MYPublicKey.h
author snej@snej-mbp.mtv.corp.google.com
Tue Apr 07 10:56:58 2009 -0700 (2009-04-07)
changeset 2 8982b8fada63
parent 0 0a6527af039b
child 3 1dfe820d7ebe
permissions -rw-r--r--
More work, mostly on documentation.
     1 //
     2 //  MYPublicKey.h
     3 //  MYCrypto
     4 //
     5 //  Created by Jens Alfke on 3/25/09.
     6 //  Copyright 2009 Jens Alfke. All rights reserved.
     7 //
     8 
     9 #import "MYKey.h"
    10 @class MYSHA1Digest;
    11 
    12 #if !TARGET_OS_IPHONE
    13 #import <Security/SecKey.h>
    14 #endif
    15 
    16 
    17 /** A public key, which can be used for encrypting data and verifying signatures.
    18     MYPublicKeys are created as part of generating a MYKeyPair, 
    19     or by being imported into a MYKeychain. */
    20 @interface MYPublicKey : MYKey <MYEncryption>
    21 {
    22     @private
    23     MYSHA1Digest *_digest;
    24 }
    25 
    26 /** The public key's SHA-1 digest. This is a convenient short (20-byte) identifier for the key. */
    27 @property (readonly) MYSHA1Digest *publicKeyDigest;
    28 
    29 /** Returns the receiver as a MYPublicKey.
    30     If the receiver already is a MYPublicKey, this just returns self.
    31     If it's a MYKeyPair, it returns a new MYPublicKey containing just the public key. */
    32 @property (readonly) MYPublicKey *asPublicKey;
    33 
    34 /** Encrypts a short piece of data using this key, returning the raw encrypted result.
    35     An RSA key can encrypt only blocks smaller than its own key size; this
    36     method will fail and return nil if the data is too long.
    37     RSA encryption is also much slower than regular symmetric-key encryption, so the correct
    38     way to encrypt a large block of data using a public key is to first generate a random
    39     symmetric key, called the "session key" (using a Cryptor), encrypt that session key with the 
    40     public key, and then encrypt your data with the session key. Send the encrypted session key
    41     and the encrypted data. */
    42 - (NSData*) encryptData: (NSData*)data;
    43 
    44 /** Verifies the signature of a block of data. If the result is YES, you can be assured that
    45     the signature was generated from the data by using this key's matching private key.
    46     If the result is NO, something is wrong: either the data or the signature was modified,
    47     or the signature was generated by a different private key.
    48     (What's actually verified using RSA is the SHA-256 digest of the data.) */
    49 - (BOOL) verifySignature: (NSData*)signature ofData: (NSData*)data;
    50     
    51 @end