Class AgileDecryptor
java.lang.Object
org.docx4j.org.apache.poi.poifs.crypt.Decryptor
org.docx4j.org.apache.poi.poifs.crypt.agile.AgileDecryptor
public class AgileDecryptor extends Decryptor
Decryptor implementation for Agile Encryption
-
Field Summary
Fields Modifier and Type Field Description protected static byte[]kCryptoKeyBlockprotected static byte[]kHashedVerifierBlockprotected static byte[]kIntegrityKeyBlockprotected static byte[]kIntegrityValueBlockprotected static byte[]kVerifierInputBlockFields inherited from class org.docx4j.org.apache.poi.poifs.crypt.Decryptor
builder, DEFAULT_PASSWORD, DEFAULT_POIFS_ENTRY -
Constructor Summary
Constructors Modifier Constructor Description protectedAgileDecryptor(AgileEncryptionInfoBuilder builder) -
Method Summary
Modifier and Type Method Description java.io.InputStreamgetDataStream(DirectoryNode dir)Return a stream with decrypted data.longgetLength()Returns the length of the encrypted data that can be safely read withDecryptor.getDataStream(org.docx4j.org.apache.poi.poifs.filesystem.DirectoryNode).protected static intgetNextBlockSize(int inputLen, int blockSize)protected static byte[]hashInput(EncryptionInfoBuilder builder, byte[] pwHash, byte[] blockKey, byte[] inputKey, int cipherMode)protected static javax.crypto.CipherinitCipherForBlock(javax.crypto.Cipher existing, int block, boolean lastChunk, EncryptionInfoBuilder builder, javax.crypto.SecretKey skey, int encryptionMode)booleanverifyPassword(java.lang.String password)set decryption passwordbooleanverifyPassword(java.security.KeyPair keyPair, java.security.cert.X509Certificate x509)instead of a password, it's also possible to decrypt via certificate.Methods inherited from class org.docx4j.org.apache.poi.poifs.crypt.Decryptor
getBlockSizeInBytes, getDataStream, getDataStream, getDataStream, getInstance, getIntegrityHmacKey, getIntegrityHmacValue, getKeySizeInBytes, getSecretKey, getVerifier, setIntegrityHmacKey, setIntegrityHmacValue, setSecretKey, setVerifier
-
Field Details
-
kVerifierInputBlock
protected static final byte[] kVerifierInputBlock -
kHashedVerifierBlock
protected static final byte[] kHashedVerifierBlock -
kCryptoKeyBlock
protected static final byte[] kCryptoKeyBlock -
kIntegrityKeyBlock
protected static final byte[] kIntegrityKeyBlock -
kIntegrityValueBlock
protected static final byte[] kIntegrityValueBlock
-
-
Constructor Details
-
Method Details
-
verifyPassword
public boolean verifyPassword(java.lang.String password) throws java.security.GeneralSecurityExceptionset decryption password- Specified by:
verifyPasswordin classDecryptor- Throws:
java.security.GeneralSecurityException
-
verifyPassword
public boolean verifyPassword(java.security.KeyPair keyPair, java.security.cert.X509Certificate x509) throws java.security.GeneralSecurityExceptioninstead of a password, it's also possible to decrypt via certificate. Warning: this code is experimental and hasn't been validated- Parameters:
keyPair-x509-- Returns:
- true, when the data can be successfully decrypted with the given private key
- Throws:
java.security.GeneralSecurityException- See Also:
- Agile encryption with certificates
-
getNextBlockSize
protected static int getNextBlockSize(int inputLen, int blockSize) -
hashInput
protected static byte[] hashInput(EncryptionInfoBuilder builder, byte[] pwHash, byte[] blockKey, byte[] inputKey, int cipherMode) -
getDataStream
public java.io.InputStream getDataStream(DirectoryNode dir) throws java.io.IOException, java.security.GeneralSecurityExceptionDescription copied from class:DecryptorReturn a stream with decrypted data.Use
Decryptor.getLength()to get the size of that data that can be safely read from the stream. Just reading to the end of the input stream is not sufficient because there are normally padding bytes that must be discarded- Specified by:
getDataStreamin classDecryptor- Parameters:
dir- the node to read from- Returns:
- decrypted stream
- Throws:
java.io.IOExceptionjava.security.GeneralSecurityException
-
getLength
public long getLength()Description copied from class:DecryptorReturns the length of the encrypted data that can be safely read withDecryptor.getDataStream(org.docx4j.org.apache.poi.poifs.filesystem.DirectoryNode). Just reading to the end of the input stream is not sufficient because there are normally padding bytes that must be discardedThe length variable is initialized in
Decryptor.getDataStream(org.docx4j.org.apache.poi.poifs.filesystem.DirectoryNode), an attempt to call getLength() prior to getDataStream() will result in IllegalStateException. -
initCipherForBlock
protected static javax.crypto.Cipher initCipherForBlock(javax.crypto.Cipher existing, int block, boolean lastChunk, EncryptionInfoBuilder builder, javax.crypto.SecretKey skey, int encryptionMode) throws java.security.GeneralSecurityException- Throws:
java.security.GeneralSecurityException
-