Expand description
§Public-key authenticated encryption
Implements libsodium’s crypto_box_* functions. A sender encrypts with the
recipient’s public key and the sender’s secret key. The recipient decrypts
with the sender’s public key and the recipient’s secret key.
Nonces are public, but a nonce must never repeat for the same sender and recipient keypair. See the libsodium documentation for details.
§Classic API example
use dryoc::classic::crypto_box::*;
use dryoc::constants::CRYPTO_BOX_MACBYTES;
use dryoc::types::*;
// Create a random sender keypair
let (sender_pk, sender_sk) = crypto_box_keypair();
// Create a random recipient keypair
let (recipient_pk, recipient_sk) = crypto_box_keypair();
// Generate a random nonce
let nonce = Nonce::generate();
let message = "hello".as_bytes();
// Encrypt message
let mut ciphertext = vec![0u8; message.len() + CRYPTO_BOX_MACBYTES];
crypto_box_easy(&mut ciphertext, message, &nonce, &recipient_pk, &sender_sk)
.expect("encrypt failed");
// Decrypt message
let mut decrypted_message = vec![0u8; ciphertext.len() - CRYPTO_BOX_MACBYTES];
crypto_box_open_easy(
&mut decrypted_message,
&ciphertext,
&nonce,
&sender_pk,
&recipient_sk,
)
.expect("decrypt failed");
assert_eq!(message, decrypted_message);Functions§
- crypto_
box_ beforenm - Computes a shared secret for the given
public_keyandsecret_key. Resulting shared secret can be used with the precalculation interface. - crypto_
box_ detached - Detached variant of
crypto_box_easy. - crypto_
box_ detached_ afternm - Precalculation variant of
crypto_box_detached. - crypto_
box_ detached_ afternm_ inplace - In-place variant of
crypto_box_detached_afternm. - crypto_
box_ detached_ inplace - In-place variant of
crypto_box_detached. - crypto_
box_ easy - Encrypts a message in a box.
- crypto_
box_ easy_ afternm - Encrypts a message using a key computed by
crypto_box_beforenm. - crypto_
box_ easy_ inplace - Encrypts a message in-place in a box.
- crypto_
box_ keypair - Generates a public/secret key pair from OS-provided random data, using
copy_randombytes. - crypto_
box_ keypair_ inplace - In-place variant of
crypto_box_keypair - crypto_
box_ open_ detached - Detached variant of
crypto_box_open_easy: decryptsciphertextwith the sender’s public keysender_public_key, the recipient’s secret keyrecipient_secret_key,nonce, and the detachedmac. - crypto_
box_ open_ detached_ afternm - Precalculation variant of
crypto_box_open_detached. - crypto_
box_ open_ detached_ afternm_ inplace - In-place variant of
crypto_box_open_detached_afternm. - crypto_
box_ open_ detached_ inplace - In-place variant of
crypto_box_open_detached: decryptsdatawith the sender’s public keysender_public_keyand the recipient’s secret keyrecipient_secret_key. - crypto_
box_ open_ easy - Decrypts
ciphertextwith recipient’s secret keyrecipient_secret_keyand sender’s public keysender_public_keyusingnonce. - crypto_
box_ open_ easy_ afternm - Decrypts a box using a key computed by
crypto_box_beforenm. - crypto_
box_ open_ easy_ inplace - Decrypts a box in-place.
- crypto_
box_ seal - Encrypts and seals a message in a box.
- crypto_
box_ seal_ open - Decrypts a sealed box.
- crypto_
box_ seed_ keypair - Deterministically derives a keypair from a 32-byte
seed. - crypto_
box_ seed_ keypair_ inplace - In-place variant of
crypto_box_seed_keypair