureAlgorithm(iaik.asn1.structures.AlgorithmID signatureAlgorithm)
signatureAlgorithm - the SignerInfo signature algorithmjava.lang.IllegalArgumentException - if the mac algorithm has been already setpublic iaik.asn1.structures.AlgorithmID getSignatureAlgorithm()
null if the signature algorithm has not been setpublic void setMacAlgorithm(iaik.asn1.structures.AlgorithmID macAlgorithm)
macAlgorithm - the AuthenticatedData mac algorithmjava.lang.IllegalArgumentException - if the signature algorithm has been already setpublic iaik.asn1.structures.AlgorithmID getMacAlgorithm()
null if the mac algorithm has not been setpublic void decode(iaik.asn1.ASN1Object obj)
throws iaik.asn1.CodingException
CMAlgorihmProtecion object for parsing
the internal structure.obj - the CMAlgorihmProtecion as ASN1Objectiaik.asn1.CodingException - if an error occurs when parsing the ASN.1 CMAlgorihmProtecionpublic iaik.asn1.ASN1Object toASN1Object()
throws iaik.asn1.CodingException
iaik.asn1.CodingException - if the ASN1Object cannot be builtpublic iaik.asn1.ObjectID getAttributeType()
getAttributeType in class iaik.asn1.structures.AttributeValuepublic boolean multipleAllowed()
false since only one AttributeValue is
allowed in the SET OF AttributeValue of an CMAlgorihmProtecion attribute.multipleAllowed in class iaik.asn1.structures.AttributeValuefalse since only one attribute value is allowedpublic void validateSignerInfo(SignerInfo signerInfo) throws CMSException
This method checks if digest and signature algorithm of the given SignerInfo comply with digest and signature algorithm of this CMSAlgorithmProtection attribute. This method does NOT check if this CMSAlgorithmProtection attribute is actually included in the given SignerInfo. It is assumed that the attribute first is got from the SignerInfo:
SignerInfo signerInfo = ...;
CMSAlgorithmProtection cmsAlgorithmProtection = (CMSAlgorithmProtection)ad.getSigneddAttributeVaue(CMSAlgorithmProtection.oid);
if (cmsAlgorithmProtection != null) {
cmsAlgorithmProtection.validated(signerInfo);
}
signerInfo - the SignerInfo to be validatedCMSException - if the validation fails for some reasonpublic void validateAuthenticatedData(AuthenticatedDataStream authenticatedData) throws CMSException
This method checks if digest and mac algorithm of the given AuthenticatedData comply with digest and mac algorithm of this CMSAlgorithmProtection attribute. This method does NOT check if this CMSAlgorithmProtection attribute is actually included in the given AuthenticatedData. It is assumed that the attribute first is got from the AuthenticatedData:
AuthenticatedData ad = ...;
Attribute attribute = authenticatedData.getAuthenticatedAttribute(CMSAlgorithmProtection.oid);
if (attribute != null) {
CMSAlgorithmProtection cmsAlgorithmProtection = (CMSAlgorithmProtection)attribute.getAttributeValue();
cmsAlgorithmProtection.validated(ad);
}
authenticatedData - the AuthenticatedData to be validatedCMSException - if the validation fails for some reasonpublic boolean equals(java.lang.Object obj)
CMSAlgorithmProtection to the specified object.equals in class java.lang.Objectobj - the object to compare this CMSAlgorithmProtection
against.true, if the given object is equal to this
CMSAlgorithmProtection,
false otherwisepublic int hashCode()
hashCode in class java.lang.Objectpublic java.lang.String toString()
toString in class iaik.asn1.structures.AttributeValue