ASN.1模块属性互斥与必现约束实现技术问询
Absolutely, you can enforce all three validation rules (plus the required mutual exclusivity between global and local attributes) using ASN.1's built-in constraint features. Let’s break this down step by step with modified code that implements every check you need.
1. Enforce Mutual Exclusivity + "At Least One Attribute Exists"
First, we need to lock in two mutually exclusive valid scenarios: either the global sKeyPkgAttrs is present (and no local sKeyAttrs exist in any OneSymmetricKey), or sKeyPkgAttrs is absent and at least one OneSymmetricKey includes local attributes. We’ll add a top-level WITH COMPONENTS constraint to SymmetricKeyPackage to enforce this:
SymmetricKeyPackage ::= SEQUENCE { version KeyPkgVersion DEFAULT v1, sKeyPkgAttrs [0] SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyPkgAttributes }} OPTIONAL, sKeys SymmetricKeys, ... } ( -- Scenario 1: Global attributes exist, no local attributes allowed WITH COMPONENTS { sKeyPkgAttrs PRESENT, sKeys WITH COMPONENTS { ALL WITH COMPONENTS { sKeyAttrs ABSENT } } } | -- Scenario 2: No global attributes, at least one local attribute exists WITH COMPONENTS { sKeyPkgAttrs ABSENT, sKeys WITH COMPONENTS { AT LEAST ONE WITH COMPONENTS { sKeyAttrs PRESENT } } } )
2. Prevent Cross-Class Attribute Duplication
To ensure no attribute appears in both global and local sets, we use ASN.1's EXCLUDES constraint to block overlap between the two attribute sequences. You can also explicitly define your attribute sets to be disjoint for extra safety:
-- Global attributes: exclude any attributes from the local set sKeyPkgAttrs [0] SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyPkgAttributes }} EXCLUDES {{ SKeyAttributes }} OPTIONAL, -- Local attributes: exclude any attributes from the global set sKeyAttrs SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyAttributes }} EXCLUDES {{ SKeyPkgAttributes }} OPTIONAL
If you control the attribute set definitions, make sure they don’t share any attributes:
SKeyPkgAttributes ATTRIBUTE ::= { pkgIdentifier, pkgExpiry, pkgOwner, ... -- Global-only attributes } SKeyAttributes ATTRIBUTE ::= { keyLabel, keyUsage, keyValidity, ... -- Local-only attributes (no overlap) }
3. Ensure Mandatory Attributes Are Present
To guarantee required attributes are included when their respective set is used, mark mandatory attributes in your attribute sets and add a CONTAINING ALL constraint to enforce their presence:
Step 1: Mark Mandatory Attributes
SKeyPkgAttributes ATTRIBUTE ::= { pkgIdentifier MANDATORY, -- Required global attribute pkgExpiry OPTIONAL, -- Optional global attribute pkgOwner OPTIONAL, ... } SKeyAttributes ATTRIBUTE ::= { keyLabel MANDATORY, -- Required local attribute keyUsage OPTIONAL, -- Optional local attribute keyValidity OPTIONAL, ... }
Step 2: Enforce Mandatory Attributes in Sequences
Update the attribute sequences to require all mandatory attributes from their set:
sKeyPkgAttrs [0] SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyPkgAttributes }} (CONTAINING ALL {{ SKeyPkgAttributes MANDATORY }}) EXCLUDES {{ SKeyAttributes }} OPTIONAL, sKeyAttrs SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyAttributes }} (CONTAINING ALL {{ SKeyAttributes MANDATORY }}) EXCLUDES {{ SKeyPkgAttributes }} OPTIONAL
Full Modified ASN.1 Module
Putting it all together, here’s the complete module with every constraint applied:
SymmetricKeyPackage ::= SEQUENCE { version KeyPkgVersion DEFAULT v1, sKeyPkgAttrs [0] SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyPkgAttributes }} (CONTAINING ALL {{ SKeyPkgAttributes MANDATORY }}) EXCLUDES {{ SKeyAttributes }} OPTIONAL, sKeys SymmetricKeys, ... } ( WITH COMPONENTS { sKeyPkgAttrs PRESENT, sKeys WITH COMPONENTS { ALL WITH COMPONENTS { sKeyAttrs ABSENT } } } | WITH COMPONENTS { sKeyPkgAttrs ABSENT, sKeys WITH COMPONENTS { AT LEAST ONE WITH COMPONENTS { sKeyAttrs PRESENT } } } ) SymmetricKeys ::= SEQUENCE SIZE (1..MAX) OF OneSymmetricKey OneSymmetricKey ::= SEQUENCE { sKeyAttrs SEQUENCE SIZE (1..MAX) OF Attribute {{ SKeyAttributes }} (CONTAINING ALL {{ SKeyAttributes MANDATORY }}) EXCLUDES {{ SKeyPkgAttributes }} OPTIONAL, sKey OCTET STRING OPTIONAL } ( WITH COMPONENTS { ..., sKeyAttrs PRESENT } | WITH COMPONENTS { ..., sKey PRESENT } ) KeyPkgVersion ::= INTEGER { v1(1) } ( v1, ... ) SKeyPkgAttributes ATTRIBUTE ::= { pkgIdentifier MANDATORY, pkgExpiry OPTIONAL, pkgOwner OPTIONAL, ... } SKeyAttributes ATTRIBUTE ::= { keyLabel MANDATORY, keyUsage OPTIONAL, keyValidity OPTIONAL, ... }
Quick Notes
- These constraints rely on ASN.1’s Information Object Class features—most modern ASN.1 compilers support this, but double-check your tooling if you run into issues.
- The
EXCLUDESconstraint adds a safety net to catch accidental attribute overlaps, even if your sets are supposed to be disjoint by definition. - The
CONTAINING ALLconstraint ensures mandatory attributes can’t be omitted when their parent sequence is used.
内容的提问来源于stack exchange,提问作者Mateusz Woźniak

