Expand description
FIPS 197 AES, with a portable constant-time backend and an optional hardware-accelerated one.
§Backend selection
The backend is chosen once, when a key is expanded, and recorded in the cipher value. On x86-64 with AES-NI that is the accelerated path; everywhere else it is the portable one. Selection depends only on the CPU, never on key material, so it leaks nothing.
Detection is compile-time when the aes target feature is already enabled
for the build (-C target-cpu=native, say), and runtime otherwise via
is_x86_feature_detected!. Under no_std only the compile-time path is
available, because runtime detection needs std.
ic_ontology::runtime::backend() reports which one is live, so an agent
deciding whether to push a gigabyte through AES-GCM can ask rather than
guess.
§Trusting the accelerated path
The portable backend is validated against the FIPS 197 and SP 800-38A vectors. The accelerated backend is then validated against the portable one, block for block, across every key length and every batch boundary. It is not an independent reimplementation to be trusted on its own; it is an optimization held to the output of something already known to be correct.
Re-exports§
pub use portable::BLOCK_LEN;
Modules§
- bitslice
- A bitsliced AES encryption path, four blocks at a time.
- portable
- The portable, constant-time AES backend.
- x86
- The x86-64 AES-NI backend.
Structs§
Enums§
- Backend
- Which implementation a cipher value is using.
Functions§
- active_
backend - The backend this build will use for AES.
- aesni_
available - Whether the AES-NI backend is usable on this CPU.
- armv8_
aes_ available - Whether the ARMv8 AES extension is usable in this build.