pub trait AeadProvider {
type Algorithm: AeadAlgorithm;
type Key: Sized;
type Tag: Sized + AsRef<[u8]>;
// Required methods
fn load_from_keydata(
&mut self,
alg: Self::Algorithm,
key: &[u8],
) -> Self::Key;
fn encrypt_in_place(
&mut self,
key: &Self::Key,
nonce: &[u8],
message: &mut [u8],
aad: impl AadGenerator,
) -> Self::Tag;
fn decrypt_in_place(
&mut self,
key: &Self::Key,
nonce: &[u8],
message: &mut [u8],
tag: &[u8],
aad: impl AadGenerator,
) -> Result<(), DecryptionFailed>;
}Expand description
Symmetric encryption with authentication and additional data.
This trait is modelled after the
aead::AeadInPlace trait,
but does not use it directly because
embedded-calpasses around an exclusive reference to its engine, and- its operation is cryptographically agile rather than monomorphized over algorithms.
Required Associated Types§
Required Methods§
Sourcefn load_from_keydata(&mut self, alg: Self::Algorithm, key: &[u8]) -> Self::Key
fn load_from_keydata(&mut self, alg: Self::Algorithm, key: &[u8]) -> Self::Key
Sourcefn encrypt_in_place(
&mut self,
key: &Self::Key,
nonce: &[u8],
message: &mut [u8],
aad: impl AadGenerator,
) -> Self::Tag
fn encrypt_in_place( &mut self, key: &Self::Key, nonce: &[u8], message: &mut [u8], aad: impl AadGenerator, ) -> Self::Tag
Encrypts data in place.
The AEAD tag is returned separately; depending on the higher-layer protocol it is appended to the message or gets sent separately.
§Panics
… if nonce’s length is not alg.nonce_length() of the algorithm that generated the key.
Sourcefn decrypt_in_place(
&mut self,
key: &Self::Key,
nonce: &[u8],
message: &mut [u8],
tag: &[u8],
aad: impl AadGenerator,
) -> Result<(), DecryptionFailed>
fn decrypt_in_place( &mut self, key: &Self::Key, nonce: &[u8], message: &mut [u8], tag: &[u8], aad: impl AadGenerator, ) -> Result<(), DecryptionFailed>
Decrypts data in place.
The AEAD tag is returned separately; depending on the higher-layer protocol it is appended to the message or gets sent separately.
§Panics
… if nonce’s length is not alg.nonce_length() of the algorithm that generated the key, or
the tag’s length is not alg.tag_length().
§Implementation guidance
As the message is passed in in a buffer that is available even in case of error, it is best practice to zero the message when verification fails, to make sure that even when the error is handled badly, an attacker can not hope to place crafted content in a place that might be mistaken for verified data.
Dyn Compatibility§
This trait is not dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".