$completeHeader * @param array $additionalHeader */ #[Override] public function encryptKey(JWK $key, string $cek, array $completeHeader, array &$additionalHeader): string { $this->checkKey($key); $pub = RSAKey::toPublic(RSAKey::createFromJWK($key)); return RSACrypt::encrypt($pub, $cek, $this->getEncryptionMode(), $this->getHashAlgorithm()); } /** * @param array $header */ #[Override] public function decryptKey(JWK $key, string $encrypted_cek, array $header): string { $this->checkKey($key); if (! $key->has('d')) { throw new InvalidArgumentException('The key is not a private key'); } $priv = RSAKey::createFromJWK($key); return RSACrypt::decrypt($priv, $encrypted_cek, $this->getEncryptionMode(), $this->getHashAlgorithm()); } #[Override] public function getKeyManagementMode(): string { return self::MODE_ENCRYPT; } protected function checkKey(JWK $key): void { if (! in_array($key->get('kty'), $this->allowedKeyTypes(), true)) { throw new InvalidArgumentException('Wrong key type.'); } } abstract protected function getEncryptionMode(): int; abstract protected function getHashAlgorithm(): ?string; }