philbin 1.0.1

A pure Rust AEGIS library with SIMD and runtime CPU detection
Documentation
(_Every part_ of this crate was _written by a human being._)

Philbin is a Rust library implementing the [AEGIS algorithm][aegis][^1] for
[symmetric-key encryption][sym] which was one of the winners of the [CAESAR
Competition][ceasar]. AEGIS is [_significantly_ faster](#benchmarks) and more
secure than other popular [AEAD] algorithms ([AES]-[GCM] and
[ChaCha20-Poly1305][chacha]) on CPUs with AES hardware acceleration. Note that
effectively _all_ desktop and mobile CPUs manufactured since ~2014 support AES
hardware acceleration.

[^1]:
    Specifically, Philbin implements AEGIS according to RFC 10032.

Philbin is the safest (and fastest) AEGIS implementation that the maintainers
know of.[^2] For safety, it contains a total of [_two lines of code_ in `unsafe`
blocks][unsafe] encapsulated by safe abstractions and guarded by both
compile-time and runtime correctness checks. For speed, it uses _runtime_ CPU
detection to dispatch to the best available [SIMD] implementation. 

[^2]:
    Philbin contains (many) SIMD implementations for `x86-64` and `aarch64`
    architectures. Other architectures and CPUs without AES hardware support use a
    software-only fallback implementation. Philbin is fastest on the listed
    architectures.

The crate is thoroughly tested and [fuzzed][fuzzing]. It is continuously tested
for constant-time operation (to prevent [timing attacks][timing]) using a
custom-built _Test Vector Leakage Assessment_ (TVLA) harness.

**More details are available in [the crate's documentation][docs].**

# Benchmarks

![Benchmarks showing Philbin's performance. AEGIS-128X4 is roughly nine times
faster than ChaCha20-Poly1305 and two times faster than AES-128-GCM; similar for
AEGIS-256X4. Philbin is 1% faster overall than the raw C `aegis` crate. Data was
collected across multiple CPU models, vendors and architectures.][benchmarks]

# Contributing

The source code in `philbin` was _written by hand_ by a professional software
engineer with decades of experience. **No AI-authored code, text or images are
included**.

The `philbin` project **[rejects _all_ contributions containing AI
content][ai-policy]**. There are **no exceptions**. 


[aegis]: https://www.rfc-editor.org/rfc/rfc10032.html
[sym]: https://en.wikipedia.org/wiki/Symmetric-key_algorithm
[ceasar]: https://en.wikipedia.org/wiki/CAESAR_Competition
[aead]: https://en.wikipedia.org/wiki/Authenticated_encryption
[chacha]: https://en.wikipedia.org/wiki/ChaCha20-Poly1305
[simd]: https://en.wikipedia.org/wiki/Single_instruction,_multiple_data
[fuzzing]: https://en.wikipedia.org/wiki/Fuzzing
[timing]: https://en.wikipedia.org/wiki/Timing_attack
[unsafe]: https://codeberg.org/Valloric/philbin/search/branch/main?path=philbin&q=unsafe+%7B&mode=exact
[aes]: https://en.wikipedia.org/wiki/Advanced_Encryption_Standard
[gcm]: https://en.wikipedia.org/wiki/Galois/Counter_Mode
[docs]: https://docs.rs/philbin
[ai-policy]: https://codeberg.org/Valloric/philbin/src/branch/main/AI_POLICY.md
[benchmarks]: https://codeberg.org/Valloric/philbin/media/branch/main/benchmarks/analysis/benchmarks.svg