Expand description
AES Key Wrap (SP 800-38F, RFC 3394 and RFC 5649).
A cipher for encrypting keys with keys. It exists because the obvious alternative — a general AEAD — needs a nonce, and the places key wrapping is used are exactly the places where nonce management is hardest: a hardware token with no clock, a backup file written once and read years later, a JOSE header with nowhere to put one.
Key Wrap solves that by being deterministic and taking no nonce at all. It buys the missing randomization with six passes over the data, so every output block depends on every input block, and integrity comes from a fixed check value recovered on unwrap rather than from a separate tag.
§Two variants
Aes256Kw wraps data that is a whole number of 64-bit blocks, at least two
of them — which covers every symmetric key anyone actually wraps.
Aes256Kwp adds RFC 5649 padding for arbitrary lengths, at the cost of
revealing the length to within eight bytes.
§What it does not do
There is no associated data, and the integrity check is 64 bits, not 128. SP 800-38F is explicit that this is a key-wrapping mechanism and not a general-purpose AEAD; for bulk data use AES-GCM or ChaCha20-Poly1305, which this workspace also has.
Structs§
- Aes128
Kw - SP 800-38F KW with AES-16*8.
- Aes128
Kwp - SP 800-38F KWP with AES-16*8, per RFC 5649.
- Aes192
Kw - SP 800-38F KW with AES-24*8.
- Aes192
Kwp - SP 800-38F KWP with AES-24*8, per RFC 5649.
- Aes256
Kw - SP 800-38F KW with AES-32*8.
- Aes256
Kwp - SP 800-38F KWP with AES-32*8, per RFC 5649.
Constants§
- OVERHEAD
- Ciphertext is one block longer than plaintext.