Skip to main content

AeadProvider

Trait AeadProvider 

Source
pub trait AeadProvider {
    type Algorithm: AeadAlgorithm;
    type Key: Sized;
    type Tag: Sized + AsRef<[u8]>;

    // Required methods
    fn load_from_keydata(
        &mut self,
        alg: Self::Algorithm,
        key: &[u8],
    ) -> Self::Key;
    fn encrypt_in_place(
        &mut self,
        key: &Self::Key,
        nonce: &[u8],
        message: &mut [u8],
        aad: impl AadGenerator,
    ) -> Self::Tag;
    fn decrypt_in_place(
        &mut self,
        key: &Self::Key,
        nonce: &[u8],
        message: &mut [u8],
        tag: &[u8],
        aad: impl AadGenerator,
    ) -> Result<(), DecryptionFailed>;
}
Expand description

Symmetric encryption with authentication and additional data.

This trait is modelled after the aead::AeadInPlace trait, but does not use it directly because

  • embedded-cal passes around an exclusive reference to its engine, and
  • its operation is cryptographically agile rather than monomorphized over algorithms.

Required Associated Types§

Required Methods§

Source

fn load_from_keydata(&mut self, alg: Self::Algorithm, key: &[u8]) -> Self::Key

Loads a key from the key’s bytes.

§Panics

… if key’s length is not alg.key_length().

Source

fn encrypt_in_place( &mut self, key: &Self::Key, nonce: &[u8], message: &mut [u8], aad: impl AadGenerator, ) -> Self::Tag

Encrypts data in place.

The AEAD tag is returned separately; depending on the higher-layer protocol it is appended to the message or gets sent separately.

§Panics

… if nonce’s length is not alg.nonce_length() of the algorithm that generated the key.

Source

fn decrypt_in_place( &mut self, key: &Self::Key, nonce: &[u8], message: &mut [u8], tag: &[u8], aad: impl AadGenerator, ) -> Result<(), DecryptionFailed>

Decrypts data in place.

The AEAD tag is returned separately; depending on the higher-layer protocol it is appended to the message or gets sent separately.

§Panics

… if nonce’s length is not alg.nonce_length() of the algorithm that generated the key, or the tag’s length is not alg.tag_length().

§Implementation guidance

As the message is passed in in a buffer that is available even in case of error, it is best practice to zero the message when verification fails, to make sure that even when the error is handled badly, an attacker can not hope to place crafted content in a place that might be mistaken for verified data.

Dyn Compatibility§

This trait is not dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§