| 53 | const ciphertextCrc32c = crc32c.calculate(ciphertext); |
| 54 | |
| 55 | async function decryptAsymmetric() { |
| 56 | const [decryptResponse] = await client.asymmetricDecrypt({ |
| 57 | name: versionName, |
| 58 | ciphertext: ciphertext, |
| 59 | ciphertextCrc32c: { |
| 60 | value: ciphertextCrc32c, |
| 61 | }, |
| 62 | }); |
| 63 | |
| 64 | // Optional, but recommended: perform integrity verification on decryptResponse. |
| 65 | // For more details on ensuring E2E in-transit integrity to and from Cloud KMS visit: |
| 66 | // https://cloud.google.com/kms/docs/data-integrity-guidelines |
| 67 | if (!decryptResponse.verifiedCiphertextCrc32c) { |
| 68 | throw new Error('AsymmetricDecrypt: request corrupted in-transit'); |
| 69 | } |
| 70 | if ( |
| 71 | crc32c.calculate(decryptResponse.plaintext) !== |
| 72 | Number(decryptResponse.plaintextCrc32c.value) |
| 73 | ) { |
| 74 | throw new Error('AsymmetricDecrypt: response corrupted in-transit'); |
| 75 | } |
| 76 | |
| 77 | // NOTE: The ciphertext must be properly formatted. In Node < 12, the |
| 78 | // crypto.publicEncrypt() function does not properly consume the OAEP |
| 79 | // padding and thus produces invalid ciphertext. If you are using Node to do |
| 80 | // public key encryption, please use version 12+. |
| 81 | const plaintext = decryptResponse.plaintext.toString('utf8'); |
| 82 | |
| 83 | console.log(`Plaintext: ${plaintext}`); |
| 84 | return plaintext; |
| 85 | } |
| 86 | |
| 87 | return decryptAsymmetric(); |
| 88 | // [END kms_decrypt_asymmetric] |