ic-cipher 0.2.4

AES, AES-GCM, ChaCha20-Poly1305, and block modes for IronCrypto
Documentation

ic-cipher — block ciphers, stream ciphers, and AEADs

Pure-Rust, no_std, dependency-free implementations of AES (FIPS 197), the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the RFC 8439 ChaCha20-Poly1305 suite.

use ic_cipher::Aes256Gcm;
use ic_core::traits::Aead;

let cipher = Aes256Gcm::new(&[0x2a; 32])?;
let mut buf = *b"ship it";
let mut tag = [0u8; 16];
cipher.seal_detached(&[0u8; 12], b"context", &mut buf, &mut tag)?;
cipher.open_detached(&[0u8; 12], b"context", &mut buf, &tag)?;
assert_eq!(&buf, b"ship it");
# Ok::<(), ic_core::Error>(())

Backend status

AES computes its S-box algebraically and GHASH multiplies without tables, so neither touches a key-dependent memory address — the cache-timing channel that table-driven AES leaves open is closed by construction.

Three backends sit behind the same traits, chosen by the CPU and never by key material: AES-NI with PCLMULQDQ on x86-64, the ARMv8 crypto extensions behind a feature, and a portable one everywhere else. The portable AES path is bitsliced for encryption — four blocks at a time in transposed form, at roughly the rate of RustCrypto's fixsliced implementation. Decryption is not bitsliced and runs a byte at a time, which is correct and slow; the modes that move volume (CTR, GCM, GCM-SIV) only encrypt.

ic_ontology::runtime::backend() reports which one is active, so an agent can decide whether a workload belongs here.