Client and backend. Every class listed here is shared: the same code is compiled into your app and into your server. The package's page in the client API lists all of it, including any classes that exist only in the app.
package com.codename1.security
The part of the client’s cryptography a server shares with it: the portable Java digests and message authentication codes, and the one-time passwords built on them.
Otp– RFC 4226 and RFC 6238 one-time passwords: the codes an authenticator application shows. Being the same class the client runs, a code made on a device is the code a server expects.Base32– the encoding an authenticator’s shared secret travels in.Hash/Hmac– MD5, SHA-1 and the SHA-2 family, and HMAC over each, written in Java. They are whatOtpcomputes with.
A server reaches for these to verify a second factor and for little else.
What a request path computes – a password hash, a token’s signature, a
digest of something large – goes through
Crypto, which is OpenSSL in a packaged server and
several times faster.
The client has more in this package – ciphers, signatures, key storage – which a server does not: see the client API reference.
Types
class Base32 | Base32 encoder/decoder per RFC 4648. |
class CryptoException | Thrown by classes in this package when a cryptographic operation fails. |
class Hash | Streaming and one-shot cryptographic hash (message digest) functions. |
class Hmac | Keyed-hash message authentication (HMAC, RFC 2104) on top of any hash algorithm supported by Hash. |
class Otp | Counter-based (HOTP, RFC 4226) and time-based (TOTP, RFC 6238) one-time password generators. |