Skip to main content

Crate oc_crypto

Crate oc_crypto 

Source
Expand description

Cryptographic core of the .cc container.

A crate-wide, lint-enforced rule: no I/O, clocks, or randomness from thin air. Nonces and RNGs are passed as arguments. This makes every test deterministic, while Wycheproof vectors exercise our own call sites, not merely the underlying crates.

Parsing ensures that plaintext never leaves the function before the authentication tag is checked: on failure the buffer is wiped, and the caller must treat it as unusable.

Re-exports§

pub use label::Label;
pub use secret::Cek;
pub use secret::ClaimSecret;
pub use secret::Kek;
pub use secret::MacKey;
pub use secret::MetaKey;
pub use secret::PayloadKey;
pub use secret::SecretA;
pub use secret::SecretB;
pub use secret::SecretBuf;
pub use secret::X25519Secret;
pub use transcript::Transcript;

Modules§

aead
Payload chunk encryption.
agreement
Key agreement behind a trait: X25519 in software, P-256 in software or in a TPM.
kdf
Key schedule: derivations K1…K9 from docs/format.md, section 3.5.
label
Domain-separation labels.
mac
Message authentication codes.
merkle
Integrity tree over chunk frames.
mlkem_p256
MLKEM768-P256: ML-KEM-768 and ECDH P-256 hybrid, slot mechanism kem_id = 5.
rsa
RSA-PSS-SHA256 signature verification: editing-device signature.
seal
Seal secrets to a slot recipient’s public key.
secret
Secret types.
sign
Signatures.
stream
Payload chunking discipline: one loop for every host. Payload chunking discipline.
tpm
TPM 2.0 credential protection: the computable part of TPM2_MakeCredential (B6a, docs/protocol.md §9.11).
transcript
Transcript: the only way to obtain bytes for a signature or MAC.
wrap
Content-key wrapping.
xwing
X-Wing: X25519 and ML-KEM-768 hybrid, slot mechanism kem_id = 4.

Enums§

AeadAlg
Algorithm identifiers covered by the header signature.
CryptoError
Cryptographic operation errors.
KemAlg
Key encapsulation mechanism. Specified per slot, not per file.
SigAlg
Signature algorithm.
TreeHashAlg
Payload-tree hash.

Constants§

MIN_CLAIM_BITS
Minimum claim-code entropy.

Functions§

digest_eq
Compare two 32-byte digests in constant time.
public_key_eq
Compare two PUBLIC keys of possibly different lengths in constant time.
sha256
SHA-256 of a byte slice.