gnu.javax.crypto.key.srp6

Class SRP6KeyAgreement

Implemented Interfaces:
IKeyAgreementParty
Known Direct Subclasses:
SRP6Host, SRP6TLSClient, SRP6TLSServer, SRP6User

public abstract class SRP6KeyAgreement
extends BaseKeyAgreementParty

The Secure Remote Password (SRP) key agreement protocol, also known as SRP-6, is designed by Thomas J. Wu (see references). The protocol, and its elements are described as follows:
  N    A large safe prime (N = 2q+1, where q is prime)
       All arithmetic is done modulo N.
  g    A generator modulo N
  s    User's salt
  I    Username
  p    Cleartext Password
  H()  One-way hash function
  ˆ    (Modular) Exponentiation
  u    Random scrambling parameter
  a,b  Secret ephemeral values
  A,B  Public ephemeral values
  x    Private key (derived from p and s)
  v    Password verifier

  The host stores passwords using the following formula:
  x = H(s | H(I ":" p))           (s is chosen randomly)
  v = gˆx                         (computes password verifier)

  The host then keeps {I, s, v} in its password database.

  The authentication protocol itself goes as follows:
  User -> Host:  I, A = gˆa         (identifies self, a = random number)
  Host -> User:  s, B = 3v + gˆb    (sends salt, b = random number)

  Both:  u = H(A, B)

  User:  x = H(s, p)               (user enters password)
  User:  S = (B - 3gˆx) ˆ (a + ux) (computes session key)
  User:  K = H(S)

  Host:  S = (Avˆu) ˆ b            (computes session key)
  Host:  K = H(S)
 

Reference:

  1. SRP Protocol Design
    Thomas J. Wu.

Field Summary

static String
GENERATOR
static String
HASH_FUNCTION
static String
HOST_PASSWORD_DB
protected BigInteger
K
The shared secret key.
protected BigInteger
N
static String
SHARED_MODULUS
static String
SOURCE_OF_RANDOMNESS
protected static BigInteger
THREE
static String
USER_IDENTITY
static String
USER_PASSWORD
protected BigInteger
g
protected SRP
srp

Fields inherited from class gnu.javax.crypto.key.BaseKeyAgreementParty

TWO, complete, initialised, irnd, name, rnd, step

Constructor Summary

SRP6KeyAgreement()
The basic constructor.

Method Summary

protected void
engineReset()
protected byte[]
engineSharedSecret()
protected BigInteger
uValue(BigInteger A, BigInteger B)

Methods inherited from class gnu.javax.crypto.key.BaseKeyAgreementParty

engineInit, engineProcessMessage, engineReset, engineSharedSecret, getSharedSecret, init, isComplete, name, nextRandomBytes, processMessage, reset

Methods inherited from class java.lang.Object

clone, equals, extends Object> getClass, finalize, hashCode, notify, notifyAll, toString, wait, wait, wait

Field Details

GENERATOR

public static final String GENERATOR
Field Value:
"gnu.crypto.srp6.ka.g"

HASH_FUNCTION

public static final String HASH_FUNCTION
Field Value:
"gnu.crypto.srp6.ka.H"

HOST_PASSWORD_DB

public static final String HOST_PASSWORD_DB
Field Value:
"gnu.crypto.srp6.ka.password.db"

K

protected BigInteger K
The shared secret key.

N

protected BigInteger N

SHARED_MODULUS

public static final String SHARED_MODULUS
Field Value:
"gnu.crypto.srp6.ka.N"

SOURCE_OF_RANDOMNESS

public static final String SOURCE_OF_RANDOMNESS
Field Value:
"gnu.crypto.srp6.ka.prng"

THREE

protected static final BigInteger THREE

USER_IDENTITY

public static final String USER_IDENTITY
Field Value:
"gnu.crypto.srp6.ka.I"

USER_PASSWORD

public static final String USER_PASSWORD
Field Value:
"gnu.crypto.srp6.ka.p"

g

protected BigInteger g

srp

protected SRP srp

Constructor Details

SRP6KeyAgreement

protected SRP6KeyAgreement()
The basic constructor. Object is special, because it has no superclass, so there is no call to super().

Method Details

engineReset

protected void engineReset()
Overrides:
engineReset in interface BaseKeyAgreementParty

engineSharedSecret

protected byte[] engineSharedSecret()
            throws KeyAgreementException
Overrides:
engineSharedSecret in interface BaseKeyAgreementParty

uValue

protected BigInteger uValue(BigInteger A,
                            BigInteger B)

SRP6KeyAgreement.java -- Copyright (C) 2003, 2006 Free Software Foundation, Inc. This file is a part of GNU Classpath. GNU Classpath is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. GNU Classpath is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with GNU Classpath; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA Linking this library statically or dynamically with other modules is making a combined work based on this library. Thus, the terms and conditions of the GNU General Public License cover the whole combination. As a special exception, the copyright holders of this library give you permission to link this library with independent modules to produce an executable, regardless of the license terms of these independent modules, and to copy and distribute the resulting executable under terms of your choice, provided that you also meet, for each linked independent module, the terms and conditions of the license of that module. An independent module is a module which is not derived from or based on this library. If you modify this library, you may extend this exception to your version of the library, but you are not obligated to do so. If you do not wish to do so, delete this exception statement from your version.