Skip to main content

KeyExchange

Struct KeyExchange 

Source
pub struct KeyExchange { /* private fields */ }
Expand description

Ephemerales DH-Schluesselpaar fuer einen einzelnen Handshake.

Nach derive_shared_secret ist die Instance verbraucht — das EphemeralPrivateKey erlaubt nach API-Design von ring nur einen agree_ephemeral-Call, was PFS (Perfect Forward Secrecy) erzwingt.

Implementations§

Source§

impl KeyExchange

Source

pub fn new() -> SecurityResult<Self>

Erzeugt ein frisches X25519-Schluesselpaar (Default).

§Errors

CryptoFailed wenn die System-RNG nicht verfuegbar ist (z.B. kein /dev/urandom in einem broken-Sandbox-Szenario).

Source

pub fn with_suite(suite: KxSuite) -> SecurityResult<Self>

Erzeugt ein Schluesselpaar fuer die gewaehlte DH-Suite.

§Errors

siehe Self::new.

Source

pub fn suite(&self) -> KxSuite

Liefert die aktive DH-Suite.

Source

pub fn public_key(&self) -> &[u8]

Liefert den lokalen Public-Key als Byte-Slice. Laenge ist suite-abhaengig (siehe KxSuite::public_key_len).

Source

pub fn derive_shared_secret( self, remote_public_key: &[u8], ) -> SecurityResult<Vec<u8>>

Leitet das SharedSecret aus dem Remote-Public-Key ab. Verbraucht das lokale ephemerale Key.

§Errors
  • BadArgument wenn remote_public_key.len() != suite.public_key_len().
  • CryptoFailed wenn ring das Agreement ablehnt (z.B. kleiner-Untergruppen-Angriff, Identity-Punkt, Off-Curve-Point).

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.