Skip to main content

HybridCrypto

Struct HybridCrypto 

Source
pub struct HybridCrypto { /* private fields */ }
Expand description

A hybrid keypair with convenience methods for the common workflows.

This is a thin wrapper around KeyPair plus the free functions seal and verify.

§Example

use quantum_shield::HybridCrypto;

let alice = HybridCrypto::generate()?;
let bob = HybridCrypto::generate()?;

// Alice encrypts for Bob.
let envelope = alice.seal_for(b"hello", bob.public_keys())?;
let plaintext = bob.open(&envelope)?;
assert_eq!(plaintext, b"hello");

// Alice signs; anyone verifies.
let sig = alice.sign(b"release-v2.tar.gz", b"code-signing")?;
quantum_shield::verify(b"release-v2.tar.gz", b"code-signing", &sig, alice.public_keys())?;

Implementations§

Source§

impl HybridCrypto

Source

pub fn generate() -> Result<Self>

Generate a fresh hybrid keypair from OS randomness.

§Errors

Returns Error::RandomnessUnavailable if the OS RNG fails.

Source

pub fn from_secret_bytes(bytes: &[u8]) -> Result<Self>

Restore a keypair from a HybridCrypto::to_secret_bytes export.

§Errors

Returns Error::InvalidKey on malformed input.

Source

pub fn to_secret_bytes(&self) -> Zeroizing<Vec<u8>>

Export the private seeds. Handle with care; the buffer zeroizes on drop.

Source

pub fn public_keys(&self) -> &PublicKeyBundle

The public half of this keypair, for sharing.

Source

pub fn seal_for( &self, plaintext: &[u8], recipient: &PublicKeyBundle, ) -> Result<Envelope>

Encrypt plaintext for recipient. Equivalent to crate::seal.

§Errors

See crate::seal.

Source

pub fn open(&self, envelope: &Envelope) -> Result<Vec<u8>>

Decrypt an Envelope addressed to this keypair.

§Errors

Returns Error::DecryptionFailed for any cryptographic failure, with no further detail by design.

Source

pub fn open_multi(&self, envelope: &MultiRecipientEnvelope) -> Result<Vec<u8>>

Decrypt a MultiRecipientEnvelope if this keypair is a recipient.

Equivalent to crate::open_multi.

§Errors

Returns Error::DecryptionFailed if this keypair is not a recipient or the envelope was tampered with.

Source

pub fn stream_opener(&self, header: &[u8]) -> Result<StreamOpener>

Begin decrypting a streaming envelope from its header bytes.

§Errors

Returns Error::InvalidEnvelope if the header is malformed.

Source

pub fn attest_rotation( &self, new_public: &PublicKeyBundle, epoch: u64, ) -> Result<RotationAttestation>

Sign new_public as this keypair’s authorized successor at epoch, producing a RotationAttestation that anyone trusting this keypair can verify with crate::verify_rotation.

Use a strictly increasing epoch across successive rotations so that verifiers can reject rolled-back attestations.

§Errors

Propagates signing errors (none expected for a valid keypair).

Source

pub fn sign(&self, message: &[u8], context: &[u8]) -> Result<HybridSignature>

Sign message under an application context (0–255 bytes) with both Ed25519 and ML-DSA-87.

The context separates uses of the same key (e.g. b"code-signing" vs b"api-auth"); pass b"" if you don’t need one, and pass the same value to crate::verify.

§Errors

Returns Error::ContextTooLong if context exceeds 255 bytes.

Trait Implementations§

Source§

impl Debug for HybridCrypto

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl From<KeyPair> for HybridCrypto

Source§

fn from(keypair: KeyPair) -> Self

Converts to this type from the input type.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.