Skip to main content

Module kem

Module kem 

Source
Expand description

§Key encapsulation

A key encapsulation mechanism (KEM) lets a sender create a fresh shared secret for the holder of a public key: encapsulate returns the shared secret and a ciphertext, and the recipient recovers the same secret with KeyPair::decapsulate. Only the recipient needs a key pair. Feed the shared secret to a key-derivation function such as crate::hkdf before using it as an encryption key. A KEM does not authenticate the sender; combine it with crate::sign or an authenticated protocol when that matters.

The items at the top of this module are xwing, the hybrid of ML-KEM-768 and X25519 that libsodium’s crypto_kem_* functions use. It stays secure if either component does, so it protects against quantum computers without giving up the security of elliptic-curve cryptography. mlkem768 offers ML-KEM-768 alone for protocols that require it.

§Example

use dryoc::kem::*;

let recipient = StackKeyPair::generate();

// The sender needs only the recipient's public key.
let (ciphertext, sender_secret): (Ciphertext, SharedSecret) =
    encapsulate(&recipient.public_key).expect("encapsulation failed");

let recipient_secret: SharedSecret = recipient
    .decapsulate(&ciphertext)
    .expect("decapsulation failed");
assert_eq!(sender_secret, recipient_secret);

§Protected memory

Every function is generic over its key, ciphertext and secret types, so secret keys and shared secrets can live in locked memory; see protected (with the protected feature).

Re-exports§

pub use xwing::*;

Modules§

mlkem768
ML-KEM-768
xwing
X-Wing (ML-KEM-768 + X25519)