kemDecapsulate
open suspend fun kemDecapsulate(alias: String, ciphertext: ByteArray, unlockReason: Reason = Reason.Unspecified): SecureByteString
Performs Key Decapsulation.
Key decapsulation is only supported for KEM keys (such as ML-KEM).
If the key needs unlocking before use (for example user authentication in any shape or form) and keyUnlockData isn't set or doesn't contain what's needed, KeyLockedException is thrown.
Return
The decapsulated shared secret as a SecureByteString.
Parameters
alias
the alias of the KEM key to use.
ciphertext
The encapsulated ciphertext from the sender.
unlockReason
the reason for unlocking.
Throws
if there is no key with the given alias or the key wasn't created with a KEM algorithm.
if the key needs unlocking.
if the key is no longer usable.
if this Secure Area does not support key decapsulation.