Skip to main content

Module keywrap

Module keywrap 

Source
Expand description

AES Key Wrap (SP 800-38F, RFC 3394 and RFC 5649).

A cipher for encrypting keys with keys. It exists because the obvious alternative — a general AEAD — needs a nonce, and the places key wrapping is used are exactly the places where nonce management is hardest: a hardware token with no clock, a backup file written once and read years later, a JOSE header with nowhere to put one.

Key Wrap solves that by being deterministic and taking no nonce at all. It buys the missing randomization with six passes over the data, so every output block depends on every input block, and integrity comes from a fixed check value recovered on unwrap rather than from a separate tag.

§Two variants

Aes256Kw wraps data that is a whole number of 64-bit blocks, at least two of them — which covers every symmetric key anyone actually wraps. Aes256Kwp adds RFC 5649 padding for arbitrary lengths, at the cost of revealing the length to within eight bytes.

§What it does not do

There is no associated data, and the integrity check is 64 bits, not 128. SP 800-38F is explicit that this is a key-wrapping mechanism and not a general-purpose AEAD; for bulk data use AES-GCM or ChaCha20-Poly1305, which this workspace also has.

Structs§

Aes128Kw
SP 800-38F KW with AES-16*8.
Aes128Kwp
SP 800-38F KWP with AES-16*8, per RFC 5649.
Aes192Kw
SP 800-38F KW with AES-24*8.
Aes192Kwp
SP 800-38F KWP with AES-24*8, per RFC 5649.
Aes256Kw
SP 800-38F KW with AES-32*8.
Aes256Kwp
SP 800-38F KWP with AES-32*8, per RFC 5649.

Constants§

OVERHEAD
Ciphertext is one block longer than plaintext.