Skip to main content

encrypt

Function encrypt 

Source
pub fn encrypt(
    plaintext: Plaintext<'_>,
    associated_data: AssociatedData<'_>,
    key: &Key256,
) -> Result<Vec<u8>>
Expand description

Uses AEGIS to AEAD encrypt the secret plaintext to a byte vector (AKA “encrypted payload”) containing the public nonce, ciphertext and authentication tag.

associated_data (which can be empty; see AssociatedData::EMPTY) is public “additional associated data” that the sender will provide along with the ciphertext to the receiver. This data is NOT encrypted, but it is authenticated along with the ciphertext during decryption.

key is the secret encryption key that MUST be randomly generated from a cryptographically secure random number generated (CSRNG).

This function internally generates a secure and unique nonce for each call.

The decrypt function can be used to decrypt the byte vector this function produces.

The structure of the returned byte vector:1

    nonce    ||      ciphertext       ||  authentication tag
  (32 bytes)    (length of plaintext)        (32 bytes)

This function requires the rand Cargo feature (it is enabled by default).

§Implementation Details

This function internally uses the AEGIS-256X4 cipher with a 256 bit authentication tag.

The maintainers of this crate stipulate that any changes to:

  • the used AEGIS cipher,
  • the byte vector framing, format, or field order,

would be accompanied by a major version number increment. (Our intention is to never make such changes short of security issues.)

The 256-bit nonce is generated using a cryptographically secure random number generator provided by the OS, which is assumed to be safe across fork().

§Errors

  • Returns Error::RandError in case of errors from the underlying CSRNG library.
  • Returns Error::InputBufferWrongSize if the length of plaintext plus the lengths of the nonce and authentication tag is greater than isize::MAX (the payload Vec cannot be allocated).

  1. || represents concatenation. ↩