Expand description
End-to-end payload encryption, layered inside the transport’s own TLS.
Why a second layer at all: QUIC/TLS protects the hop. If a transfer is relayed, or the far endpoint terminates TLS somewhere you do not control, the relay sees plaintext. This layer is keyed by the two endpoints only, so a relay forwards bytes it cannot read.
Nonce discipline, which is the part that has to be exactly right:
every chunk is sealed under a per-file subkey with
nonce = chunk_index (8 LE) || epoch (4 LE). file_id is unique within a
session and is bound into the subkey; chunk_index is unique within a file.
epoch increments when a chunk is re-encoded (a retry that changed the
compression decision), so the same (key, nonce) pair never covers two
different plaintexts. Session keys are ephemeral, so a resumed transfer
starts from fresh keys rather than replaying an old nonce space.
Structs§
- Handshake
- One side’s in-progress key exchange. Built, written to the wire, then finished with the peer’s message.
- Sealer
- Per-worker AEAD handle. Holds a small cache of per-file subkeys so a multi-file transfer does not run HKDF on every chunk.
- Session
Crypto - Derived session keys. Cheap to clone into per-worker sealers.
Enums§
- Role
- Which side of the exchange we are. Decides key direction, nothing else.
Constants§
Functions§
- generate_
identity - Generate an X25519 identity as
(secret, public). - random_
key - Generate a random 32-byte key, for callers that want a PSK.