pub fn encrypt(
plaintext: Plaintext<'_>,
associated_data: AssociatedData<'_>,
key: &Key256,
) -> Result<Vec<u8>>Expand description
Uses AEGIS to AEAD encrypt the secret
plaintext to a byte vector (AKA “encrypted payload”)
containing the public nonce, ciphertext and authentication tag.
associated_data (which can be empty; see
AssociatedData::EMPTY) is public
“additional associated data” that the sender will provide along with the
ciphertext to the receiver. This data is NOT encrypted, but it is
authenticated along with the ciphertext during decryption.
key is the secret encryption key that MUST be randomly
generated from a cryptographically secure random number generated (CSRNG).
This function internally generates a secure and unique nonce for each call.
The decrypt function can be used to decrypt the
byte vector this function produces.
The structure of the returned byte vector:1
nonce || ciphertext || authentication tag
(32 bytes) (length of plaintext) (32 bytes)This function requires the rand Cargo feature (it is enabled by default).
§Implementation Details
This function internally uses the AEGIS-256X4 cipher with a 256 bit authentication tag.
The maintainers of this crate stipulate that any changes to:
- the used AEGIS cipher,
- the byte vector framing, format, or field order,
would be accompanied by a major version number increment. (Our intention is to never make such changes short of security issues.)
The 256-bit nonce is generated using a cryptographically secure random number
generator provided by the OS, which is assumed to be safe across
fork().
§Errors
- Returns
Error::RandErrorin case of errors from the underlying CSRNG library. - Returns
Error::InputBufferWrongSizeif the length ofplaintextplus the lengths of the nonce and authentication tag is greater thanisize::MAX(the payloadVeccannot be allocated).
||represents concatenation. ↩