Class KEM.Encapsulator

java.lang.Object
javax.crypto.KEM.Encapsulator
Enclosing class:
KEM

public static final class KEM.Encapsulator extends Object
An encapsulator, generated by KEM.newEncapsulator(PublicKey) on the KEM sender side.

This class represents the key encapsulation function of a KEM. Each invocation of the encapsulate method generates a new secret key and key encapsulation message that is returned in an KEM.Encapsulated object.

Since:
21
  • Method Summary

    Modifier and Type
    Method
    Description
    The key encapsulation function.
    encapsulate(int from, int to, String algorithm)
    The key encapsulation function.
    int
    Returns the size of the key encapsulation message.
    Returns the name of the provider.
    int
    Returns the size of the shared secret.

    Methods declared in class Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
    Modifier and Type
    Method
    Description
    protected Object
    Answers a new instance of the same class as the receiver, whose slots have been filled in with the values in the slots of the receiver.
    boolean
    Compares the argument to the receiver, and answers true if they represent the same object using a class specific comparison.
    protected void
    Deprecated, for removal: This API element is subject to removal in a future version.
    May cause performance issues, deadlocks and hangs.
    final Class<? extends Object>
    Answers the unique instance of java.lang.Class which represents the class of the receiver.
    int
    Answers an integer hash code for the receiver.
    final void
    Causes one thread which is waiting on the receiver to be made ready to run.
    final void
    Causes all threads which are waiting on the receiver to be made ready to run.
    Answers a string containing a concise, human-readable description of the receiver.
    final void
    Causes the thread which sent this message to be made not ready to run pending some change in the receiver (as indicated by notify or notifyAll).
    final void
    wait(long time)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
    final void
    wait(long time, int frac)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
  • Method Details

    • providerName

      public String providerName()
      Returns the name of the provider.
      Returns:
      the name of the provider
    • encapsulate

      public KEM.Encapsulated encapsulate()
      The key encapsulation function.

      This method is equivalent to encapsulate(0, secretSize(), "Generic"). This combination of arguments must be supported by every implementation.

      The generated secret key is usually passed to a key derivation function (KDF) as the input keying material.

      Returns:
      a KEM.Encapsulated object containing the shared secret, key encapsulation message, and optional parameters. The shared secret is a SecretKey containing all of the bytes of the secret, and an algorithm name of "Generic".
    • encapsulate

      public KEM.Encapsulated encapsulate(int from, int to, String algorithm)
      The key encapsulation function.

      Each invocation of this method generates a new secret key and key encapsulation message that is returned in an KEM.Encapsulated object.

      An implementation may choose to not support arbitrary combinations of from, to, and algorithm.

      Parameters:
      from - the initial index of the shared secret byte array to be returned, inclusive
      to - the final index of the shared secret byte array to be returned, exclusive
      algorithm - the algorithm name for the secret key that is returned. See the SecretKey Algorithms section in the Java Security Standard Algorithm Names Specification for information about standard secret key algorithm names. Specify "Generic" if the output will be used as the input keying material of a key derivation function (KDF).
      Returns:
      a KEM.Encapsulated object containing a portion of the shared secret, key encapsulation message, and optional parameters. The portion of the shared secret is a SecretKey containing the bytes of the secret ranging from from to to, exclusive, and an algorithm name as specified. For example, encapsulate(0, 16, "AES") uses the first 16 bytes of the shared secret as a 128-bit AES key.
      Throws:
      IndexOutOfBoundsException - if from < 0, from > to, or to > secretSize()
      NullPointerException - if algorithm is null
      UnsupportedOperationException - if the combination of from, to, and algorithm is not supported by the encapsulator
      External Specifications
    • secretSize

      public int secretSize()
      Returns the size of the shared secret.

      This method can be called to find out the length of the shared secret before encapsulate is called or if the obtained SecretKey is not extractable.

      Returns:
      the size of the shared secret
    • encapsulationSize

      public int encapsulationSize()
      Returns the size of the key encapsulation message.

      This method can be called to find out the length of the encapsulation message before encapsulate is called.

      Returns:
      the size of the key encapsulation message