Skip to main content

Module crypto_kem_xwing

Module crypto_kem_xwing 

Source
Expand description

§X-Wing hybrid key encapsulation

Implements libsodium’s crypto_kem_xwing_* functions: X-Wing (draft-connolly-cfrg-xwing-kem), which combines ML-KEM-768 with X25519. Its shared secret stays secure as long as either ML-KEM-768 or X25519 does, so it protects against quantum computers without giving up the security of elliptic-curve cryptography. crate::classic::crypto_kem uses X-Wing.

The 32-byte secret key is a seed; the ML-KEM-768 and X25519 keys are derived from it with SHAKE256 whenever they are needed. The public key is the ML-KEM-768 public key followed by the X25519 public key, and the ciphertext is the ML-KEM-768 ciphertext followed by an ephemeral X25519 public key. The shared secret is SHA3-256 of both component secrets, the X25519 ciphertext and public key, and a fixed label.

A KEM does not authenticate the sender. Feed the shared secret to a key-derivation function before using it as an encryption key.

use dryoc::classic::crypto_kem_xwing::*;

let (public_key, secret_key) = crypto_kem_xwing_keypair();

let mut ciphertext = [0u8; dryoc::constants::CRYPTO_KEM_XWING_CIPHERTEXTBYTES];
let mut sender_secret = SharedSecret::default();
crypto_kem_xwing_enc(&mut ciphertext, &mut sender_secret, &public_key)
    .expect("encapsulation failed");

let mut recipient_secret = SharedSecret::default();
crypto_kem_xwing_dec(&mut recipient_secret, &ciphertext, &secret_key)
    .expect("decapsulation failed");
assert_eq!(sender_secret, recipient_secret);

Functions§

crypto_kem_xwing_dec
Recovers the shared secret encapsulated in ciphertext with secret_key, writing it to shared_secret. A ciphertext not created for this key yields an unrelated pseudorandom secret, not an error.
crypto_kem_xwing_enc
Creates a random shared secret for public_key, writing it to shared_secret and its encapsulation to ciphertext.
crypto_kem_xwing_enc_deterministic
Deterministic variant of crypto_kem_xwing_enc with the encapsulation randomness taken from seed. For known-answer tests; a repeated seed repeats the shared secret.
crypto_kem_xwing_keypair
Returns a randomly generated key pair.
crypto_kem_xwing_keypair_inplace
In-place variant of crypto_kem_xwing_keypair.
crypto_kem_xwing_seed_keypair
Deterministically derives a key pair from seed. The secret key is the seed itself.
crypto_kem_xwing_seed_keypair_inplace
In-place variant of crypto_kem_xwing_seed_keypair.

Type Aliases§

Ciphertext
X-Wing ciphertext: the ML-KEM-768 ciphertext, then an ephemeral X25519 public key.
EncSeed
Encapsulation seed: the ML-KEM-768 message, then the ephemeral X25519 secret key.
PublicKey
X-Wing public key: the ML-KEM-768 public key, then the X25519 public key.
SecretKey
X-Wing secret key: the 32-byte seed both component keys derive from.
Seed
Key-generation seed; the secret key is the seed itself.
SharedSecret
Shared secret produced by encapsulation and decapsulation.