Expand description
§ic-cipher — block ciphers, stream ciphers, and AEADs
Pure-Rust, no_std, dependency-free implementations of AES (FIPS 197),
the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the
RFC 8439 ChaCha20-Poly1305 suite.
use ic_cipher::{Aes256Gcm, Opener, Sealer};
// A session key, from a key exchange and a KDF in real use.
let key = [0x2a; 32];
let mut tx = Sealer::<Aes256Gcm>::new(&key, *b"c->s")?;
let mut rx = Opener::<Aes256Gcm>::new(&key, *b"c->s")?;
let mut buf = *b"ship it";
let mut tag = [0u8; 16];
let nonce = tx.seal(b"context", &mut buf, &mut tag)?;
rx.open(&nonce, b"context", &mut buf, &tag)?;
assert_eq!(&buf, b"ship it");Sealer chooses every nonce itself and Opener refuses replays; see
sealer for when that is enough. The AEAD types underneath take a nonce
from the caller, which is what protocols with their own nonce rules (TLS,
QUIC, HPKE) need, and which is where nonce reuse comes from.
§Backend status
AES computes its S-box algebraically and GHASH multiplies without tables, so neither touches a key-dependent memory address — the cache-timing channel that table-driven AES leaves open is closed by construction.
Three backends sit behind the same traits, chosen by the CPU and never by key material: AES-NI with PCLMULQDQ on x86-64, the ARMv8 crypto extensions behind a feature, and a portable one everywhere else. The portable AES path is bitsliced for encryption — four blocks at a time in transposed form, at roughly the rate of RustCrypto’s fixsliced implementation. Decryption is not bitsliced and runs a byte at a time, which is correct and slow; the modes that move volume (CTR, GCM, GCM-SIV) only encrypt.
ic_ontology::runtime::backend() reports which one is active, so an agent
can decide whether a workload belongs here.
Re-exports§
pub use aes::Aes128;pub use aes::Aes192;pub use aes::Aes256;pub use chacha::chacha20_xor;pub use chacha::ChaCha20Poly1305;pub use chacha::Poly1305;pub use gcm::Aes128Gcm;pub use gcm::Aes192Gcm;pub use gcm::Aes256Gcm;pub use gcm::GcmLimits;pub use gcm_siv::Aes128GcmSiv;pub use gcm_siv::Aes256GcmSiv;pub use keywrap::Aes128Kw;pub use keywrap::Aes128Kwp;pub use keywrap::Aes192Kw;pub use keywrap::Aes192Kwp;pub use keywrap::Aes256Kw;pub use keywrap::Aes256Kwp;pub use modes::cbc_decrypt;pub use modes::cbc_encrypt;pub use modes::ctr_xor;pub use modes::pkcs7_pad;pub use modes::pkcs7_unpad;pub use sealer::Opener;pub use sealer::Sealer;
Modules§
- aes
- FIPS 197 AES, with a portable constant-time backend and an optional hardware-accelerated one.
- chacha
- RFC 8439 ChaCha20, Poly1305, and the ChaCha20-Poly1305 AEAD.
- gcm
- NIST SP 800-38D Galois/Counter Mode.
- gcm_siv
- AES-GCM-SIV (RFC 8452): authenticated encryption that survives nonce reuse.
- gf
- Constant-time GF(2^8) arithmetic for AES.
- keywrap
- AES Key Wrap (SP 800-38F, RFC 3394 and RFC 5649).
- modes
- NIST SP 800-38A confidentiality modes.
- polyval
- POLYVAL, the universal hash underneath AES-GCM-SIV (RFC 8452 section 3).
- sealer
- An AEAD that chooses its own nonces.
- shamir
- Shamir secret sharing over GF(2^8).
Constants§
- AEAD_
IDS - Ontology identifiers for the AEADs this crate provides.
- BLOCK_
CIPHER_ IDS - Ontology identifiers for the raw block ciphers this crate provides.