2017-07-07 137 views
1

我有一個Thales nShield HSM,其中我創建了一個(CKA_SENSATIVE,false)AES密鑰,但是,我無法弄清楚如何在java中執行它。我的主要創作看起來就像這樣:HSM AES密鑰提取

CK_ATTRIBUTE[] aesKeyObject = new CK_ATTRIBUTE[14]; 

    try 
    { 
     aesKeyObject[0] = new CK_ATTRIBUTE(CKA_CLASS, CKO_SECRET_KEY); 
     aesKeyObject[1] = new CK_ATTRIBUTE(CKA_KEY_TYPE, CKK_AES); 
     aesKeyObject[2] = new CK_ATTRIBUTE(CKA_VALUE_LEN, 32); 
     aesKeyObject[3] = new CK_ATTRIBUTE(CKA_TOKEN, true); 
     aesKeyObject[4] = new CK_ATTRIBUTE(CKA_LABEL, "TestAES".getBytes()); 
     aesKeyObject[5] = new CK_ATTRIBUTE(CKA_PRIVATE, true); 
     aesKeyObject[6] = new CK_ATTRIBUTE(CKA_EXTRACTABLE, true); 
     aesKeyObject[7] = new CK_ATTRIBUTE(CKA_WRAP, true); 
     aesKeyObject[8] = new CK_ATTRIBUTE(CKA_UNWRAP, true); 
     aesKeyObject[9] = new CK_ATTRIBUTE(CKA_ENCRYPT, true); 
     aesKeyObject[10] = new CK_ATTRIBUTE(CKA_DECRYPT, true); 
     aesKeyObject[11] = new CK_ATTRIBUTE(CKA_TRUSTED, true); 
     aesKeyObject[12] = new CK_ATTRIBUTE(CKA_ID, 1550); 
     aesKeyObject[13] = new CK_ATTRIBUTE(CKA_SENSITIVE, false); 

     CK_MECHANISM mech = new CK_MECHANISM(CKM_AES_KEY_GEN); 

     long newAESKeyHandle = p11.C_GenerateKey(hSession, mech, aesKeyObject);  
    }catch(Exception e) 
    { 
    } 
+0

@zaph它是nShield –

回答

0

您需要閱讀生成的密鑰對象的屬性與C_GetAttributeValue功能。

+0

是的,我在前一篇文章中看到了答案。你能更具體一點嗎?我做了: p11.C_GetAttributeValue(hSession,newAESKeyHandle,CKA_VALUE);我給了我1126的價值。不太確定那是什麼。我已經完成了: CK_ATTRIBUTE [] KeyValue = new CK_ATTRIBUTE [] { new CK_ATTRIBUTE(CKA_VALUE,newAESKeyHandle) }; –