Skip to main content

Module dryocaead

Module dryocaead 

Source
Expand description

§Authenticated encryption with additional data

DryocAead provides libsodium-compatible XChaCha20-Poly1305-IETF authenticated encryption. The chacha20poly1305_ietf module provides the RFC 8439 variant with shorter, 96-bit nonces. Both encrypt a message and can authenticate unencrypted metadata, called additional data. If the ciphertext or additional data changes, decryption fails.

Use DryocAead when your application manages nonces and needs libsodium’s ciphertext || tag wire format. Use DryocAeadEnvelope to have dryoc generate a random XChaCha20 nonce and store it as nonce || ciphertext || tag.

Nonces are public, but a nonce must never repeat with the same key. DryocAeadEnvelope generates and stores a nonce for each message. Callers using DryocAead must enforce nonce uniqueness themselves.

If the serde feature is enabled, serde::Deserialize and serde::Serialize are implemented for AeadBox and AeadEnvelope. If the wincode_0_6 feature is enabled, wincode::SchemaRead and wincode::SchemaWrite are implemented for VecBox and VecEnvelope.

§Rustaceous API example

use dryoc::dryocaead::*;
use dryoc::types::*;

let key = Key::generate();
let nonce = Nonce::generate();
let message = b"Arbitrary data to encrypt";
let aad = b"metadata";

let dryocaead =
    DryocAead::encrypt_to_vecbox(message, Some(aad), &nonce, &key).expect("encrypt failed");
let bytes = dryocaead.to_vec();
let dryocaead = VecBox::from_bytes(&bytes).expect("from bytes");
let decrypted = dryocaead
    .decrypt_to_vec(Some(aad), &nonce, &key)
    .expect("decrypt failed");

assert_eq!(message, decrypted.as_slice());

§Generated nonce envelope example

use dryoc::dryocaead::*;
use dryoc::types::*;

let key = Key::generate();
let message = b"Arbitrary data to encrypt";
let aad = b"metadata";

let envelope =
    DryocAeadEnvelope::seal_to_vecbox(message, Some(aad), &key).expect("seal failed");
let bytes = envelope.to_vec();
let envelope = VecEnvelope::from_bytes(&bytes).expect("from bytes");
let decrypted = envelope.open_to_vec(Some(aad), &key).expect("open failed");

assert_eq!(message, decrypted.as_slice());

Re-exports§

pub use xchacha20poly1305_ietf::*;

Modules§

chacha20poly1305_ietf
ChaCha20-Poly1305-IETF Rustaceous AEAD API.
xchacha20poly1305_ietf
XChaCha20-Poly1305-IETF Rustaceous AEAD API, the default algorithm.

Structs§

AeadBox
Authenticated encrypted data for a concrete AEAD algorithm.
AeadEnvelope
Authenticated encrypted data with its nonce stored alongside it.
ChaCha20Poly1305Ietf
ChaCha20-Poly1305-IETF AEAD algorithm marker.
XChaCha20Poly1305Ietf
XChaCha20-Poly1305-IETF AEAD algorithm marker.

Traits§

AeadAlgorithm
Marker trait for AEAD algorithms supported by dryoc.