Abblix.Jwt.EncryptionAlgorithms
EncryptionAlgorithms.KeyManagement Class
Key management algorithms ("alg" parameter in the JWE header). These wrap or derive the Content Encryption Key (CEK) that is then used by a content encryption algorithm.
public static class EncryptionAlgorithms.KeyManagementInheritance System.Object → KeyManagement
Fields
EncryptionAlgorithms.KeyManagement.Aes128Gcmkw Field
AES-GCM Key Wrap with a 128-bit key (RFC 7518 Section 4.7). Backed by .NET AesGcm.
The 96-bit IV and 128-bit authentication tag are carried in the JOSE header parameters
iv and tag (RFC 7518 Section 4.7.1); the JWE Encrypted Key is the wrapped-CEK ciphertext.
public const string Aes128Gcmkw = "A128GCMKW";Field Value
EncryptionAlgorithms.KeyManagement.Aes128KW Field
AES Key Wrap with a 128-bit key (RFC 7518 Section 4.4). The CEK is wrapped with the RFC 3394 AES Key Wrap construction over the platform AES-ECB primitive; the wrap's own integrity check register protects the wrapped key, so no extra header parameters are used.
public const string Aes128KW = "A128KW";Field Value
EncryptionAlgorithms.KeyManagement.Aes192Gcmkw Field
AES-GCM Key Wrap with a 192-bit key (RFC 7518 Section 4.7). Backed by .NET AesGcm.
public const string Aes192Gcmkw = "A192GCMKW";Field Value
EncryptionAlgorithms.KeyManagement.Aes192KW Field
AES Key Wrap with a 192-bit key (RFC 7518 Section 4.4). See Aes128KW.
public const string Aes192KW = "A192KW";Field Value
EncryptionAlgorithms.KeyManagement.Aes256Gcmkw Field
AES-GCM Key Wrap with a 256-bit key (RFC 7518 Section 4.7). Backed by .NET AesGcm.
Recommended choice when both peers can share a symmetric key.
public const string Aes256Gcmkw = "A256GCMKW";Field Value
EncryptionAlgorithms.KeyManagement.Aes256KW Field
AES Key Wrap with a 256-bit key (RFC 7518 Section 4.4). See Aes128KW. Recommended choice when a peer requires plain AES Key Wrap; otherwise prefer Aes256Gcmkw for authenticated wrapping with a random IV.
public const string Aes256KW = "A256KW";Field Value
EncryptionAlgorithms.KeyManagement.Dir Field
Direct use of a shared symmetric key as the Content Encryption Key (RFC 7518 Section 4.5). No key wrap is performed and the JWE "encrypted_key" is the empty octet sequence. The shared key length must match the key size required by the chosen content encryption algorithm.
public const string Dir = "dir";Field Value
EncryptionAlgorithms.KeyManagement.EcdhEs Field
Elliptic Curve Diffie-Hellman Ephemeral Static key agreement in Direct Key Agreement mode
(RFC 7518 Section 4.6). The CEK is derived from the ephemeral-static agreement via the
Concat KDF (computed natively by ECDiffieHellman.DeriveKeyFromHash) and the JWE
Encrypted Key is empty. Supports the NIST curves P-256, P-384 and P-521.
public const string EcdhEs = "ECDH-ES";Field Value
EncryptionAlgorithms.KeyManagement.EcdhEsAes128KW Field
ECDH-ES key agreement wrapping the CEK with AES-128 Key Wrap (RFC 7518 Section 4.6). The agreement derives a 128-bit KEK that wraps a random CEK per RFC 3394.
public const string EcdhEsAes128KW = "ECDH-ES+A128KW";Field Value
EncryptionAlgorithms.KeyManagement.EcdhEsAes192KW Field
ECDH-ES key agreement wrapping the CEK with AES-192 Key Wrap (RFC 7518 Section 4.6). See EcdhEsAes128KW.
public const string EcdhEsAes192KW = "ECDH-ES+A192KW";Field Value
EncryptionAlgorithms.KeyManagement.EcdhEsAes256KW Field
ECDH-ES key agreement wrapping the CEK with AES-256 Key Wrap (RFC 7518 Section 4.6). See EcdhEsAes128KW. Recommended choice for EC-key-based JWE deployments.
public const string EcdhEsAes256KW = "ECDH-ES+A256KW";Field Value
EncryptionAlgorithms.KeyManagement.Pbes2HmacSha256Aes128KW Field
PBES2 with HMAC SHA-256 and AES-128 Key Wrap (RFC 7518 Section 4.8). The KEK is derived
from a password with PBKDF2 (native Rfc2898DeriveBytes.Pbkdf2) using the
'p2s'/'p2c' header parameters, then wraps the CEK per RFC 3394. Inbound iteration counts
are bounded to keep an attacker-supplied token from demanding arbitrary PBKDF2 work.
Opt-in: the PBES2 family is enabled by AddPbes2KeyManagement, not by default -
accepting password-based key management from token producers is an explicit hosting decision.
public const string Pbes2HmacSha256Aes128KW = "PBES2-HS256+A128KW";Field Value
EncryptionAlgorithms.KeyManagement.Pbes2HmacSha384Aes192KW Field
PBES2 with HMAC SHA-384 and AES-192 Key Wrap (RFC 7518 Section 4.8). See Pbes2HmacSha256Aes128KW.
public const string Pbes2HmacSha384Aes192KW = "PBES2-HS384+A192KW";Field Value
EncryptionAlgorithms.KeyManagement.Pbes2HmacSha512Aes256KW Field
PBES2 with HMAC SHA-512 and AES-256 Key Wrap (RFC 7518 Section 4.8). See Pbes2HmacSha256Aes128KW.
public const string Pbes2HmacSha512Aes256KW = "PBES2-HS512+A256KW";Field Value
EncryptionAlgorithms.KeyManagement.Rsa1_5 Field
RSAES-PKCS1-v1_5 key encryption (RFC 7518 Section 4.2). Backed by .NET RSA
with RSAEncryptionPadding.Pkcs1.
Kept for interoperability with legacy peers; OAEP variants should be preferred
because PKCS#1 v1.5 padding is vulnerable to chosen-ciphertext attacks (Bleichenbacher)
and NIST SP 800-131A Rev. 2 disallows it for key transport.
Opt-in: enabled by AddRsaPkcs1KeyManagement, not by default.
public const string Rsa1_5 = "RSA1_5";Field Value
EncryptionAlgorithms.KeyManagement.RsaOaep Field
RSAES-OAEP with SHA-1 and MGF1-SHA-1 (RFC 7518 Section 4.3). Backed by .NET RSA
with RSAEncryptionPadding.OaepSHA1.
Use when interoperating with peers that have not adopted RSA-OAEP-256;
otherwise prefer RsaOaep256.
public const string RsaOaep = "RSA-OAEP";Field Value
EncryptionAlgorithms.KeyManagement.RsaOaep256 Field
RSAES-OAEP with SHA-256 and MGF1-SHA-256 (RFC 7518 Section 4.3). Backed by .NET RSA
with RSAEncryptionPadding.OaepSHA256. Recommended choice for new RSA-based JWE deployments.
public const string RsaOaep256 = "RSA-OAEP-256";