Expand description
§X-Wing hybrid key encapsulation
Implements libsodium’s crypto_kem_xwing_* functions: X-Wing
(draft-connolly-cfrg-xwing-kem), which combines ML-KEM-768 with X25519.
Its shared secret stays secure as long as either ML-KEM-768 or X25519
does, so it protects against quantum computers without giving up the
security of elliptic-curve cryptography. crate::classic::crypto_kem
uses X-Wing.
The 32-byte secret key is a seed; the ML-KEM-768 and X25519 keys are derived from it with SHAKE256 whenever they are needed. The public key is the ML-KEM-768 public key followed by the X25519 public key, and the ciphertext is the ML-KEM-768 ciphertext followed by an ephemeral X25519 public key. The shared secret is SHA3-256 of both component secrets, the X25519 ciphertext and public key, and a fixed label.
A KEM does not authenticate the sender. Feed the shared secret to a key-derivation function before using it as an encryption key.
use dryoc::classic::crypto_kem_xwing::*;
let (public_key, secret_key) = crypto_kem_xwing_keypair();
let mut ciphertext = [0u8; dryoc::constants::CRYPTO_KEM_XWING_CIPHERTEXTBYTES];
let mut sender_secret = SharedSecret::default();
crypto_kem_xwing_enc(&mut ciphertext, &mut sender_secret, &public_key)
.expect("encapsulation failed");
let mut recipient_secret = SharedSecret::default();
crypto_kem_xwing_dec(&mut recipient_secret, &ciphertext, &secret_key)
.expect("decapsulation failed");
assert_eq!(sender_secret, recipient_secret);Functions§
- crypto_
kem_ xwing_ dec - Recovers the shared secret encapsulated in
ciphertextwithsecret_key, writing it toshared_secret. A ciphertext not created for this key yields an unrelated pseudorandom secret, not an error. - crypto_
kem_ xwing_ enc - Creates a random shared secret for
public_key, writing it toshared_secretand its encapsulation tociphertext. - crypto_
kem_ xwing_ enc_ deterministic - Deterministic variant of
crypto_kem_xwing_encwith the encapsulation randomness taken fromseed. For known-answer tests; a repeated seed repeats the shared secret. - crypto_
kem_ xwing_ keypair - Returns a randomly generated key pair.
- crypto_
kem_ xwing_ keypair_ inplace - In-place variant of
crypto_kem_xwing_keypair. - crypto_
kem_ xwing_ seed_ keypair - Deterministically derives a key pair from
seed. The secret key is the seed itself. - crypto_
kem_ xwing_ seed_ keypair_ inplace - In-place variant of
crypto_kem_xwing_seed_keypair.
Type Aliases§
- Ciphertext
- X-Wing ciphertext: the ML-KEM-768 ciphertext, then an ephemeral X25519 public key.
- EncSeed
- Encapsulation seed: the ML-KEM-768 message, then the ephemeral X25519 secret key.
- Public
Key - X-Wing public key: the ML-KEM-768 public key, then the X25519 public key.
- Secret
Key - X-Wing secret key: the 32-byte seed both component keys derive from.
- Seed
- Key-generation seed; the secret key is the seed itself.
- Shared
Secret - Shared secret produced by encapsulation and decapsulation.