Skip to main content

Crate moq_e2ee

Crate moq_e2ee 

Source
Expand description

End-to-end encryption for MoQ groups, datagrams, and track names.

Implements profile moq-e2ee-00 from draft-lcurley-moq-e2ee. Relays forward ciphertext; content keys never enter moq-net.

A Credential is what the application distributes out of band. Each publisher instance mints an Epoch and binds it as a Generation, which derives opaque track names and protects moq-net tracks. Subscribers discover the epoch from the broadcast path and bind the same generation.

AES-128-GCM is inline and synchronous: a 1 KiB frame costs about a microsecond on one core (see the protect bench), so there is no async encryption pump.

Re-exports§

pub use credential::Credential;

Modules§

credential
The out-of-band broadcast credential and the derivations scoped to it alone.
datagram
Decrypted datagrams and the events a protected datagram read yields.
group
Grouped-frame producer and consumer for one group identity.
track
Grouped-frame and datagram writers and readers for one physical track.

Structs§

Epoch
One publisher instance’s scope: a nonempty path segment that no other instance under the credential reuses.
Generation
One credential under one epoch: the scope of every name, key, and nonce.
Name
An opaque physical track name: 22 unpadded base64url characters derived from a semantic name.

Enums§

Error
Typed failures from draft-lcurley-moq-e2ee.

Constants§

MAX_DATAGRAM_PLAINTEXT
Largest plaintext a datagram can carry: 1160 bytes.
MAX_GROUPED_PLAINTEXT
Largest plaintext a grouped frame can carry: 32 MiB minus the tag.
SECRET_LEN
Broadcast secret length in bytes.

Type Aliases§

Result
A Result using this crate’s Error.