Expand description
§Key encapsulation
A key encapsulation mechanism (KEM) lets a sender create a fresh shared
secret for the holder of a public key: encapsulate returns the shared
secret and a ciphertext, and the recipient recovers the same secret with
KeyPair::decapsulate. Only the recipient needs a key pair. Feed the
shared secret to a key-derivation function such as crate::hkdf before
using it as an encryption key. A KEM does not authenticate the sender;
combine it with crate::sign or an authenticated protocol when that
matters.
The items at the top of this module are xwing, the hybrid of
ML-KEM-768 and X25519 that libsodium’s crypto_kem_* functions use. It
stays secure if either component does, so it protects against quantum
computers without giving up the security of elliptic-curve cryptography.
mlkem768 offers ML-KEM-768 alone for protocols that require it.
§Example
use dryoc::kem::*;
let recipient = StackKeyPair::generate();
// The sender needs only the recipient's public key.
let (ciphertext, sender_secret): (Ciphertext, SharedSecret) =
encapsulate(&recipient.public_key).expect("encapsulation failed");
let recipient_secret: SharedSecret = recipient
.decapsulate(&ciphertext)
.expect("decapsulation failed");
assert_eq!(sender_secret, recipient_secret);§Protected memory
Every function is generic over its key, ciphertext and secret types, so
secret keys and shared secrets can live in locked memory; see
protected (with the protected feature).
Re-exports§
pub use xwing::*;