Reject AlgorithmParameters of wrong type.
This makes Android Keystore Cipher implementations reject rather than ignore AlgorithmParameters of wrong algorithm type. The danger in not doing so is that a Cipher will produce output that does not actually depend on the provided AlgorithmParameters. Bug: 22330716 Change-Id: Ifa9de2c74f2fe4b738a3731c895059dddd075a13
This commit is contained in:
@@ -129,6 +129,12 @@ abstract class AndroidKeyStoreAuthenticatedAESCipherSpi extends AndroidKeyStoreC
|
||||
return;
|
||||
}
|
||||
|
||||
if (!"GCM".equalsIgnoreCase(params.getAlgorithm())) {
|
||||
throw new InvalidAlgorithmParameterException(
|
||||
"Unsupported AlgorithmParameters algorithm: " + params.getAlgorithm()
|
||||
+ ". Supported: GCM");
|
||||
}
|
||||
|
||||
GCMParameterSpec spec;
|
||||
try {
|
||||
spec = params.getParameterSpec(GCMParameterSpec.class);
|
||||
|
||||
@@ -197,6 +197,12 @@ class AndroidKeyStoreUnauthenticatedAESCipherSpi extends AndroidKeyStoreCipherSp
|
||||
return;
|
||||
}
|
||||
|
||||
if (!"AES".equalsIgnoreCase(params.getAlgorithm())) {
|
||||
throw new InvalidAlgorithmParameterException(
|
||||
"Unsupported AlgorithmParameters algorithm: " + params.getAlgorithm()
|
||||
+ ". Supported: AES");
|
||||
}
|
||||
|
||||
IvParameterSpec ivSpec;
|
||||
try {
|
||||
ivSpec = params.getParameterSpec(IvParameterSpec.class);
|
||||
|
||||
Reference in New Issue
Block a user