001/* 002 * nimbus-jose-jwt 003 * 004 * Copyright 2012-2016, Connect2id Ltd and contributors. 005 * 006 * Licensed under the Apache License, Version 2.0 (the "License"); you may not use 007 * this file except in compliance with the License. You may obtain a copy of the 008 * License at 009 * 010 * http://www.apache.org/licenses/LICENSE-2.0 011 * 012 * Unless required by applicable law or agreed to in writing, software distributed 013 * under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR 014 * CONDITIONS OF ANY KIND, either express or implied. See the License for the 015 * specific language governing permissions and limitations under the License. 016 */ 017 018package com.nimbusds.jose.crypto.utils; 019 020 021/** 022 * Array utilities. 023 * 024 * @author Vladimir Dzhuvinov 025 * @version 2017-04-26 026 */ 027public class ConstantTimeUtils { 028 029 030 /** 031 * Checks the specified arrays for equality in constant time. Intended 032 * to mitigate timing attacks. 033 * 034 * @param a The first array. Must not be {@code null}. 035 * @param b The second array. Must not be {@code null}. 036 * 037 * @return {@code true} if the two arrays are equal, else 038 * {@code false}. 039 */ 040 public static boolean areEqual(final byte[] a, final byte[] b) { 041 042 // From http://codahale.com/a-lesson-in-timing-attacks/ 043 044 if (a.length != b.length) { 045 return false; 046 } 047 048 int result = 0; 049 for (int i = 0; i < a.length; i++) { 050 result |= a[i] ^ b[i]; 051 } 052 053 return result == 0; 054 } 055 056 057 /** 058 * Prevents public instantiation. 059 */ 060 private ConstantTimeUtils() { } 061}