Package org.cryptacular.bean
Class BCryptHashBean
java.lang.Object
org.cryptacular.bean.BCryptHashBean
- All Implemented Interfaces:
HashBean<CharSequence>
HashBean implementation that uses the bcrypt algorithm for hashing. Hash strings of the following
format are supported:
$2n$cost$xxxxxxxxxxxxxxxxxxxxxxxxyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
where:
n is an optional bcrypt algorithm version (typically "a" or "b")
4 ≤ cost ≤ 31
x is 22 characters of encoded salt
y is 31 characters of encoded hash bytes
The encoding for salt and hash bytes is a variant of base-64 encoding without padding in the following alphabet:
./ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic classHandles encoding and decoding a bcrypt hash of the form$2n$cost$xxxxxxxxxxxxxxxxxxxxxxxxyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy. -
Field Summary
Fields -
Constructor Summary
ConstructorsConstructorDescriptionCreates a new instance.BCryptHashBean(int costFactor) Creates a new instance that uses the given cost factor when hashing.BCryptHashBean(int costFactor, String version) Creates a new instance that uses the given cost factor when hashing. -
Method Summary
Modifier and TypeMethodDescriptionbooleancompare(CharSequence hash, Object... data) Compares a bcrypt hash of the form$2n$cost$xxxxxxxxxxxxxxxxxxxxxxxxyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyywith the computed hash from the given password.private static byte[]Decodes an input string into a byte array using the configured decoder.private static Stringencode(byte[] bytes, int length) Encodes an input byte array into a string using the configured encoder.Compute a bcrypt hash of the form$2n$cost$xxxxxxxxxxxxxxxxxxxxxxxxyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyygiven a salt and a password.private static byte[]Converts an input object into a password as an array of UTF-8 bytes.private static byte[]Converts an input object into a salt as an array of bytes.
-
Field Details
-
ALPHABET
Custom base-64 alphabet.- See Also:
-
DEFAULT_COST
private static final int DEFAULT_COSTDefault cost. Value is 12.- See Also:
-
DEFAULT_VERSION
Default version. Value is '2b'.- See Also:
-
costFactor
private final int costFactorBCrypt cost factor in the range [4, 31]. Default value is . -
version
BCrypt version used when computing hashes. Default value is .
-
-
Constructor Details
-
BCryptHashBean
public BCryptHashBean()Creates a new instance. -
BCryptHashBean
public BCryptHashBean(int costFactor) Creates a new instance that uses the given cost factor when hashing.- Parameters:
costFactor- BCrypt cost in the range [4, 31].
-
BCryptHashBean
Creates a new instance that uses the given cost factor when hashing.- Parameters:
costFactor- BCrypt cost in the range [4, 31].version- Bcrypt version, e.g. "2b"
-
-
Method Details
-
hash
Compute a bcrypt hash of the form$2n$cost$xxxxxxxxxxxxxxxxxxxxxxxxyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyygiven a salt and a password.- Specified by:
hashin interfaceHashBean<CharSequence>- Parameters:
data- A 2-element array containing salt and password. The salt may be encoded per the bcrypt standard or raw bytes.- Returns:
- An encoded bcrypt hash,
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyin the specification above. - Throws:
CryptoException- on bcrypt algorithm errors.
-
compare
Compares a bcrypt hash of the form$2n$cost$xxxxxxxxxxxxxxxxxxxxxxxxyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyywith the computed hash from the given password. The bcrypt algorithm parameters are derived from the reference bcrypt hash string.- Specified by:
comparein interfaceHashBean<CharSequence>- Parameters:
hash- Known hash value.data- A 1-element array containing password.- Returns:
- True if the computed hash is exactly equal to the reference hash, false otherwise.
- Throws:
CryptoException- on bcrypt algorithm errors.StreamException- on stream IO errors.
-
encode
Encodes an input byte array into a string using the configured encoder.- Parameters:
bytes- Input bytes to encode.length- Number of bytes of input to encode.- Returns:
- Input encoded as a string.
-
decode
Decodes an input string into a byte array using the configured decoder.- Parameters:
input- Input string to decode.length- Desired output size in bytes.- Returns:
- Input decoded as a byte array.
-
salt
Converts an input object into a salt as an array of bytes.- Parameters:
data- Input salt as a byte array or encoded string.- Returns:
- Salt as byte array.
-
password
Converts an input object into a password as an array of UTF-8 bytes. A null terminator is added if the supplied data does not end with one.- Parameters:
version- Bcrypt version, e.g. "2a".data- Input password.- Returns:
- Null terminated password as UTF-8 byte array.
-