ic-cipher — block ciphers, stream ciphers, and AEADs
Pure-Rust, no_std, dependency-free implementations of AES (FIPS 197),
the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the
RFC 8439 ChaCha20-Poly1305 suite.
use Aes256Gcm;
use Aead;
let cipher = new?;
let mut buf = *b"ship it";
let mut tag = ;
cipher.seal_detached?;
cipher.open_detached?;
assert_eq!;
# Ok::
Backend status
AES computes its S-box algebraically and GHASH multiplies without tables, so neither touches a key-dependent memory address — the cache-timing channel that table-driven AES leaves open is closed by construction.
Three backends sit behind the same traits, chosen by the CPU and never by key material: AES-NI with PCLMULQDQ on x86-64, the ARMv8 crypto extensions behind a feature, and a portable one everywhere else. The portable AES path is bitsliced for encryption — four blocks at a time in transposed form, at roughly the rate of RustCrypto's fixsliced implementation. Decryption is not bitsliced and runs a byte at a time, which is correct and slow; the modes that move volume (CTR, GCM, GCM-SIV) only encrypt.
ic_ontology::runtime::backend() reports which one is active, so an agent
can decide whether a workload belongs here.