JavaKey中的AESKey LinkedList / Array

时间:2015-09-21 14:50:16

标签: java applet cryptography javacard

这篇文章与我几天前提出的问题有关:Store symmetric keys in Java Card

我想在Java Card中实现LinkedList来存储AESKey。所以我用这种方式写了一个课KeyElement

package LinkedList;

import javacard.security.AESKey;
import javacard.security.KeyBuilder;


class KeyElement {
    private KeyElement next;
    private short id;
    private AESKey key;
    private boolean isUsed;

    /**
     * Constructor.
     * 
     * @param upperBound
     *            An upper bound to indicate of many elements it cans contain at
     *            maximum. It is essential to instanciate the structure this way
     *            to reserve all the necessary memory at the installation time.
     */
    public KeyElement(short upperBound) {
       this.id = (short) 0x0000;
       this.key = (AESKey) KeyBuilder.buildKey(KeyBuilder.TYPE_AES,
           KeyBuilder.LENGTH_AES_256, false);
       this.isUsed = false;
       this.next = null;
       for (short i = (short) 0x0001; i < upperBound; i++) {
           KeyElement e = new KeyElement();
           this.addKeyElement(e);
       }
    }

    public KeyElement() {
       this.id = (short) 0x0000;
       this.key = (AESKey) KeyBuilder.buildKey(KeyBuilder.TYPE_AES,
           KeyBuilder.LENGTH_AES_256, false);
       this.isUsed = false;
       this.next = null;
    }

    public KeyElement getNext() {
       return this.next;
    }

    public short getID() {
       return this.id;
    }

    public boolean isUsed() {
       return isUsed;
    }

    public void setNext(KeyElement e) {
       this.next = e;
    }

    public static boolean addKey(KeyElement main, final short id, byte[] key) {
       for (KeyElement p = main; p != null; p = p.getNext()) {
            if (!p.isUsed()) {
              p.isUsed = true;
              p.id = id;
              p.key.setKey(key, (short) 0x0000);
              return true;
           }
       }
       return false;
    }



    public void addKeyElement(KeyElement e) {
       e.setNext(this.getNext());
       this.setNext(e);
    }


    public static boolean getKey(final KeyElement e, final short id,
        byte[] key) {
       for (KeyElement p = e; p != null; p = p.getNext()) {
           if (p.id == id) {
              p.key.getKey(key, (short) 0x0000);
              return true;
           }
       }
       return false;
    }
}

我有一个小程序LinkedListKey,它使用之前描述的类KeyElement

package LinkedList;

import javacard.framework.APDU;
import javacard.framework.APDUException;
import javacard.framework.Applet;
import javacard.framework.ISO7816;
import javacard.framework.ISOException;
import javacard.framework.PINException;
import javacard.framework.SystemException;
import javacard.framework.TransactionException;
import javacard.framework.Util;
import javacard.framework.service.ServiceException;
import javacard.security.CryptoException;
import javacard.security.RandomData;

public class LinkedListKey extends Applet {

    byte[] rdm;
    RandomData rand;
    KeyElement e;

    private LinkedListKey(final byte[] aidArray, final short aidOffset,
        final byte aidLength, final byte[] dataArray, short dataOffset,
        final short dataLength) throws ISOException {

       e = new KeyElement((short) 0x0064);

       rdm = new byte[(short) 0x0020];

       KeyElement.addKey(e, (short) 0x7514, new byte[] { (byte) 0x75, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x75, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x14, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x75, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x75, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x14, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x75, (byte) 0x14,
        (byte) 0x75, (byte) 0x14, (byte) 0x75, (byte) 0x14,
        (byte) 0x75, (byte) 0x14 });

       register();
    }

    public static void install(final byte[] buffer, short offset,
        final byte length) throws ISOException {
       if (length == 0) {
          ISOException.throwIt(ISO7816.SW_WRONG_LENGTH);
       }

       short remainingBytes = makeShort(length);

       // Save instance AID.
       byte aidLength = buffer[offset++];
       short aidOffset = offset;

       // Skip instance AID.
       offset += makeShort(aidLength);

       remainingBytes--;
       remainingBytes -= makeShort(aidLength);

       if (remainingBytes <= (short) 0x0000) {
           ISOException.throwIt(ISO7816.SW_WRONG_LENGTH);
       }

       // Skip control data.
       byte infoLength = buffer[offset++];

       offset += makeShort(infoLength);

       remainingBytes--;
       remainingBytes -= makeShort(infoLength);

       if (remainingBytes <= (short) 0x0000) {
           ISOException.throwIt(ISO7816.SW_WRONG_LENGTH);
       }

       // Instantiate the application.
       // The length of the application data maybe greater than 127 bytes.
       short dataLength = makeShort(buffer[offset++]);

       remainingBytes--;

       if (remainingBytes != dataLength) {
           ISOException.throwIt(ISO7816.SW_WRONG_LENGTH);
       }

       new LinkedListKey(buffer, aidOffset, aidLength, buffer, offset,
           dataLength);
    }

    public void process(final APDU apdu) throws ISOException {
       byte[] apduBuffer = apdu.getBuffer();

       if (selectingApplet()) {
           apdu.setOutgoingAndSend((short) 0x0000, (short) 0x0019);

           return;
        }

    // Send result.
    try {
        if (apduBuffer[ISO7816.OFFSET_INS] == (byte) 0x00) {
           for (short i = 0x0000; i < (short) 0x0008; i++) {
               rand.generateData(rdm, (short) 0x0000, (short) rdm.length);
               KeyElement.addKey(e, i, rdm);
           }
           KeyElement.addKey(e, (short) 0x7503, new byte[] { (byte) 0x75, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x75, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x14, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x75, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x75, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x14, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x75, (byte) 0x03,
            (byte) 0x75, (byte) 0x03, (byte) 0x75, (byte) 0x03,
            (byte) 0x75, (byte) 0x03 });
        }
        else if (apduBuffer[ISO7816.OFFSET_INS] == (byte) 0x01){
           KeyElement.getKey(e, (short) 0x7503, apduBuffer);
           setOutgoingAndSend((short) 0x0000, (short) 0x0020);
        }
        else {
           KeyElement.getKey(e, (short) 0x7514, apduBuffer);
           setOutgoingAndSend((short) 0x0000, (short) 0x0020);
        }
    } catch (ArithmeticException e) {
        ISOException.throwIt((short) 0x0100);
    } catch (ArrayStoreException e) {
        ISOException.throwIt((short) 0x0200);
    } catch (APDUException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x03,
            (byte) e.getReason()));
    } catch (CryptoException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x04,
            (byte) e.getReason()));
    } catch (ISOException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x05,
            (byte) e.getReason()));
    } catch (PINException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x06,
            (byte) e.getReason()));
    } catch (ServiceException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x07,
            (byte) e.getReason()));
    } catch (SystemException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x08,
            (byte) e.getReason()));
    } catch (TransactionException e) {
        ISOException.throwIt(Util.makeShort((byte) 0x09,
            (byte) e.getReason()));
    } catch (ClassCastException e) {
        ISOException.throwIt((short) 0x0A00);
    } catch (IndexOutOfBoundsException e) {
        ISOException.throwIt((short) 0x0B00);
    } catch (NegativeArraySizeException e) {
        ISOException.throwIt((short) 0x0C00);
    } catch (NullPointerException e) {
        ISOException.throwIt((short) 0x0D00);
    } catch (SecurityException e) {
        ISOException.throwIt((short) 0x0E00);
    } catch (RuntimeException e) {
    }
 }


    static private short makeShort(final byte value) {
    return Util.makeShort((byte) 0x00, value);
    }

    private void setOutgoingAndSend(final short dataOffset, short dataLength) throws ISOException {
    APDU.getCurrentAPDU().setOutgoingAndSend(dataOffset, dataLength);
    }
}

所以我写了if / else条件来计算需要花费多少时间:

  • 填写列表(INS = 0x00)
  • 获取列表的最后一个元素(当INS = 0x01时)
  • 获取列表的第一个元素(当INS = 0x02时)

因此,使用上面给出的代码,我可以毫无问题地在Java卡上安装我的applet。

但是当我运行我的applet时,我得到一个异常0x0D00,它引用了NullPointerException

那么,什么?我是否必须断定我的KeyElement对象实例失败了?但是,正如它在安装时所做的那样,我认为它应该在安装过程中给我一个错误,但它没有。

更确切地说,它在步骤中失败了:

// Send result.
 try {
   if (apduBuffer[ISO7816.OFFSET_INS] == (byte) 0x00) {
      for (short i = 0x0000; i < (short) 0x0008; i++) {
         rand.generateData(rdm, (short) 0x0000, (short) rdm.length);
         KeyElement.addKey(e, i, rdm);
      }
...

更准确地说,在KeyElement.addKey(e, i, rdm);,为什么e提升NullPointerException即使安装成功也是如此...

2 个答案:

答案 0 :(得分:2)

您尚未创建生成rand的{​​{1}}实例。你需要使用:

NullPointerException

带算法

RandomData.getInstance(byte algorithm) 

答案 1 :(得分:1)

我没有详细浏览所有代码,因为你没有真正了解关于

的链接列表的要点
public KeyElement(short upperBound)

查看一些示例Java链接列表实现,并通过捕获异常或在分配之前检查剩余空间来安全地使用EERPOM