Skip to main content

NodeKey

Struct NodeKey 

Source
pub struct NodeKey { /* private fields */ }
Expand description

One of a node’s keys in its profile: the ML-DSA-87 half, and in pq_hybrid the RSA-PSS-4096 half. It signs as a whole, never with one half on its own. Showing it gives its purpose, profile and key id, never a private half.

Implementations§

Source§

impl NodeKey

Source

pub fn save(&self, path: &Path) -> Result<(), KeyFileError>

Writes the key to path in the seed form, readable by its owner only. The file is created in a new owner-only directory beside path, written, synced and renamed over any file at path; then path’s directory is synced and the new one removed. Nothing else in the directory is read, written or removed.

Source

pub fn load( path: &Path, purpose: Purpose, profile: Profile, ) -> Result<NodeKey, KeyFileError>

The key saved at path for purpose in profile, checked before it is returned. A path that names anything but a regular file, directly or through a symlink, is refused before it is opened, and the opened file is checked again: a regular file, owned by the effective user, that its group and others cannot read, of at most 64 KiB. Then a key for another purpose or profile, halves that do not fit the profile, a stored public key its private key does not derive, and a key that fails a sign-and-verify round trip are refused.

Source

pub fn load_or_create( path: &Path, profile: Profile, ) -> Result<NodeKey, KeyFileError>

The identity key at path in profile, or, when nothing is there, a new one with the admission puzzle solved, saved there first. Anything at path that does not load as such a key is refused and left as it is, never replaced.

Source

pub fn save_to_keystore(&self, store: &dyn KeyStore) -> Result<(), KeyFileError>

Keeps the key in store, as the bytes of its key file: the platform secure store a mobile app keeps its key in (see crate::keystore).

Source

pub fn load_from_keystore( store: &dyn KeyStore, purpose: Purpose, profile: Profile, ) -> Result<NodeKey, KeyFileError>

The key kept in store for purpose in profile, checked as a key file’s is, but for the file’s owner and permissions, which the store keeps.

Source§

impl NodeKey

Source

pub fn generate(purpose: Purpose, profile: Profile) -> Result<NodeKey, KeyError>

A new key for purpose in profile.

Source

pub fn generate_identity( profile: Profile, difficulty: u32, ) -> Result<NodeKey, KeyError>

A new identity key in profile whose node_id starts with difficulty zero bits, found in about 2^difficulty tries. Each try makes a new ML-DSA-87 half; a pq_hybrid key keeps its RSA-PSS half, since the node_id covers both.

Source

pub fn purpose(&self) -> Purpose

What the key is for.

Source

pub fn profile(&self) -> Profile

The profile the key belongs to.

Source

pub fn public_key(&self) -> Vec<u8> ⓘ

The key as carried (D13): the 2,592-byte ML-DSA-87 key, followed in pq_hybrid by the DER RSAPublicKey.

Source

pub fn node_id(&self) -> Result<[u8; 32], KeyError>

The node_id of an identity key (D5).

Source

pub fn key_id(&self) -> [u8; 32]

The id that names the key in signed objects: an identity key’s node_id, and the key id of any other key.

Source

pub fn sign(&self, message: &[u8]) -> Result<Vec<u8>, KeyError>

Signs message: with ML-DSA-87 alone in pq_pure, and in pq_hybrid with the composite, where both halves sign the message representative, the ML-DSA-87 half with the composite label as its context, and the signature is the ML-DSA-87 signature followed by the RSA-PSS one. ML-DSA-87 signs hedged and RSA-PSS salted, so each signature is new.

Trait Implementations§

Source§

impl Debug for NodeKey

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for NodeKey

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more