1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
//! # ic-cipher — block ciphers, stream ciphers, and AEADs
//!
//! Pure-Rust, `no_std`, dependency-free implementations of AES (FIPS 197),
//! the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the
//! RFC 8439 ChaCha20-Poly1305 suite.
//!
//! ```
//! use ic_cipher::Aes256Gcm;
//! use ic_core::traits::Aead;
//!
//! let cipher = Aes256Gcm::new(&[0x2a; 32])?;
//! let mut buf = *b"ship it";
//! let mut tag = [0u8; 16];
//! cipher.seal_detached(&[0u8; 12], b"context", &mut buf, &mut tag)?;
//! cipher.open_detached(&[0u8; 12], b"context", &mut buf, &tag)?;
//! assert_eq!(&buf, b"ship it");
//! # Ok::<(), ic_core::Error>(())
//! ```
//!
//! ## Backend status
//!
//! AES computes its S-box algebraically and GHASH multiplies without tables, so
//! neither touches a key-dependent memory address — the cache-timing channel
//! that table-driven AES leaves open is closed by construction.
//!
//! Three backends sit behind the same traits, chosen by the CPU and never by
//! key material: AES-NI with PCLMULQDQ on x86-64, the ARMv8 crypto extensions
//! behind a feature, and a portable one everywhere else. The portable AES path
//! is bitsliced for encryption — four blocks at a time in transposed form, at
//! roughly the rate of RustCrypto's fixsliced implementation. Decryption is
//! not bitsliced and runs a byte at a time, which is correct and slow; the
//! modes that move volume (CTR, GCM, GCM-SIV) only encrypt.
//!
//! `ic_ontology::runtime::backend()` reports which one is active, so an agent
//! can decide whether a workload belongs here.
// Every unsafe operation inside an unsafe fn must be marked explicitly, so the
// SIMD backends cannot smuggle one in under the function signature.
// And unsafe may only appear where a CPU intrinsic is being called, which is
// what the allowances below mark. Everywhere else in this crate -- the modes,
// the key wrapping, the field arithmetic -- it is a compile error.
// AES-NI and the ARMv8 crypto extensions, behind runtime detection.
// AVX2 for the ChaCha20 keystream, behind runtime detection.
// The carry-less multiply instruction.
// GHASH via CLMUL when the CPU has it.
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
/// Ontology identifiers for the AEADs this crate provides.
pub const AEAD_IDS: & = &;
/// Ontology identifiers for the raw block ciphers this crate provides.
pub const BLOCK_CIPHER_IDS: & = &;