跳到主要内容

RFC 7518 - JSON Web Algorithms (JWA)

  • 状态: Proposed Standard
  • 发布日期: May 2015
  • Stream: IETF
  • 勘误: 无勘误

摘要

本规范注册用于 JSON Web Signature (JWS), JSON Web Encryption (JWE) 和 JSON Web Key (JWK) 规范的 cryptographic algorithms 和 identifiers. 它为这些 identifiers 定义了若干 IANA registries.


目录

附录


相关资源

JOSE 规范系列

  • RFC 7515 - JSON Web Signature (JWS), 即 JSON Web 签名
  • RFC 7516 - JSON Web Encryption (JWE), 即 JSON Web 加密
  • RFC 7517 - JSON Web Key (JWK), 即 JSON Web 密钥
  • RFC 7518 - JSON Web Algorithms (JWA), 本文档
  • RFC 7519 - JSON Web Token (JWT), 即 JSON Web 令牌

核心算法概览

Digital Signature and MAC Algorithms

  • HS256, HS384, HS512 - 使用 SHA-2 的 HMAC
  • RS256, RS384, RS512 - RSASSA-PKCS1-v1_5 签名
  • ES256, ES384, ES512 - ECDSA 签名
  • PS256, PS384, PS512 - RSASSA-PSS 签名
  • none - 无完整性保护 (not recommended)

Key Management Algorithms

  • RSA1_5, RSA-OAEP, RSA-OAEP-256 - RSA Key Encryption
  • A128KW, A192KW, A256KW - AES Key Wrap
  • dir - 直接使用 shared symmetric key
  • ECDH-ES, ECDH-ES+A128KW, ECDH-ES+A192KW, ECDH-ES+A256KW - ECDH Key Agreement
  • A128GCMKW, A192GCMKW, A256GCMKW - AES GCM Key Encryption
  • PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW - Password-Based Key Encryption

Content Encryption Algorithms

  • A128CBC-HS256, A192CBC-HS384, A256CBC-HS512 - AES CBC 与 HMAC SHA-2 组合
  • A128GCM, A192GCM, A256GCM - AES GCM 内容加密