Skip to main content

is_valid_public_key

Function is_valid_public_key 

Source
pub fn is_valid_public_key<PK: ByteArray<CRYPTO_BOX_PUBLICKEYBYTES>>(
    key: &PK,
) -> bool
Expand description

Checks if the given public key is valid according to X25519 rules.

For X25519 (crypto_box, DryocBox), this performs a trial scalar multiplication and rejects public keys that produce an all-zero shared secret, including low-order inputs rejected by libsodium. As required by RFC 7748, the high bit of the encoded public key is ignored.

Use crate::sign::is_valid_public_key for Ed25519 signing keys.

ยงValidating Protected Keys

You can validate keys stored in protected memory directly, as the validation functions operate on references.

use dryoc::constants::{CRYPTO_BOX_PUBLICKEYBYTES, CRYPTO_BOX_SECRETKEYBYTES};
use dryoc::keypair::{KeyPair, is_valid_public_key};
use dryoc::protected::{HeapByteArray, LockedRO};

// Generate a keypair stored in locked, read-only memory
let protected_kp: KeyPair<
    LockedRO<HeapByteArray<CRYPTO_BOX_PUBLICKEYBYTES>>,
    LockedRO<HeapByteArray<CRYPTO_BOX_SECRETKEYBYTES>>,
> = KeyPair::generate_readonly_locked_keypair().expect("Failed to generate locked keypair");

// Validate the X25519 public key.
assert!(
    is_valid_public_key(&protected_kp.public_key),
    "Protected X25519 key should be valid"
);