Package com.codename1.security


package com.codename1.security

The part of the client's cryptography a server shares with it: the portable Java digests and message authentication codes, and the one-time passwords built on them.

  • Otp -- RFC 4226 and RFC 6238 one-time passwords: the codes an authenticator application shows. Being the same class the client runs, a code made on a device is the code a server expects.
  • Base32 -- the encoding an authenticator's shared secret travels in.
  • Hash / Hmac -- MD5, SHA-1 and the SHA-2 family, and HMAC over each, written in Java. They are what Otp computes with.

A server reaches for these to verify a second factor and for little else. What a request path computes -- a password hash, a token's signature, a digest of something large -- goes through Crypto, which is OpenSSL in a packaged server and several times faster.

The client has more in this package -- ciphers, signatures, key storage -- which a server does not: see the client API reference.

  • Class
    Description
    Base32 encoder/decoder per RFC 4648.
    Thrown by classes in this package when a cryptographic operation fails.
    Streaming and one-shot cryptographic hash (message digest) functions.
    Keyed-hash message authentication (HMAC, RFC 2104) on top of any hash algorithm supported by Hash.
    Counter-based (HOTP, RFC 4226) and time-based (TOTP, RFC 6238) one-time password generators.