Skip to main content

Key

Struct Key 

Source
pub struct Key(/* private fields */);
Expand description

A master key for the key derivation function

This key is used to derive multiple subkeys for different purposes. It must be exactly 32 bytes (256 bits) long and should be generated using a cryptographically secure random number generator.

§Security Properties

  • High entropy: Contains 256 bits of entropy when generated properly
  • Secret: Must be kept confidential to maintain security of all derived subkeys
  • Single source of truth: Allows multiple application-specific keys to be derived from a single master key

§Best Practices

  • Generate using the generate() method, which uses libsodium’s secure RNG
  • Store securely, preferably in a hardware security module or secure enclave
  • Rotate periodically according to your security policy
  • Consider using a key management service for production applications

§Example

use libsodium_rs as sodium;
use sodium::crypto_kdf;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Generate a master key
let master_key = crypto_kdf::Key::generate().unwrap();

// Or create from existing bytes
let key_bytes = [0x42; crypto_kdf::KEYBYTES]; // Example bytes
let master_key = crypto_kdf::Key::from_slice(&key_bytes).unwrap();

Implementations§

Source§

impl Key

Source

pub fn generate() -> Result<Self>

Generates a new random key for key derivation

This function generates a new random master key suitable for deriving subkeys. The key is generated using libsodium’s secure random number generator.

§Example
use libsodium_rs as sodium;
use sodium::crypto_kdf;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Generate a master key
let master_key = crypto_kdf::Key::generate().unwrap();
§Returns
  • Result<Self> - A new randomly generated key or an error
Source

pub fn from_slice(slice: &[u8]) -> Result<Self>

Creates a key from an existing byte slice

This function creates a master key from an existing byte slice. The slice must be exactly KEYBYTES (32) bytes long.

§Example
use libsodium_rs as sodium;
use sodium::crypto_kdf;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Create a key from existing bytes
let key_bytes = [0x42; crypto_kdf::KEYBYTES]; // Example bytes
let master_key = crypto_kdf::Key::from_slice(&key_bytes).unwrap();
§Arguments
  • slice - Byte slice of exactly KEYBYTES length
§Returns
  • Result<Self> - A new key created from the slice or an error
§Errors

Returns an error if the slice is not exactly KEYBYTES bytes long

Source

pub fn as_bytes(&self) -> &[u8]

Returns a reference to the key as a byte slice

This function returns a reference to the internal byte representation of the key. This is useful when you need to pass the key to other functions.

§Example
use libsodium_rs as sodium;
use sodium::crypto_kdf;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Generate a master key
let master_key = crypto_kdf::Key::generate().unwrap();

// Get the bytes of the key
let key_bytes = master_key.as_bytes();
assert_eq!(key_bytes.len(), crypto_kdf::KEYBYTES);
§Returns
  • &[u8] - Reference to the key bytes

Trait Implementations§

Source§

impl AsRef<[u8]> for Key

Source§

fn as_ref(&self) -> &[u8]

Converts this type into a shared reference of the (usually inferred) input type.
Source§

impl Clone for Key

Source§

fn clone(&self) -> Key

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Key

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for Key

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more
Source§

impl Eq for Key

Source§

impl From<Key> for [u8; 32]

Source§

fn from(key: Key) -> Self

Converts to this type from the input type.
Source§

impl From<[u8; 32]> for Key

Source§

fn from(bytes: [u8; 32]) -> Self

Converts to this type from the input type.
Source§

impl PartialEq for Key

Source§

fn eq(&self, other: &Key) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl StructuralPartialEq for Key

Source§

impl TryFrom<&[u8]> for Key

Source§

type Error = SodiumError

The type returned in the event of a conversion error.
Source§

fn try_from(slice: &[u8]) -> Result<Self, Self::Error>

Performs the conversion.
Source§

impl Zeroize for Key

Source§

fn zeroize(&mut self)

Zero out this object from memory using Rust intrinsics which ensure the zeroization operation is not “optimized away” by the compiler.

Auto Trait Implementations§

§

impl Freeze for Key

§

impl RefUnwindSafe for Key

§

impl Send for Key

§

impl Sync for Key

§

impl Unpin for Key

§

impl UnsafeUnpin for Key

§

impl UnwindSafe for Key

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.