pub struct SecureKeyStore { /* private fields */ }Expand description
Secure keystore for encrypted key storage.
The keystore encrypts all keys at rest using a master key derived from a password. Each key is encrypted with a unique nonce and integrity-protected with HMAC.
Implementations§
Source§impl SecureKeyStore
impl SecureKeyStore
Sourcepub fn new(password: &[u8]) -> KeyStoreResult<Self>
pub fn new(password: &[u8]) -> KeyStoreResult<Self>
Create a new keystore with the given password.
The password is used to derive the master encryption and HMAC keys using Argon2. A random salt is generated for key derivation.
§Example
use chie_crypto::keystore::SecureKeyStore;
let keystore = SecureKeyStore::new(b"my-password").unwrap();Sourcepub fn with_salt(password: &[u8], salt: [u8; 32]) -> KeyStoreResult<Self>
pub fn with_salt(password: &[u8], salt: [u8; 32]) -> KeyStoreResult<Self>
Create a keystore with an explicit salt (for loading from storage).
Sourcepub fn store_key(
&mut self,
key_id: &str,
key_data: &[u8],
key_type: KeyType,
) -> KeyStoreResult<()>
pub fn store_key( &mut self, key_id: &str, key_data: &[u8], key_type: KeyType, ) -> KeyStoreResult<()>
Store a key in the keystore.
§Arguments
key_id- Unique identifier for the keykey_data- The key bytes to encrypt and storekey_type- Type of the key
§Errors
Returns KeyAlreadyExists if a key with the same ID already exists.
§Example
use chie_crypto::keystore::{SecureKeyStore, KeyType};
let mut keystore = SecureKeyStore::new(b"password")?;
keystore.store_key("key1", b"secret", KeyType::Generic)?;Sourcepub fn retrieve_key(&mut self, key_id: &str) -> KeyStoreResult<Vec<u8>>
pub fn retrieve_key(&mut self, key_id: &str) -> KeyStoreResult<Vec<u8>>
Retrieve a key from the keystore.
§Errors
Returns KeyNotFound if the key doesn’t exist, or IntegrityCheckFailed
if the HMAC verification fails.
§Example
use chie_crypto::keystore::{SecureKeyStore, KeyType};
let mut keystore = SecureKeyStore::new(b"password")?;
keystore.store_key("key1", b"secret", KeyType::Generic)?;
let retrieved = keystore.retrieve_key("key1")?;
assert_eq!(retrieved, b"secret");Sourcepub fn delete_key(&mut self, key_id: &str) -> KeyStoreResult<()>
pub fn delete_key(&mut self, key_id: &str) -> KeyStoreResult<()>
Delete a key from the keystore.
The key data is securely zeroized before removal.
§Example
use chie_crypto::keystore::{SecureKeyStore, KeyType};
let mut keystore = SecureKeyStore::new(b"password")?;
keystore.store_key("key1", b"secret", KeyType::Generic)?;
keystore.delete_key("key1")?;
assert!(keystore.get_metadata("key1").is_err());Sourcepub fn get_metadata(&self, key_id: &str) -> KeyStoreResult<&KeyMetadata>
pub fn get_metadata(&self, key_id: &str) -> KeyStoreResult<&KeyMetadata>
Get metadata for a key.
Sourcepub fn update_metadata<F>(&mut self, key_id: &str, f: F) -> KeyStoreResult<()>where
F: FnOnce(&mut KeyMetadata),
pub fn update_metadata<F>(&mut self, key_id: &str, f: F) -> KeyStoreResult<()>where
F: FnOnce(&mut KeyMetadata),
Update key metadata.
Sourcepub fn rotate_key(
&mut self,
key_id: &str,
new_key_data: &[u8],
) -> KeyStoreResult<()>
pub fn rotate_key( &mut self, key_id: &str, new_key_data: &[u8], ) -> KeyStoreResult<()>
Rotate a key to a new version.
This stores the new key data while incrementing the version number and preserving other metadata.
Sourcepub fn serialize(&self) -> KeyStoreResult<Vec<u8>>
pub fn serialize(&self) -> KeyStoreResult<Vec<u8>>
Serialize the keystore to bytes for persistent storage.
The serialized format includes the salt and all encrypted entries.
Sourcepub fn deserialize(password: &[u8], data: &[u8]) -> KeyStoreResult<Self>
pub fn deserialize(password: &[u8], data: &[u8]) -> KeyStoreResult<Self>
Deserialize a keystore from bytes with the given password.
Sourcepub fn contains_key(&self, key_id: &str) -> bool
pub fn contains_key(&self, key_id: &str) -> bool
Check if a key exists in the keystore.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for SecureKeyStore
impl RefUnwindSafe for SecureKeyStore
impl Send for SecureKeyStore
impl Sync for SecureKeyStore
impl Unpin for SecureKeyStore
impl UnwindSafe for SecureKeyStore
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.