Skip to main content

Module crypto_kem

Module crypto_kem 

Source
Expand description

§Key encapsulation

Implements libsodium’s crypto_kem_* functions, which use X-Wing: the hybrid of ML-KEM-768 and X25519 in crate::classic::crypto_kem_xwing. X-Wing stays secure if either component does, so it protects against quantum computers without giving up the security of elliptic-curve cryptography.

A key encapsulation mechanism (KEM) lets a sender create a fresh shared secret for the holder of a public key. crypto_kem_enc returns the shared secret and a ciphertext; the recipient recovers the same secret with crypto_kem_dec and its secret key. Only the recipient needs a key pair. Feed the shared secret to a key-derivation function such as crate::classic::crypto_kdf’s HKDF before using it as an encryption key. A KEM does not authenticate the sender; combine it with signatures or an authenticated key exchange when that matters.

use dryoc::classic::crypto_kem::*;

let (public_key, secret_key) = crypto_kem_keypair();

let mut ciphertext = [0u8; dryoc::constants::CRYPTO_KEM_CIPHERTEXTBYTES];
let mut sender_secret = SharedSecret::default();
crypto_kem_enc(&mut ciphertext, &mut sender_secret, &public_key).expect("encapsulation failed");

let mut recipient_secret = SharedSecret::default();
crypto_kem_dec(&mut recipient_secret, &ciphertext, &secret_key).expect("decapsulation failed");
assert_eq!(sender_secret, recipient_secret);

Re-exports§

pub use crate::classic::crypto_kem_xwing::Ciphertext;
pub use crate::classic::crypto_kem_xwing::PublicKey;
pub use crate::classic::crypto_kem_xwing::SecretKey;
pub use crate::classic::crypto_kem_xwing::Seed;
pub use crate::classic::crypto_kem_xwing::SharedSecret;

Functions§

crypto_kem_dec
Recovers the shared secret encapsulated in ciphertext with secret_key, writing it to shared_secret.
crypto_kem_enc
Creates a random shared secret for public_key, writing it to shared_secret and its encapsulation to ciphertext.
crypto_kem_keypair
Returns a randomly generated key pair.
crypto_kem_keypair_inplace
In-place variant of crypto_kem_keypair.
crypto_kem_seed_keypair
Deterministically derives a key pair from seed.
crypto_kem_seed_keypair_inplace
In-place variant of crypto_kem_seed_keypair.