kemDecapsulate

open suspend override fun kemDecapsulate(alias: String, ciphertext: ByteArray, unlockReason: Reason): SecureByteString

Performs Key Decapsulation.

Key decapsulation is only supported for KEM keys (such as ML-KEM).

If the key needs unlocking before use (for example user authentication in any shape or form) and keyUnlockData isn't set or doesn't contain what's needed, KeyLockedException is thrown.

Return

The decapsulated shared secret as a SecureByteString.

Parameters

alias

the alias of the KEM key to use.

ciphertext

The encapsulated ciphertext from the sender.

unlockReason

the reason for unlocking.

Throws

if there is no key with the given alias or the key wasn't created with a KEM algorithm.

if the key needs unlocking.

if the key is no longer usable.

if this Secure Area does not support key decapsulation.