Skip to main content

Crate ic_cipher

Crate ic_cipher 

Source
Expand description

§ic-cipher — block ciphers, stream ciphers, and AEADs

Pure-Rust, no_std, dependency-free implementations of AES (FIPS 197), the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the RFC 8439 ChaCha20-Poly1305 suite.

use ic_cipher::{Aes256Gcm, Opener, Sealer};

// A session key, from a key exchange and a KDF in real use.
let key = [0x2a; 32];
let mut tx = Sealer::<Aes256Gcm>::new(&key, *b"c->s")?;
let mut rx = Opener::<Aes256Gcm>::new(&key, *b"c->s")?;
let mut buf = *b"ship it";
let mut tag = [0u8; 16];
let nonce = tx.seal(b"context", &mut buf, &mut tag)?;
rx.open(&nonce, b"context", &mut buf, &tag)?;
assert_eq!(&buf, b"ship it");

Sealer chooses every nonce itself and Opener refuses replays; see sealer for when that is enough. The AEAD types underneath take a nonce from the caller, which is what protocols with their own nonce rules (TLS, QUIC, HPKE) need, and which is where nonce reuse comes from.

§Backend status

AES computes its S-box algebraically and GHASH multiplies without tables, so neither touches a key-dependent memory address — the cache-timing channel that table-driven AES leaves open is closed by construction.

Three backends sit behind the same traits, chosen by the CPU and never by key material: AES-NI with PCLMULQDQ on x86-64, the ARMv8 crypto extensions behind a feature, and a portable one everywhere else. The portable AES path is bitsliced for encryption — four blocks at a time in transposed form, at roughly the rate of RustCrypto’s fixsliced implementation. Decryption is not bitsliced and runs a byte at a time, which is correct and slow; the modes that move volume (CTR, GCM, GCM-SIV) only encrypt.

ic_ontology::runtime::backend() reports which one is active, so an agent can decide whether a workload belongs here.

Re-exports§

pub use aes::Aes128;
pub use aes::Aes192;
pub use aes::Aes256;
pub use chacha::chacha20_xor;
pub use chacha::ChaCha20Poly1305;
pub use chacha::Poly1305;
pub use gcm::Aes128Gcm;
pub use gcm::Aes192Gcm;
pub use gcm::Aes256Gcm;
pub use gcm::GcmLimits;
pub use gcm_siv::Aes128GcmSiv;
pub use gcm_siv::Aes256GcmSiv;
pub use keywrap::Aes128Kw;
pub use keywrap::Aes128Kwp;
pub use keywrap::Aes192Kw;
pub use keywrap::Aes192Kwp;
pub use keywrap::Aes256Kw;
pub use keywrap::Aes256Kwp;
pub use modes::cbc_decrypt;
pub use modes::cbc_encrypt;
pub use modes::ctr_xor;
pub use modes::pkcs7_pad;
pub use modes::pkcs7_unpad;
pub use sealer::Opener;
pub use sealer::Sealer;

Modules§

aes
FIPS 197 AES, with a portable constant-time backend and an optional hardware-accelerated one.
chacha
RFC 8439 ChaCha20, Poly1305, and the ChaCha20-Poly1305 AEAD.
gcm
NIST SP 800-38D Galois/Counter Mode.
gcm_siv
AES-GCM-SIV (RFC 8452): authenticated encryption that survives nonce reuse.
gf
Constant-time GF(2^8) arithmetic for AES.
keywrap
AES Key Wrap (SP 800-38F, RFC 3394 and RFC 5649).
modes
NIST SP 800-38A confidentiality modes.
polyval
POLYVAL, the universal hash underneath AES-GCM-SIV (RFC 8452 section 3).
sealer
An AEAD that chooses its own nonces.
shamir
Shamir secret sharing over GF(2^8).

Constants§

AEAD_IDS
Ontology identifiers for the AEADs this crate provides.
BLOCK_CIPHER_IDS
Ontology identifiers for the raw block ciphers this crate provides.