KeyGenParameterSpec 類別
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
AlgorithmParameterSpec 用於初始化 Android Keystore 系統的 a KeyPairGenerator 或 a KeyGenerator 。
[Android.Runtime.Register("android/security/keystore/KeyGenParameterSpec", ApiSince=23, DoNotGenerateAcw=true)]
public sealed class KeyGenParameterSpec : Java.Lang.Object, IDisposable, Java.Security.Spec.IAlgorithmParameterSpec
[<Android.Runtime.Register("android/security/keystore/KeyGenParameterSpec", ApiSince=23, DoNotGenerateAcw=true)>]
type KeyGenParameterSpec = class
inherit Object
interface IAlgorithmParameterSpec
interface IJavaObject
interface IDisposable
interface IJavaPeerable
- 繼承
- 屬性
- 實作
備註
AlgorithmParameterSpec用於初始化 KeyPairGenerator的 a KeyGenerator 或 a。 規範決定金鑰的授權用途,例如使用金鑰是否需要使用者驗證、授權哪些操作(例如簽名但不需解密)、參數(例如僅限特定填充方案或摘要),以及金鑰的有效開始與結束日期。 規範中所描述的金鑰使用授權僅適用於秘密金鑰與私鑰——公鑰可用於任何支援的操作。
要產生非對稱金鑰對或對稱金鑰,請使用Builder該類別的實例,從提供KeyPairGenerator者初始KeyGeneratorEC化所需金鑰類型(例如,AESKeyProperties或 -- 見 KEY_ALGORITHM. 常AndroidKeyStore數),KeyGenParameterSpec然後使用 KeyGenerator#generateKey() 或 KeyPairGenerator#generateKeyPair()產生金鑰或金鑰對。
產生的金鑰對或金鑰將由產生器回傳,並以本規範指定的別名儲存在 Android 金鑰庫中。若要從 Android Keystore 取得秘密或私密金鑰,請使用 java.security.KeyStore#getKey(String, char[]) KeyStore.getKey(String, null) 或 java.security.KeyStore#getEntry(String, java.security.KeyStore.ProtectionParameter) KeyStore.getEntry(String, null)。 要從 Android Keystore 取得公鑰,請使用 java.security.KeyStore#getCertificate(String) ,然後 Certificate#getPublicKey()。
為了幫助取得儲存在 Android Keystore 中的密鑰對的演算法專屬公開參數,產生私鑰的 Implement java.security.interfaces.ECKey 或 java.security.interfaces.RSAKey 介面,而公鑰則是 Implement java.security.interfaces.ECPublicKey 或 java.security.interfaces.RSAPublicKey interface。
對於非對稱金鑰對,也會產生並儲存在 Android 金鑰庫中的 X.509 憑證。 這是因為抽象 java.security.KeyStore 化不支援在沒有憑證的情況下儲存金鑰對。 證書的主題、序號及有效日期可在此規範中自訂。該證書可在日後由憑證授權機構(CA)簽署的證書取代。
注意:若未使用 Builder#setAttestationChallenge(byte[])請求認證,產生的證書可自行簽署。 若私鑰未被授權簽署該憑證,則憑證將以無效的簽章建立,無法進行驗證。 這類憑證仍然有用,因為它提供公開金鑰的存取權限。 要產生有效的憑證簽章,金鑰必須獲得以下所有授權<:ul><li>KeyProperties#PURPOSE_SIGN、</li><li>操作且不需使用者認證(參見Builder#setUserAuthenticationRequired(boolean))、</li><li 此>刻簽署/發起(參見 Builder#setKeyValidityStart(Date) 及Builder#setKeyValidityForOriginationEnd(Date))、</li><li>適合摘要,</li><li>(僅限 RSA 金鑰)填充方案。KeyProperties#SIGNATURE_PADDING_RSA_PKCS1</li></ul>
注意:產生的對稱與私鑰的金鑰材料無法存取。 公鑰的鑰匙資料是可存取的。
此類別的實例是不可變的。
<h3>已知問題</h3> Android 6.0(API Level 23)中的一個已知錯誤,導致即使是公開金鑰也被強制執行與使用者驗證相關的授權。 為了解決這個問題,請將公開金鑰資料擷取到用於 Android Keystore 以外的資料。 例如:
{@code
PublicKey unrestrictedPublicKey =
KeyFactory.getInstance(publicKey.getAlgorithm()).generatePublic(
new X509EncodedKeySpec(publicKey.getEncoded()));
}
<h3>範例:NIST P-256 EC 金鑰對,用於使用 ECDSA/<h3> 進行簽署/驗證 此範例說明如何在 Android KeyStore 系統中以別名 key1 方式產生 NIST P-256(又名 secp256r1,或 prime256v1)EC 金鑰對,該私鑰僅被授權用於使用 SHA-256、SHA-384 或 SHA-512 摘要簽署,且僅限於使用者在過去五分鐘內完成驗證。 公開金鑰的使用不受限制(參見已知問題)。
{@code
KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance(
KeyProperties.KEY_ALGORITHM_EC, "AndroidKeyStore");
keyPairGenerator.initialize(
new KeyGenParameterSpec.Builder(
"key1",
KeyProperties.PURPOSE_SIGN)
.setAlgorithmParameterSpec(new ECGenParameterSpec("secp256r1"))
.setDigests(KeyProperties.DIGEST_SHA256,
KeyProperties.DIGEST_SHA384,
KeyProperties.DIGEST_SHA512)
// Only permit the private key to be used if the user authenticated
// within the last five minutes.
.setUserAuthenticationRequired(true)
.setUserAuthenticationValidityDurationSeconds(5 * 60)
.build());
KeyPair keyPair = keyPairGenerator.generateKeyPair();
Signature signature = Signature.getInstance("SHA256withECDSA");
signature.initSign(keyPair.getPrivate());
...
// The key pair can also be obtained from the Android Keystore any time as follows:
KeyStore keyStore = KeyStore.getInstance("AndroidKeyStore");
keyStore.load(null);
PrivateKey privateKey = (PrivateKey) keyStore.getKey("key1", null);
PublicKey publicKey = keyStore.getCertificate("key1").getPublicKey();
}
<h3>範例:使用 RSA-PSS</h3> 進行簽署/驗證的 RSA 金鑰對 本範例說明如何在 Android KeyStore 系統中產生 RSA 金鑰對,該別名 key1 授權僅用於使用 RSA-PSS 簽名填充方案與 SHA-256 或 SHA-512 摘要進行簽署。 公鑰的使用不受限制。
{@code
KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance(
KeyProperties.KEY_ALGORITHM_RSA, "AndroidKeyStore");
keyPairGenerator.initialize(
new KeyGenParameterSpec.Builder(
"key1",
KeyProperties.PURPOSE_SIGN)
.setDigests(KeyProperties.DIGEST_SHA256, KeyProperties.DIGEST_SHA512)
.setSignaturePaddings(KeyProperties.SIGNATURE_PADDING_RSA_PSS)
.build());
KeyPair keyPair = keyPairGenerator.generateKeyPair();
Signature signature = Signature.getInstance("SHA256withRSA/PSS");
signature.initSign(keyPair.getPrivate());
...
// The key pair can also be obtained from the Android Keystore any time as follows:
KeyStore keyStore = KeyStore.getInstance("AndroidKeyStore");
keyStore.load(null);
PrivateKey privateKey = (PrivateKey) keyStore.getKey("key1", null);
PublicKey publicKey = keyStore.getCertificate("key1").getPublicKey();
}
<h3>範例:使用 RSA OAEP</h3> 進行加密/解密的 RSA 金鑰對 本範例說明如何在 Android KeyStore 系統中以別名 key1 方式產生 RSA 金鑰對,其中私鑰僅被授權用於 RSA OAEP 加密填充方案與 SHA-256 或 SHA-512 摘要進行解密。 公鑰的使用不受限制。
{@code
KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance(
KeyProperties.KEY_ALGORITHM_RSA, "AndroidKeyStore");
keyPairGenerator.initialize(
new KeyGenParameterSpec.Builder(
"key1",
KeyProperties.PURPOSE_DECRYPT)
.setDigests(KeyProperties.DIGEST_SHA256, KeyProperties.DIGEST_SHA512)
.setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_RSA_OAEP)
.build());
KeyPair keyPair = keyPairGenerator.generateKeyPair();
Cipher cipher = Cipher.getInstance("RSA/ECB/OAEPWithSHA-256AndMGF1Padding");
cipher.init(Cipher.DECRYPT_MODE, keyPair.getPrivate());
...
// The key pair can also be obtained from the Android Keystore any time as follows:
KeyStore keyStore = KeyStore.getInstance("AndroidKeyStore");
keyStore.load(null);
PrivateKey privateKey = (PrivateKey) keyStore.getKey("key1", null);
PublicKey publicKey = keyStore.getCertificate("key1").getPublicKey();
}
<h3>範例:用於 GCM 模式</h3> 加密/解密的 AES 金鑰 以下範例說明如何在 Android KeyStore 系統中產生 AES 金鑰,該金鑰授權 key2 僅用於 GCM 模式的加密/解密,且無填充。
{@code
KeyGenerator keyGenerator = KeyGenerator.getInstance(
KeyProperties.KEY_ALGORITHM_AES, "AndroidKeyStore");
keyGenerator.init(
new KeyGenParameterSpec.Builder("key2",
KeyProperties.PURPOSE_ENCRYPT | KeyProperties.PURPOSE_DECRYPT)
.setBlockModes(KeyProperties.BLOCK_MODE_GCM)
.setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_NONE)
.build());
SecretKey key = keyGenerator.generateKey();
Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding");
cipher.init(Cipher.ENCRYPT_MODE, key);
...
// The key can also be obtained from the Android Keystore any time as follows:
KeyStore keyStore = KeyStore.getInstance("AndroidKeyStore");
keyStore.load(null);
key = (SecretKey) keyStore.getKey("key2", null);
}
<h3>範例:使用 SHA-256</h3> 產生 MAC 的 HMAC 金鑰 本範例說明如何在 Android KeyStore 系統中產生 HMAC 金鑰,該別名 key2 僅授權用於使用 SHA-256 產生 HMAC。
{@code
KeyGenerator keyGenerator = KeyGenerator.getInstance(
KeyProperties.KEY_ALGORITHM_HMAC_SHA256, "AndroidKeyStore");
keyGenerator.init(
new KeyGenParameterSpec.Builder("key2", KeyProperties.PURPOSE_SIGN).build());
SecretKey key = keyGenerator.generateKey();
Mac mac = Mac.getInstance("HmacSHA256");
mac.init(key);
...
// The key can also be obtained from the Android Keystore any time as follows:
KeyStore keyStore = KeyStore.getInstance("AndroidKeyStore");
keyStore.load(null);
key = (SecretKey) keyStore.getKey("key2", null);
}
<h3 id=“example:ecdh”> 範例:ECD 金鑰協議<的 EC 金鑰 - h3> 此範例說明如何產生橢圓曲線金鑰對,用於利用 ECDH 金鑰協議與另一方建立共享秘密。
{@code
KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance(
KeyProperties.KEY_ALGORITHM_EC, "AndroidKeyStore");
keyPairGenerator.initialize(
new KeyGenParameterSpec.Builder(
"eckeypair",
KeyProperties.PURPOSE_AGREE_KEY)
.setAlgorithmParameterSpec(new ECGenParameterSpec("secp256r1"))
.build());
KeyPair myKeyPair = keyPairGenerator.generateKeyPair();
// Exchange public keys with server. A new ephemeral key MUST be used for every message.
PublicKey serverEphemeralPublicKey; // Ephemeral key received from server.
// Create a shared secret based on our private key and the other party's public key.
KeyAgreement keyAgreement = KeyAgreement.getInstance("ECDH", "AndroidKeyStore");
keyAgreement.init(myKeyPair.getPrivate());
keyAgreement.doPhase(serverEphemeralPublicKey, true);
byte[] sharedSecret = keyAgreement.generateSecret();
// sharedSecret cannot safely be used as a key yet. We must run it through a key derivation
// function with some other data: "salt" and "info". Salt is an optional random value,
// omitted in this example. It's good practice to include both public keys and any other
// key negotiation data in info. Here we use the public keys and a label that indicates
// messages encrypted with this key are coming from the server.
byte[] salt = {};
ByteArrayOutputStream info = new ByteArrayOutputStream();
info.write("ECDH secp256r1 AES-256-GCM-SIV\0".getBytes(StandardCharsets.UTF_8));
info.write(myKeyPair.getPublic().getEncoded());
info.write(serverEphemeralPublicKey.getEncoded());
// This example uses the Tink library and the HKDF key derivation function.
AesGcmSiv key = new AesGcmSiv(Hkdf.computeHkdf(
"HMACSHA256", sharedSecret, salt, info.toByteArray(), 32));
byte[] associatedData = {};
return key.decrypt(ciphertext, associatedData);
}
Java 文件 android.security.keystore.KeyGenParameterSpec。
本頁部分內容為基於 Open Source Project 所創建與分享的作品,並依授權條款所描述的使用進行修改。
屬性
| 名稱 | Description |
|---|---|
| AlgorithmParameterSpec |
回傳用於建立金鑰的演算法專屬 |
| AttestKeyAlias |
回傳用於簽署所產生金鑰證明證書的別名。 |
| CertificateNotAfter |
回傳用於 X 的終止日期。 |
| CertificateNotBefore |
回傳開始日期,用於 X 表格。 |
| CertificateSerialNumber |
回傳用於 X 的序號。 |
| CertificateSubject |
回傳主題的區別名稱,用於 X 字。 |
| Class |
回傳此 |
| Handle |
底層 Android 實例的帳號。 (繼承來源 Object) |
| IsDevicePropertiesAttestationIncluded |
若被要求在產生的金鑰的認證憑證中加入基礎裝置屬性( |
| IsDigestsSpecified |
若指定可用於該金鑰的摘要演算法集合,則回傳 |
| IsInvalidatedByBiometricEnrollment |
若在新生物識別註冊或所有註冊生物識別資料被移除後,該金鑰不可逆轉地失效,則會退還 |
| IsMgf1DigestsSpecified |
|
| IsRandomizedEncryptionRequired |
如果使用此金鑰加密,則返回 |
| IsStrongBoxBacked |
如果鑰匙有 Strongbox 安全晶片保護,則會回傳 |
| IsUnlockedDeviceRequired |
若鑰匙被授權只能在裝置解鎖時使用,則會退貨 |
| IsUserAuthenticationRequired |
若金鑰被授權僅在使用者已認證時使用,則會回傳 |
| IsUserAuthenticationValidWhileOnBody |
若金鑰僅在裝置從使用者體內移除為止,且有效期限內仍被授權,則會回傳 |
| IsUserConfirmationRequired |
若金鑰被授權僅用於使用者確認的訊息,則會回傳 |
| IsUserPresenceRequired |
若金鑰被授權僅在 與 |
| JniIdentityHashCode |
取得由互通執行時指派給此 Java 對等端的身份雜湊碼。 (繼承來源 Object) |
| JniManagedPeerState |
|
| JniPeerMembers |
|
| KeySize |
回傳請求的金鑰大小。 |
| KeystoreAlias |
回傳將 |
| KeyValidityForConsumptionEnd |
回傳金鑰在解密與驗證時不再有效的時間點,若 |
| KeyValidityForOriginationEnd |
回傳金鑰不再用於加密與簽署的時間點,若 |
| KeyValidityStart |
回傳金鑰尚未有效或 |
| MaxUsageCount |
回傳有限使用金鑰允許使用的最大次數,或 |
| Mgf1Digests |
回傳可由MGF1遮罩產生函數使用的消化集合(例如: |
| PeerReference |
取得這個 Java 節點的 JNI 物件參考。 (繼承來源 Object) |
| Purposes |
返回目的集合(例如: |
| ThresholdClass |
此 API 支援 Mono for Android 基礎架構,並非直接從你的程式碼中使用。 (繼承來源 Object) |
| ThresholdType |
此 API 支援 Mono for Android 基礎架構,並非直接從你的程式碼中使用。 (繼承來源 Object) |
| UserAuthenticationType |
取得可授權使用此金鑰的認證模式。 |
| UserAuthenticationValidityDurationSeconds |
取得使用者成功認證後,該金鑰被授權使用的時間(秒數)。 |
方法
| 名稱 | Description |
|---|---|
| Clone() |
建立並回傳此物件的副本。 (繼承來源 Object) |
| Construct(JniObjectReference, JniObjectReferenceOptions) |
|
| Dispose() |
釋放該 Java 節點所持有的資源。 (繼承來源 Object) |
| Dispose(Boolean) |
釋放該 Java 節點所持有的資源。 (繼承來源 Object) |
| DisposeUnlessReferenced() |
|
| Equals(Object) |
|
| Equals(Object) |
表示是否有其他物體「等同」於此物。 (繼承來源 Object) |
| GetAttestationChallenge() |
回傳將放置於此金鑰組合的證明證書中的認證挑戰值。 |
| GetBlockModes() |
得到區塊模式集合(例如 |
| GetDigests() |
回傳一組消化演算法(例如: |
| GetEncryptionPaddings() |
回傳填充方案集合(例如。 |
| GetHashCode() |
回傳物件的雜湊碼值。 (繼承來源 Object) |
| GetSignaturePaddings() |
得到一組填充方案(例如: |
| JavaFinalize() |
已淘汰.
當垃圾回收判定該物件不再有相關參考時,由垃圾回收器呼叫。 (繼承來源 Object) |
| Notify() |
喚醒一個正在該物件監視器上等待的執行緒。 (繼承來源 Object) |
| NotifyAll() |
喚醒所有等待該物件監視器的執行緒。 (繼承來源 Object) |
| SetHandle(IntPtr, JniHandleOwnership) |
設定 Handle 屬性。 (繼承來源 Object) |
| SetPeerReference(JniObjectReference, JniObjectReferenceOptions) |
|
| ToArray<T>() |
從這個 Java 陣列包裝器建立一個受管理陣列。 (繼承來源 Object) |
| ToString() |
回傳物件的字串表示。 (繼承來源 Object) |
| UnregisterFromRuntime() |
將此 Java 節點從互通執行時中取消註冊。 (繼承來源 Object) |
| Wait() |
導致目前執行緒等待被喚醒,通常是透過 <em>通知</><em 或 em>中斷</em> 來喚醒。 (繼承來源 Object) |
| Wait(Int64, Int32) |
會讓目前執行緒等待喚醒,通常是透過 <em>通知</><em 或 em>中斷</em>,或是經過一定的真實時間。 (繼承來源 Object) |
| Wait(Int64) |
會讓目前執行緒等待喚醒,通常是透過 <em>通知</><em 或 em>中斷</em>,或是經過一定的真實時間。 (繼承來源 Object) |
明確介面實作
| 名稱 | Description |
|---|---|
| IJavaPeerable.Disposed() |
|
| IJavaPeerable.Finalized() |
|
| IJavaPeerable.JniObjectReferenceControlBlock |
|
| IJavaPeerable.SetJniIdentityHashCode(Int32) |
|
| IJavaPeerable.SetJniManagedPeerState(JniManagedPeerStates) |
|
| IJavaPeerable.SetPeerReference(JniObjectReference) |
|
| IJavaPeerable.UnregisterFromRuntime() |
|
擴充方法
| 名稱 | Description |
|---|---|
| GetJniTypeName(IJavaPeerable) |
取得實例 |
| JavaAs<TResult>(IJavaPeerable) |
試著強制 |
| JavaCast<TResult>(IJavaObject) |
執行 Android 執行時檢查型別轉換。 |
| JavaCast<TResult>(IJavaObject) |
|
| TryJavaCast<TResult>(IJavaPeerable, TResult) |
試著強制 |