Abblix.Jwt.Encryption Namespace
| Classes | |
|---|---|
| DeterministicAeadEncryptor | Deterministic authenticated encryption bound to associated data: the same plaintext and associated data always seal to the same bytes, different inputs seal to unrelated bytes, and tampering or a wrong associated data is rejected on opening. This is the property a reversible, stable pseudonym needs - a value that is opaque and unlinkable to outsiders yet recoverable by the holder of the key, and identical across sessions and hosts for the same input. |
| EncryptedData | Represents the result of JWE content encryption operation. Contains the components required for JWE Compact Serialization per RFC 7516. |
| Interfaces | |
|---|---|
| IContentKeyDecryptor | The JWE key-recovery seam: recovers the Content Encryption Key for a recipient key, routed per key to the backend that owns it. This is the encryption counterpart of IDataSigner and, like it, carries ONLY the private operation: recovering the CEK needs the recipient's private/secret half, so a public-only key routes to an external custodian. Producing a JWE (wrapping the CEK) uses the recipient's PUBLIC half for asymmetric algorithms, or a locally held shared secret for symmetric ones, so it never needs a custodian and never passes through this seam - it stays in IJsonWebTokenEncryptor, exactly as signature verification stays out of IDataSigner. Backends compose as peers behind Abblix.Jwt.Encryption.CompositeDecryptor: Abblix.Jwt.Encryption.LocalKeyDecryptor unwraps in process, an external custodian backend (Abblix.Jwt.ExternalKeys.ExternalKeyDecryptor) unwraps against an HSM/KMS/vault. |
| IKeyManagementAlgorithm<TJsonWebKey> | Interface for JWE (JSON Web Encryption) key encryption and decryption operations. Encrypts and decrypts the Content Encryption Key (CEK) using a specific key management algorithm. Implements RFC 7516 Section 5 (Key Encryption) and RFC 7518 Section 4 (Key Management Algorithms). |