Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Мазмұны
Кіріспе
Криптографиялық қолданбалы бағдарламалау интерфейсі
Cryptographic application programming interface
Bouncy Castle – криптографияда қолданылатын API жиынтығы. Ол Java және C# бағдарламалау тілдері үшін API-лерді қамтиды. Бұл API-лерді Австралияда тіркелген қайырымдылық ұйымы қолдайды: Bouncy Castle Inc.
Bouncy Castle is a collection of APIs used in cryptography. It includes APIs for both the Java and the C# programming languages. The APIs are supported by a registered Australian charitable organization: Legion of the Bouncy Castle Inc.
Bouncy Castle Австралияда жасалған, сондықтан АҚШ-тың криптографияны экспорттауға қатысты шектеулері оған қолданылмайды.
Bouncy Castle is Australian in origin and therefore American restrictions on the export of cryptography from the United States do not apply to it.
Сәулет
Bouncy Castle архитектурасы негізгі криптографиялық мүмкіндіктерді қолдайтын екі негізгі компоненттен тұрады. Бұл – «жеңіл салмақты» API және Java Cryptography Extension (JCE) провайдері. JCE провайдеріне негізделген қосымша компоненттер PGP қолдауы, S/MIME сияқты қосымша функционалдықты қолдайды. Төменгі деңгейлі немесе «жеңіл салмақты» API – барлық негізгі криптографиялық алгоритмдерді іске асыратын API жиынтығы. Бұл API қажет болған жағдайда қолдануға оңай болу үшін жасалды, бірақ JCE провайдері үшін негізгі құрылыс блогы болды. Мақсаты – төменгі деңгейлі API-ді жады шектеулі құрылғыларда (JavaME) немесе JCE кітапханаларына оңай қол жеткізу мүмкін болмаған жағдайларда (мысалы, апплеттерді тарату) пайдалану. «Жеңіл салмақты» API тек Java коды болғандықтан, Java виртуалды машинасы (JVM) кодтың жұмысына ешқандай шектеу қоймайды. Bouncy Castle тарихының басында, бұл JCE провайдерлерінің жұмысын шектемейтін Jurisdiction Policy файлдарынан зардап көрмеген, күшті криптографияны дамытудың жалғыз жолы болды. JCE үйлесімді провайдері төменгі деңгейлі API-дің негізінде құрылған. Сондықтан, JCE провайдерінің бастапқы коды төменгі деңгейлі API-ді пайдалана отырып, көптеген «жалпы» криптографиялық мәселелерді шешудің мысалы болып табылады. JCE провайдерін қолдана отырып көптеген жобалар жасалды, соның ішінде ашық бастапқы кодты сертификаттау органы EJBCA.
The Bouncy Castle architecture consists of two main components that support the base cryptographic capabilities. These are known as the 'light weight' API, and the Java Cryptography Extension (JCE) provider. Further components built upon the JCE provider support additional functionality, such as PGP support, S/MIME, etc. The low level, or 'light weight', API is a set of APIs that implement all the underlying cryptographic algorithms. The APIs were designed to be simple enough to use if needed, but provided the basic building blocks for the JCE provider. The intent is to use the low level API in memory constrained devices (JavaME) or when easy access to the JCE libraries is not possible (such as distribution in an applet). As the light weight API is just Java code, the Java virtual machine (JVM) does not impose any restrictions on the operation of the code, and at early times of the Bouncy Castle history it was the only way to develop strong cryptography that was not crippled by the Jurisdiction Policy files that prevented JCE providers from performing "strong" encryption. The JCE compatible provider is built upon the low level APIs. As such, the source code for the JCE provider is an example of how to implement many of the "common" crypto problems using the low level API. Many projects have been built using the JCE provider, including an Open Source Certificate Authority EJBCA.
Сертификатталған шығарылымдар
C# және Java нұсқаларында FIPS 140 2 деңгейі 1 сертификатталған ағындар да бар. Бұл нұсқалар стандартты нұсқалардан осылай ерекшеленеді: модульдер стандартты нұсқалар сияқты құрылған болғанымен, төменгі деңгейдегі API-лар мүлдем басқа – бұл негізінен алгоритм қолданылған кезде FIPS талап ететін бақылауларды күшейту үшін жасалған. Java API-нің JCE деңгейі үшін провайдер әлі де стандартты нұсқаның орнын толыққанды алмастыра алады. FIPS сертификатталған алғашқы нұсқалар 2016 жылдың қараша айында жарияланды, Java-ның ең соңғы нұсқасына 4616 сертификат нөмірі, ал C#-тың ең соңғы нұсқасына 4416 сертификат нөмірі тағайындалды.
The C# and Java releases have FIPS 140 2 Level 1 certified streams as well. These differ from the regular releases in that, while the modules are designed in a similar fashion to the regular releases, the low level APIs are quite different – largely to support the enforcement of controls that FIPS requires when an algorithm is used. In the case of the JCE level of the Java API, the provider is still largely a drop in replacement for the regular release. The first FIPS certified releases were made available in November 2016, with the latest Java version being assigned certification number 4616 and the latest C# version being assigned certification number 4416.
Спунджы қамалы
Android операциялық жүйесі 2014 жылдың басында Bouncy Castle-дың өңделген нұсқасын қамтиды. Сынып атауларының қақтығысуына байланысты, бұл Android қолданбаларына Bouncy Castle-дың ресми нұсқасын өзгеріссіз қосуға және пайдалануға мүмкіндік бермейді. Spongy Castle деп аталатын үшінші тараптық жоба осы мәселенің шешімі ретінде кітапхананың атауын өзгертілген нұсқасын таратады.
The Android operating system, as of early 2014, includes a customized version of Bouncy Castle. Due to class name conflicts, this prevents Android applications from including and using the official release of Bouncy Castle as is. A third party project called Spongy Castle distributes a renamed version of the library to work around this issue.
Сызықты қамал
Бастапқыда, Spongy Castle-дың FIPS 140 2 нұсқасы да жасалуы мүмкін деп есептелді. Бірақ Android-тің DEX файлдарын өңдеу процесі көрсеткендей, FIPS талаптарына сәйкес, провайдер қосымшадан бөлек, тікелей құрылғыға орнатылуы керек болды. Android үшін FIPS 140 2 нұсқасы енді Stripy Castle деп аталады және org.stripycastle пакетімен таратылады. Бұл, Android-тің Bouncy Castle нұсқасымен және Spongy Castle-ды пайдаланатын, бірақ FIPS 140 2 сертификатталған қызметтерді қажет етпейтін қосымшалармен келесідей қақтығыстарды болдырмау үшін қажет болды.
Originally, it was assumed a FIPS 140 2 version of Spongy Castle could also be done. It turned out due to Android's DEX file processing that for FIPS purposes the provider needs to be installed on the device separate from the application. The FIPS 140 2 release for Android is now called Stripy Castle and is packaged under org. stripycastle. This was needed in order to avoid clashes with Android's version of Bouncy Castle as well as clashes for applications that might be using Spongy Castle and not requiring FIPS 140 2 certified services.