ic-cipher 0.1.0

AES, AES-GCM, ChaCha20-Poly1305, and block modes for IronCrypto
Documentation
ic-cipher-0.1.0 has been yanked.

ic-cipher — block ciphers, stream ciphers, and AEADs

Pure-Rust, no_std, dependency-free implementations of AES (FIPS 197), the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the RFC 8439 ChaCha20-Poly1305 suite.

use ic_cipher::Aes256Gcm;
use ic_core::traits::Aead;

let cipher = Aes256Gcm::new(&[0x2a; 32])?;
let mut buf = *b"ship it";
let mut tag = [0u8; 16];
cipher.seal_detached(&[0u8; 12], b"context", &mut buf, &mut tag)?;
cipher.open_detached(&[0u8; 12], b"context", &mut buf, &tag)?;
assert_eq!(&buf, b"ship it");
# Ok::<(), ic_core::Error>(())

Backend status

This is the portable constant-time backend. AES computes its S-box algebraically and GHASH multiplies bit by bit, so neither touches a key-dependent memory address — the cache-timing channel that table-driven AES leaves open is closed by construction. The cost is throughput: expect single-digit MB/s rather than the GB/s an AES-NI or bitsliced backend delivers. Hardware backends are a planned addition behind the same traits, and the ontology reports which backend is active via ic_ontology::runtime::backend(), so an agent can decide whether a workload belongs here.