1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
//! Typed newtypes for ML-KEM key material.
//!
//! # Responsibility scope
//! This module owns the concrete newtype wrappers around raw byte vectors that hold
//! ML-KEM cryptographic material. Every secret-bearing type implements [`zeroize::ZeroizeOnDrop`]
//! so that key bytes are overwritten when the value is dropped.
//!
//! # Key types exported
//! - [`MlKemPublicKey`] — encapsulation key (public; not zeroized, safe to share)
//! - [`MlKemSecretKey`] — decapsulation key (secret; `ZeroizeOnDrop`)
//! - [`KemCiphertext`] — KEM ciphertext produced by encapsulation (not secret itself)
//! - [`KemSharedSecret`] — shared secret derived from encapsulation/decapsulation (`ZeroizeOnDrop`)
//!
//! # Concurrency
//! All types are `Send + Sync` (they contain only `Vec<u8>` and a `PhantomData` marker).
//!
//! # Errors
//! This module produces no errors directly; it is data-only.
//!
//! # Examples
//! ```rust,no_run
//! use crypt_guard::kem::types::KemSharedSecret;
//! let ss = KemSharedSecret::from_bytes(vec![0u8; 32]);
//! assert_eq!(ss.as_ref().len(), 32);
//! ```
use PhantomData;
use ZeroizeOnDrop;
/// Marker for the ML-KEM security parameter set (512, 768, or 1024).
/// ML-KEM public (encapsulation) key newtype.
///
/// # Description
/// Wraps the raw public key bytes for a given ML-KEM parameter set `N`.
/// Not secret; safe to transmit. Does not implement `ZeroizeOnDrop` because
/// public keys carry no secret material.
///
/// # Concurrency
/// `Send + Sync` — contains only a `Vec<u8>` and a `PhantomData` marker.
/// Borrows the raw public-key bytes.
///
/// # Returns
/// A `&[u8]` slice over the wrapped encapsulation-key bytes.
/// ML-KEM secret (decapsulation) key newtype.
///
/// # Description
/// Wraps the raw secret key bytes. Secret-bearing; implements [`ZeroizeOnDrop`] so
/// the bytes are overwritten when this value is dropped.
///
/// # Concurrency
/// `Send + Sync` — contains only a `Vec<u8>` and a `PhantomData` marker.
/// Borrows the raw secret-key bytes.
///
/// # Returns
/// A `&[u8]` slice over the wrapped decapsulation-key bytes. The borrow does not
/// affect the [`ZeroizeOnDrop`] guarantee; bytes are still cleared on drop.
/// KEM ciphertext newtype.
///
/// # Description
/// Wraps the ciphertext produced during KEM encapsulation. The ciphertext is not secret
/// and does not require zeroization; it is transmitted to the decapsulating party.
///
/// # Concurrency
/// `Send + Sync`.
/// Borrows the raw ciphertext bytes.
///
/// # Returns
/// A `&[u8]` slice over the wrapped KEM ciphertext bytes.
/// KEM shared secret newtype.
///
/// # Description
/// Holds the shared secret produced by both KEM encapsulation (sender) and decapsulation
/// (receiver). Secret-bearing; implements [`ZeroizeOnDrop`].
///
/// # Concurrency
/// `Send + Sync`.
/// Borrows the raw shared-secret bytes.
///
/// # Returns
/// A `&[u8]` slice over the wrapped shared-secret bytes. The borrow does not affect
/// the [`ZeroizeOnDrop`] guarantee; bytes are still cleared on drop.