Client and backend. Every class listed here is shared: the same code is compiled into your app and into your server. The package's page in the client API lists all of it, including any classes that exist only in the app.

package com.codename1.security

The part of the client’s cryptography a server shares with it: the portable Java digests and message authentication codes, and the one-time passwords built on them.

  • Otp – RFC 4226 and RFC 6238 one-time passwords: the codes an authenticator application shows. Being the same class the client runs, a code made on a device is the code a server expects.
  • Base32 – the encoding an authenticator’s shared secret travels in.
  • Hash / Hmac – MD5, SHA-1 and the SHA-2 family, and HMAC over each, written in Java. They are what Otp computes with.

A server reaches for these to verify a second factor and for little else. What a request path computes – a password hash, a token’s signature, a digest of something large – goes through Crypto, which is OpenSSL in a packaged server and several times faster.

The client has more in this package – ciphers, signatures, key storage – which a server does not: see the client API reference.

Types

class Base32Base32 encoder/decoder per RFC 4648.
class CryptoExceptionThrown by classes in this package when a cryptographic operation fails.
class HashStreaming and one-shot cryptographic hash (message digest) functions.
class HmacKeyed-hash message authentication (HMAC, RFC 2104) on top of any hash algorithm supported by Hash.
class OtpCounter-based (HOTP, RFC 4226) and time-based (TOTP, RFC 6238) one-time password generators.