1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
use crate::;
use Debug;
// Only needed by rustdoc
use crateError;
/// Stores the nonce bytes used in AEGIS encryption and decryption.
///
/// <div class="warning">
///
/// **Nonce misuse is a common source of vulnerabilities.**
/// Use the APIs in the [`easy`][crate::easy] module since they handle
/// nonces internally. You'll never have to touch this type and you'll eliminate
/// a whole category of vulnerabilities.
///
/// </div>
///
/// This type takes a const generic parameter (`BYTES`) specifying the
/// number of nonce bytes. `AEGIS-128[L|X]` ciphers use 128 bit nonces while
/// `AEGIS-256[X]` ciphers use 256 bit nonces. (All ciphers validate the
/// provided `Nonce` size at compile time making it impossible to use an
/// incorrect `Nonce` size.)
///
/// Since only 128 or 256 bit nonces are valid for AEGIS ciphers, only values
/// `16` and `32` are supported for the `Nonce`'s `BYTES` const generic
/// parameter. This too is validated at compile time.
///
/// [`Nonce128`] (for `Nonce<16>`) and [`Nonce256`] (for `Nonce<32>`) type
/// aliases are provided for convenience and should be preferred over raw
/// `Nonce` usage.
///
/// **Use [`Nonce::generate()`] to securely create random `Nonce`s** instead of
/// generating nonce bytes yourself and passing them to [`Nonce::new()`]. The
/// [`Nonce::generate()`] method will use an appropriate cryptographically
/// secure random number generator (CSRNG).
///
/// `Nonce` can be converted into an owned array with [`Nonce::into_array()`].
/// There is also a [`From<Nonce>`][From] impl for the appropriate [`[u8;
/// N]`][array] type.
///
/// Convenience methods and impls to create a `Nonce` from a _borrowed_ slice
/// are intentionally omitted to make it difficult to accidentally re-use the
/// same nonce to encrypt _multiple_ plaintexts with the _same_ key since that
/// would lead to system compromise.
/// A type alias for a 128 bit (16 byte) [`Nonce`].
pub type Nonce128 = ;
/// A type alias for a 256 bit (32 byte) [`Nonce`].
pub type Nonce256 = ;