1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
use crate::error::*;
pub trait RemotePublicKey {
fn from_raw(raw: &[u8]) -> Result<Self>
where
Self: Sized;
fn as_raw(&self) -> Result<Vec<u8>>;
}
pub trait LocalKeyPair {
fn generate_random() -> Result<Self>
where
Self: Sized;
fn pub_as_raw(&self) -> Result<Vec<u8>>;
fn from_raw_components(components: &EcKeyComponents) -> Result<Self>
where
Self: Sized;
fn raw_components(&self) -> Result<(EcKeyComponents)>;
}
#[derive(Clone, Debug, PartialEq)]
#[cfg_attr(
feature = "serializable-keys",
derive(serde::Serialize, serde::Deserialize)
)]
pub enum EcCurve {
P256,
}
impl Default for EcCurve {
fn default() -> Self {
EcCurve::P256
}
}
#[derive(Clone, Debug, PartialEq)]
#[cfg_attr(
feature = "serializable-keys",
derive(serde::Serialize, serde::Deserialize)
)]
pub struct EcKeyComponents {
curve: EcCurve,
private_key: Vec<u8>,
public_key: Vec<u8>,
}
impl EcKeyComponents {
pub fn new<T: Into<Vec<u8>>>(private_key: T, public_key: T) -> Self {
EcKeyComponents {
private_key: private_key.into(),
public_key: public_key.into(),
curve: Default::default(),
}
}
pub fn curve(&self) -> &EcCurve {
&self.curve
}
pub fn private_key(&self) -> &[u8] {
&self.private_key
}
pub fn public_key(&self) -> &[u8] {
&self.public_key
}
}
pub trait Crypto: Sized {
type RemotePublicKey: RemotePublicKey;
type LocalKeyPair: LocalKeyPair;
fn generate_ephemeral_keypair() -> Result<Self::LocalKeyPair>;
fn compute_ecdh_secret(
remote: &Self::RemotePublicKey,
local: &Self::LocalKeyPair,
) -> Result<Vec<u8>>;
fn hkdf_sha256(salt: &[u8], secret: &[u8], info: &[u8], len: usize) -> Result<Vec<u8>>;
fn aes_gcm_128_encrypt(key: &[u8], iv: &[u8], data: &[u8], tag_len: usize) -> Result<Vec<u8>>;
fn aes_gcm_128_decrypt(key: &[u8], iv: &[u8], data: &[u8], tag: &[u8]) -> Result<Vec<u8>>;
fn random(dest: &mut [u8]) -> Result<()>;
}