RFC 7518 - JSON Web Algorithms (JWA)
- 状态: Proposed Standard
- 发布日期: May 2015
- Stream: IETF
- 勘误: 无勘误
摘要
本规范注册用于 JSON Web Signature (JWS), JSON Web Encryption (JWE) 和 JSON Web Key (JWK) 规范的 cryptographic algorithms 和 identifiers. 它为这些 identifiers 定义了若干 IANA registries.
目录
- 1. 简介
- 1.1 记法约定
- 2. 术语
- 3. 用于 Digital Signatures 和 MACs 的 Cryptographic Algorithms
- 3.1 JWS 的 "alg" Header Parameter Values
- 3.2 使用 SHA-2 Functions 的 HMAC
- 3.3 使用 RSASSA-PKCS1-v1_5 的 Digital Signature
- 3.4 使用 ECDSA 的 Digital Signature
- 3.5 使用 RSASSA-PSS 的 Digital Signature
- 3.6 使用算法 "none"
- 4. 用于 Key Management 的 Cryptographic Algorithms
- 4.1 JWE 的 "alg" Header Parameter Values
- 4.2 使用 RSAES-PKCS1-v1_5 的 Key Encryption
- 4.3 使用 RSAES OAEP 的 Key Encryption
- 4.4 使用 AES Key Wrap 的 Key Wrapping
- 4.5 使用 Shared Symmetric Key 的 Direct Encryption
- 4.6 使用 ECDH-ES 的 Key Agreement
- 4.7 使用 AES GCM 的 Key Encryption
- 4.8 使用 PBES2 的 Key Encryption
- 5. 用于 Content Encryption 的 Cryptographic Algorithms
- 5.1 JWE 的 "enc" Header Parameter Values
- 5.2 AES_CBC_HMAC_SHA2 Algorithms
- 5.3 使用 AES GCM 的 Content Encryption
- 6. 用于 Keys 的 Cryptographic Algorithms
- 6.1 "kty" Parameter Values
- 6.2 Elliptic Curve Keys 的参数
- 6.3 RSA Keys 的参数
- 6.4 Symmetric Keys 的参数
- 7. IANA 考虑事项
- 8. 安全考虑事项
- 9. 参考文献
附录
- Appendix A. Algorithm Identifier 交叉引用
- Appendix B. AES_CBC_HMAC_SHA2 的测试用例
- Appendix C. ECDH-ES Key Agreement 示例
相关资源
- 官方文本: RFC 7518
- 官方页面: RFC 7518 DataTracker
- 勘误: RFC Editor Errata
JOSE 规范系列
- RFC 7515 - JSON Web Signature (JWS), 即 JSON Web 签名
- RFC 7516 - JSON Web Encryption (JWE), 即 JSON Web 加密
- RFC 7517 - JSON Web Key (JWK), 即 JSON Web 密钥
- RFC 7518 - JSON Web Algorithms (JWA), 本文档
- RFC 7519 - JSON Web Token (JWT), 即 JSON Web 令牌
核心算法概览
Digital Signature and MAC Algorithms
- HS256, HS384, HS512 - 使用 SHA-2 的 HMAC
- RS256, RS384, RS512 - RSASSA-PKCS1-v1_5 签名
- ES256, ES384, ES512 - ECDSA 签名
- PS256, PS384, PS512 - RSASSA-PSS 签名
- none - 无完整性保护 (not recommended)
Key Management Algorithms
- RSA1_5, RSA-OAEP, RSA-OAEP-256 - RSA Key Encryption
- A128KW, A192KW, A256KW - AES Key Wrap
- dir - 直接使用 shared symmetric key
- ECDH-ES, ECDH-ES+A128KW, ECDH-ES+A192KW, ECDH-ES+A256KW - ECDH Key Agreement
- A128GCMKW, A192GCMKW, A256GCMKW - AES GCM Key Encryption
- PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW - Password-Based Key Encryption
Content Encryption Algorithms
- A128CBC-HS256, A192CBC-HS384, A256CBC-HS512 - AES CBC 与 HMAC SHA-2 组合
- A128GCM, A192GCM, A256GCM - AES GCM 内容加密