Expand description
§Extendable-output functions
Implements libsodium’s crypto_xof_shake128_*, crypto_xof_shake256_*,
crypto_xof_turboshake128_* and crypto_xof_turboshake256_* functions.
An extendable-output function (XOF) hashes input of any length into output of any length. SHAKE is specified in FIPS 202; TurboSHAKE (RFC 9861) uses 12 Keccak rounds instead of 24 and is about twice as fast.
Absorb input with update, then call squeeze as many times as needed:
the calls continue one output stream. Once squeezing has started, update
returns an error and leaves the state unchanged. init_with_domain
selects a custom domain byte in 0x01..=0x7f.
libsodium documents the same rules but does not enforce them: it accepts
any domain byte, and an update after squeezing returns -1 after
resetting the state and absorbing the input anyway. dryoc returns an
error in both cases instead.
use dryoc::classic::crypto_xof::*;
let mut digest = [0u8; 32];
crypto_xof_turboshake128(&mut digest, b"Arbitrary data to hash");
let mut state = crypto_xof_shake256_init();
crypto_xof_shake256_update(&mut state, b"Arbitrary data to hash").expect("update failed");
let (mut key1, mut key2) = ([0u8; 32], [0u8; 32]);
crypto_xof_shake256_squeeze(&mut state, &mut key1);
crypto_xof_shake256_squeeze(&mut state, &mut key2);
assert_ne!(key1, key2);Structs§
- Shake128
State - Incremental SHAKE128 state.
- Shake256
State - Incremental SHAKE256 state.
- Turbo
Shake128 State - Incremental TurboSHAKE128 state.
- Turbo
Shake256 State - Incremental TurboSHAKE256 state.
Functions§
- crypto_
xof_ shake128 - Computes SHAKE128 of
input, fillingoutput. - crypto_
xof_ shake256 - Computes SHAKE256 of
input, fillingoutput. - crypto_
xof_ shake128_ init - Initializes SHAKE128 with the standard domain.
- crypto_
xof_ shake128_ init_ with_ domain - Initializes SHAKE128 with a custom
domainbyte. - crypto_
xof_ shake128_ squeeze - Fills
outputwith the next bytes of the SHAKE128 output stream, finishing absorption on the first call. - crypto_
xof_ shake128_ update - Absorbs
inputinto the SHAKE128state. - crypto_
xof_ shake256_ init - Initializes SHAKE256 with the standard domain.
- crypto_
xof_ shake256_ init_ with_ domain - Initializes SHAKE256 with a custom
domainbyte. - crypto_
xof_ shake256_ squeeze - Fills
outputwith the next bytes of the SHAKE256 output stream, finishing absorption on the first call. - crypto_
xof_ shake256_ update - Absorbs
inputinto the SHAKE256state. - crypto_
xof_ turboshake128 - Computes TurboSHAKE128 of
input, fillingoutput. - crypto_
xof_ turboshake256 - Computes TurboSHAKE256 of
input, fillingoutput. - crypto_
xof_ turboshake128_ init - Initializes TurboSHAKE128 with the standard domain.
- crypto_
xof_ turboshake128_ init_ with_ domain - Initializes TurboSHAKE128 with a custom
domainbyte. - crypto_
xof_ turboshake128_ squeeze - Fills
outputwith the next bytes of the TurboSHAKE128 output stream, finishing absorption on the first call. - crypto_
xof_ turboshake128_ update - Absorbs
inputinto the TurboSHAKE128state. - crypto_
xof_ turboshake256_ init - Initializes TurboSHAKE256 with the standard domain.
- crypto_
xof_ turboshake256_ init_ with_ domain - Initializes TurboSHAKE256 with a custom
domainbyte. - crypto_
xof_ turboshake256_ squeeze - Fills
outputwith the next bytes of the TurboSHAKE256 output stream, finishing absorption on the first call. - crypto_
xof_ turboshake256_ update - Absorbs
inputinto the TurboSHAKE256state.