Skip to main content

Module dryocsecretbox

Module dryocsecretbox 

Source
Expand description

§Secret-key authenticated encryption

DryocSecretBox provides libsodium-compatible authenticated encryption with a shared secret key. It uses XSalsa20 to encrypt the message and Poly1305 to detect tampering.

Use a DryocSecretBox when all parties already share a secret key. The key can be generated directly or derived with Kdf, Session, or a password-hashing function such as crypto_pwhash.

Anyone who knows the key can create valid messages. In a group, a secretbox proves that a member created the message, not which member created it.

Nonces are public, but a nonce must never repeat with the same key. Store each nonce with its ciphertext, or use a counter that cannot repeat for that key.

With the serde feature, serde::Deserialize and serde::Serialize are implemented for DryocSecretBox. With wincode_0_6, wincode::SchemaRead and wincode::SchemaWrite are implemented for VecBox.

§Rustaceous API example

use dryoc::dryocsecretbox::*;
use dryoc::types::*;

// Generate a random secret key and nonce
let secret_key = Key::generate();
let nonce = Nonce::generate();
let message = b"A message to encrypt";

// Encrypt the message into a vector-backed box.
let dryocsecretbox =
    DryocSecretBox::encrypt_to_vecbox(message, &nonce, &secret_key).expect("encrypt failed");

// Serialize the box in libsodium's wire format, then read it back.
let sodium_box = dryocsecretbox.to_vec();
let dryocsecretbox = DryocSecretBox::from_bytes(&sodium_box).expect("unable to load box");

// Decrypt the box.
let decrypted = dryocsecretbox
    .decrypt_to_vec(&nonce, &secret_key)
    .expect("unable to decrypt");

assert_eq!(message, decrypted.as_slice());

§Additional resources

Modules§

protectedprotected
Protected memory type aliases for DryocSecretBox

Structs§

DryocSecretBox
An authenticated secret-key encrypted box, compatible with a libsodium box. Use with either VecBox or protected::LockedBox type aliases.

Type Aliases§

Key
Stack-allocated secret for authenticated secret box.
Mac
Stack-allocated secret box message authentication code.
Nonce
Stack-allocated nonce for authenticated secret box.
VecBoxalloc
Vec-based authenticated secret box.