Expand description
§Authenticated encryption with additional data
DryocAead provides libsodium-compatible XChaCha20-Poly1305-IETF
authenticated encryption. The chacha20poly1305_ietf module provides the
RFC 8439 variant with shorter, 96-bit nonces. Both encrypt a message and can
authenticate unencrypted metadata, called additional data. If the
ciphertext or additional data changes, decryption fails.
Use DryocAead when your application manages nonces and needs libsodium’s
ciphertext || tag wire format. Use DryocAeadEnvelope to have dryoc
generate a random XChaCha20 nonce and store it as
nonce || ciphertext || tag.
Nonces are public, but a nonce must never repeat with the same key.
DryocAeadEnvelope generates and stores a nonce for each message. Callers
using DryocAead must enforce nonce uniqueness themselves.
If the serde feature is enabled,
serde::Deserialize and
serde::Serialize are implemented
for AeadBox and AeadEnvelope.
If the wincode_0_6 feature is enabled,
wincode::SchemaRead and
wincode::SchemaWrite are
implemented for VecBox and VecEnvelope.
§Rustaceous API example
use dryoc::dryocaead::*;
use dryoc::types::*;
let key = Key::generate();
let nonce = Nonce::generate();
let message = b"Arbitrary data to encrypt";
let aad = b"metadata";
let dryocaead =
DryocAead::encrypt_to_vecbox(message, Some(aad), &nonce, &key).expect("encrypt failed");
let bytes = dryocaead.to_vec();
let dryocaead = VecBox::from_bytes(&bytes).expect("from bytes");
let decrypted = dryocaead
.decrypt_to_vec(Some(aad), &nonce, &key)
.expect("decrypt failed");
assert_eq!(message, decrypted.as_slice());§Generated nonce envelope example
use dryoc::dryocaead::*;
use dryoc::types::*;
let key = Key::generate();
let message = b"Arbitrary data to encrypt";
let aad = b"metadata";
let envelope =
DryocAeadEnvelope::seal_to_vecbox(message, Some(aad), &key).expect("seal failed");
let bytes = envelope.to_vec();
let envelope = VecEnvelope::from_bytes(&bytes).expect("from bytes");
let decrypted = envelope.open_to_vec(Some(aad), &key).expect("open failed");
assert_eq!(message, decrypted.as_slice());Re-exports§
pub use xchacha20poly1305_ietf::*;
Modules§
- chacha20poly1305_
ietf - ChaCha20-Poly1305-IETF Rustaceous AEAD API.
- xchacha20poly1305_
ietf - XChaCha20-Poly1305-IETF Rustaceous AEAD API, the default algorithm.
Structs§
- AeadBox
- Authenticated encrypted data for a concrete AEAD algorithm.
- Aead
Envelope - Authenticated encrypted data with its nonce stored alongside it.
- ChaCha20
Poly1305 Ietf - ChaCha20-Poly1305-IETF AEAD algorithm marker.
- XCha
Cha20 Poly1305 Ietf - XChaCha20-Poly1305-IETF AEAD algorithm marker.
Traits§
- Aead
Algorithm - Marker trait for AEAD algorithms supported by dryoc.