Expand description
§encryptman
AES-256-GCM encryption for application settings with HKDF key derivation.
This crate provides a simple, secure way to encrypt and decrypt string values using a master key. It uses HKDF-SHA256 for key derivation and AES-256-GCM for authenticated encryption. Each encryption call generates a fresh random nonce, so encrypting the same plaintext twice produces different ciphertext.
§Quick Start
use encryptman::{encrypt, decrypt, generate_master_key};
// Generate a master key (store this securely — e.g., OS keychain)
let master_key = generate_master_key();
// Encrypt
let ciphertext = encrypt(&master_key, "my_database_password").unwrap();
// Decrypt
let plaintext = decrypt(&master_key, &ciphertext).unwrap();
assert_eq!(plaintext, "my_database_password");§Design
The encryption pipeline:
- Key derivation: HKDF-SHA256 derives a unique AES key from the master
key using the application context as the
infoparameter (RFC 5869). - Encryption: AES-256-GCM encrypts the plaintext with a random 12-byte nonce. The nonce is prepended to the ciphertext.
- Encoding: The version + nonce + ciphertext is base64-encoded for safe storage.
master_key → HKDF-SHA256("encryptman:{context}") → AES key
plaintext + random nonce → AES-256-GCM → ciphertext
version || nonce || ciphertext → base64 → encoded string§When NOT to use this crate
This crate is designed for encrypting small strings (passwords, API keys, tokens). It is not suitable for:
- Password hashing — use
argon2orbcryptinstead. - File encryption — use a streaming AEAD like
XSalsa20Poly1305orChaCha20Poly1305with proper chunking. - Database-at-rest encryption — use your database’s built-in encryption
(e.g., PostgreSQL
pgcrypto, MySQLAES_ENCRYPT). - Large data — this crate allocates the entire plaintext/ciphertext in memory. For large data, use streaming encryption.
Structs§
- Master
Key - A master key for encryption/decryption.
Enums§
- Crypto
Error - Errors that can occur during encryption or decryption.
- Encoding
- Ciphertext encoding variant.
Functions§
- decrypt
- Decrypt a ciphertext string using a master key.
- decrypt_
bytes_ with_ context - Decrypt arbitrary bytes with a custom context.
- decrypt_
with_ context - Decrypt a ciphertext string with a custom context.
- decrypt_
with_ encoding - Decrypt a ciphertext string with a custom context and encoding.
- encrypt
- Encrypt a plaintext string using a master key.
- encrypt_
bytes_ with_ context - Encrypt arbitrary bytes with a custom context.
- encrypt_
with_ context - Encrypt a plaintext string with a custom context and encoding.
- encrypt_
with_ encoding - Encrypt a plaintext string with a custom context and encoding.
- generate_
master_ key - Generate a random master key.