Expand description
§Secret-key authenticated encryption
DryocSecretBox provides libsodium-compatible authenticated encryption
with a shared secret key. It uses XSalsa20 to encrypt the message and
Poly1305 to detect tampering.
Use a DryocSecretBox when all parties already share a secret key. The
key can be generated directly or derived with Kdf,
Session, or a password-hashing function such as
crypto_pwhash.
Anyone who knows the key can create valid messages. In a group, a secretbox proves that a member created the message, not which member created it.
Nonces are public, but a nonce must never repeat with the same key. Store each nonce with its ciphertext, or use a counter that cannot repeat for that key.
With the serde feature,
serde::Deserialize and
serde::Serialize are implemented
for DryocSecretBox. With wincode_0_6,
wincode::SchemaRead and
wincode::SchemaWrite are
implemented for VecBox.
§Rustaceous API example
use dryoc::dryocsecretbox::*;
use dryoc::types::*;
// Generate a random secret key and nonce
let secret_key = Key::generate();
let nonce = Nonce::generate();
let message = b"A message to encrypt";
// Encrypt the message into a vector-backed box.
let dryocsecretbox =
DryocSecretBox::encrypt_to_vecbox(message, &nonce, &secret_key).expect("encrypt failed");
// Serialize the box in libsodium's wire format, then read it back.
let sodium_box = dryocsecretbox.to_vec();
let dryocsecretbox = DryocSecretBox::from_bytes(&sodium_box).expect("unable to load box");
// Decrypt the box.
let decrypted = dryocsecretbox
.decrypt_to_vec(&nonce, &secret_key)
.expect("unable to decrypt");
assert_eq!(message, decrypted.as_slice());§Additional resources
- See the libsodium documentation for more about secret boxes
- For public-key encryption, see
DryocBox - For encrypted message streams, see
DryocStream - See the
protectedmodule for an example that stores keys in protected memory
Modules§
- protected
protected - Protected memory type aliases for
DryocSecretBox
Structs§
- Dryoc
Secret Box - An authenticated secret-key encrypted box, compatible with a libsodium box.
Use with either
VecBoxorprotected::LockedBoxtype aliases.