PKCS#11生成AES密钥 [英] PKCS#11 Generate AES key

查看:698
本文介绍了PKCS#11生成AES密钥的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

Hei,
这个问题不是真的关于Ncryptoki,但我did not知道别的地方问。所以如果有人可以帮助,请帮助我。
Im tryng生成AES密钥并处理我现在的代码:

Hei, The question is not really about Ncryptoki but i didnt know anywhere else to ask.. so if anybody can help please help me. Im tryng to generate AES key and heres the code what i have right now:

CK_MECHANISM keyGenMech = new CK_MECHANISM(CKM.AES_KEY_GEN);

CK_ATTRIBUTE[] template =
{
    new CK_ATTRIBUTE(CKA.CLASS, CKO.SECRET_KEY),
    new CK_ATTRIBUTE(CKA.TOKEN, CK_BBOOL.TRUE),
    new CK_ATTRIBUTE(CKA.SENSITIVE, CK_BBOOL.TRUE),
    new CK_ATTRIBUTE(CKA.VALUE_LEN, 32),
    new CK_ATTRIBUTE(CKA.KEY_TYPE, CKK.AES),
    new CK_ATTRIBUTE(CKA.LABEL, "testAES".getBytes()),
    new CK_ATTRIBUTE(CKA.PRIVATE, new CK_BBOOL(bPrivate))
};
CryptokiEx.C_GenerateKey(session, keyGenMech, template, template.length, wrappingKey);

但这给我一个错误:

C_GenerateKey rv=0x62 - key size range

我有一个想法从这里去解决这个..

Can anybody give me some idea where to go from here to solve this..

编辑:信息 - 我有SafeNet HSM和im使用java PKCS#11包装称为 jprov SafeNet ProtectToolkit附带了什么。

Just for info - I have SafeNet HSM and im using java PKCS#11 wrapper called jprov what comes with SafeNet ProtectToolkit.

推荐答案

$ c> new CK_ATTRIBUTE(CKA.VALUE_LEN,32),,32中有CK_ULONG值,所以当我这样做:

I found the answere, new CK_ATTRIBUTE(CKA.VALUE_LEN, 32), , the 32 in there has to be CK_ULONG value so when i do this:

LongRef l = new LongRef((long)32);

CK_ATTRIBUTE[] template =
{
    new CK_ATTRIBUTE(CKA.CLASS,     CKO.SECRET_KEY),
    new CK_ATTRIBUTE(CKA.TOKEN,     CK_BBOOL.TRUE),
    new CK_ATTRIBUTE(CKA.SENSITIVE, CK_BBOOL.TRUE),
    new CK_ATTRIBUTE(CKA.VALUE_LEN, l.value),
    //new CK_ATTRIBUTE(CKA.VALUE,     key),
    new CK_ATTRIBUTE(CKA.KEY_TYPE,  CKK.AES),
    new CK_ATTRIBUTE(CKA.LABEL,     "testAES".getBytes()),
    new CK_ATTRIBUTE(CKA.PRIVATE,   new CK_BBOOL(bPrivate))
};

其中 LongRef 为:

public class LongRef {

    public long value; 

    public LongRef(long l) {
        //compiled code
        throw new RuntimeException("Compiled Code");
    }
}

希望这有助于某人。

这篇关于PKCS#11生成AES密钥的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆