Skip to main content

CryptoSensitive

Struct CryptoSensitive 

Source
pub struct CryptoSensitive<const N: usize> { /* private fields */ }
Expand description

A cryptographic material represented in a cross-platform way, as a fixed-length array in a well-defined format.

Thus, it can be imported into any Crypto provider and exported from it without worrying about endianness or other platform-specific representation issues.

The reason for wrapping the array with a newtype is so that the following protection measures are taken:

  • The material is not accidentally printed in logs or debug output.
  • The material has a single access / access_mut method and deliberately does not implement Deref or AsRef traits to avoid accidental leakage.
  • The material is zeroed out when dropped; note however that this has a limited use case, in Rust, because of the Rust move semantics.

Regarding sensitivity, rs-matter takes a radical approach and assumes that all cryptographic material is sensitive. Including, but not limited to:

  • Secret keys (obviously)
  • Signatures (because they can leak information about the secret key)
  • Hashes (because they can be pre-images of sensitive data)
  • Public keys (just in case)

Implementations§

Source§

impl<const N: usize> CryptoSensitive<N>

Source

pub const fn new() -> CryptoSensitive<N>

Create a new zeroed CryptoSensitive instance.

Source

pub const fn new_from_ref( other: CryptoSensitiveRef<'_, N>, ) -> CryptoSensitive<N>

Create a new CryptoSensitive instance by loading data from the provided reference.

Source

pub fn init() -> impl Init<CryptoSensitive<N>>

Return an in-place initializer for a zeroed CryptoSensitive instance.

Source

pub fn zeroize(&mut self)

Zeroizes the cryptographic material held by this instance.

Source

pub const fn reference(&self) -> CryptoSensitiveRef<'_, N>

Get a reference to this cryptographic material.

Source

pub const fn load(&mut self, other: CryptoSensitiveRef<'_, N>)

Load data from another cryptographic material reference.

Source

pub const fn load_from_array(&mut self, data: &[u8; N])

Load data from a byte array.

Source

pub fn try_load_from_slice(&mut self, data: &[u8]) -> Result<(), Error>

Try to load data from a byte slice.

Returns an error if the slice length does not match the expected length.

Source

pub const fn access(&self) -> &[u8; N]

Access the underlying data as a byte array reference.

NOTE: care should be taken when using this method, as it exposes the sensitive data.

Source

pub const fn access_mut(&mut self) -> &mut [u8; N]

Access the underlying data as a mutable byte array reference.

NOTE: care should be taken when using this method, as it exposes the sensitive data.

Trait Implementations§

Source§

impl<const N: usize> Clone for CryptoSensitive<N>

Source§

fn clone(&self) -> CryptoSensitive<N>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<const N: usize> Debug for CryptoSensitive<N>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl<const N: usize> Default for CryptoSensitive<N>

Source§

fn default() -> CryptoSensitive<N>

Returns the “default value” for a type. Read more
Source§

impl<const N: usize> Drop for CryptoSensitive<N>

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more
Source§

impl<'a, const N: usize> From<&'a CryptoSensitive<N>> for CryptoSensitiveRef<'a, N>

Source§

fn from(cs: &'a CryptoSensitive<N>) -> CryptoSensitiveRef<'a, N>

Converts to this type from the input type.
Source§

impl<const N: usize> From<&[u8; N]> for CryptoSensitive<N>

Source§

fn from(data: &[u8; N]) -> CryptoSensitive<N>

Converts to this type from the input type.
Source§

impl<const N: usize> From<CryptoSensitiveRef<'_, N>> for CryptoSensitive<N>

Source§

fn from(other: CryptoSensitiveRef<'_, N>) -> CryptoSensitive<N>

Converts to this type from the input type.
Source§

impl<const N: usize> From<[u8; N]> for CryptoSensitive<N>

Source§

fn from(data: [u8; N]) -> CryptoSensitive<N>

Converts to this type from the input type.
Source§

impl<'a, const N: usize> FromTLV<'a> for CryptoSensitive<N>

Source§

fn from_tlv(element: &TLVElement<'a>) -> Result<CryptoSensitive<N>, Error>

Deserialize the type from a TLV-encoded element.
Source§

fn init_from_tlv( element: TLVElement<'a>, ) -> impl Init<CryptoSensitive<N>, Error>

Generate an in-place initializer for the type that initializes the type from a TLV-encoded element.
Source§

fn nullable_from_tlv(element: &TLVElement<'a>) -> Result<Self, Error>

Deserialize the type from a TLV-encoded element. Read more
Source§

fn init_nullable_from_tlv(element: TLVElement<'a>) -> impl Init<Self, Error>

Generate an in-place initializer for the type that initializes the type from a TLV-encoded element. Read more
Source§

impl<const N: usize> ToTLV for CryptoSensitive<N>

Source§

fn to_tlv<W>(&self, tag: &TLVTag, tw: W) -> Result<(), Error>
where W: TLVWrite,

Serialize the type to a TLV-encoded stream.
Source§

fn tlv_iter(&self, tag: TLVTag) -> impl Iterator<Item = Result<TLV<'_>, Error>>

Serialize the type as an iterator of TLV instances by potentially borrowing data from the type.
Source§

fn nullable_to_tlv<W>(&self, tag: &TLVTag, tw: W) -> Result<(), Error>
where W: TLVWrite,

Serialize the type to a TLV-encoded stream. Read more
Source§

fn nullable_tlv_iter( &self, tag: TLVTag, ) -> impl Iterator<Item = Result<TLV<'_>, Error>>

Serialize the type as an iterator of TLV instances by potentially borrowing data from the type. Read more
Source§

impl<const N: usize> TryFrom<&[u8]> for CryptoSensitive<N>

Source§

type Error = Error

The type returned in the event of a conversion error.
Source§

fn try_from( data: &[u8], ) -> Result<CryptoSensitive<N>, <CryptoSensitive<N> as TryFrom<&[u8]>>::Error>

Performs the conversion.

Auto Trait Implementations§

§

impl<const N: usize> Freeze for CryptoSensitive<N>

§

impl<const N: usize> RefUnwindSafe for CryptoSensitive<N>

§

impl<const N: usize> Send for CryptoSensitive<N>

§

impl<const N: usize> Sync for CryptoSensitive<N>

§

impl<const N: usize> Unpin for CryptoSensitive<N>

§

impl<const N: usize> UnsafeUnpin for CryptoSensitive<N>

§

impl<const N: usize> UnwindSafe for CryptoSensitive<N>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, E> Init<T, E> for T

Source§

unsafe fn __init(self, slot: *mut T) -> Result<(), E>

Initializes slot. Read more
Source§

fn chain<F>(self, f: F) -> ChainInit<Self, F, T, E>
where F: FnOnce(&mut T) -> Result<(), E>,

First initializes the value using self then calls the function f with the initialized value. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T, I> IntoFallibleInit<T> for I
where I: Init<T>,

Source§

fn into_fallible<E>(self) -> impl Init<T, E>

Convert the infallible initializer to a fallible one.
Source§

impl<Source, Target> OctetsInto<Target> for Source
where Target: OctetsFrom<Source>,

Source§

type Error = <Target as OctetsFrom<Source>>::Error

Source§

fn try_octets_into( self, ) -> Result<Target, <Source as OctetsInto<Target>>::Error>

Performs the conversion.
Source§

fn octets_into(self) -> Target
where Self::Error: Into<Infallible>,

Performs an infallible conversion.
Source§

impl<T, E> PinInit<T, E> for T

Source§

unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E>

Initializes slot. Read more
Source§

fn pin_chain<F>(self, f: F) -> ChainPinInit<Self, F, T, E>
where F: FnOnce(Pin<&mut T>) -> Result<(), E>,

First initializes the value using self then calls the function f with the initialized value. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V