This class represents a factory for secret keys.
Key factories are used to convert keys (opaque
cryptographic keys of type Key
) into key specifications
(transparent representations of the underlying key material), and vice
versa.
Secret key factories operate only on secret (symmetric) keys.
Key factories are bi-directional, i.e., they allow to build an opaque key object from a given key specification (key material), or to retrieve the underlying key material of a key object in a suitable format.
Application developers should refer to their provider's documentation
to find out which key specifications are supported by the
generateSecret
and
getKeySpec
methods.
For example, the DES secret-key factory supplied by the "SunJCE" provider
supports DESKeySpec
as a transparent representation of DES
keys, and that provider's secret-key factory for Triple DES keys supports
DESedeKeySpec
as a transparent representation of Triple DES
keys.
Android provides the following SecretKeyFactory
algorithms:
Algorithm | Supported API Levels |
---|---|
AES | 23+ |
DES | 1+ |
DESede | 1+ |
HmacSHA1 | 23+ |
HmacSHA224 | 23+ |
HmacSHA256 | 23+ |
HmacSHA384 | 23+ |
HmacSHA512 | 23+ |
PBEwithHmacSHA1 | 1+ |
PBEwithHmacSHA1AndAES_128 | 26+ |
PBEwithHmacSHA1AndAES_256 | 26+ |
PBEwithHmacSHA224AndAES_128 | 26+ |
PBEwithHmacSHA224AndAES_256 | 26+ |
PBEwithHmacSHA256AndAES_128 | 26+ |
PBEwithHmacSHA256AndAES_256 | 26+ |
PBEwithHmacSHA384AndAES_128 | 26+ |
PBEwithHmacSHA384AndAES_256 | 26+ |
PBEwithHmacSHA512AndAES_128 | 26+ |
PBEwithHmacSHA512AndAES_256 | 26+ |
PBEwithMD5AND128BITAES-CBC-OPENSSL | 1+ |
PBEwithMD5AND192BITAES-CBC-OPENSSL | 1+ |
PBEwithMD5AND256BITAES-CBC-OPENSSL | 1+ |
PBEwithMD5ANDDES | 1+ |
PBEwithMD5ANDRC2 | 1+ |
PBEwithSHA1ANDDES | 1+ |
PBEwithSHA1ANDRC2 | 1+ |
PBEwithSHA256AND128BITAES-CBC-BC | 1+ |
PBEwithSHA256AND192BITAES-CBC-BC | 1+ |
PBEwithSHA256AND256BITAES-CBC-BC | 1+ |
PBEwithSHAAND128BITAES-CBC-BC | 1+ |
PBEwithSHAAND128BITRC2-CBC | 10+ |
PBEwithSHAAND128BITRC4 | 10+ |
PBEwithSHAAND192BITAES-CBC-BC | 1+ |
PBEwithSHAAND2-KEYTRIPLEDES-CBC | 1+ |
PBEwithSHAAND256BITAES-CBC-BC | 1+ |
PBEwithSHAAND3-KEYTRIPLEDES-CBC | 1+ |
PBEwithSHAAND40BITRC2-CBC | 1+ |
PBEwithSHAAND40BITRC4 | 10+ |
PBEwithSHAANDTWOFISH-CBC | 10+ |
PBKDF2withHmacSHA1 | 10+ |
PBKDF2withHmacSHA1And8BIT | 19+ |
PBKDF2withHmacSHA224 | 26+ |
PBKDF2withHmacSHA256 | 26+ |
PBKDF2withHmacSHA384 | 26+ |
PBKDF2withHmacSHA512 | 26+ |
Protected Constructor Summary
SecretKeyFactory(SecretKeyFactorySpi keyFacSpi, Provider provider, String algorithm)
Creates a SecretKeyFactory object.
|
Public Method Summary
final SecretKey |
generateSecret(KeySpec keySpec)
Generates a
SecretKey object from the provided key
specification (key material). |
final String |
getAlgorithm()
Returns the algorithm name of this
SecretKeyFactory object. |
final static SecretKeyFactory |
getInstance(String algorithm)
Returns a
SecretKeyFactory object that converts
secret keys of the specified algorithm. |
final static SecretKeyFactory |
getInstance(String algorithm, String provider)
Returns a
SecretKeyFactory object that converts
secret keys of the specified algorithm. |
final static SecretKeyFactory |
getInstance(String algorithm, Provider provider)
Returns a
SecretKeyFactory object that converts
secret keys of the specified algorithm. |
final KeySpec |
getKeySpec(SecretKey key, Class<?> keySpec)
Returns a specification (key material) of the given key object
in the requested format.
|
final Provider |
getProvider()
Returns the provider of this
SecretKeyFactory object. |
final SecretKey |
translateKey(SecretKey key)
Translates a key object, whose provider may be unknown or potentially
untrusted, into a corresponding key object of this secret-key factory.
|
Inherited Method Summary
Protected Constructors
protected SecretKeyFactory (SecretKeyFactorySpi keyFacSpi, Provider provider, String algorithm)
Creates a SecretKeyFactory object.
Parameters
keyFacSpi | the delegate |
---|---|
provider | the provider |
algorithm | the secret-key algorithm |
Public Methods
public final SecretKey generateSecret (KeySpec keySpec)
Generates a SecretKey
object from the provided key
specification (key material).
Parameters
keySpec | the specification (key material) of the secret key |
---|
Returns
- the secret key
Throws
InvalidKeySpecException | if the given key specification is inappropriate for this secret-key factory to produce a secret key. |
---|
public final String getAlgorithm ()
Returns the algorithm name of this SecretKeyFactory
object.
This is the same name that was specified in one of the
getInstance
calls that created this
SecretKeyFactory
object.
Returns
- the algorithm name of this
SecretKeyFactory
object.
public static final SecretKeyFactory getInstance (String algorithm)
Returns a SecretKeyFactory
object that converts
secret keys of the specified algorithm.
This method traverses the list of registered security Providers, starting with the most preferred Provider. A new SecretKeyFactory object encapsulating the SecretKeyFactorySpi implementation from the first Provider that supports the specified algorithm is returned.
Note that the list of registered providers may be retrieved via
the Security.getProviders()
method.
Parameters
algorithm | the standard name of the requested secret-key algorithm. See the SecretKeyFactory section in the Java Cryptography Architecture Standard Algorithm Name Documentation for information about standard algorithm names. |
---|
Returns
- the new
SecretKeyFactory
object.
Throws
NullPointerException | if the specified algorithm is null. |
---|---|
NoSuchAlgorithmException | if no Provider supports a SecretKeyFactorySpi implementation for the specified algorithm. |
See Also
public static final SecretKeyFactory getInstance (String algorithm, String provider)
Returns a SecretKeyFactory
object that converts
secret keys of the specified algorithm.
A new SecretKeyFactory object encapsulating the SecretKeyFactorySpi implementation from the specified provider is returned. The specified provider must be registered in the security provider list.
Note that the list of registered providers may be retrieved via
the Security.getProviders()
method.
Parameters
algorithm | the standard name of the requested secret-key algorithm. See the SecretKeyFactory section in the Java Cryptography Architecture Standard Algorithm Name Documentation for information about standard algorithm names. |
---|---|
provider | the name of the provider. |
Returns
- the new
SecretKeyFactory
object.
Throws
NoSuchAlgorithmException | if a SecretKeyFactorySpi implementation for the specified algorithm is not available from the specified provider. |
---|---|
NullPointerException | if the specified algorithm is null. |
NoSuchProviderException | if the specified provider is not registered in the security provider list. |
IllegalArgumentException | if the provider
is null or empty. |
See Also
public static final SecretKeyFactory getInstance (String algorithm, Provider provider)
Returns a SecretKeyFactory
object that converts
secret keys of the specified algorithm.
A new SecretKeyFactory object encapsulating the SecretKeyFactorySpi implementation from the specified Provider object is returned. Note that the specified Provider object does not have to be registered in the provider list.
Parameters
algorithm | the standard name of the requested secret-key algorithm. See the SecretKeyFactory section in the Java Cryptography Architecture Standard Algorithm Name Documentation for information about standard algorithm names. |
---|---|
provider | the provider. |
Returns
- the new
SecretKeyFactory
object.
Throws
NullPointerException | if the specified algorithm is null. |
---|---|
NoSuchAlgorithmException | if a SecretKeyFactorySpi implementation for the specified algorithm is not available from the specified Provider object. |
IllegalArgumentException | if the provider
is null. |
See Also
public final KeySpec getKeySpec (SecretKey key, Class<?> keySpec)
Returns a specification (key material) of the given key object in the requested format.
Parameters
key | the key |
---|---|
keySpec | the requested format in which the key material shall be returned |
Returns
- the underlying key specification (key material) in the requested format
Throws
InvalidKeySpecException | if the requested key specification is
inappropriate for the given key (e.g., the algorithms associated with
key and keySpec do not match, or
key references a key on a cryptographic hardware device
whereas keySpec is the specification of a software-based
key), or the given key cannot be dealt with
(e.g., the given key has an algorithm or format not supported by this
secret-key factory).
|
---|
public final Provider getProvider ()
Returns the provider of this SecretKeyFactory
object.
Returns
- the provider of this
SecretKeyFactory
object
public final SecretKey translateKey (SecretKey key)
Translates a key object, whose provider may be unknown or potentially untrusted, into a corresponding key object of this secret-key factory.
Parameters
key | the key whose provider is unknown or untrusted |
---|
Returns
- the translated key
Throws
InvalidKeyException | if the given key cannot be processed by this secret-key factory. |
---|