Class AgileEncryptionWriter


  • public class AgileEncryptionWriter
    extends Object
    Builds the agile key material and the descriptor which carries it.

    This is the inverse of AgileEncryptionProvider, which is what makes it testable without ms access: taking the salts out of a database ms access encrypted, decrypting its three wrapped values and encrypting them again has to give back the bytes ms access wrote.

    Nothing here writes a dataIntegrity element. No .accdb ms access produced carries one, from 2007 to a current version, and the read path does not look for it.

    Author:
    James Ahlborn
    • Constructor Detail

      • AgileEncryptionWriter

        public AgileEncryptionWriter​(AgileEncryptionConfig config,
                                     String password)
        Generates fresh key material for the given password.
      • AgileEncryptionWriter

        public AgileEncryptionWriter​(AgileEncryptionConfig config,
                                     String password,
                                     byte[] keyDataSalt,
                                     byte[] pwdSalt,
                                     byte[] keyValue,
                                     byte[] verifierInput)
        Uses the given key material rather than generating it, which is how the forward direction is checked against a database ms access wrote.
    • Method Detail

      • getKeyValue

        public byte[] getKeyValue()
        Returns the key the pages are encrypted with.
      • getKeyDataSalt

        public byte[] getKeyDataSalt()
        Returns the salt which also serves as the page cipher IV base.
      • encryptVerifierHashInput

        public byte[] encryptVerifierHashInput()
      • encryptVerifierHashValue

        public byte[] encryptVerifierHashValue()
      • unwrapKeyValue

        public byte[] unwrapKeyValue​(byte[] wrapped)
        Reverses encryptKeyValue(), which is how the pair is checked.
      • encryptKeyValue

        public byte[] encryptKeyValue()
      • createDescriptor

        public byte[] createDescriptor()
        Returns the descriptor xml, which is what page 0 carries after the version and the reserved value.
      • encryptPage

        public static void encryptPage​(AgileEncryptionConfig config,
                                       byte[] keyValue,
                                       byte[] salt,
                                       byte[] blockBytes,
                                       byte[] pageBytes)
        Encrypts one page under the content key. The IV comes from the key data salt and the block bytes, which are the encoding key xored with the page number, so every page gets its own IV without moving any data.