Skip to main content

moq_e2ee/
lib.rs

1//! End-to-end encryption for MoQ groups, datagrams, and track names.
2//!
3//! Implements profile `moq-e2ee-00` from [draft-lcurley-moq-e2ee]. Relays forward
4//! ciphertext; content keys never enter `moq-net`.
5//!
6//! [draft-lcurley-moq-e2ee]: https://datatracker.ietf.org/doc/draft-lcurley-moq-e2ee/
7//!
8//! A [`Credential`] is what the application distributes out of band. Each publisher
9//! instance mints an [`Epoch`] and binds it as a [`Generation`], which derives opaque
10//! track names and protects `moq-net` tracks. Subscribers discover the epoch from the
11//! broadcast path and bind the same generation.
12//!
13//! AES-128-GCM is inline and synchronous: a 1 KiB frame costs about a microsecond
14//! on one core (see the `protect` bench), so there is no async encryption pump.
15
16#![warn(missing_docs)]
17
18pub mod credential;
19pub mod datagram;
20pub mod group;
21pub mod track;
22
23mod epoch;
24mod error;
25mod generation;
26mod key;
27mod limits;
28mod name;
29mod protect;
30mod window;
31
32pub use credential::Credential;
33pub use epoch::Epoch;
34pub use error::{Error, Result};
35pub use generation::Generation;
36pub use limits::{MAX_DATAGRAM_PLAINTEXT, MAX_GROUPED_PLAINTEXT, SECRET_LEN};
37pub use name::Name;
38
39#[cfg(test)]
40mod tests;