Skip to main content

ic_mac/
lib.rs

1//! # ic-mac — message authentication codes
2//!
3//! * [`Hmac`] — FIPS 198-1, generic over any [`Digest`](ic_core::traits::Digest) in `ic-hash`.
4//! * [`CmacAes128`] / [`CmacAes256`] — SP 800-38B CMAC over AES.
5//! * [`Poly1305`] — re-exported from `ic-cipher` for one-time authentication.
6//!
7//! All verification goes through [`ic_core::ct::verify`], so tag comparison
8//! cannot become a timing oracle.
9//!
10//! ```
11//! use ic_mac::HmacSha256;
12//! use ic_core::traits::Mac;
13//!
14//! let tag = HmacSha256::mac(b"key", b"message")?;
15//! HmacSha256::verify(b"key", b"message", tag.as_ref())?;
16//! assert!(HmacSha256::verify(b"key", b"tampered", tag.as_ref()).is_err());
17//! # Ok::<(), ic_core::Error>(())
18//! ```
19#![cfg_attr(not(feature = "std"), no_std)]
20#![forbid(unsafe_code)]
21#![deny(missing_docs)]
22#![warn(clippy::all)]
23
24mod cmac;
25mod hmac;
26mod kmac;
27
28pub use cmac::{CmacAes128, CmacAes192, CmacAes256};
29pub use hmac::{
30    Hmac, HmacSha256, HmacSha384, HmacSha3_256, HmacSha3_512, HmacSha512, HmacSha512_256,
31};
32pub use ic_cipher::Poly1305;
33pub use kmac::{Kmac128, Kmac256};
34
35/// Ontology identifiers for the MACs this crate provides.
36pub const MAC_IDS: &[&str] = &[
37    "hmac-sha2-256",
38    "hmac-sha2-384",
39    "hmac-sha2-512",
40    "hmac-sha2-512-256",
41    "hmac-sha3-256",
42    "hmac-sha3-512",
43    "cmac-aes-128",
44    "cmac-aes-192",
45    "cmac-aes-256",
46    "poly1305",
47];